In the ordinary course of business, we collect, receive, store, process, generate, use, transfer, disclose, make accessible, protect, secure, dispose of, transmit, and share (collectively, process or processing) personal data and other sensitive information, including proprietary and confidential business data, trade secrets, employee data, intellectual property, data we collect about trial participants in connection with clinical trials, and other sensitive third-party data (collectively, sensitive data). Our data processing activities may subject us to numerous data privacy and security obligations, such as various laws, regulations, guidance, industry standards, external and internal privacy and security policies, contractual requirements, and other obligations relating to data privacy and security.
Various federal, state, local and foreign legislative and regulatory bodies, or self-regulatory organizations, may expand current laws, rules or regulations, enact new laws, rules or regulations or issue revised rules or guidance regarding data privacy and security. In the United States, federal, state, and local governments have enacted numerous data privacy and security laws, including data breach notification laws, personal data privacy laws, consumer protection laws, e.g., Section 5 of the Federal Trade Commission Act, and other similar laws, e.g., wiretapping laws. HIPAA, as amended by the Health Information Technology for Economic and Clinical Health Act of 2009 and their respective implementing regulations (collectively, HIPAA), imposes certain privacy and security requirements for individually identifiable health information on certain entities, namely certain healthcare providers, health plans, and healthcare clearinghouses (covered entities) and their respective "business associates" who directly or as a subcontractor provide services involving the creation, use, maintenance or disclosure of individually identifiable health information on covered entities' behalf. As a clinical trial sponsor, we are not directly subject to HIPAA, but we do have relationships with providers and other entities subject to the law and thus must structure those relationships in a manner consistent with HIPAA requirements. If any of the physicians or other health care providers or entities with whom we expect to do business are found to be not in compliance with HIPAA or other applicable privacy laws, they may be subject to criminal, civil or administrative sanctions, including exclusions from government funded health care programs. If regulatory authorities challenge our activities, or those of a collaborator or other third party on which we rely, under HIPAA or other privacy laws applicable to the privacy and security of health information, any such challenge could have a material adverse effect on our reputation, business, results of operations and financial condition. Any investigation of or enforcement against us or the third parties with whom we contract, including a research collaborator, regardless of the outcome, would be costly and time consuming, and may negatively affect our ability to conduct clinical trials, results of operations and financial condition. Additionally, the California Consumer Privacy Act (CCPA) applies to personal information of consumers, business representatives, and employees, and among other things requires covered businesses to provide specific disclosures in privacy notices and honor requests of California residents to exercise certain privacy rights, including the right to opt out of certain disclosures of their information. The CCPA provides for civil penalties of up to $7,500 per violation as well as a private right of action with statutory damages for certain data breaches, thereby potentially increasing risks associated with a data breach. Although the law includes limited exceptions, including for certain information collected as part of clinical trials, the CCPA may impact our processing of personal information and increase our compliance costs. Additionally, the California Privacy Rights Act of 2020 (CPRA) significantly expands the CCPA, such as granting additional rights to California residents, including the right to correct personal information and additional opt-out rights. The CPRA also establishes a regulatory agency dedicated to enforcing the CCPA and the CPRA. Other states, such as Connecticut, Colorado, Indiana, Iowa, Texas and Utah, have also passed comprehensive privacy laws, and similar laws are being considered in several other states, as well as at the federal and local levels. While these state privacy laws, like the CCPA, also exempt some data processed in the context of clinical trials (and most also exempt employee and business personal data), these developments further complicate compliance efforts, and increase legal risk and compliance costs for us and the third parties upon whom we rely. The scope and enforcement of these laws is uncertain and subject to rapid change. For example, increasing concerns about health information privacy have recently prompted the federal government to take a newly expansive view of the scope of existing privacy laws and regulations. Congress and some states are considering (and in some cases have passed) new laws and regulations that further and more broadly protect the privacy and security of personal health information.
In addition to government activity, privacy advocacy groups and technology and other industries are considering various new, additional or different self-regulatory standards that may place additional burdens on us.
There are also various laws and regulations in other jurisdictions outside the United States relating to data privacy and security, with which we may need to comply. For example, the EU GDPR and the United Kingdom's equivalent (UK GDPR, and together with the EU GDPR, the GDPR), impose strict requirements for processing personal data. Notably, the EU GDPR and UK GDPR impose large penalties for noncompliance, including the potential for fines of up to €20 million under the EU GDPR / £17.5 million under the UK GDPR, or 4% of the annual global revenue of the noncompliant entity, whichever is greater. The EU GDPR and UK GDPR also provide for private litigation related to processing of personal data brought by classes of data subjects or consumer protection organizations authorized at law to represent their interests. Additionally, EU member states may introduce further conditions, including limitations, and make their own laws and regulations further limiting the processing of ‘special categories of personal data, including personal data related to health, biometric data used for unique identification purposes and genetic information, which could limit our ability to collect, use and share EU data, and could cause our compliance costs to increase, ultimately adversely affecting our business, financial condition, results of operations and prospects.
