In our processing of travel transactions and information about members and their stays, we receive and store data, including personal data and other data relating to individuals. Numerous federal, state, local and international laws and regulations relate to privacy, data protection, information security and the storing, sharing, use, transfer, disclosure protection and other processing of personal information and other content, the scope of which are changing, subject to differing interpretations, and may be inconsistent among jurisdictions or conflict with other rules. These laws and regulations relating to privacy, data protection and information security are evolving and may result in ever-increasing regulatory and public scrutiny and escalating levels of enforcement and sanctions. For example, the General Data Protection Regulation (the "GDPR") promulgated by the European Union (the "EU") provides for penalties for noncompliance of up to the greater of €20 million or four percent of worldwide annual revenues. The Court of Justice of the European Union ("the CJEU") decision to not recognize the U.S. – EU Privacy Shield and other future legal challenges also could result in Inspirato being required to implement duplicative, and potentially expensive, information technology infrastructure and business operations or could limit our ability to collect or process personal information in Europe or other regions, may necessitate additional contractual negotiations and may serve as a basis for our personal data handling practices, or those of our service providers or other third parties we work with, to be challenged. Any of these or other changes or developments impacting cross-border data transfers could disrupt our business and otherwise adversely impact our business, financial condition and operating results.
The number of data protection laws globally is rising as more jurisdictions explore new or updated comprehensive data protection regimes or propose or enact other laws or regulations addressing local storage of data or other matters.
In the U.S., the California Consumer Privacy Act (the "CCPA") went into effect on January 1, 2020. Among other things, the CCPA requires covered companies to provide new disclosures to California consumers and afford such consumers new abilities to access and delete their personal information and to opt-out of certain sales of personal information. The California Privacy Rights Act (the "CPRA"), which became effective January 1, 2023, significantly modifies the CCPA and further aligns California privacy laws with the GDPR.
Similar legislation has been proposed or adopted in other states. For example, Virginia, Colorado, Utah, and Connecticut have all enacted omnibus privacy legislation that went into effect in 2023. These state laws in Virginia, Colorado, Utah and Connecticut share similarities with the CCPA, CPRA and legislation proposed in other states. Aspects of the CCPA, the CPRA and these other state laws and regulations, as well as their enforcement, remain unclear. Additionally, the U.S. federal government is contemplating data security and privacy legislation.
We will need to closely monitor developments, including enforcement actions or private litigation under the GDPR, CCPA, CPRA and other laws to determine whether we will need to modify our data processing practices and policies, which may result in us incurring additional costs and expenses in an effort to comply.
We are also subject to the terms of our privacy policies and contractual obligations to third parties related to privacy, data protection and information security and may be subject to other actual or asserted obligations, including industry standards, relating to privacy, data protection and information security. We strive to comply with applicable laws, regulations, policies and other legal obligations relating to privacy, data protection and information security to the extent possible. However, the regulatory frameworks for privacy, data protection and information security worldwide are evolving rapidly, and it is possible that these or other actual or alleged obligations may be interpreted and applied in a manner that is inconsistent from one jurisdiction to another and may conflict with other rules or our practices.
Any failure or perceived failure by us to comply with our privacy policies, our privacy-related obligations to members or other third parties, applicable laws or regulations or any of our other legal obligations could materially adversely affect our business.
Additionally, if third parties we work with, such as subprocessors, vendors or developers, violate applicable laws or regulations, contractual obligations or our policies, or if it is perceived that such violations have occurred, such actual or perceived violations may also have an adverse effect on our business. Further, any significant change to applicable laws, regulations or industry practices regarding the collection, use, retention, security, disclosure or other processing of data, or regarding the manner in which the express or implied consent of users for the collection, use, retention, disclosure or other processing of data is obtained, could increase our costs and require us to modify our business practices.