We are subject to a variety of laws and regulations, including regulation by various federal government agencies, including the FTC, the Federal Communications Commission and state and local agencies, as well as data privacy and security laws in jurisdictions outside of the United States. We collect personal information and other potentially protected information from our employees, our current and prospective customers and their users. The U.S. federal and various state and foreign governments have adopted or proposed limitations on, or requirements regarding, the collection, distribution, use, security and storage of personal information, payment card information or other confidential information of individuals and the FTC and many state attorneys general are applying federal and state consumer protection laws to impose standards on the online collection, use and dissemination of data. Self-regulatory obligations, other industry standards, policies and other legal obligations may apply to our collection, distribution, use, security or storage of personal information, payment card information, payment solution know-your-customer and risk information or other confidential information relating to individuals. These obligations may be interpreted and applied inconsistently from one jurisdiction to another and may conflict with one another, other regulatory requirements or our internal practices. Any failure or perceived failure by us to comply with United States, European Union or other foreign privacy or security laws, policies, industry standards or legal obligations or any security incident resulting in the unauthorized access to, or acquisition, release or transfer of, personal information, payment card information, payment solution know-your-customer and risk information or other confidential information relating to our customers, employees or others may result in governmental enforcement actions, litigation, fines and penalties or adverse publicity and could cause our customers to lose trust in us, which could have an adverse effect on our reputation, business, financial condition and results of operations.
We expect there will continue to be newly enacted and proposed laws and regulations as well as emerging industry standards concerning privacy, data protection and information security in the United States, the European Union and other jurisdictions, and we cannot yet determine the impact such future laws, regulations and standards may have on our business. Such laws, regulations, standards and other obligations could impair our ability to, or the manner in which we collect or use information to target advertising to our customers, thereby having a negative impact on our ability to maintain and grow our customer base and increase revenue. For example, the CCPA requires, among other things, that covered companies such as ours provide new disclosures to California consumers and affords such consumers new rights, including the right to access and delete their information and to opt-out of certain sharing and sales of personal information or opt into certain financial incentive programs. The law also prohibits covered businesses from discriminating against consumers (e.g., charging more for services) for exercising any of their CCPA rights. The CCPA took effect on January 1, 2020 and enforcement of the CCPA began on July 1, 2020. The CCPA imposes a severe statutory damages framework as well as a private right of action for certain data breaches that result in the loss of personal information. This private right of action is expected to increase the likelihood of, and risks associated with, data breach litigation. It remains unclear how various provisions of the CCPA will be interpreted and enforced. The CCPA has been amended on multiple occasions and is the subject of regulations of the California Privacy Protection Agency. Additionally, the California Secretary of State certified the California Privacy Rights Act (the "CPRA"), which California voters approved on November 4, 2020. This initiative significantly modified the CCPA, resulting in further uncertainty and requiring us to incur additional costs and expenses in an effort to comply. Other states have passed and others may pass comparable legislation, with potentially greater penalties and more rigorous compliance requirements relevant to our business. The effects of the CCPA, and other similar state or federal laws, are potentially significant and may require us to modify our data processing practices and policies and to incur substantial costs and potential liability in an effort to comply with such legislation. Future restrictions on the collection, use, sharing or disclosure of our customers' data or additional requirements for express or implied consent of customers for the collection, use, disclosure, sharing or other processing of such information could increase our operating expenses, require us to modify our solutions, possibly in a material manner, or stop offering certain solutions, and could limit our ability to develop and implement new solutions.
In addition, several foreign countries and governmental bodies, including the European Union and Canada, have laws and regulations concerning the collection and use of their residents' personal information and payment card information, which are often more restrictive than those in the United States. Laws and regulations in these jurisdictions apply broadly to the collection, use, storage, disclosure and security of personal information and payment card information identifying, or which may be used to identify, an individual, such as names, email addresses and, in some jurisdictions, Internet Protocol (IP) addresses, device identifiers and other data. Although we are working to comply with those laws and regulations applicable to us, these and other obligations may be modified and interpreted in different ways by courts, and new laws and regulations may be enacted in the future. We are subject to the E.U. General Data Protection Regulation 2016/679 (the "GDPR"), and following the United Kingdom's exit from the European Union, from January 1, 2021, we are also subject to the United Kingdom GDPR (the "U.K. GDPR"), which, together with the amended U.K. Data Protection Act of 2018 (the "U.K. Data Protection Act"), retains the GDPR in U.K. national law. The U.K. GDPR mirrors the fines under the GDPR. It remains unclear how the U.K. GDPR, the U.K. Data Protection Act and other U.K. data protection laws or regulations will develop in the medium to longer term. In addition, some countries are considering or have enacted legislation requiring local storage and processing of data that could increase the cost and complexity of delivering our solutions. Any new laws, regulations, other legal obligations or industry standards or any changed interpretation of existing laws, regulations or other standards may require us to incur additional costs and restrict our business operations.
