Some of the data we store, process, and use, contains personal information, subjecting us to a variety of laws and regulations in the United States and other countries with respect to privacy, rights of publicity, data protection, content, protection of minors, and consumer protection. These laws can be particularly restrictive. Both in the United States and abroad, these laws and regulations are evolving and remain subject to change. Several proposals are pending before federal, state and foreign legislative and regulatory bodies that could significantly affect our business. A number of states have enacted laws or are considering the enactment of laws governing the release of credit card or other personal information received from consumers:
- California has enacted legislation, the California Consumer Privacy Act ("CCPA") that, among other things, will require covered companies to provide new disclosures to California consumers, and afford such consumers new abilities to opt-out of certain sales of personal information. The CCPA went into effect on January 1, 2020.
- The EU General Data Protection Regulation ("GDPR"), effective May, 2018, establishes new requirements applicable to the processing of personal data (i.e., data which identifies an individual or from which an individual is identifiable), affords new data protection rights to individuals, and imposes penalties for serious data breaches. Individuals also have a right to compensation under GDPR for financial or non-financial losses. GDPR has imposed additional responsibility and liability in relation to our processing of personal data in the EU. GDPR has also required us to change our various policies and procedures in the EU and, if we are not compliant, could materially adversely affect our business, results of operations and financial condition.
- Canada's Personal Information and Protection of Electronic Documents Act provides Canadian residents with privacy protections in regard to transactions with businesses and organizations in the private sector and sets out ground rules for how private sector organizations may collect, use, and disclose personal information in the course of commercial activities.
- In November 2016, the Standing Committee of China's National People's Congress passed its Cybersecurity Law ("CSL"), which took effect in June 2017. The CSL is the first Chinese law that systematically lays out regulatory requirements on cybersecurity and data protection, subjecting many previously under-regulated or unregulated activities in cyberspace to government scrutiny.
The costs of compliance with, and other burdens imposed by, the GDPR, CSL and related laws may limit the use and adoption of our products and services and could have an adverse impact on our business, operating results and financial condition. Foreign governments also may attempt to apply such laws extraterritorially or through treaties or other arrangements with U.S. governmental entities. In addition, the application and interpretation of these laws and regulations are often uncertain and could result in investigations, claims, changes to our business practices, increased cost of operations and declines in sales, any of which could materially adversely affect our business, results of operations and financial condition. We cannot assure you that the privacy policies and other statements regarding our practices will be found sufficient to protect us from liability or adverse publicity relating to the privacy and security of personal information. Whether and how existing local and international privacy and consumer protection laws in various jurisdictions apply to the internet and other online technologies is still uncertain and may take years to resolve. Privacy laws and regulations, if drafted or interpreted broadly, could be deemed to apply to the technology we use and could restrict our information collection methods or decrease the amount and utility of the information that we would be permitted to collect. A determination by a court or government agency of a failure, or perceived failure, by us, the third parties with whom we work or our products and services to protect employee, applicant, vendor, website visitor or customer personal data (including as a result of a breach by or of a third-party provider) or to comply with any privacy-related laws, government regulations or directives or industry self-regulatory principles or our posted privacy policies could result in damage to our reputation, legal proceedings or actions against us by governmental entities or otherwise, which could have an adverse effect on our business. In addition, concerns about our practices with regard to the collection, use, disclosure, or security of personally identifiable information or other privacy-related matters, even if unfounded and even if we are in compliance with applicable laws, could damage our reputation and harm our business. We have and post on our website our own privacy policy and cookie statement concerning the collection, use and disclosure of user personal data.