In the ordinary course of our business, we might collect and store in our internal and external data centers, cloud services and networks sensitive data, including our proprietary business information and that of our customers, suppliers and business partners, as well as personal information of our customers, employees and others. The secure processing, maintenance and transmission of this information is critical to our operations and business strategy. The number and sophistication of attempted attacks and intrusions that companies have experienced from third parties has increased over the past few years. Despite our security measures, it is impossible for us to eliminate this risk.
Many U.S. states have enacted data privacy and security laws and regulations that govern the collection, use, disclosure, transfer, storage, disposal, and protection of personal information, such as social security numbers, financial information and other sensitive personal information. For example, all 50 states and several U.S. territories now have data breach laws that require timely notification to affected individuals, and at times regulators, credit reporting agencies and other bodies, if a company has experienced the unauthorized access or acquisition of certain personal information. Other state laws include the California Consumer Privacy Act, as amended ("CCPA"). The CCPA, among other things, contains disclosure obligations for businesses that collect personal information about California residents and affords those individuals new rights relating to their personal information that may affect our ability to collect and/or use personal information. Other states and the federal government are considering new data privacy and/or security laws. We will continue to monitor and assess the impact of these laws, which may impose substantial penalties for violations, impose significant costs for investigations and compliance, allow private class-action litigation and carry significant potential liability for our business.
Data protection laws enacted outside of the U.S., such as the EU General Data Protection Regulation (the "GDPR"), also might apply to some of our operations or business partners. Legal requirements in these countries relating to the collection, storage, processing and transfer of personal data/information continue to evolve. The GDPR imposes, among other things, data protection requirements that include strict obligations and restrictions on the ability to collect, analyze and transfer EU personal data/information, a requirement for prompt notice of data breaches to data subjects and supervisory authorities in certain circumstances, and possible substantial fines for any violations (including possible fines for certain violations of up to the greater of 20 million Euros or 4% of total company revenue). Other governmental authorities around the world have enacted or are considering similar types of legislative and regulatory proposals concerning data protection.
The interpretation and enforcement of the laws and regulations described above are uncertain and subject to change, and may require substantial costs to monitor and implement and maintain adequate compliance programs. Failure to comply with U.S. and international data protection laws and regulations could result in government enforcement actions (which could include substantial civil and/or criminal penalties), private litigation and/or adverse publicity and could negatively affect our operating results and business.