The global data protection landscape is rapidly evolving, and we are or may become subject to numerous state, federal and foreign laws, requirements and regulations governing the collection, use, disclosure, retention, and security of personal information, such as information that we may collect in connection with clinical trials in the U.S. and abroad. Implementation standards and enforcement practices are likely to remain uncertain for the foreseeable future, and we cannot yet determine the impact future laws, regulations, standards, or perception of their requirements may have on our business. This evolution may create uncertainty in our business, affect our ability to operate in certain jurisdictions or to collect, store, transfer use and share personal information, necessitate the acceptance of more onerous obligations in our contracts, result in liability or impose additional costs on us. Compliance with these privacy and data security requirements is rigorous and time-intensive and may increase our cost of doing business. Any failure or perceived failure by us to comply with federal, state or foreign laws or regulations, our internal policies and procedures or our contracts governing our processing of personal information could result in negative publicity, fines and penalties, litigation and reputational harm, which could materially and adversely affect our business, financial condition and results of operations.
In the United States, we and our partners may be subject to numerous federal and state laws and regulations, including state data breach notification laws, state health information privacy laws, and federal and state consumer protection laws and regulations, that govern the collection, use, disclosure, and protection of health-related and other personal information could apply to our operations or the operations of our partners. In addition, we may obtain health information from third parties (including research institutions from which we obtain clinical trial data) that are subject to privacy and security requirements under the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations (collectively, "HIPAA"). Depending on the facts and circumstances, we could be subject to criminal penalties if we knowingly obtain, use, or disclose individually identifiable health information maintained by a HIPAA covered entity in a manner that is not authorized or permitted by HIPAA.
Even when HIPAA does not apply, according to the Federal Trade Commission ("FTC"), failing to take appropriate steps to keep consumers' personal information secure constitutes unfair acts or practices in or affecting commerce in violation of Section 5(a) of the Federal Trade Commission Act. The FTC expects a company's data security measures to be reasonable and appropriate in light of the sensitivity and volume of consumer information it holds, the size and complexity of its business, and the cost of available tools to improve security and reduce vulnerabilities. The FTC has authority to initiate enforcement actions against entities that make deceptive statements about privacy and data sharing in privacy policies, fail to limit third-party use of personal health information, fail to implement policies to protect personal health information or engage in other unfair practices that harm customers or that may violate Section 5(a) of the FTC Act. Additionally, federal and state consumer protection laws are increasingly being applied by the FTC and states' attorneys general to regulate the collection, use, storage, and disclosure of personal information, through websites or otherwise, and to regulate the presentation of website content.
In addition, state laws govern the privacy and security of personal information in certain circumstances, many of which differ from each other in significant ways and may not have the same requirements, thus complicating compliance efforts. By way of example, California enacted the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, the "CCPA"), which requires covered businesses that process the personal information of California residents to, among other things: (i) provide certain disclosures to California residents regarding the business's collection, use, and disclosure of their personal information; (ii) receive and respond to requests from California residents to access, delete, and correct their personal information, or to opt out of certain disclosures of their personal information; and (iii) enter into specific contractual provisions with service providers that process California resident personal information on the business's behalf. Similar laws have passed in other states and are continuing to be proposed at the state and federal level, reflecting a trend toward more stringent privacy legislation in the United States. The enactment of such laws could have potentially conflicting requirements that would make compliance challenging. In the event that we are subject to or affected by HIPAA, the CCPA or other domestic privacy and data protection laws, any liability from failure to comply with the requirements of these laws could adversely affect our business and financial condition.
In addition, the regulatory framework for the receipt, collection, processing, use, safeguarding, sharing and transfer of personal data is rapidly evolving and is likely to remain uncertain for the foreseeable future as new global privacy rules are being enacted and existing ones are being updated and strengthened. For example, on May 25, 2018, the General Data Protection Regulation ("GDPR") took effect. The GDPR is applicable in each EEA member state and applies to companies established in the EEA as well as companies that collect and use personal data to offer goods or services to, or monitor the behavior of, individuals in the EEA, including, for example, through the conduct of clinical trials. GDPR introduces more stringent data protection obligations for processors and controllers of personal data. Among other things, the GDPR requires the establishment of a lawful basis for the processing of data, includes requirements relating to the consent of the individuals to whom the personal data relates, including detailed notices for clinical trial subjects and investigators, as well as requirements regarding the security of personal data and notification of data processing obligations or security incidents to appropriate data protection authorities or data subjects. The GDPR regulates transfers of personal data subject to the GDPR to third countries that have not been found to provide adequate protection to such personal data, including the United States; and the efficacy and longevity of current transfer mechanisms between the EEA and the United States remains uncertain. Case law from the Court of Justice of the European Union ("CJEU") states that reliance on the standard contractual clauses - a standard form of contract approved by the European Commission as an adequate personal data transfer mechanism - alone may not necessarily be sufficient in all circumstances and that transfers must be assessed on a case-by-case basis. On July 10, 2023, the European Commission adopted its Adequacy Decision in relation to the new EU-US Data Privacy Framework ("DPF") rendering the DPF effective as a GDPR transfer mechanism to U.S. entities self-certified under the DPF. We expect the existing legal complexity and uncertainty regarding international personal data transfers to continue. In particular, we expect the DPF Adequacy Decision to be challenged and international transfers to the United States and to other jurisdictions more generally to continue to be subject to enhanced scrutiny by regulators. As a result, we may have to make certain operational changes and we will have to implement revised standard contractual clauses and other relevant documentation for existing data transfers within required time frames. Penalties and fines for failure to comply with GDPR are significant, including fines of up to €20 million or 4% of the total worldwide annual turnover of a non-compliant undertaking, whichever is higher. In addition to fines, a breach of the GDPR may result in regulatory investigations, reputational damage, orders to cease/ change our data processing activities, enforcement notices, assessment notices (for a compulsory audit) and/ or civil claims (including class actions).
Further, since the beginning of 2021, we have also been subject to the United Kingdom General Data Protection Regulation and Data Protection Act 2018, which collectively imposes separate but similar obligations to those under the GDPR and comparable penalties, including fines of up to £17.5 million or 4% of a noncompliant undertaking's global annual revenue for the preceding financial year, whichever is greater. On October 12, 2023, the U.K. Extension to the DPF came into effect (as approved by the U.K. government), as a data transfer mechanism from the U.K. to U.S. entities self-certified under the DPF. Other foreign jurisdictions are increasingly implementing or developing their own privacy regimes with complex and onerous compliance obligations and robust regulatory enforcement powers. As we continue to expand into other foreign countries and jurisdictions, we may be subject to additional laws and regulations that may affect how we conduct business.
Although we work to comply with applicable laws, regulations and standards, our contractual obligations and other legal obligations, these requirements are evolving and may be modified, interpreted and applied in an inconsistent manner from one jurisdiction to another, and may conflict with one another or other legal obligations with which we must comply. Any failure or perceived failure by us or our employees, representatives, contractors, consultants or other third parties to comply with such requirements or adequately address privacy and security concerns, even if unfounded,could result in additional cost and liability to us, damage our reputation, and have a material adverse effect on our business, financial condition and results of operations.