In addition to the GDPR and U.S. data privacy laws, virtually every international jurisdiction in which we operate has established its own legal framework relating to privacy, data protection, and information security matters to which we may also be subject. For example, we are also subject to laws in China. Under the Cybersecurity Law of the People's Republic of China (China's Cybersecurity Law), any collection, use, transfer and storage of personal information of a Chinese citizen through a network by the network operator should be based on the three principles of legitimacy, justification and necessity and requires the consent of the data subject. The rules, purposes, methods and ranges of such collection should also be disclosed to the data subject. China's data localization requirements are becoming increasingly common in sector-specific regulations, and laws including data localization requirements exist in many of the other jurisdictions in which we operate. For example, China's Cybersecurity Law requires operators of critical information infrastructure (CIIOs) to store personal information and important data collected and generated from the critical information infrastructure within China. Non-compliance with China's Cybersecurity Law can result in fines for the relevant entity as well as for the personnel directly responsible. On September 14, 2022, the Cyberspace Administration of China (CAC), China's top cybersecurity regulator, released new amendments to China's Cybersecurity Law for public consultation and if the amendments are passed, the amended law will increase the penalties for violations of cybersecurity obligations under the Cybersecurity Law to up to RMB 50 million, in line with those under the Data Security Law and PIPL.
Building on this, China's Data Security Law (Data Security Law) became effective on September 1, 2021. The primary purpose of the Data Security Law is to regulate data activities, safeguard data security, promote data development and usage, protect individuals and entities' legitimate rights and interests, and safeguard state sovereignty, state security and development interests. The Data Security Law applies extraterritorially, and to a broad range of activities that involve "data" (not only personal or sensitive data). Under the Data Security Law, entities and individuals carrying out data activities must abide by various data security obligations. For example, the Data Security Law proposes to classify and protect data based on the importance of data to the state's economic development, as well as the degree of harm it will cause to national security, public interests, or legitimate rights and interests of individuals or organizations when such data is tampered with, destroyed, leaked, or illegally acquired or used. The appropriate level of protective measures is required to be taken for each respective class of data. The Data Security Law also echoes the data localization requirement in the Cybersecurity Law and requires important data to be stored locally in China. Such important data may only be transferred outside of China subject to compliance with certain data transfer restrictions, such as passing a security assessment organized by the relevant authorities.
The Cybersecurity Review Measures, which took effect on February 15, 2022 in China, clarify when entities must apply for a mandatory cybersecurity review from the Chinese government authorities. These circumstances include (i) when CIIOs purchase network products that may affect national security, (ii) when a network platform operator's data processing activities may affect national security, or (iii) when a network platform operator holds personal information of more than one million individuals and plans on listing publicly outside China. Network platform operators are not defined under the Cybersecurity Review Measures, but are understood to be broadly interpreted to include all Internet platform operators or service providers, thus providing for a broad application. A mandatory cybersecurity review is likely to prolong the timeline of any contemplated listing timeline outside China and increase the regulatory compliance burden on entities that are subject to this requirement. At this time, the Company does not act as a network platform operator and does not hold the personal information of more than one million individuals in China, and as such, we do not believe the Company would be subject to the Cybersecurity Review Measures. However, the relevant Chinese authorities have great discretion and it is generally uncertain as to how they may interpret and enforce the Cybersecurity Review Measures in practice.
Additionally, on August 20, 2021, China announced the Personal Information Protection Law (PIPL), which took effect on November 1, 2021. The PIPL is intended to clarify the scope of application, the definitions of personal information and sensitive personal information, the legality of personal information processing and the basic requirements of notice and consent, among other things. The PIPL also sets out data localization requirements for CIIOs and personal information processors who process personal information above a certain threshold prescribed by the relevant authorities. The PIPL also includes a list of rules which must be complied with prior to the transfer of personal information outside of China, such as compliance with a security assessment or certification by an agency designated by the relevant authorities or entering into standard form model contracts approved by the relevant authorities with the overseas recipient.
