The global data protection landscape is rapidly evolving, and we are or may become subject to numerous state, federal and foreign laws, requirements and regulations governing the collection, use, disclosure, retention, and security of personal data, such as information that we may collect in connection with clinical trials in the U.S. and abroad. Implementation standards and enforcement practices are likely to remain uncertain for the foreseeable future, and we cannot yet determine the impact future laws, regulations, standards, or perception of their requirements may have on our business. This evolution may create uncertainty in our business, affect our ability to operate in certain jurisdictions or to collect, store, transfer use and share personal information, necessitate the acceptance of more onerous obligations in our contracts, result in liability or impose additional costs on us. The cost of compliance with these laws, regulations and standards can be high and is likely to increase in the future. Any failure or perceived failure by us to comply with federal, state or foreign laws or regulation, our internal policies and procedures or our contracts governing our processing of personal information could result in negative publicity, government investigations and enforcement actions, claims by third parties and damage to our reputation, any of which could have a material adverse effect on our operations, financial performance and business.
As our operations and business grow, we may become subject to or affected by new or additional data protection laws and regulations and face increased scrutiny or attention from regulatory authorities. In the U.S., HIPAA, as amended by the Health Information Technology for Economic and Clinical Health Act of 2009 and their implementing regulations, imposes, among other things, certain standards relating to the privacy, security, transmission and breach reporting of individually identifiable health information on covered entities (defined as health plans, health care clearinghouses and certain health care providers) and their respective business associates, individuals or entities that create, receive, maintain or transmit protected health information in connection with providing a service for or on behalf of a covered entity. HIPAA mandates the reporting of certain breaches of health information to the Department of Health and Human Services ("HHS"), affected individuals and if the breach is large enough, the media. Most healthcare providers, including research institutions from which we obtain patient health information, are subject to privacy and security regulations promulgated under HIPAA. While we do not believe that we are currently acting as a covered entity or business associate under HIPAA and thus are not directly regulated under HIPAA, any person may be prosecuted under HIPAA's criminal provisions either directly or under aiding-and-abetting or conspiracy principles. Consequently, depending on the facts and circumstances, we could face substantial criminal penalties if we knowingly receive individually identifiable health information from a HIPAA-covered healthcare provider or research institution that has not satisfied HIPAA's requirements for disclosure of individually identifiable health information.
Certain states have also adopted comparable privacy and security laws and regulations, some of which may be more stringent than HIPAA. Such laws and regulations will be subject to interpretation by various courts and other governmental authorities, thus creating potentially complex compliance issues for us and our future customers and strategic partners. For example, California enacted the California Consumer Privacy Act of 2018 ("CCPA"), which went into effect on January 1, 2020. The CCPA creates individual privacy rights for California consumers and increases the privacy and security obligations of entities handling certain personal information. The CCPA provides for civil penalties for violations, as well as a private right of action for data breaches that has increased the likelihood of, and risks associated with, data breach litigation. Further, the California Privacy Rights Act ("CPRA") generally went into effect on January 1, 2023, and significantly amends the CCPA. The CPRA imposes additional data protection obligations on covered businesses, including additional consumer rights processes, limitations on data uses, new audit requirements for higher risk data, and opt outs for certain uses of sensitive data. It also creates a new California data protection agency authorized to issue substantive regulations and could result in increased privacy and information security enforcement. Similar laws have passed in a number of states, and have been proposed in other states and at the federal level, reflecting a trend toward more stringent privacy legislation in the United States. The enactment of such laws could have potentially conflicting requirements that would make compliance challenging. In the event that we are subject to or affected by HIPAA, the CCPA, the CPRA or other domestic privacy and data protection laws, any liability from failure to comply with the requirements of these laws could adversely affect our financial condition.
In Europe, the European Union General Data Protection Regulation ("GDPR") went into effect in May 2018 and imposes strict requirements for processing the personal data of individuals within the European Economic Area ("EEA"). Companies that must comply with the GDPR face increased compliance obligations and risk, including more robust regulatory enforcement of data protection requirements, and potential fines for noncompliance of up to €20 million or 4% of the annual global revenues of the noncompliant company, whichever is greater. Since January 1, 2021 we have also been subject to compliance with the GDPR and the UK GDPR, which, together with the amended UK Data Protection Act 2018, retains the GDPR in UK national law. The UK GDPR mirrors the fines under the GDPR, i.e., fines up to the greater of €20 million/ £17 million or 4% of global turnover.
Legal developments in Europe have created complexity and uncertainty regarding transfers of personal data from the EEA and the UK to the U.S. Most recently, on July 16, 2020, the Court of Justice of the European Union ("CJEU") invalidated the EU-US Privacy Shield Framework, also known as the Privacy Shield, under which personal data could be transferred from the EEA to US entities who had self-certified under the Privacy Shield scheme. In March 2022, the U.S. and EU announced a new regulatory regime intended to replace the invalidated regulations; however, this new EU-US Data Privacy Framework has not been implemented beyond an executive order signed by President Biden on October 7, 2022 on Enhancing Safeguards for Untied States Signals Intelligence Activities. European court and regulatory decisions subsequent to the CJEU decision of July 16, 2020 have taken a restrictive approach to international data transfers. Additionally, the EU adopted the EU Clinical Trials Regulation, which came into effect on January 31, 2022. This regulation imposes obligations on the use of data generated from clinical trials and enables European patients to have the opportunity to access information about clinical trials.
These recent developments may require us to review and amend the legal mechanisms by which we make and/or receive personal data transfers to/in the U.S. As supervisory authorities issue further guidance on personal data export mechanisms, including circumstances where the standard contractual clauses cannot be used, and/or start taking enforcement action, we could suffer additional costs, complaints and/or regulatory investigations or fines, and/or if we are otherwise unable to transfer personal data between and among countries and regions in which we operate, it could affect the manner in which we provide our services, the geographical location or segregation of our relevant systems and operations, and could adversely affect our financial results.
Despite our efforts to monitor evolving social media communication guidelines and comply with applicable rules, there is risk that the use of social media by us or our employees to communicate about our product candidates or business may cause us to be found in violation of applicable requirements. In addition, our employees may knowingly or inadvertently make use of social media in ways that may not comply with our internal policies or other legal or contractual requirements, which may give rise to liability, lead to the loss of trade secrets or other intellectual property, or result in public exposure of personal information of our employees, clinical trial patients, customers and others. Our potential patient population may also be active on social media and use these platforms to comment on the effectiveness of, or adverse experiences with, our product candidates. Negative posts or comments about us or our product candidates on social media could seriously damage our reputation, brand image and goodwill.
Although we work to comply with applicable laws, regulations and standards, our contractual obligations and other legal obligations, these requirements are evolving and may be modified, interpreted and applied in an inconsistent manner from one jurisdiction to another, and may conflict with one another or other legal obligations with which we must comply. Any failure or perceived failure by us or our employees, representatives, contractors, consultants, CROs, collaborators, or other third parties to comply with such requirements or adequately address privacy and security concerns, even if unfounded, could result in additional cost and liability to us, damage our reputation, and adversely affect our business and results of operations.