We may be subject to laws and regulations that address privacy and data security in the U.S. and in states in which we conduct our business. The legislative and regulatory landscape for privacy and data protection continues to evolve, and there has been an increasing focus on privacy and data protection issues which may affect our business. In the U.S., numerous federal and state laws and regulations govern the collection, use, disclosure, and protection of health-related and other personal information, including state data breach notification laws, state health information privacy laws, state genetic privacy laws, and federal and state consumer protection and privacy laws (including, for example, Section 5 of the FTC Act and the CCPA). Compliance with these laws is difficult, constantly evolving, and time consuming. In addition, state laws govern the privacy and security of health, research and genetic information in specified circumstances, many of which differ from each other in significant ways and may not have the same effect, thus complicating compliance efforts. Failure to comply with these laws and regulations could result in government enforcement actions and create liability for us, which could include civil and/or criminal penalties, as well as private litigation and/or adverse publicity that could negatively affect our operating results and business.
For instance, HIPAA imposes certain obligations, including mandatory contractual terms, with respect to safeguarding the privacy, security and transmission of individually identifiable health information and imposes notification obligations in the event of a breach of the privacy or security of individually identifiable health information on entities subject to HIPAA and their business associates that perform certain activities that involve the use or disclosure of protected health information on their behalf. We may obtain health information from third parties (e.g., research institutions from which we obtain clinical trial data) that are subject to privacy and security requirements under HIPAA. Although we are not directly subject to HIPAA – other than potentially with respect to providing certain employee benefits – we could potentially be subject to criminal penalties if we, our affiliates, or our agents knowingly obtain, use, or disclose individually identifiable health information maintained by a HIPAA-covered entity in a manner that is not authorized or permitted by HIPAA.
In addition, the CCPA establishes certain requirements for data use and sharing transparency and provides California consumers (as defined in the law) certain rights concerning the use, disclosure, and retention of their personal data. In November 2020, California voters approved the California Privacy Rights Act (CPRA) ballot initiative which introduced significant amendments to the CCPA and established and funded a dedicated California privacy regulator, the California Privacy Protection Agency (CPPA). The amendments introduced by the CPRA went into effect on January 1, 2023, and new implementing regulations are expected to be introduced by the CPPA. Failure to comply with the CCPA may result in, among other things, significant civil penalties and injunctive relief, or statutory or actual damages. In addition, California residents have the right to bring a private right of action in connection with certain types of incidents. These claims may result in significant liability and damages. Similarly, there are a number of legislative proposals in the United States, at both the federal and state level, that could impose new obligations or limitations in areas affecting our business. For example, other states, including Virginia, Colorado, Utah, Indiana, Iowa, Tennessee, Montana, Texas, and Connecticut have enacted privacy laws similar to the CCPA that impose new obligations or limitations in areas affecting our business. These laws and regulations are evolving and subject to interpretation and may impose limitations on our activities or otherwise adversely affect our business. The obligations to comply with the CCPA and evolving legislation may require us, among other things, to update our notices and develop new processes internally and with our partners. We may be subject to fines, penalties, or private actions in the event of non-compliance with such laws. In addition, we could be subject to regulatory actions and/or claims made by individuals and groups in private litigation involving privacy issues related to data collection and use practices and other data privacy laws and regulations, including claims for misuse or inappropriate disclosure of data, as well as unfair or deceptive acts or practices in violation of Section 5(a) of the Federal Trade Commission Act (FTC Act). The FTC expects a company's data security measures to be reasonable and appropriate in light of the sensitivity and volume of consumer information it holds, the size and complexity of its business, and the cost of available tools to improve security and reduce vulnerabilities. Individually identifiable health information is considered sensitive data that merits stronger safeguards. With respect to privacy, the FTC also sets expectations that companies honor the privacy promises made to individuals about how the company handles consumers' personal information; any failure to honor promises, such as the statements made in a privacy policy or on a website, may also constitute unfair or deceptive acts or practices in violation of the FTC Act. Enforcement by the FTC under the FTC Act can result in civil penalties or decades-long enforcement actions.
