We collect and process certain personal data of our users, including email addresses, usage data, identification information, and additional information. We also collect and process billing information and phone numbers of our users.
We are subject to the privacy and data protection laws and regulations in various jurisdictions, such as China and the European Union. Privacy laws provide restrictions and guidance in connection with our storage, use, processing, disclosure, transfer, and protection of personal information. We strive to comply with all applicable laws, regulations, and policies relating to privacy and data protection. We are also subject to privacy and data security-related obligations deriving from our privacy policy and terms of use with our users, and we may be liable to third parties in the event we are deemed to have wrongfully processed, used, stored, disclosed, or otherwise disposed of personal data.
Data security and protection has become one of the policy focuses of PRC regulators. The PRC regulatory and enforcement regime in this regard is relatively new and may change from time to time. See "Item 4. Information of the Company-B. Business Overview-PRC Government Regulations-Regulations Relating to Internet Information Security and Privacy Protection" for details. Substantial uncertainties remain with respect to the interpretation and enforcement of the data security and privacy protection regulations and their impact to us, which makes it difficult to determine what actions or inactions may be deemed to be in violation of the applicable laws and regulations in certain circumstances.
Nevertheless, PRC government authorities have wide discretion in the interpretation and enforcement of these laws. As a major internet platform, we are exposed to risks of being deemed to be a critical information infrastructure operator or a network platform operator meeting the above criteria under the PRC cybersecurity laws. If we are identified as a critical information infrastructure operator, we would be required to fulfill various obligations as required under PRC cybersecurity laws and other applicable laws for critical information infrastructure operators that are currently not applicable to us, including, among others, setting up a special security management organization, organizing regular cybersecurity education and training, formulating emergency plans for cyber security incidents, and conducting regular emergency drills. Moreover, although the internet products and services that we purchase are primarily bandwidth, servers, and marketing services, we may need to follow cybersecurity review procedure and apply with Cybersecurity Review Office before making certain purchases of network products and services. During cybersecurity review, we may be required to undertake certain business adjustments, which may cause disruptions to our business and operations. The cybersecurity review could lead to a diversion of time and attention of our management and our other resources. It could be costly and time-consuming for us to prepare application materials and make the applications. Furthermore, we cannot assure you that we will obtain the clearance or approval for these applications from the Cybersecurity Review Office and the government authorities in a timely manner, or at all. If we are found to be in violation of cybersecurity requirements in China, the government authorities may, at their discretion, conduct investigations, levy fines, request app stores to take down our apps, and cease to provide viewing and downloading services related to our apps, prohibit the registration of new users on our platform, or require us to change our business practices in a manner materially adverse to our business. Any of these actions may disrupt our operations and materially and adversely affect our business, financial condition, and results of operations.
The European Union traditionally takes a broader view as to what is considered personal information and has imposed greater obligations under their privacy and data protection laws. In particular, the European Union adopted the General Data Protection Regulation in April 2016, which came into effect in May 2018. The General Data Protection Regulation results in more stringent requirements for data processors and controllers, including more fulsome disclosures about the processing of personal information, data retention limits, and deletion requirements, mandatory notification in the case of a data breach, and elevated standards regarding valid consent in some specific cases of data processing. The General Data Protection Regulation also includes substantially higher penalties for failure to comply with the requirements. For example, in the event of violations, a fine up to 20 million Euros or up to 4% of the annual worldwide turnover, whichever is greater, may be imposed. In addition to the General Data Protection Regulation, when other future laws and regulations relating to data privacy in China or other jurisdictions come into effect, the more stringent requirements on privacy user notifications and data handling will require us to adapt our business and incur additional costs.
In addition, to the extent we have accessed data in Hong Kong and Macao, we have been in compliance with the laws and regulations in both jurisdictions regarding data security, such as the Personal Data (Privacy) Ordinance and the Unsolicited Electronic Messages Ordinance, which impose protocols and obligations regarding the handling of personal data in Hong Kong including, among other things, that (i) personal data must be collected for a lawful purpose, necessary, and not excessive, (ii) personal data must be collected by means that are lawful and fair in the circumstances of the case, and (iii) the person from whom personal data is collected is informed of the purpose of collecting the data. As of the date of this annual report, we believe that these laws and regulations in Hong Kong and Macao regarding data security do not, nor would any non-compliance therewith, if any, have any material adverse impact on our business. However, if certain laws and regulations in Hong Kong or Macao were to result in oversight over data security that materially impacts our business in the applicable jurisdiction, we may be required to incur additional cost to ensure our compliance with such laws and regulations, and any violation could result in a material adverse impact on our business, financial condition, and results of operations.
Privacy and data protection concerns are becoming more widely acknowledged and may cause our users to resist providing the personal data necessary to allow them to use our platform effectively. We have implemented multiple measures and security protocols to maintain and improve our privacy protection capability. However, since the privacy and data protection laws and regulations are relatively new, there are uncertainties as to the interpretation and application of these laws and regulations, and it is possible that our privacy and data protection practices are or will be incompliant with the applicable regulatory requirements and/or our terms of use with our users. Any violation of the provisions and requirements under these laws, regulations, obligations or our terms of use with our users may subject us to warnings, fines, confiscation of illegal gains, revocation of licenses, suspension of business, shutting down of websites or even criminal liabilities. Complying with such requirements could cause us to incur substantial expenses or to alter or change our practice in a manner that could harm our business. Any systems failure or security breach or lapse that results in the unauthorized release of our user data could harm our reputation and brand and, consequently, our business, in addition to exposing us to potential legal liability.