In the ordinary course of business, we and our collaborators and third-party providers may collect, receive, store, process, generate, use, transfer, disclose, make accessible, protect, secure, dispose of, transmit, and share (collectively, process) personal data and other sensitive information, such as proprietary and confidential business data, trade secrets, intellectual property, and data we collect about trial participants in connection with our clinical trials. Our data processing activities may subject us to numerous data privacy and security obligations, such as various laws, regulations, guidance, industry standards, external and internal privacy and security policies, contracts, and other obligations that govern the processing of sensitive information by us and on our behalf. In the United States, federal, state, and local laws and regulations, including federal health information privacy laws, state data breach notification laws, state health information privacy laws and federal and state consumer protection laws (e.g., Section 5 of the Federal Trade Commission Act), govern the collection, use, disclosure and protection of health-related and other personal data and could apply to our operations or the operations of our collaborators and third-party providers. In addition, we may obtain health information from third parties (including research institutions from which we obtain clinical trial data) that are subject to privacy and security requirements under HIPAA, as amended by HITECH, which imposes specific requirements relating to the privacy, security, and transmission of individually identifiable health information. Depending on the facts and circumstances, we could be subject to significant penalties if we violate HIPAA.
In the past few years, numerous U.S. states-including California, Virginia, Colorado, Connecticut, and Utah-have enacted comprehensive privacy laws that impose certain obligations on covered businesses, including providing specific disclosures in privacy notices and affording residents with certain rights concerning their personal information. As applicable, such rights may include the right to access, correct, or delete certain personal information, and to opt-out of certain data processing activities, such as targeted advertising, profiling, and automated decision-making. The exercise of these rights may impact our business and ability to provide our products and services. These state laws also allow for statutory fines for noncompliance. For example, the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, collectively the CCPA, applies to personal information of consumers, business representatives, and employees who are California residents and requires businesses to provide specific disclosures in privacy notices and honor requests of California residents to exercise certain privacy rights . The CCPA provides for fines of up to $7,500 per intentional violation and allows private litigants affected by certain data breaches to seek to recover potentially significant statutory damages. While the CCPA and many of these state laws also exempt some data processed in the context of clinical trials, these developments further complicate compliance efforts, and increase legal risk and compliance costs for us and the third parties upon whom we rely. We expect more states to pass similar laws in the future.
Outside the United States, an increasing number of laws, regulations, and industry standards govern data privacy and security. For example, the European Union's General Data Protection Regulation, or EU GDPR, the United Kingdom's GDPR, or UK GDPR, Brazil's General Data Protection Law (Lei Geral de Proteção de Dados Pessoais, or LGPD) (Law No. 13,709/2018), and China's Personal Information Protection Law, or PIPL, impose strict requirements for processing personal data. In particular, the EU GDPR applies to any company established in the European Economic Area, or EEA, and to companies established outside the EEA that process personal data in connection with the offering of goods or services to data subjects in the EEA or the monitoring of the behavior of data subjects in the EEA. The obligations from the EU GDPR and UK GDPR, together referred to as GDPR, may include limiting personal data processing to only what is necessary for specified, explicit, and legitimate purposes; requiring a legal basis for personal data processing; complying with specific requirements to process health-related data; requiring the appointment of a data protection officer in certain circumstances; increasing transparency obligations to data subjects; requiring data protection impact assessments in certain circumstances; limiting the collection and retention of personal data; increasing rights for data subjects; formalizing a heightened and codified standard of data subject consents; requiring the implementation and maintenance of technical and organizational safeguards for personal data; mandating notice of certain personal data breaches to the relevant supervisory authority(ies) and affected individuals; and mandating the appointment of representatives in the UK and/or the EU in certain circumstances. Under the GDPR, companies may face temporary or definitive bans on data processing and other corrective actions; fines of up to 20 million Euros under the EU GDPR (17.5 million British Pounds under the UK GDPR) or 4% of annual global revenue, in each case, whichever is greater; or private litigation related to processing of personal data brought by classes of data subjects or consumer protection organizations authorized at law to represent their interests.