On July 7, 2022, the CAC issued Security Assessment Measures for Outbound Data Transfers, which became effective on September 1, 2022. The Security Assessment Measures for Outbound Data Transfers clarifies the security assessment requirement under the PIPL and requires a data processor to apply for the security assessment organized by the CAC under any of the following circumstances before the information is transferred outbound: (i) where a data processor provides key data overseas, (ii) critical information infrastructure operator and personal information processors who process more than one million individuals' personal information; (iii) where a data processor has cumulatively provided personal information of over 100,000 individuals or sensitive personal information of over 10,000 individuals in total abroad since January 1st of the previous year. Additionally, on November 18, 2022, the CAC and the State Administration of Market Regulation issued the Implementation Rules for Personal Information Protection Certification which apply with immediate effect and which provide important guidance on obtaining a personal information certification for lawful cross-border transfer of personal information under the PIPL.
Notably, the PIPL, similar to both the GDPR and certain U.S. privacy laws, applies extraterritorially. Failure to comply with PIPL can result in fines of up to RMB 50 million or 5% of the prior year's total annual revenue for the personal information processor and/or a suspension of services or data processing activities. Other potential penalties include a fine of up to RMB 1 million on the person in charge or directly responsible personnel and, in serious cases, individuals and entities may be exposed to criminal liabilities under other local Chinese law, such as the Criminal Law of the People's Republic of China. The PIPL also prohibits responsible personnel for violations of the PIPL from holding high level management or data protection officer positions in relevant enterprises.
In addition to China's Cybersecurity Law, the Data Security Law and the PIPL, the government agencies of China promulgated several regulations or released a number of draft regulations for public comments which are designed to provide further implemental guidance in accordance with the laws mentioned above. We cannot predict what impact the new laws and regulations or the increased costs of compliance, if any, will have on our operations in China, in particular the Data Security Law or PIPL, or the increased costs of compliance, if any, will have on our operations in China due to their recent enactment and the limited guidance available on their scope and applicability, particularly on PIPL. It is also generally unclear how the laws will be interpreted and enforced in practice by the relevant government authorities as often the abovementioned laws are drafted broadly and thus leaves great discretion to the relevant government authorities to exercise.
The evolving and overarching complexity of privacy and data protection laws and regulations around the world may require us to design, implement and maintain different types of state- or country-based, privacy-related compliance controls and programs simultaneously in multiple jurisdictions, thereby further increasing the complexity and cost of compliance. These costs, including others relating to increased regulatory oversight and compliance, could materially and adversely affect our business or our growth plans and result in damages or liability in other forms as a result of failure to implement proper programmatic controls, failure to adhere to those controls, or the malicious or inadvertent breach of applicable privacy and data protection requirements by us, our employees, our business partners, or our customers.
In addition, we may be unable to transfer personal data from Europe and other jurisdictions to the United States or other countries due to data localization requirements or limitations on cross-border data flows. Europe and other jurisdictions have enacted laws requiring data to be localized or limiting the transfer of personal data to other countries. In particular, the European Economic Area (EEA) and the UK have significantly restricted the transfer of personal data to the United States and other countries whose privacy laws it believes are inadequate.
Other jurisdictions may adopt similarly stringent interpretations of their data localization and cross-border data transfer laws. Although there are currently various mechanisms that may be used to transfer personal data from the EEA and the UK to the United States in compliance with law, such as the EEA and UK's standard contractual clauses, these mechanisms are subject to legal challenges, and there is no assurance that we can satisfy or rely on these measures to lawfully transfer personal data to the United States. If there is no lawful manner for us to transfer personal data from the EEA, the UK or other jurisdictions to the United States, or if the requirements for a legally-compliant transfer are too onerous, we could face significant adverse consequences, including the interruption or degradation of our operations, the need to relocate part of or all of our business or data processing activities to other jurisdictions at significant expense, increased exposure to regulatory actions, substantial fines and penalties, the inability to transfer data and work with partners, vendors and other third parties, and injunctions against our processing or transferring of personal data necessary to operate our business. Additionally, companies that transfer personal data out of the EEA and the UK to other jurisdictions, particularly to the United States, are subject to increased scrutiny from regulators, individual litigants, and activist groups. Some European regulators have ordered certain companies to suspend or permanently cease certain transfers out of Europe for allegedly violating the EU GDPR's cross-border data transfer limitations.
In addition to data privacy and security laws, we are also bound by other contractual obligations related to data privacy and security, and our efforts to comply with such obligations may not be successful.
