The global data protection landscape is rapidly evolving, and we are or may become subject to numerous state, federal and foreign laws, requirements and regulations governing the collection, use, disclosure, retention, and security of personal information, such as information that we may collect in connection with clinical trials in the U.S. and abroad. Implementation standards and enforcement practices are likely to remain uncertain for the foreseeable future, and we cannot yet determine the impact future laws, regulations, standards, or perception of their requirements may have on our business. This evolution may create uncertainty in our business, affect our ability to operate in certain jurisdictions or to collect, store, transfer use and share personal information, necessitate the acceptance of more onerous obligations in our contracts, result in liability or impose additional costs on us. The cost of compliance with these laws, regulations and standards is high and is likely to increase in the future. Any failure or perceived failure by us to comply with federal, state or foreign laws or regulation, our internal policies and procedures or our contracts governing our processing of personal information could result in negative publicity, government investigations and enforcement actions, claims by third parties and damage to our reputation, any of which could have a material adverse effect on our operations, financial performance and business.
As our operations and business grow, we may become subject to or affected by new or additional data protection laws and regulations and face increased scrutiny or attention from regulatory authorities. In the U.S., HIPAA imposes, among other things, certain standards relating to the privacy, security, transmission and breach reporting of individually identifiable health information. Most healthcare providers, including research institutions from which we obtain patient health information, are subject to privacy and security regulations promulgated under HIPAA. While we do not believe that we are currently acting as a covered entity or business associate under HIPAA and thus are not directly regulated under HIPAA, any person may be prosecuted under HIPAA's criminal provisions either directly or under aiding-and-abetting or conspiracy principles. Consequently, depending on the facts and circumstances, we could face substantial criminal penalties if we knowingly receive individually identifiable health information from a HIPAA-covered healthcare provider or research institution that has not satisfied HIPAA's requirements for disclosure of individually identifiable health information. In addition, we may maintain sensitive health-related or other personal information, that we receive throughout the clinical trial process, in the course of our research collaborations, and directly from individuals (or their healthcare providers) who enroll in our patient assistance programs. As such, we may be subject to state laws requiring notification of affected individuals and state regulators in the event of a breach of personal information, which is a broader class of information than the health information protected by HIPAA.
Certain states have also adopted comparable privacy and security laws and regulations, some of which may be more stringent than HIPAA. Such laws and regulations will be subject to interpretation by various courts and other governmental authorities, thus creating potentially complex compliance issues for us and our future customers and strategic partners. For example, the California Consumer Privacy Act, or CCPA, went into effect on January 1, 2020. The CCPA creates individual privacy rights for California consumers and increases the privacy and security obligations of entities handling certain personal information. The CCPA provides for civil penalties for violations, as well as a private right of action for certain data breaches that has increased the likelihood of, and risks associated with, data breach litigation. The CCPA may increase our compliance costs and potential liability. Further, the California Privacy Rights Act, or CPRA, generally went into effect on January 1, 2023, and significantly amends the CCPA. It imposes additional data protection obligations on covered companies doing business in California, including additional consumer rights processes, limitations on data uses, new audit requirements for higher risk data, and opt outs for certain uses of sensitive data. It also created a new California data protection agency specifically tasked to issue substantive regulations and enforce the CCPA and CPRA, which has increased regulatory scrutiny of covered businesses in the areas of data protection and security. Additional compliance investment and potential business process changes may also be required. Similar laws have passed in other states, and continue to be proposed at the state and federal level, reflecting a trend toward more stringent privacy legislation in the U.S. The enactment of such laws could have potentially conflicting requirements that would make compliance challenging. In the event that we are subject to or affected by HIPAA, the CCPA, the CPRA or other domestic privacy and data protection laws, any liability from failure to comply with the requirements of these laws could adversely affect our financial condition.