In addition, we may be unable to transfer personal data from Europe and other jurisdictions to the United States or other countries due to data localization requirements or limitations on cross-border data flows. Europe and other jurisdictions have enacted laws requiring data to be localized or limiting the transfer of personal data to other countries. In particular, the EEA and UK have significantly restricted the transfer of personal data to the United States and other countries whose data privacy laws they generally believe are inadequate. Other jurisdictions may adopt similarly stringent interpretations of their data localization and cross-border data transfer laws. Although there are currently various mechanisms that may be used to transfer personal data from the EEA and UK to the United States in compliance with law, such as the EU's standard contractual clauses, the UK's International Data Transfer Agreement/Addendum, and the EU-U.S. Data Privacy Framework and the UK extension thereto (which allows for transfers for relevant U.S.-based organizations who self-certify compliance and participate in the Framework), these mechanisms may be subject to legal challenges, and there is no assurance that we can satisfy or rely on these measures to lawfully transfer personal data to the United States. If there is no lawful manner for us to transfer personal data from the EEA, the UK, or other jurisdictions to the United States, or if the requirements for a legally-compliant transfer are too onerous, we could face significant adverse consequences, including the interruption or degradation of our operations, the need to relocate part of or all of our business or data processing activities to other jurisdictions at significant expense, increased exposure to regulatory actions, substantial fines and penalties, the inability to transfer data and work with partners, vendors and other third parties, and injunctions against our processing or transferring of personal data necessary to operate our business. Additionally, companies that transfer personal data out of the EEA and UK to other jurisdictions, particularly to the United States, are subject to increased scrutiny from regulators, individual litigants, and activities groups. Some European regulators have ordered certain companies to suspend or permanently cease certain transfers of personal data out of Europe for allegedly violating the EU GDPR's cross-border data transfer limitations. In addition to data privacy and security laws, we are also bound by contractual obligations related to data privacy and security, and our efforts to comply with such obligations may not be successful. For example, certain privacy laws, such as the GDPR and the CCPA, require our customers to impose specific contractual restrictions on their service providers.
We publish privacy policies, marketing materials and other statements, such as confirmation of compliance with certain certifications or self-regulatory principles, regarding data privacy and security. If these policies, materials or statements are found to be deficient, lacking in transparency, deceptive, unfair, or misrepresentative of our practices, we may be subject to investigation, enforcement actions by regulators or other adverse consequences.
Obligations related to data privacy and security (and consumers' data privacy expectations) are quickly changing, becoming increasingly stringent, and creating uncertainty. Additionally, these obligations may be subject to differing applications and interpretations, which may be inconsistent or conflict among jurisdictions. Preparing for and complying with these obligations requires us to devote significant resources, which may necessitate changes to our services, information technologies, systems, and practices and to those of any third parties that process personal data on our behalf. In addition, these obligations may require us to change our business model.
We may at times fail (or be perceived to have failed) in our efforts to comply with our data privacy and security obligations. Moreover, despite our efforts, our personnel or third parties on whom we rely may fail to comply with such obligations, which could negatively impact our business operations. If we or the third parties on which we rely fail, or are perceived to have failed, to address or comply with applicable data privacy and security obligations, we could face significant consequences, including but not limited to: government enforcement actions (e.g., investigations, fines, penalties, audits, inspections, and similar); litigation (including class-action claims and mass arbitration demands); indemnification obligations; negative publicity; reputational harm; monetary fund diversions; diversion of management's attention; additional reporting requirements and/or oversight; bans on processing personal data; orders to destroy or not use personal data; and imprisonment of company officials. In particular, plaintiffs have become more active in bringing privacy-related claims against companies, including class claims and mass arbitration demands. Some of these claims allow for the recovery of statutory damages on a per violation basis, and, if viable, carry the potential for monumental statutory damages, depending on the volume of data and the number of violations.
Any of these events could have a material adverse effect on our reputation, business, or financial condition, including but not limited to: loss of customers; interruptions or stoppages in our business operations (including, as relevant, clinical trials); interruptions or stoppages of data collection needed to train our algorithms; inability to process personal data or to operate in certain jurisdictions; limited ability to develop or commercialize our products; expenditure of time and resources to defend any claim or inquiry; adverse publicity; or substantial changes to our business model or operations.