National and local governments and agencies in the countries in which we operate and in which customers have adopted, are considering adopting, or may adopt laws and regulations regarding the collection, use, storage, processing, and disclosure of information regarding consumers and other individuals, which could impact our ability to offer services in certain jurisdictions. Laws and regulations relating to the collection, use, disclosure, security, and other processing of individuals' information can vary significantly from jurisdiction to jurisdiction and are particularly stringent in Europe. The costs of compliance with, and other burdens imposed by, laws, regulations, standards, and other obligations relating to privacy, data protection, and information security are significant. In addition, some companies, particularly larger enterprises, often will not contract with vendors that do not meet these rigorous standards. Accordingly, the failure, or perceived inability, to comply with these laws, regulations, standards, and other obligations may limit the use and adoption of our solutions, reduce overall demand, lead to regulatory investigations, litigation, and significant fines, penalties, or liabilities for actual or alleged noncompliance, or slow the pace at which we close sales transactions, any of which could harm our business. Moreover, if we or any of our employees or contractors fails or is believed to fail to adhere to appropriate practices regarding customers' data, it may damage our reputation and brand.
Additionally, existing laws, regulations, standards, and other obligations may be interpreted in new and differing manners in the future, and may be inconsistent among jurisdictions. Future laws, regulations, standards, and other obligations, and changes in the interpretation of existing laws, regulations, standards, and other obligations could result in increased regulation, increased costs of compliance and penalties for non-compliance, and limitations on data collection, use, disclosure, and transfer for us and our customers. The European Union and United States agreed in 2016 to a framework for data transferred from the European Union to the United States, but this framework has been challenged and recently declared invalid by the Court of Justice of the European Union, thereby creating additional legal risk for us. Additionally, the European Union adopted the GDPR in 2016, and it became effective in May 2018. The GDPR establishes requirements applicable to the handling of personal data and imposes penalties for non-compliance of up to the greater of €20 million or 4% of worldwide revenue. The costs of compliance with, and other burdens imposed by, the GDPR may limit the use and adoption of our products and services and could have an adverse impact on our business. Further, California adopted the California Consumer Privacy Protection Act ("CCPA") and the California State Attorney General has begun enforcement actions. We may be exposed to ongoing legal risks related to CCPA and any amendments that may be made in connection with the California Privacy Rights Act approved by voters in the November 2020 election.
The costs of compliance with, and other burdens imposed by, laws and regulations relating to privacy, data protection, and information security that are applicable to the businesses of customers may adversely affect ability and willingness to process, handle, store, use, and transmit certain types of information, such as demographic and other personal information. In addition, the other bases on which we and our customers rely for the transfer of personal data across national borders, such as the Standard Contractual Clauses promulgated by the EU Commission Decision 2010/87/EU, commonly referred to as the Model Clauses, continue to be subjected to regulatory and judicial scrutiny. If we or our customers are unable to transfer data between and among countries and regions in which we operate, it could decrease demand for our products and services or require us to modify or restrict some of our products or services.
In addition to government activity, privacy advocacy groups, the technology industry, and other industries have established or may establish various new, additional, or different self-regulatory standards that may place additional burdens on technology companies. Customers may expect that we will meet voluntary certifications or adhere to other standards established by them or third parties. If we are unable to maintain these certifications or meet these standards, it could reduce demand for our solutions and adversely affect our business.