Each of these laws, rules, regulations and contractual obligations relating to data privacy and security, and any other such changes or new laws, rules, regulations or contractual obligations could impose significant limitations, require changes to our business, or restrict our collection, use, storage or processing of personal information, which may increase our compliance expenses and make our business more costly or less efficient to conduct. In addition, any such changes could compromise our ability to develop an adequate marketing strategy and pursue our growth strategy effectively or even prevent us from providing certain products in jurisdictions in which we currently operate and in which we may operate in the future or incur potential liability in an effort to comply with such legislation, which, in turn, could adversely affect our business, financial condition, results of operations and prospects. Complying with these numerous, complex and often changing laws, regulations and contractual requirements is expensive and difficult, and suspected and actual failure to comply with any data privacy or security requirements, whether by us, one of our CROs, business partners or another third party, could adversely affect our business, financial condition, results of operations and prospects, including but not limited to: investigation costs; material fines and penalties; compensatory, special, punitive and statutory damages; litigation; consent orders regarding our privacy and security practices; requirements that we provide notices, credit monitoring services and/or credit restoration services or other relevant services to impacted individuals; adverse actions against our licenses to do business; reputational damage; and injunctive relief. The recent implementation of the CCPA, EU GDPR and UK GDPR have increased our responsibility and liability in relation to personal data that we process, including in clinical trials, and we may in the future be required to put in place additional mechanisms to ensure compliance with the CCPA and other applicable state laws, EU GDPR and UK GDPR and other applicable laws and regulations, which could divert management's attention and increase our cost of doing business. In addition, new regulation or legislative actions regarding data privacy and security (together with applicable industry standards) may increase our costs of doing business. In this regard, we expect that there will continue to be new proposed laws, regulations and industry standards relating to privacy and data protection in the United States, the EEA and other jurisdictions, and we cannot determine the impact such future laws, regulations and standards may have on our business.
Any actual or perceived failure by us or our third-party service providers to comply with any federal, state or foreign laws, rules, regulations, industry self-regulatory principles, industry standards or codes of conduct, regulatory guidance, orders to which we may be subject or other legal obligations relating to privacy, data protection, data security or consumer protection could adversely affect our reputation, brand and business. We may also be contractually required to indemnify and hold harmless third parties from the costs or consequences of non-compliance with any standards, laws, rules and regulations or other legal obligations relating to privacy or any inadvertent or unauthorized use or disclosure of data that we store or handle as part of operating our business. Any of these events could adversely affect our reputation, business, or financial condition, including but not limited to: loss of customers; interruptions or stoppages in our business operations (including clinical trials); inability to process personal data or to operate in certain jurisdictions; limited ability to develop or commercialize our products; expenditure of time and resources to defend any claim or inquiry; adverse publicity; or substantial changes to our business model or operations. We cannot assure you that our CROs, CMOs or other third-party service providers with access to our or our suppliers', manufacturers', collaborators', trial participants' and employees' sensitive information in relation to which we are responsible will not breach contractual obligations imposed by us, or that they will not experience data security incidents, which could have a corresponding effect on our business, including putting us in breach of our obligations under privacy laws and regulations and/or which could in turn adversely affect our business, financial condition, results of operations and prospects. We cannot assure you that our contractual measures and our own privacy and security-related safeguards will protect us from the risks associated with the third-party processing of such information. Any of the foregoing could adversely affect our business, financial condition, results of operations and prospects.
We also publicly post our privacy policies and practices concerning our collection, use, disclosure and other processing of the personal information provided to us by our website visitors and by our customers. Although we endeavor to comply with our public statements and documentation, we may at times fail to do so or be perceived to have failed to do so. Our publication of our privacy policies and other statements we publish that provide promises and assurances about privacy and security can subject us to potential state and federal action if they are found to be deceptive, unfair or misrepresentative of our actual practices. Any actual or perceived failure by us to comply with federal, state or foreign laws, rules or regulations, industry standards, contractual or other legal obligations, or any actual, perceived or suspected cybersecurity incident, whether or not resulting in unauthorized access to, or acquisition, release or transfer of personal information or other data, may result in enforcement actions and prosecutions, private litigation, significant fines, penalties and censure, claims for damages by customers and other affected individuals, regulatory inquiries and investigations or adverse publicity and could cause our customers and collaborators to lose trust in us, any of which could adversely affect our business, financial condition, results of operations and prospects.
The successful assertion of one or more large claims against us that exceeds our available insurance coverage, or results in changes to our insurance policies (including premium increases or the imposition of large deductible or co-insurance requirements), could have an adverse effect on our business. In addition, we cannot be sure that our existing insurance coverage will continue to be available on acceptable terms or that our insurers will not deny coverage as to any future claim.