We process personal data and other sensitive data (including health data we collect about trial participants in connection with clinical trials); proprietary and confidential business data; trade secrets; intellectual property; and sensitive third-party data. Our data processing activities subject us to numerous data privacy and security obligations, such as various laws, regulations, guidance, industry standards, external and internal privacy and security policies, contracts, and other obligations that govern the processing of personal data by us and on our behalf.
Data privacy and information security have become significant issues in the United States, countries in Europe, and in other countries in which we operate. The legal and regulatory framework for privacy and security issues is rapidly evolving, and is expected to increase our compliance costs and exposure to liability. In the United States, federal, state, and local governments have enacted numerous data privacy and security laws, including data breach notification laws, personal data privacy laws, consumer protection laws, and other similar laws (e.g., wiretapping laws). These privacy laws include, without limitation, the following laws and regulations: Section 5 of the Federal Trade Commission Act, the Health Insurance Portability and Accountability Act of 1996 (HIPAA), and the California Privacy Rights Act of 2020 (CPRA). HIPAA, as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH), imposes specific requirements relating to the privacy, security, and transmission of individually identifiable health information. The CPRA imposes obligations on businesses to which it applies that include, but are not limited to, providing specific disclosures in privacy notices and affording California residents certain rights related to their personal data. The CPRA allows for statutory fines for noncompliance (up to $7,500 per violation) and allows private litigants affected by certain data breaches to recover significant statutory damages. Although the CPRA exempts some data processed in the context of clinical trials, the CPRA may increase compliance costs and potential liability with respect to other personal data we may maintain about California residents. In addition, the CPRA extends to personal information of business representatives and employees and established a new regulatory agency to implement and enforce the law. Other states, like Colorado, Connecticut, Utah, and Virginia, have passed comprehensive data privacy laws which differ from the CPRA and all of which went into effect in 2023. In addition, data privacy and security laws have been proposed at the federal, state, and local levels in recent years, which could further complicate compliance efforts and may increase legal risk and compliance costs for us and the third parties upon whom we rely. Additionally, under various privacy laws and other obligations, we may be required to obtain certain consents to process personal data. Our inability or failure to do so could result in adverse consequences. If we are or become subject to these laws and/or new or amended data privacy laws, the risk of enforcement actions against us could increase because we may be subject to obligations under applicable regulatory frameworks and the number of individuals or entities that could initiate actions against us may increase (including individuals via a private right of action), in addition to further complicating our compliance efforts. In addition, privacy advocates and industry groups have proposed, and may propose in the future, standards with which we are legally or contractually bound to comply.
Outside the United States, an increasing number of laws, regulations, and industry standards apply to data privacy and security. For example, the European Union's General Data Protection Regulation (EU GDPR) and the equivalent law in the United Kingdom (UK GDPR) impose strict requirements for processing the personal data of individuals, including sensitive data that we may process such as health data. For example, under the EU GDPR, government regulators may impose temporary or definitive bans on data processing, as well as fines of up to 20 million euros or 4% of annual global revenue, whichever is greater. Similar processing penalties and fines exist under the UK GDPR and the uncertainty of data protection laws in the UK following Brexit has increased the complexity of our compliance efforts. Further, individuals may initiate litigation related to our processing of their personal data.
In the ordinary course of business, we may transfer personal data from Europe and other jurisdictions to the United States or other countries. Europe and other jurisdictions have enacted laws requiring data to be localized or limiting the transfer of personal data to other countries. In particular, the European Economic Area (EEA) and the United Kingdom (UK) have significantly restricted the transfer of personal data to the United States and other countries whose privacy laws it believes are inadequate. Most jurisdictions have adopted similarly stringent data protection laws which include data localization and cross-border data transfer limitations. Although there are currently various mechanisms that may be used to transfer personal data from the EEA and UK to the United States in compliance with law, such as the EEA and UK's standard contractual clauses, these mechanisms are subject to legal challenges, and there is no assurance that we can satisfy or rely on these measures to lawfully transfer personal data to the United States. If there is no lawful manner for us to transfer personal data from the EEA, the UK or other jurisdictions to the United States, or if the requirements for a legally-compliant transfer are too onerous, we could face significant adverse consequences, including the interruption or degradation of our operations, the need to relocate part of or all of our business or data processing activities to other jurisdictions at significant expense, increased exposure to regulatory actions, substantial fines and penalties, the inability to transfer data and work with partners, vendors and other third parties, and injunctions against our processing or transferring of personal data necessary to operate our business. Some European regulators have prevented companies from transferring personal data out of Europe for allegedly violating the GDPR's cross-border data transfer limitations. Other jurisdictions require all processing of sensitive personal information be done inside the borders of that jurisdiction.
We may also be bound by contractual obligations related to data privacy and security, and our efforts to comply with such obligations may not be successful. For example, certain privacy laws, such as the GDPR and the CPRA, require our customers to impose specific contractual restrictions on their service providers. We may publish privacy policies, marketing materials and other statements, such as compliance with certain certifications or self-regulatory principles, regarding data privacy and security. If these policies, materials or statements are found to be deficient, lacking in transparency, deceptive, unfair, or misrepresentative of our practices, we may be subject to investigation, enforcement actions by regulators or other adverse consequences.
Our obligations related to data privacy and security are quickly changing, becoming increasingly stringent and creating some uncertainty as to the effective future legal framework. Additionally, these obligations may be subject to differing applications and interpretations, which may be inconsistent or in direct conflict among jurisdictions. Preparing for and complying with these obligations requires us to devote significant resources (including, without limitation, financial and time-related resources). These obligations may necessitate changes to our services, information technologies, systems, and practices and to those of any third parties that process personal data on our behalf. In addition, these obligations may require us to change our business model. Our business model materially depends on our ability to process personal data, so we are particularly exposed to the risks associated with the rapidly changing legal landscape. For example, we may be at heightened risk of regulatory scrutiny, and any changes in the regulatory framework could require us to fundamentally change our business model.
Although we endeavor to comply with all applicable data privacy and security obligations, we may at times fail (or be perceived to have failed) to do so. Despite our efforts, our personnel or third parties upon whom we rely may fail to comply with such obligations, which could negatively impact our business operations and compliance posture. For example, any failure by a third-party processor to comply with applicable law, regulations, or contractual obligations could result in adverse effects, including inability to operate our business and proceedings against us by governmental entities or others. Moreover, clinical trial subjects about whom we or our potential collaborators obtain information, as well as the third-party providers (such as contract research organizations) who share this information with us, may contractually limit our ability to use and disclose the information.
If we or the third parties on which we rely fail, or are perceived to have failed, to address or comply with data privacy and security obligations, we could face significant consequences. These consequences may include, but are not limited to, government enforcement actions (e.g., investigations, fines, penalties, audits, inspections, and similar); litigation (including class-related claims); additional reporting requirements and/or oversight; bans on processing personal data; and orders to destroy or not use personal data. Any of these events could have a material adverse effect on our reputation, business, or financial condition, including but not limited to: loss of customers; interruptions or stoppages in our business operations (including our clinical trials); inability to process personal data or to operate in certain jurisdictions; limited ability to develop or commercialize our product candidates; expenditure of time and resources to defend any claim or inquiry; adverse publicity; or revision or restructuring of our operations.