We maintain a quantity of sensitive information, including confidential business and patient health information in connection with our clinical trials, and are subject to U.S. and international laws and regulations governing the privacy and security of such information. Each of these laws is subject to varying interpretations and constantly evolving. In the United States, there are numerous federal and state privacy and data security laws and regulations governing the collection, use, disclosure and protection of personal information, including federal and state health information privacy laws, federal and state security breach notification laws, and federal and state consumer protection laws. In contrast, the EU and United Kingdom ("UK") GDPR, which applies extraterritorially, imposes several strict requirements for controllers and processors of personal information. These include higher standards for obtaining consent from individuals to process their personal information, increased requirements pertaining to the processing of special categories of personal information (such as health information) and pseudonymized (i.e., key-coded) data, and heightened transfer requirements of personal information from the European Economic Area/UK/Switzerland to countries not deemed to have adequate data protections laws. The GDPR also provides that countries in the European Economic Area may establish their own laws and regulations further restricting the processing of certain personal information, including genetic data, biometric data, and health data. Companies that must comply with the GDPR face increased compliance obligations and risk, including more robust regulatory enforcement of data protection requirements and potential fines for noncompliance of up to €20 million (approximately $22.6 million) or 4 percent of the annual global revenues of the noncompliant company, whichever is greater.
In the United States, in addition to HIPAA, various federal (for example, the Federal Trade Commission) and state regulators have adopted, or are considering adopting, laws and regulations concerning personal information and data security. Certain state laws may be more stringent or broader in scope, or offer greater individual rights, with respect to personal information than federal, international, or other state laws, and such laws may differ from each other, all of which may complicate compliance efforts. For example, California enacted the California Consumer Privacy Act (the "CCPA"), later amended by ballot measure through the California Privacy Rights Act (the "CPRA"). Failure to comply with the CCPA and the CPRA may result in significant civil penalties, injunctive relief, or statutory or actual damages as determined by the California Privacy Protection Agency and California Attorney General through its investigative authority. Many other states have or are considering enacting comparable consumer privacy laws. Compliance with this new privacy legislation may result in additional costs and expense of resources to maintain compliance. There is also discussion in the U.S. of a new comprehensive federal data privacy law to which we would become subject if it is enacted.
We cannot provide assurance that (i) current or future legislation will not prevent us from generating or maintaining personal information, or (ii) patients will consent to the use of their personal information (as necessary). Either of these circumstances may prevent us from undertaking or continuing essential research and development, manufacturing, and commercialization, which could have a material adverse effect on our business, results of operations, financial condition, and prospects.
Federal, state, and foreign government requirements include obligations to notify regulators and/or individuals of security breaches or other similar reportable incidents experienced by us, or our vendors, contractors, or organizations with whom we had specific contractual obligations to protect our data. Further, the improper access to, use of, or disclosure of our data or a third-party's personal information could subject us to individual or consumer class action litigation and governmental investigations and proceedings by federal, state, and local regulatory entities in the U.S. and by international regulatory entities. Compliance with these and any other applicable privacy and data security laws and regulations is a rigorous and time-intensive process, and we may be required to put in place additional mechanisms ensuring compliance with existing and new data protection rules and possible government oversight.
In addition to government regulation, privacy advocates and industry groups have and may in the future propose self-regulatory standards from time to time. These and other industry standards may legally or contractually apply to us, or we may elect to comply with such standards. It is possible that if our practices are not consistent or viewed as not consistent with legal and regulatory requirements, including changes in laws, regulations and standards or new interpretations or applications of existing laws, regulations and standards, we may become subject to audits, inquiries, whistleblower complaints, adverse media coverage, investigations, loss of export privileges, or severe criminal or civil sanctions, all of which may have a material adverse effect on our business, operating results, reputation, and financial condition. All of these evolving compliance and operational requirements impose significant costs, such as costs related to organizational changes, implementing additional protection technologies, training employees and engaging consultants, which are likely to increase over time. In addition, such requirements may require us to modify our data processing practices and policies, distract management or divert resources from other initiatives and projects, all of which could have a material adverse effect on our business, financial condition, results of operations and prospects. Any failure or perceived failure by us to comply with any applicable federal, state, or similar foreign laws and regulations relating to data privacy and security could result in damage to our reputation, as well as proceedings or litigation by governmental agencies or other third parties, including class action privacy litigation in certain jurisdictions, which would subject us to significant fines, sanctions, awards, injunctions, penalties, or judgments. Any of the foregoing could have a material adverse effect on our business, results of operations, financial condition, and prospects.