In the EU, the EU General Data Protection Regulation, or GDPR, went into effect in May 2018 and imposes strict requirements for processing the personal data of individuals within the European Economic Area, or EEA, or in the context of our activities within the EEA. In addition, some of the personal data we process in respect of clinical trial participants is special category or sensitive personal data under the GDPR, and subject to additional compliance obligations and to local law derogations. Companies that must comply with the GDPR face increased compliance obligations and risk, including more robust regulatory enforcement of data protection requirements and potential fines for noncompliance of up to €20 million or 4% of the annual global revenues of the noncompliant company, whichever is greater. In addition to fines, a breach of the GDPR may result in regulatory investigations, reputational damage, orders to cease/ change our data processing activities, enforcement notices, assessment notices (for a compulsory audit) and/ or civil claims (including class actions). Among other requirements, the GDPR regulates transfers of personal data subject to the GDPR to third countries that have not been found to provide adequate protection to such personal data, including the U.S., and the efficacy and longevity of current transfer mechanisms between the EEA and the U.S. remains uncertain. Case law from the Court of Justice of the EU, or the CJEU, states that reliance on the standard contractual clauses- a standard form of contract approved by the European Commission as an adequate personal data transfer mechanism-alone may not necessarily be sufficient in all circumstances and that transfers must be assessed on a case-by-case basis. On October 7, 2022 President Biden signed an Executive Order on ‘Enhancing Safeguards for United States Signals Intelligence Activities' which introduced new redress mechanisms and binding safeguards to address the concerns raised by the CJEU in relation to data transfers from the EEA to the U.S. and which formed the basis of the new EU-US Data Privacy Framework, or DPF, as released on December 13, 2022. The European Commission adopted its Adequacy Decision in relation to the DPF on July 10, 2023, rendering the DPF effective as a GDPR transfer mechanism to U.S. entities self-certified under the DPF. The DPF also introduced a new redress mechanism for EU citizens which addresses a key concern in the previous CJEU judgments and may mean transfers under standard contractual clauses are less likely to be challenged in future. We expect the existing legal complexity and uncertainty regarding international personal data transfers to continue. In particular, we expect the DPF Adequacy Decision to be challenged and international transfers to the U.S. and to other jurisdictions more generally to continue to be subject to enhanced scrutiny by regulators. To the extent we are unable to transfer personal data between and among regions in which we operate or intend to operate as a result of regulatory authorities issuing further guidance on personal data export mechanisms, including circumstances where the standard contractual clauses cannot be used, and/or start taking enforcement action, it could affect the manner in which we operate and could adversely affect our financial results.
Further, since January 1, 2021, companies have had to comply with the GDPR and also the UK GDPR, which, together with the amended UK Data Protection Act 2018, retains the GDPR in UK national law, or collectively, the UK GDPR. The UK GDPR mirrors the fines under the GDPR, i.e., fines up to the greater of €20 million (£17.5 million) or 4% of global turnover. On October 12, 2023, the UK Extension to the DPF came into effect (as approved by the UK Government), as a UK GDPR data transfer mechanism to U.S. entities self-certified under the UK Extension to the DPF. As we continue to expand into other foreign countries and jurisdictions, we may be subject to additional laws and regulations that may affect how we conduct business. Although we work to comply with applicable laws, regulations and standards, our contractual obligations and other legal obligations, these requirements are evolving and may be modified, interpreted and applied in an inconsistent manner from one jurisdiction to another, and may conflict with one another or other legal obligations with which we must comply. If we or our third-party CROs or other contractors or consultants fail to comply with applicable federal, state or local regulatory requirements, we could be subject to a range of regulatory actions that could affect our or our contractors' ability to develop and commercialize our product candidates and could harm or prevent sales of any affected products that we are able to commercialize, or could substantially increase the costs and expenses of developing, commercializing and marketing our products. Any threatened or actual government enforcement action could also generate adverse publicity and require that we devote substantial resources that could otherwise be used in other aspects of our business. Further, the use of social media by our, and our third-party service providers', employees and contractors could give rise to liability with respect to intentional or inadvertent data privacy and security breaches involving our data or result in other incidents that could cause reputational damage.