We are or may become subject to a variety of laws and regulations in the United States and abroad regarding privacy, data security, cybersecurity and data protection. These laws and regulations are continuously evolving and developing. The scope and interpretation of the laws that are or may be applicable to us and our business, including our webstore sales, are often uncertain and may be conflicting, particularly with respect to foreign laws.
In particular, there are numerous U.S. federal, state, and local laws and regulations and foreign laws and regulations regarding privacy and the collection, sharing, use, processing, disclosure, and protection of personal information and other user data. Such laws and regulations often have changes in scope, may be subject to differing interpretations, and may be inconsistent among different jurisdictions. The costs of compliance with, and other burdens imposed by, these regulations may limit the use and adoption of our products and services and could have an adverse impact on our business, results of operations and financial condition.
For example, in April 2016, the E.U. Parliament approved a new data protection regulation, known as the General Data Protection Regulation ("GDPR"), which came into force on May 25, 2018. The GDPR includes operational requirements for companies that receive or process personal data of residents of the European Union that are different than those previously in place in the European Union, and that include significant penalties for non-compliance. Another example, in November 2016, the Standing Committee of China's National People's Congress passed China's first Cybersecurity Law ("CSL"), which took effect in June 2017. The CSL is the first Chinese law that systematically lays out the regulatory requirements on cybersecurity and data protection, subjecting many previously under-regulated or unregulated activities in cyberspace to government scrutiny. More recently, the Personal Information
Security Specification went into effect in October 2020, which has broad but uncertain applications and imposes a number of new privacy and data security obligations. China is also implementing new legislation on the protection of privacy and personal data, including a Personal Information Protection Law and a Data Security Law, each of which went into effect in September 2021 and may impose new obligations on us.
Additionally, California enacted the California Consumer Privacy Act, as amended (the "CCPA") that, among other things, requires covered companies to provide new disclosures to California consumers, and afford such consumers new abilities to opt-out of certain sales of personal information. The CCPA took effect on January 1, 2020 with the privacy provisions enforceable by the California Attorney General as of July 1, 2020, and the regulations becoming enforceable as of August 1, 2020. The CCPA was significantly expanded on January 1, 2023, when the California Privacy Rights Act ("CPRA") became effective. The CPRA amendments, among other things, give California residents the ability to limit use of certain sensitive personal information, further restrict the use of cross-contextual advertising, establish restrictions on the retention of personal information, expand the types of data breaches subject to the CCPA's private right of action, provide for increased penalties for CCPA violations concerning California residents under the age of 16, and establish a new California Privacy Protection Agency to implement and enforce the new law. In addition, data privacy and security laws have been proposed at the federal, state, and local levels in recent years, which could further complicate compliance efforts. For example, states such as Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Virginia, and Utah have enacted their own data privacy laws. Given the recent implementation of these regulations, we cannot yet predict the impact of these regulations on our business or operations.
We strive to comply with all applicable laws, policies and legal obligations relating to privacy, data security, cybersecurity and data protection. However, given that the scope, interpretation, and application of these laws and regulations are often uncertain and may be conflicting, it is possible that these obligations may be interpreted and applied in a manner that is inconsistent from one jurisdiction to another and may conflict with other rules or our practices. Any failure or perceived failure by us or third-party service-providers to comply with our privacy or security policies or privacy-related legal obligations, or any compromise of security that results in the unauthorized release or transfer of personally identifiable information or other user data, may result in governmental enforcement actions, litigation, or negative publicity, and could have an adverse effect on our brand, results of operations and financial condition.
Governments are continuing to focus on privacy, cybersecurity, data protection and data security and it is possible that new privacy or data security laws will be passed or existing laws will be amended in a way that is material to our business. Any significant change to applicable laws, regulations, or industry practices regarding our employees' and users' data could require us to modify our business, services and products features, possibly in a material manner, and may limit our ability to develop new products, services, and features. Although we have made efforts to design our policies, procedures, and systems to comply with the current requirements of applicable state, federal, and foreign laws, changes to applicable laws and regulations in this area could subject us to additional regulation and oversight, any of which could significantly increase our operating costs.