We are subject to regulation by various federal, state, provincial, local and foreign governmental authorities, including those responsible for monitoring and enforcing employment and labor laws, anti-bribery laws, lobbying and election laws, securities laws and tax laws. These laws and regulations are subject to change over time and thus we must continue to monitor and dedicate resources to ensure continued compliance.
In addition, our business is subject to regulation by various federal, state, provincial and foreign governmental agencies responsible for monitoring and enforcing privacy and data protection laws and regulations. Numerous foreign, federal and state laws and regulations govern collection, dissemination, use and confidentiality of personally identifiable health information, including state privacy and confidentiality laws (including state laws requiring disclosure of breaches); federal and state consumer protection and employment laws; the Health Insurance Portability and Accountability Act of 1996, or HIPAA; and European and other foreign data protection laws.
We receive, store, process, and use personal information and other user content. The regulatory framework for privacy issues worldwide, including in the United States, is rapidly evolving and is likely to remain uncertain for the foreseeable future, as many new laws and regulations regarding the collection, use and disclosure of personally identifiable information, or PII, and other data have been adopted or are under consideration and existing laws and regulations may be subject to new and changing interpretations. In the United States, the Federal Trade Commission and many state attorneys general are applying federal and state consumer protection laws to impose standards for the online collection, use and dissemination of data. The California Consumer Privacy Act of 2018, or CCPA imposes significant additional requirements with respect to the collection of personal information from California residents. The CCPA, among other things, creates new data privacy obligations for covered companies and provides new privacy rights to California residents, including the right to opt out of certain disclosures of their information. The CCPA also creates a private right of action with statutory damages for certain data breaches, thereby potentially increasing risks associated with a data breach. It remains unclear what, if any, modifications will be made to this legislation or how it will be interpreted. Additionally, a new privacy law, the California Privacy Rights Act, or CPRA, significantly modified the CCPA, which has resulted in further uncertainty and requiring us to incur additional costs and expenses. The CPRA created a new California state agency charged with enforcing state privacy laws, and there is uncertainty about potential enforcement actions that the new agency may take in the future. The effects of the CCPA and the CPRA remain far-reaching, and depending on final regulatory guidance and related developments, may require us to modify our data processing practices and policies and to incur substantial costs and expenses in an effort to comply.
We are also currently subject to a variety of, and may in the future become subject to additional U.S. federal, state and local laws and regulations on advertising that are continuously evolving and developing, including the Telephone Consumer Protection Act, or the TCPA, the Telemarketing Sales Rule, the Controlling the Assault of Non-Solicited Pornography and Marketing Act, or the CAN-SPAM Act, and, at the state level, the CCPA (as described above), the Virginia Consumer Data Protection Act of 2021, or VCDPA, and the Colorado Privacy Act, or CPA. Many states are discussing potentially adopting similar comprehensive privacy legislation and we expect many of these will be implemented over the course of the next few years. These laws and regulations directly impact our business and require ongoing compliance, monitoring and internal and external audits as they continue to evolve, and may result in ever-increasing public and regulatory scrutiny and escalating levels of enforcement and sanctions. Subsequent changes to data protection and privacy laws and regulations could also impact how we process personal information and, therefore, limit the effectiveness of our product offerings or our ability to operate or expand our business, including limiting strategic relationships that may involve the sharing of personal information.
Many foreign countries and governmental bodies, including Canada and other relevant jurisdictions where we conduct or may, in the future, conduct business, have laws and regulations concerning the collection and use of PII and other data obtained from their residents or by businesses operating within their jurisdiction. These laws and regulations often are more restrictive than those in the United States Laws and regulations in these jurisdictions apply broadly to the collection, use, storage, disclosure and security of data that identifies or may be used to identify or locate an individual, such as names, email addresses and, in some jurisdictions, internet protocol addresses and other types of data. In Canada, the federal Personal Information Protection and Electronic Documents Act, or PIPEDA, governs the collection, use and disclosure of PII in many provinces in Canada, and though it is silent with respect to territorial reach, the Federal Court of Canada has found that PIPEDA will apply to businesses established in other jurisdictions if there is a "real and substantial connection" between the organization's activities and Canada. Provincial privacy commissioners take a similar approach to the interpretation and application of provincial private-sector privacy laws equivalent to PIPEDA. Further, Canada has robust anti-spam legislation. Organizations sending commercial electronic messages to individuals must either have express consent from the individual in the prescribed form or the situation must qualify as an instance of implied consent or other authorization set out in Canada's Anti-Spam Legislation, or CASL. The penalties for non-compliance under CASL are significant and the regulator, the Canadian Radio- Television and Telecommunications Commission, is active with respect to enforcement.
Although we are working to comply with those federal, state, provincial and foreign laws and regulations, industry standards, governmental standards, contractual obligations and other legal obligations that apply to us, those laws, regulations, standards and obligations are evolving and may be modified, interpreted and applied in an inconsistent manner from one jurisdiction to another, and may conflict with one another, other requirements or legal obligations, our practices or the features of our applications or platform. Any failure or perceived failure by us or our contractors to comply with federal, state, provincial or foreign laws or regulations, industry standards, contractual obligations or other legal obligations, or any actual or suspected security incident, whether or not resulting in loss of, unauthorized access to, or acquisition, alteration, destruction, release or transfer of PII or other data, may result in governmental enforcement actions and prosecutions, private litigation, fines and penalties or adverse publicity and could cause employees, clients and consumers to lose trust in us, which could have an adverse effect on our reputation and business. Any inability or perceived inability (even if unfounded) on our part to adequately address privacy, data protection, and information security concerns, or comply with applicable laws, regulations, policies, industry standards, governmental standards, contractual obligations, or other legal obligations, could result in additional cost and liability to us, damage our reputation, inhibit sales, restrict our ability to utilize collected personal information, and adversely affect our business.
We also expect that there will continue to be new proposed laws, regulations and industry standards concerning privacy, data protection and information security in the United States, Canada and other jurisdictions, and we cannot yet determine the impact such future laws, regulations and standards may have on our business. Future laws, regulations, standards and other obligations, or amendments or changes in the interpretation of existing laws, regulations, standards and other obligations, could impair our or our clients' ability to collect, use, disclose or otherwise process information relating to employees or consumers, which could decrease demand for our applications, increase our costs and impair our ability to maintain and grow our client and consumer bases and increase revenue. Such laws and regulations may require us to implement privacy and security policies, permit users to access, correct and delete personal information stored or maintained by such companies, inform individuals of security breaches that affect their personal information, and, in some cases, obtain individuals' consent to use PII or other data for certain purposes. In addition, a foreign government could require that any data collected in a country not be transferred or disseminated outside of that country, or impose restrictions or conditions upon such dissemination, and we may face difficulty in complying with any such requirements for certain geographic regions. Indeed, many privacy laws, such as those in force in Canada, already impose these requirements. If we fail to comply with federal, state, provincial and foreign data privacy laws and regulations, our ability to successfully operate our business and pursue our business goals could be harmed. Furthermore, due to our acceptance of credit cards, we are subject to the Payment Card Industry Data Security Standard (also known as the "PCI-DSS"), which is designed to protect the information of credit card users.
In the event our determinations are challenged and found to have been incorrect, we may be subject to unfavorable publicity or claims by one or more state attorneys general, federal regulators, or private plaintiffs, any of which could damage our reputation, inhibit sales and adversely affect our business.