Consumer personal privacy and data security have become significant issues and the subject of rapidly evolving regulation in the U.S. Furthermore, federal, state and local government bodies or agencies have in the past adopted, and may in the future adopt, more laws and regulations affecting data privacy. For example, the state of California enacted the California Consumer Privacy Act of 2018 ("CCPA"), and California voters recently approved the California Privacy Rights Act ("CPRA"). The CCPA creates individual privacy rights for consumers and places increased privacy and security obligations on entities handling the personal data of consumers or households. The CCPA went into effect in January 2020, and it requires covered companies to provide new disclosures to California consumers, provides such consumers, business-to-business contacts and employees new ways to opt-out of certain sales of personal information, and allows for a new private right of action for data breaches. The CPRA modifies the CCPA and imposes additional data protection obligations on companies doing business in California, including additional consumer rights processes and opt outs for certain uses of sensitive data. The CCPA and the CPRA may significantly impact Complete Solaria's business activities and require substantial compliance costs that adversely affect its business, operating results, prospects and financial condition. To date, we have not experienced substantial compliance costs in connection with fulfilling the requirements under the CCPA or CPRA. However, we cannot be certain that compliance costs will not increase in the future with respect to the CCPA and CPRA or any other recently passed consumer privacy regulation.
Outside the U.S., an increasing number of laws, regulations, and industry standards may govern data privacy and security. For example, the European Union's General Data Protection Regulation ("EU GDPR") and the United Kingdom's GDPR ("UK GDPR") impose strict requirements for processing personal data. Under the EU GDPR, companies may face temporary or definitive bans on data processing and other corrective actions; fines of up to 20 million Euros or 4% of annual global revenue, whichever is greater; or private litigation related to processing of personal data brought by classes of data subjects or consumer protection organizations authorized at law to represent their interests. Non-compliance with the UK GDPR may result in substantially similar adverse consequences to those in relation to the EU GDPR, including monetary penalties of up to £17.5 million or 4% of worldwide revenue, whichever is higher.
In addition, we may be unable to transfer personal data from Europe and other jurisdictions to the U.S. or other countries due to data localization requirements or limitations on cross-border data flows. Europe and other jurisdictions have enacted laws requiring data to be localized or limiting the transfer of personal data to other countries. In particular, the European Economic Area ("EEA") and the United Kingdom have significantly restricted the transfer of personal data to the U.S. and other countries whose privacy laws it believes are not adequate. Other jurisdictions may adopt similarly stringent interpretations of their data localization and cross- border data transfer laws. Although there are currently various mechanisms that may be used to transfer personal data from the EEA and UK to the U.S. in compliance with law, such as the EEA and UK's standard contractual clauses, these mechanisms are subject to legal challenges, and there is no assurance that Complete Solaria can satisfy or rely on these measures to lawfully transfer personal data to the U.S. If there is no lawful manner for us to transfer personal data from the EEA, the UK, or other jurisdictions to the U.S., or if the requirements for a legally-compliant transfer are too onerous, we could face significant adverse consequences, including the interruption or degradation of its operations, the need to relocate part of or all of its business or data processing activities to other jurisdictions at significant expense, increased exposure to regulatory actions, substantial fines and penalties, the inability to transfer data and work with partners, vendors and other third parties, and injunctions against its processing or transferring of personal data necessary to operate its business. Some European regulators have ordered certain companies to suspend or permanently cease certain transfers out of Europe for allegedly violating the EU GDPR's cross-border data transfer limitations.
Any inability to adequately address privacy and security concerns, even if unfounded, or comply with applicable privacy and data security laws, regulations and policies, could result in additional cost and liability to us damage our reputation, inhibit sales and adversely affect our business. Furthermore, the costs of compliance with, and other burdens imposed by, the laws, regulations and policies that are applicable to our business may limit the use and adoption of, and reduce the overall demand for, its solutions. If we are not able to adjust to changing laws, regulations and standards related to privacy or security, our business may be harmed.