We are subject to stringent privacy and data protection requirements and these requirements may become more complex as we grow our business and begin to operate in other jurisdictions. For example, the collection, use, storage, disclosure, transfer, or other processing of personal data, including health-related information, regarding individuals in the European Economic Area, or EEA, is governed by the European General Data Protection Regulation, or the GDPR, which became effective on May 25, 2018. The GDPR applies to any business, regardless of its location, that provides goods or services to residents in the EU or monitors the behavior of individuals within the European Union. The GDPR is wide ranging in scope and imposes stringent operational requirements for processors and controllers of personal data, including, for example, special protections for "sensitive information" which includes health and genetic information, expanded disclosures to individuals about how their personal data is to be used, limitations on retention of information, increased requirements pertaining to health data and pseudonymized (i.e., key-coded) data, implementing safeguards to protect the security and confidentiality of personal data, mandatory data breach notification requirements and higher standards for controllers to demonstrate that they have obtained valid consent for certain data processing activities. The GDPR grants individuals the opportunity to object to the processing of their personal information, allows them to request deletion of personal information in certain circumstances, and provides the individual with an express right to seek legal remedies in the event the individual believes his or her rights have been violated. Further, the GDPR imposes strict rules on the transfer of personal data out of the European Union to the U.S. and other jurisdictions that have not been deemed to offer "adequate" privacy protections.
In addition to the requirement of the GDPR, European Union Member States may make their own further laws and regulations in relation to the processing of genetic, biometric or health data, which could result in differences between Member States, limit our ability to use and share personal data or could cause our costs to increase, and harm our business and financial condition. Should we commence clinical trial activity within the member states of the European Union, such activity will be regulated by the GDPR as well as applicable member state laws. In addition, we are subject to evolving and strict rules on the transfer of personal data out of the European Union to the U.S.. For example, evolution of laws governing the cross-border transfer of data, such as the invalidation of the EU–U.S. Privacy Shield, creates additional uncertainty around the legality and mechanics of such transfers. Compliance with the GDPR will be a rigorous and time-intensive process that may increase our cost of doing business or require us to change our business practices, and despite those efforts, there is a risk that we may be subject to fines and penalties, litigation, and reputational harm in connection with any future European activities. We could be adversely affected if we fail to comply fully with all of these requirements. Failure to comply with European Union data protection laws may result in fines (for example, of up to €20,000,000 or up to 4% of the total worldwide annual turnover of the preceding financial year (whichever is higher) under the GDPR) and other administrative penalties, which may be onerous and adversely affect our business, financial condition, results of operations and prospects.
In addition, further to the United Kingdom's (UK) exit from the EU on January 31, 2020, the GDPR ceased to apply in the UK at the end of the transition period on December 31, 2020. However, as of January 1, 2021, the UK's European Union (Withdrawal) Act 2018 incorporated the GDPR (as it existed on December 31, 2020 but subject to certain UK specific amendments) into UK law (referred to as the ‘UK GDPR'). The UK GDPR and the UK Data Protection Act 2018 set out the UK's data protection regime, which is independent from but aligned to the EU's data protection regime. Non-compliance with the UK GDPR may result in monetary penalties of up to £17.5 million or 4% of worldwide revenue, whichever is higher. Although the UK is regarded as a third country under the EU's GDPR, the European Commission has now issued a decision recognizing the UK as providing adequate protection under the EU GDPR and, therefore, transfers of personal data originating in the EU to the UK remain unrestricted. Like the EU GDPR, the UK GDPR restricts personal data transfers outside the UK to countries not regarded by the UK as providing adequate protection. The UK government has confirmed that personal data transfers from the UK to the EEA remain free flowing.
This lack of clarity on future UK laws and regulations and their interaction with EU laws and regulations could add legal risk, uncertainty, complexity and cost to our handling of EU personal information and our privacy and data security compliance programs. It is possible that over time the UK Data Protection Act could become less aligned with the EU General Data Protection Regulation, or GDPR, which could require us to implement different compliance measures for the UK and the European Union and result in potentially enhanced compliance obligations for EU personal data.
In the U.S., there has been a flurry of activity at the state level. In California, the California Consumer Privacy Act, or CCPA, was enacted in June 2018, became effective on January 1, 2020, and became subject to enforcement by the California Attorney General's office on July 1, 2020. The CCPA broadly defines personal information, and creates new individual privacy rights and protections for California consumers (as defined in the law), places increased privacy and security obligations on entities handling personal data of consumers or households, and provides for civil penalties for violations and a private right of action for data breaches. The CCPA requires covered companies to provide certain disclosures to consumers about its data collection, use and sharing practices, and to provide affected California residents with ways to opt-out of certain sales or transfers of personal information. While there is an exception for protected health information that is subject to HIPAA and clinical trial regulations, the CCPA may impact our business activities if we become a "Business" regulated by the scope of the CCPA.
In addition to the CCPA, new privacy and data security laws have been proposed in more than half of the states in the U.S. and in the U.S. Congress, reflecting a trend toward more stringent privacy legislation in the U.S., which trend may accelerate depending on the new U.S. presidential administration. The effects of the CCPA, and other similar state or federal laws, are potentially significant and may require us to modify our data processing practices and policies and to incur substantial costs and potential liability in an effort to comply with such legislation.
Further, various jurisdictions around the world continue to propose new laws that regulate the privacy and/or security of certain types of personal data. Complying with these laws, if enacted, would require significant resources and leave us vulnerable to possible fines and penalties if we are unable to comply. The regulatory framework governing the collection, processing, storage, use and sharing of certain information is rapidly evolving and is likely to continue to be subject to uncertainty and varying interpretations. It is possible that these laws may be interpreted and applied in a manner that is inconsistent with our existing data management practices or the features of our services and platform capabilities. Any failure or perceived failure by us, or any third parties with which we do business, to comply with our posted privacy policies, evolving laws, rules and regulations, industry standards, or contractual obligations to which we or such third parties are or may become subject, may result in actions or other claims against