The regulatory environment applicable to the handling of European Economic Area ("EEA"), Swiss and United Kingdom individuals' personal data (as such item is used in the GDPR), and our actions taken in response, may cause us to face a risk of enforcement actions by data protection authorities in the EEA, Switzerland and the United Kingdom, assume additional liabilities or incur additional costs and could result in our business, financial condition and results of operations being harmed. In particular, with regard to transfers to the United States of personal data of our European and United
Kingdom employees and our European, Swiss and United Kingdom customers and their users, the European Commission, the United Kingdom Government, and the Swiss Federal Administration (working with the U.S. Department of Commerce) adopted an adequacy decision pursuant to the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework and the UK Extension to the EU-U.S. Data Privacy Frameworks (each individually and jointly, the "Data Privacy Frameworks"). We comply with the Data Privacy Frameworks to provide an additional legal basis for transfers of personal data to the United States from the EEA, Switzerland and the United Kingdom. It is expected that the Data Privacy Frameworks will be subject to legal challenge to be invalidated through the Court of Justice of the European Union and the E.U. Model Clauses have been subject to legal challenge and may be modified or invalidated. The European Commission has adopted new modular E.U. Model Clauses and the non-legally binding guidance on Supplementary Measures that has been issued by the European Data Protection Board casts doubt on the ability to transfer unencrypted data to the United States. We are monitoring the developments related to the Data Privacy Frameworks and E.U. Model Clauses, but depending on the outcome, we may be unsuccessful in maintaining a legitimate means for our transfer and receipt of personal data from the EEA, Switzerland and United Kingdom in the United States and any other countries that are not considered adequate by the European Union, Switzerland or the United Kingdom. We may, in addition to other impacts, experience additional costs associated with increased compliance burdens and be required to engage in new contract negotiations with third-parties that aid in processing data on our behalf or localize certain data. We may experience reluctance or refusal by current or prospective European, Swiss or United Kingdom customers to use our solutions, and we may find it necessary or desirable to make further changes to our handling of personal data of EEA, Switzerland and United Kingdom residents.
We are also subject to evolving privacy laws on tracking technologies, including cookies and e-marketing. For example, in the European Union and the United Kingdom, regulators are increasingly focusing on compliance with requirements in the online behavioral advertising ecosystem, and current national laws that implement the ePrivacy Directive are highly likely to be replaced by an E.U. regulation known as the ePrivacy Regulation which will significantly increase fines for non-compliance. Guidance and case law in the European Union and the United Kingdom require opt-in consent for the placement of a cookie or similar tracking technologies on a customer's device and for direct electronic marketing. Evolving privacy laws on cookies and e-marketing could lead to substantial costs, require significant systems changes, limit the effectiveness of our marketing activities, divert the attention of our technology personnel, adversely affect our margins, increase costs and subject us to additional liabilities. Regulation of cookies and similar technologies, and any decline of cookies or similar online tracking technologies as a means to identify and potentially target users, may lead to broader restrictions and impairments on our marketing and personalization activities and may negatively impact our efforts to understand our customers.
Consumers can, with increasing ease, implement technologies that limit our ability to collect and use data to deliver or advertise our services, or otherwise limit the effectiveness of our platform. Cookies may be deleted or blocked by consumers. The most commonly used Internet browsers allow consumers to modify their browser settings to block first-party cookies (placed from the domain of the website owner that the consumer is browsing) or third-party cookies (placed from a different domain), and some browsers block third-party cookies by default. Some prominent technology companies, including Google, the owner of the Chrome browser, have announced intentions to discontinue support of third-party cookies, and to develop alternative methods and mechanisms for tracking consumers. Many applications and other devices allow consumers to avoid receiving advertisements by paying for subscriptions or other downloads. Mobile devices using Android and iOS operating systems limit the ability of cookies, or similar technology, to track consumers while they are using applications other than their web browser on the device.
If our privacy or data security measures fail to comply with current or future laws, regulations, policies, legal obligations or industry standards, or are perceived to have failed to so comply, we may be subject to litigation, regulatory investigations and related actions, significant fines (which, for certain breaches of the GDPR or U.K. GDPR, may be up to the greater of €20 million or 4% of total global annual turnover), civil claims including representative actions and other class action type litigation (potentially amounting to significant compensation or damages liabilities) or other liabilities, negative publicity and a potential loss of business. Moreover, if future laws, regulations, other legal obligations or industry standards, or any changed interpretations of the foregoing, limit our customers' ability to use and share personal information, including payment card information, or our ability to store, process and share such personal information or other data, demand for our solutions could decrease, our costs could increase and our business, financial condition and results of operations could be harmed.