Personal privacy and information security are significant issues in the United States and the other jurisdictions in which we operate or make our products and applications available. The legislative and regulatory framework for privacy and security issues worldwide is rapidly evolving and is likely to remain uncertain for the foreseeable future. Our handling of data is subject to a variety of laws and regulations, including regulation by various government agencies, including the U.S. Federal Trade Commission, or FTC, and various state, local and foreign agencies. We may collect personally identifiable information, or PII, and other data from our customers. We use this information to provide services to our customers and to support, expand and improve our business. We may also share customers' PII with third parties as allowed by applicable law and agreements and authorized by the customer or as described in our privacy policy.
The U.S. federal and various state and foreign governments have adopted or proposed limitations on the collection, distribution, transfer, use and storage of PII. In the United States, the FTC and many state attorneys general are applying federal and state consumer protection laws as imposing standards for the online collection, use and dissemination of data. Many foreign countries and governmental bodies, including Canada, the European Union and other relevant jurisdictions, have laws and regulations concerning the collection and use of PII obtained from their residents or by businesses operating within their jurisdiction. These laws and regulations often are more restrictive than those in the United States. Laws and regulations in these jurisdictions apply broadly to the collection, use, storage, disclosure and security of data that identifies or may be used to identify or locate an individual, such as names, email addresses and, in some jurisdictions, Internet Protocol, or IP, addresses. Within the European Union, legislators have adopted the General Data Protection Regulation, or GDPR, effective May 2018 which may impose additional obligations and risk upon our business, and which may increase substantially the penalties to which we could be subject in the event of any non-compliance. We may incur substantial expense in complying with the obligations imposed by the governments of the foreign jurisdictions in which we do business or seek to do business and we may be required to make significant changes in our business operations, all of which may adversely impact our revenues and our business overall.
Although we are working to comply with those federal, state, and foreign laws and regulations, industry standards, contractual obligations and other legal obligations that apply to us, those laws, regulations, standards and obligations are evolving and may be modified, interpreted and applied in an inconsistent manner from one jurisdiction to another, and may conflict with one another, other requirements or legal obligations, our practices or the features of our products or applications. At state level, lawmakers continue to pass new laws concerning privacy and data security. Particularly notable in this regard is the California Consumer Privacy Act, or CCPA, which became effective on January 1, 2020. The CCPA will introduce significant new disclosure obligations and provide California consumers with significant new privacy rights. Any failure or perceived failure by us to comply with federal, state or foreign laws or regulations, industry standards, contractual obligations or other legal obligations, or any actual or suspected security incident, whether or not resulting in unauthorized access to, or acquisition, release or transfer of PII or other data, may result in governmental enforcement actions and prosecutions, private litigation, fines and penalties or adverse publicity and could cause our customers to lose trust in us, which could have an adverse impact on our reputation and business. Any inability to adequately address privacy and security concerns, even if unfounded, or comply with applicable laws, regulations, policies, industry standards, contractual obligations, or other legal obligations could result in additional cost and liability to us, damage our reputation, inhibit sales and adversely impact our business.
We also expect that there will continue to be new proposed laws, regulations and industry standards concerning privacy, data protection and information security in the United States, the European Union and other jurisdictions, and we cannot yet determine the impact such future laws, regulations and standards may have on our business. New laws, amendments to or re-interpretations of existing laws and regulations, industry standards, contractual obligations and other obligations may require us to incur additional costs and restrict our business operations. Such laws and regulations may require companies to implement privacy and security policies, permit users to access, correct and delete personal information stored or maintained by such companies, inform individuals of security breaches that affect their personal information, and, in some cases, obtain individuals' consent to use PII for certain purposes. In addition, a foreign government could require that any PII collected in a country not be disseminated outside of that country, and we are not currently equipped to comply with such a requirement.