We collect, process, store and transmit large amounts of data, including confidential, sensitive, proprietary, business and personal information. The effectiveness of our technology, including our artificial intelligence ("AI") systems, and our ability to offer our products and services to sellers and buyers depends on the collection, storage and use of data concerning customer activity, including personally identifying or other sensitive data. Our collection and use of this data for targeted advertisements, product recommendations, data analytics and outreach communications might raise privacy and data protection concerns that could negatively impact the demand for our products and services. We use third-party technology and systems for encryption, employee email, content delivery to buyers and other functions. Although we have developed systems and processes designed to protect seller and buyer information and prevent and mitigate the impact of data breaches and other fraudulent activities (whether directly through us or indirectly through our sellers or buyers), such measures cannot guarantee the security of such data and may be circumvented or fail to operate as intended.
We may also be subject to claims or regulatory sanctions for actions of third parties that are beyond our control, such as the misrepresentation of information or other inappropriate or unlawful actions with respect to use and processing of buyer and seller data. In our seller agreements and buyer contracts, we have specific clauses where we explicitly deny any responsibility for actions by third parties or for the accuracy of information they provide to us, and such actions are violations of our terms and conditions to misuse our services. Nevertheless, there can be no assurance that these preventative measures will fully protect us from such actions, which, regardless of merit, may force us to participate in time-consuming and costly litigation or investigations, divert significant management and staff attention, and damage our reputation.
The Russian Parliament and Government enacted consumer data privacy and data protection laws and regulations on, among other things, the solicitation, collection, transfer, processing and use of personal data. Regulation of this nature could reduce demand for our products and services if we fail to design or develop our operations in a way to be compliant with the applicable regulations. The failure to prevent or mitigate data loss, theft, misuse or other security breaches or vulnerabilities affecting our or our sellers' and buyers' systems, could expose us or our customers to the risk of loss, disclosure or misuse of such information, could result in liability and expose us to litigation and regulatory action (including under privacy or data protection laws), deter buyers or sellers from using our platform and services, and otherwise harm our business and reputation.
In Russia, in order to process an individual's personal data, we must obtain the individual's consent. This consent may be revoked at any time and, if revoked, the relevant personal data must be deleted. We do not collect or perform any operations on our customers' personal data, except when such collection or processing is in accordance with our terms of services and privacy policies which are available on our websites. Subject to several exemptions, processors of personal data, including ourselves, must register as personal data operators with Roskomnadzor, the Russian regulatory authority for data protection. Roskomnadzor, among its other functions, ensures compliance with the data protection legislation and conducts scheduled and unscheduled audits to ensure such compliance, maintains the registers of personal data operators, infringers of personal data processing requirements and blocked websites, and initiates legal proceedings in case of violations and if required, the imposition of fines or other penalties. The trans-border transfer of personal data is allowed, subject to consent of the individual.
Under Russian law, processors of personal data are obliged to record, systematize, accumulate, store, clarify (update, modify) and retrieve Russian citizens' personal data using databases located only within Russia (subject to a limited number of exceptions), as well as to provide, upon request, Roskomnadzor with information regarding the location of databases containing the personal data of Russian citizens. A failure to comply with these legal requirements may result in restrictions on our operations, including restricting access to our Buyer Website and including OZON in the special register for infringers of personal data processing requirements, as well as significant fines (up to P6 million or P18 million for repeat violations). Roskomnadzor also conducts scheduled and unscheduled audits to ensure compliance with the personal data legislation and may initiate legal proceedings in case of violations.
Some of the legal restrictions may be subject to broad interpretation. For example, no standard definition of a "database" exists within the law and, under definitions contained in the Russian Civil Code (the "Civil Code"), a variety of documents and virtual objects (for example, Microsoft Office files) may be referred to as a database. Our information resources, including personal data, may be stored in a virtual environment (as part of our own cloud computing), which may significantly hinder the determination of the exact location of each virtual object and make it more difficult for us to provide the required information on the location within the required period.
In addition, Russia continues to develop its legal framework, including with respect to data privacy and data protection. See "-The legal framework governing e-commerce, data protection and related internet services in Russia is not well developed, and we may be subject to the newly adopted legislation, as well as the changes to the existing legislation, which may be costly to comply with or may limit our flexibility to run our business." Any uncertainties in the current Russian legislation on data privacy and data protection may be interpreted adversely to us by the Russian regulatory authorities and courts, and we may face liability for collection, processing, storage and transmission of personal data as a result, which could have a material adverse effect on our business, prospects, results of operations and financial condition.
Although we believe we are in compliance with these regulations, any change in the regulations or in their interpretation could make it costly, difficult or impossible for us to comply with them and may require us to incur significant efforts and resources.
If we were found in violation of any privacy or data protection laws or regulations, this could lead to legal liability, and our business may be materially and adversely affected, and we may have to change our business practices or potentially our products and services. In addition, such laws and regulations could impose significant costs on us and could make it more difficult for us to use our current technology. If a data breach were to occur, or if a violation of privacy or data protection laws and regulations were to be alleged, our platform may be perceived as less desirable, and our reputation, business, prospects, financial condition and results of operations could be materially and adversely affected.