The global data protection landscape is rapidly evolving, and we are or may become subject to numerous state, federal and ex-U.S. laws, requirements and regulations governing the collection, use, disclosure, retention, and security of personal information, such as information that we may collect in connection with clinical trials. Implementation standards and enforcement practices are likely to remain uncertain for the foreseeable future, and we cannot yet determine the impact future laws, regulations, standards, or perception of their requirements may have on our business. This evolution may create uncertainty in our business, affect our ability to operate in certain jurisdictions or to collect, store, transfer use and share personal information, necessitate the acceptance of more onerous obligations in our contracts, result in liability or impose additional costs on us. The cost of compliance with these laws, regulations and standards is high and is likely to increase in the future. Any failure or perceived failure by us to comply with federal, state or ex-U.S. laws or regulations, our internal policies and procedures or our contracts governing our processing of personal information could result in negative publicity, government investigations and enforcement actions, claims by third parties and damage to our reputation, any of which could have a material adverse effect on our business, results of operation, and financial condition.
In the United States, HIPAA imposes, among other things, certain standards relating to the privacy, security, transmission and breach reporting of individually identifiable health information. We do not believe that we are currently acting as a covered entity or business associate under HIPAA and thus are not directly subject to its requirements or penalties, but we may obtain health information from third parties (including research institutions from which we obtain clinical trial data) that are subject to privacy and security requirements under HIPAA. Depending on the facts and circumstances, we could be subject to significant penalties if we violate HIPAA. For example, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, or collectively, the CCPA, requires covered businesses that process the personal information of California residents to, among other things: provide certain disclosures to California residents regarding the business's collection, use, and disclosure of their personal information; receive and respond to requests from California residents to access, delete, and correct their personal information, or to opt out of certain disclosures of their personal information, and enter into specific contractual provisions with service providers that process California resident personal information on the business's behalf. Similar laws have passed in other states, and are continuing to be proposed at the state and federal level, reflecting a trend toward more stringent privacy legislation in the United States. The enactment of such laws could have potentially conflicting requirements that would make compliance challenging. In the event that we are subject to or affected by HIPAA, the CCPA or other domestic privacy and data protection laws, any liability from failure to comply with the requirements of these laws could adversely affect our financial condition.
Our operations abroad may also be subject to increased scrutiny or attention from data protection authorities. For instance, the EU General Data Protection Regulation, or GDPR, went into effect in May 2018 and imposes strict requirements for processing the personal data of individuals within the European Economic Area, or the EEA, or in the context of our activities in the EEA. In addition, some of the personal data we process in respect of clinical trial participants is special category or sensitive personal data under the GDPR, and subject to additional compliance obligations and to local law derogations. Companies that must comply with the GDPR face increased compliance obligations and risk, including more robust regulatory enforcement of data protection requirements, administrative penalties and potential fines for noncompliance of up to €20 million or 4% of the annual global revenues of the noncompliant company, whichever is greater. In addition to fines, a breach of the GDPR may result in regulatory investigations, reputational damage, orders to cease/change our data processing activities, enforcement notices, assessment notices (for a compulsory audit) and/or civil claims (including class actions). Among other requirements, the GDPR regulates transfers of personal data subject to the GDPR to third countries that have not been found to provide adequate protection to such personal data, including the United States, and the efficacy and longevity of current transfer mechanisms between the EEA and the United States remains uncertain. On July 10, 2023, the European Commission adopted its Adequacy Decision in relation to the new EU-US Data Privacy Framework, or the DPF, rendering the DPF effective as a GDPR transfer mechanism to U.S. entities self-certified under the DPF. We currently rely on the EU standard contractual clauses, the UK Addendum to the EU standard contractual clauses and the UK International Data Transfer Agreement, as relevant, to transfer personal data outside the EEA and the UK, including to the United States, with respect to both intragroup and third party transfers. We may also rely on individual consent to transfer personal data in certain circumstances. We expect the existing legal complexity and uncertainty regarding international personal data transfers to continue. In particular, we expect the DPF Adequacy Decision to be challenged and international transfers to the United States and to other jurisdictions more generally to continue to be subject to enhanced scrutiny by regulators. As a result, we may have to make certain operational changes, and we will have to implement revised standard contractual clauses and other relevant documentation for existing data transfers within required time frames.
Further, from January 1, 2021, we have had to comply with both the GDPR and also the UK GDPR, which, together with the amended UK Data Protection Act 2018, retains the GDPR in United Kingdom national law. The UK GDPR mirrors the fines under the GDPR, i.e., fines up to the greater of £17.5 million or 4% of global turnover. On October 12, 2023, the UK Extension to the DPF came into effect (as approved by the UK Government), as a data transfer mechanism from the UK to U.S. entities self-certified under the DPF. As we continue to expand into other foreign countries and jurisdictions, we may be subject to additional laws and regulations that may affect how we conduct business.