We are subject relating various risks and costs associated with to the collection, use, sharing, retention, security, and transfer of confidential and private information, such as personal information and other data. This data is wide ranging and relates to our investors, employees, contractors and other counterparties and third parties. Our compliance obligations include those relating to the Data Protection Act (As Revised) of the Cayman Islands and the relevant PRC laws in this regard. These PRC laws apply not only to third-party transactions, but also to transfers of information between us, our WFOE, the VIE, and the VIE's subsidiaries, and among us, our WFOE, the VIE, and the VIE's subsidiaries, and other parties with which we have commercial relations. These laws continue to develop, and the PRC government may adopt other rules and restrictions in the future. Non-compliance could result in penalties or other significant legal liabilities.
Pursuant to the PRC Cybersecurity Law, which was promulgated by the Standing Committee of the National People's Congress on November 7, 2016 and took effect on June 1, 2017, personal information and important data collected and generated by a critical information infrastructure operator in the course of its operations in China must be stored in China, and if a critical information infrastructure operator purchases internet products and services that affects or may affect national security, it should be subject to cybersecurity review by the CAC. Due to the lack of further interpretations, the exact scope of "critical information infrastructure operator" remains unclear. On December 28, 2021, the CAC published the CAC Revised Measures which further restates and expands the applicable scope of the cybersecurity review. The CAC Revised Measures took effect on February 15, 2022. Pursuant to the CAC Revised Measures, if a network platform operator holding personal information of over one million users seeks for "foreign" listing, it must apply for the cybersecurity review. In addition, operators of critical information infrastructure purchasing network products and services are also obligated to apply for the cybersecurity review for such purchasing activities. Although the CAC Revised Measures provides no further explanation on the extent of "network platform operator" and "foreign" listing, as confirmed by our PRC counsel, Jingtian & Gongcheng, we are not subject to cybersecurity review with the CAC , because (i) we are not in possession of or otherwise holding personal information of over one million users and it is also very unlikely that it will reach such threshold in the near future; and (ii) as of the date of this annual report, we have not received any notice or determination from applicable PRC governmental authorities identifying it as a critical information infrastructure operator. However, we cannot guarantee that we will not be subject to cybersecurity review in the future as we offer IT services and sell hardware and software in China. During such review, we may be required to suspend our operation experience other disruptions to our operations. Cybersecurity review could also result in negative publicity with respect to our company and diversion of our managerial and financial resources.
Furthermore, if we were found to be in violation of applicable laws and regulations in China during such review, we could be subject to administrative penalties, such as warnings, fines, or service suspension. Therefore, cybersecurity review could materially and adversely affect our business, financial condition, and results of operations.
In addition, the PRC Data Security Law, which was promulgated by the Standing Committee of the National People's Congress on June 10, 2021 and took effect on September 1, 2021, requires data collection to be conducted in a legitimate and proper manner, and stipulates that, for the purpose of data protection, data processing activities must be conducted based on data classification and hierarchical protection system for data security. As the Data Security Law was recently promulgated, we may be required to make further adjustments to our business practices to comply with this law. If our data processing activities were found to be not in compliance with this law, we could be ordered to make corrections, and under certain serious circumstances, such as severe data divulgence, we could be subject to penalties, including the revocation of our business licenses or other permits. Furthermore, the recently issued Opinions on Strictly Cracking Down Illegal Securities Activities in Accordance with the Law require (i) speeding up the revision of the provisions on strengthening the confidentiality and archives management relating to overseas issuance and listing of securities and (ii) improving the laws and regulations relating to data security, cross-border data flow, and management of confidential information. As there remain uncertainties regarding the further interpretation and implementation of those laws and regulations, we cannot assure you that we will be compliant such new regulations in all respects, and we may be ordered to rectify and terminate any actions that are deemed illegal by the regulatory authorities and become subject to fines and other sanctions. As a result, we may be required to suspend our relevant businesses, shut down our website, take down our operating applications, or face other penalties, which may materially and adversely affect our business, financial condition, and results of operations.
On August 20, 2021, the Standing Committee of the National People's Congress of China promulgated the Personal Information Protection Law of the PRC, or the PIPL, which took effect in November 2021. As the first systematic and comprehensive law specifically for the protection of personal information in the PRC, the PIPL provides, among others, that (i) an individual's consent shall be obtained to use sensitive personal information, such as biometric characteristics and individual location tracking, (ii) personal information operators using sensitive personal information shall notify individuals of the necessity of such use and impact on the individual's rights, and (iii) where personal information operators reject an individual's request to exercise his or her rights, the individual may file a lawsuit with a People's Court. As uncertainties remain regarding the interpretation and implementation of the PIPL, we cannot assure you that we will comply with the PIPL in all respects, we may become subject to fines and/or other penalties which may have material adverse effect on our business, operations and financial condition.
While we take measures to comply with all applicable data privacy and protection laws and regulations, we cannot guarantee the effectiveness of the measures undertaken by us and our business partners. However, compliance with any additional laws could be expensive, and may place restrictions on our business operations and the manner in which we interact with our users. In addition, any failure to comply with applicable cybersecurity, privacy, and data protection laws and regulations could result in proceedings against us by government authorities or others, including notification for rectification, confiscation of illegal earnings, fines, or other penalties and legal liabilities against us, which could materially and adversely affect our business, financial condition, results of operations and the value of our Ordinary Shares. In addition, any negative publicity on our website or platform's safety or privacy protection mechanism and policy could harm our public image and reputation and materially and adversely affect our business, financial condition, and results of operations.