If we, our agents, or our third party partners fail to comply or are alleged to have failed to comply with these or other applicable data protection and privacy laws and regulations, or if we were to experience a data breach involving personal information, we could be subject to government enforcement actions or private lawsuits. Any associated claims, inquiries, or investigations or other government actions could lead to unfavorable outcomes that have a material impact on our business including through significant penalties or fines, monetary judgments or settlements including criminal and civil liability for us and our officers and directors, increased compliance costs, delays or impediments in the development of new products, negative publicity, increased operating costs, diversion of management time and attention, or other remedies that harm our business, including orders that we modify or cease existing business practices.
Outside the U.S., the legislative and regulatory landscape for privacy and data security continues to evolve. There has been increased attention to privacy and data security issues that could potentially affect our business, including the EU General Data Protection Regulation including as implemented in the UK, (collectively, GDPR), which imposes penalties for the most serious breaches of up to EUR 20 million or 4% of a noncompliant company's annual global revenue, whichever is greater. The GDPR regulates the processing of personal data (including health data from clinical trials) and places certain obligations on the processing of personal data including ensuring the lawfulness of processing personal data (including obtaining valid consent of the individuals to whom the personal data relates, where applicable), the processing details disclosed to the individuals, the adequacy, relevance and necessity of the personal data collected, the retention of personal data, the sharing of personal data with third parties, the transfer of personal data out of the European Economic Area/UK to third countries including the U.S., contracting requirements (such as with clinical trial sites and vendors), the use of personal data in accordance with individual rights, the security of personal data and security breach/incident notifications. Data protection authorities from the different European Member States and the UK may interpret the GDPR and applicable related national laws differently and impose requirements additional to those provided in the GDPR and that sit alongside the GDPR, as set out under applicable local data protection law. In addition, guidance on implementation and compliance practices may be issued, updated or otherwise revised. Enforcement by European and UK regulators is generally active, and failure to comply with the GDPR or applicable Member State/UK local law may result in fines, amongst other things (such as notices requiring compliance within a certain timeframe). Further, the UK Government may amend/update UK data protection law, which may result in changes to our business operations and potentially incur commercial cost.
European/UK data protection laws, including the GDPR, generally restrict the transfer of personal data from the European Economic Area (EEA), including the EU, United Kingdom, and Switzerland, to the U.S. and most other countries (except those deemed to be adequate by the European Commission/UK Secretary of State as applicable) unless the parties to the transfer have implemented specific safeguards to protect the transferred personal data. Some available lawful transfer mechanisms are under scrutiny and in flux, such as the European Commission's Standard Contractual Clauses (SCCs). On July 10, 2023, the European Commission adopted its adequacy decision for the EU-U.S. Data Privacy Framework, meaning that personal data can now flow freely from the EEA to U.S. companies that participate in the Data Privacy Framework. There are also recent developments regarding data transfers in the UK, which formally approved two mechanisms for transferring UK data overseas and that came into force on March 21, 2022: the International Data Transfer Agreement or the International Data Transfer Addendum to the SCCs. The UK Information Commissioner's Office also issued guidance on how to approach undertaking risk assessments for transfers of UK data to non-adequate countries outside the UK.
A lack of valid transfer mechanisms for GDPR-covered data could increase exposure to enforcement actions as described above, and may affect our business operations and require commercial cost (including potentially limiting our ability to collaborate/work with certain third parties and/or requiring an increase in our data processing capabilities in the EU/UK). Further, the European/UK data protection laws (including laws on data transfers as set out above) may also be updated/revised, accompanied by new guidance and/or judicial/regulatory interpretations, which could entail further impacts on our compliance efforts and increased cost.
Additionally, other countries outside of Europe/UK have enacted or are considering enacting similar cross-border data transfer restrictions and laws requiring local data residency, which could increase the cost and complexity of delivering our services and operating our business. The type of challenges we face in Europe/UK will likely also arise in other jurisdictions that adopt laws similar in construction to the GDPR or regulatory frameworks of equivalent complexity.
Furthermore, following the UK's exit from the EU, the UK became a third country to the EU in terms of personal data transfers. The European Commission has adopted an Adequacy Decision concerning the level of personal data protection in the UK under which personal data may now flow freely from the EU to the UK. However, personal data transfers from the EU to the UK may nevertheless be at a greater risk than before because the Adequacy Decision may be suspended.