We collect, use, store, disclose or transfer (collectively, "process") personal information, including from employees and customers, in connection with the operation of our business. A wide variety of local and international laws as well as regulations and industry guidelines apply to the privacy and collecting, storing, use, processing, disclosure, and protection of personal information and may be inconsistent among countries or conflict with other rules. Data protection and privacy laws and regulations are changing, subject to differing interpretations and being tested in courts and may result in increasing regulatory and public scrutiny and escalating levels of enforcement and sanctions.
A variety of data protection legislation apply in the United States at both the federal and state level, including new laws that may impact our operations. For example, the State of California has enacted the California Consumer Privacy Act of 2018 ("CCPA"), which generally requires companies that collect, use, share and otherwise process "personal information" (which is broadly defined) of California residents to make disclosures about their data collection, use, and sharing practices, allows consumers to opt-out of certain data sharing with third parties or the sale of personal information, allows consumers to exercise certain rights with respect to any personal information collected and provides a new cause of action for data breaches. In addition, a new privacy law, the California Privacy Rights Act ("CPRA"), which significantly modifies the CCPA, was recently approved by ballot initiative during the November 3, 2021 general election. On January 1, 2023 the CCPA became effective and added additional privacy protection. This may require us to incur additional expenditures to ensure compliance. Additionally, the Federal Trade Commission, and many state attorneys general are interpreting federal and state consumer protection laws to impose standards for the online collection, use, dissemination, and security of data. The burdens imposed by the CCPA and other similar laws that have been or may be enacted at the federal and state level may require us to modify our data processing practices and policies and to incur additional expenditures in order to comply.
Foreign laws and regulations relating to privacy, data protection, information security and consumer protection often are more restrictive than those in the United States. The European Union, for example, traditionally has imposed stricter obligations under its laws and regulations relating to privacy, data protection and consumer protection than the United States. In May 2018 the European Union's new regulation governing data practices and privacy called the General Data Protection Regulation, or GDPR, became effective and substantially replaced the data protection laws of the individual European Union member states. The law requires companies to meet more stringent requirements regarding the handling of personal data of individuals in the EU than were required under predecessor EU requirements. In the United Kingdom, a Data Protection Bill that substantially implements the GDPR also became law in May 2018. The GDPR and other similar regulations require companies to give specific types of notice and in some cases seek consent from consumers and other data subjects before collecting or using their data for certain purposes, including some marketing activities. Outside of the European Union, many countries have laws, regulations, or other requirements relating to privacy, data protection, information security, and consumer protection, and new countries are adopting such legislation or other obligations with increasing frequency. Many of these laws may require consent from consumers for the use of data for various purposes, including marketing, which may reduce our ability to market our products. There is no harmonized approach to these laws and regulations globally. Consequently, we would increase our risk of non-compliance with applicable foreign data protection laws by expanding internationally. We may need to change and limit the way we use personal information in operating our business and may have difficulty maintaining a single operating model that is compliant. In addition, various federal, state and foreign legislative and regulatory bodies, or self-regulatory organizations, may expand current laws or regulations, enact new laws or regulations or issue revised rules or guidance regarding privacy, data protection, information security and consumer protection.
Compliance with these and any other applicable privacy and data protection laws and regulations is a rigorous and time-intensive process, and we may be required to put in place additional mechanisms ensuring compliance with the new privacy and data protection laws and regulations. Our actual or alleged failure to comply with any applicable privacy and data protection laws and regulations, industry standards or contractual obligations, or to protect such information and data that we process, could result in litigation, regulatory investigations, and enforcement actions against us, including fines, orders, public censure, claims for damages by employees, customers and other affected individuals, public statements against us by consumer advocacy groups, damage to our reputation and competitive position and loss of goodwill (both in relation to existing customers and prospective customers) any of which could have a material adverse effect on our business, financial condition, results of operations, and cash flows. Additionally, if third parties that we work with, such as vendors or developers, violate applicable laws or our policies, such violations may also place personal information at risk and have an adverse effect on our business. Even the perception of privacy concerns, whether or not valid, may harm our reputation, subject us to regulatory scrutiny and investigations, and inhibit adoption of our wines by existing and potential customers.