We receive, store, process, use, and share data, some of which contains personal information and other data relating to our players, employees and business contacts, and we enable our players to share their personal information with each other and with third parties, including on the Internet and mobile platforms. There are numerous federal, state, and local laws around the world regarding privacy and the storing, sharing, use, processing, disclosure, and protection of personal information, the scopes of which are changing, subject to differing interpretations, and may be inconsistent between jurisdictions or conflict with other rules.
We are subject to European Union rules with respect to cross-border transfers of personal data out of the EEA and the UK. Recent legal developments in Europe have created complexity and uncertainty regarding transfers of personal data from the EEA and the UK to the U.S. On July 16, 2020, the Court of Justice of the European Union ("CJEU") invalidated the EU-US Privacy Shield Framework, or Privacy Shield, under which personal data could be transferred from the EEA to U.S. entities, such as ourselves, who had self-certified under the Privacy Shield scheme. While the CJEU upheld the adequacy of the standard contractual clauses (a standard form of contract approved by the European Commission as an adequate personal data transfer mechanism, and potential alternative to the Privacy Shield), it made clear that reliance on them alone may not necessarily be sufficient in all circumstances.
These recent and ongoing developments will require us to continually review and amend the legal mechanisms by which we make and/ or receive personal data transfers to in the U.S. As supervisory authorities issue further guidance on personal data export mechanisms, including circumstances where the standard contractual clauses and other mechanisms cannot be used, and/or start taking enforcement action, we could suffer additional costs, complaints, and regulatory investigations or fines, or if we are otherwise unable to transfer personal data between and among countries and regions in which we operate, it could affect the manner in which we provide our services, the geographical location or segregation of our relevant systems and operations, and could adversely affect our financial results.
In addition, various government and consumer agencies have called for new regulation and changes in industry practices and are continuing to review the need for greater regulation for the collection of information concerning consumer behavior on the Internet, including regulation aimed at restricting certain targeted advertising practices.
In the U.S., there are numerous federal and state privacy and data protection laws and regulations governing the collection, use, disclosure, protection, and other processing of personal information, including federal and state data privacy laws, data breach notification laws, and consumer protection laws. For example, the California Consumer Privacy Act of 2018, or CCPA, became effective on January 1, 2020 and created new privacy rights for consumers residing in the state of California. The CCPA gives California residents expanded rights to access and delete their personal information, opt out of certain personal information sharing, and receive detailed information about how their personal information is used. The CCPA allows for the California Attorney General to impose civil penalties for violations and also provides a private right of action for certain data breaches. In November 2020, California voters passed the California Privacy Rights Act, or CPRA, which became effective on January 1, 2023. The CPRA significantly expands the CCPA, including by introducing additional obligations such as data minimization and storage limitations, granting additional rights to consumers, such as correction of personal information and additional opt-out rights, and creates a new entity, the California Privacy Protection Agency, to implement and enforce the law. The CCPA and CPRA could subject us to additional compliance costs as well as potential fines, individual claims and commercial liabilities.
There currently are a number of additional proposals related to data privacy or security pending before federal, state, and foreign legislative and regulatory bodies, and a number of U.S. states have adopted consumer protection laws similar to the CCPA. This legislation may add additional complexity, variation in requirements, restrictions and potential legal risk, require additional investment in resources to compliance programs, and could impact strategies and availability of previously useful data and could result in increased compliance costs and/or changes in business practices and policies.
In the European Economic Area, or EEA, we are subject to the European Union's General Data Protection Regulation, or GDPR, which became effective in May 2018, and from January 1, 2021, we are also subject to the UK GDPR and UK Data Protection Act 2018, which retains the GDPR in UK national law. The GDPR and national implementing legislation in EEA member states and the UK impose a strict data protection compliance regime in relation to our collection,control, processing, sharing, disclosure, and other use of personal data, including providing detailed disclosures about how personal data is collected and processed, granting new rights for data subjects to access, delete, or object to the processing of their data, mandatory breach notification to supervisory authorities (and in certain cases, affected individuals) of certain data breaches, and significant documentary requirements to demonstrate compliance through policies, procedures, training, and audit. In particular, European Union privacy supervisory authorities have focused on compliance with requirements relating to the processing of children's personal data and ensuring that services offered to children are age appropriate, and we may be subject to regulatory scrutiny and subsequent enforcement actions if we are found to be processing children's data given the nature of our services.
We are also subject to European Union rules with respect to cross-border transfers of personal data out of the EEA and the UK. Recent legal developments in Europe have created complexity and uncertainty regarding transfers of personal data from the EEA and the UK to the U.S. On July 16, 2020, the Court of Justice of the European Union, or CJEU, invalidated the EU-US Privacy Shield Framework, or Privacy Shield, under which personal data could be transferred from the EEA to U.S. entities, such as ourselves, who had self-certified under the Privacy Shield scheme. While the CJEU upheld the adequacy of the standard contractual clauses (a standard form of contract approved by the European Commission as an adequate personal data transfer mechanism, and potential alternative to the Privacy Shield), it made clear that reliance on them alone may not necessarily be sufficient in all circumstances.
The U.S. Children's Online Privacy Protection Act ("COPPA"), regulates the collection, use and disclosure of personal information from children under 13 years of age. While our social casino games do not target children under 18 years of age as their primary audience, the Federal Trade Commission (the "FTC"), as well as consumer organizations, may consider whether the characteristics of our games attract children under 13 years of age. The FTC has taken action against other gaming companies relating to children's' privacy, including against Epic Games, the maker of the popular game Fortnite, pursuant to which Epic Games agreed to pay a $275 million fine for alleged violations of COPPA as well as take other corrective actions. While none of our games are directed at children under 13 years of age, if COPPA were to apply to us, failure to comply with COPPA may increase our costs, subject us to expensive and distracting government investigations and could result in substantial fines. Although we have taken measures to identify which of our games are subject to COPPA due to their child-appealing nature and to comply with COPPA with respect to those games, if COPPA were to apply to us in a manner other than we have assessed or prepared for, our actual or alleged failure to comply with COPPA may increase our costs, subject us to expensive and distracting lawsuits or government investigations, could result in substantial fines or civil damages and could cause us to temporarily or permanently discontinue certain games or certain features and functions in games.
While our social casino games do not target children under 18 years of age as their primary audience, the United Kingdom in 2020 enacted the "Age Appropriate Design Code" (commonly referred to as the "Children's Code"), a statutory code of practice pursuant to the United Kingdom Data Protection Act 2018, which became enforceable on September 2, 2021. The code requires online services, including our games that are likely to be accessed by children under 18, to put the best interests of the child's privacy first in the design, development and data-related behavior of the game. The UK government is also separately consulting on legislation in relation to user safety online. The Data Protection Commission in Ireland published its Fundamentals for a Child-Oriented Approach to Data Processing, introducing certain child-specific data protection measures. It is possible that other countries within and outside the European Union will follow with their own codes or guidance documents relating to processing personal information from children or in relation to online harms; currently, other countries are considering or have issued drafts of similar codes, including France, Denmark, and Switzerland. These may result in substantial additional costs and may necessitate changes to our business practices which may compromise our growth strategy, adversely affect our ability to attract, monetize or retain players, and otherwise adversely affect our business, reputation, legal exposures, financial condition and results of operations.
In addition, in some cases, we are dependent upon our platform providers to solicit, collect and provide us with information regarding our players that is necessary for compliance with these various types of regulations. Our business, including our ability to operate and expand internationally, could be adversely affected if laws or regulations are adopted, interpreted or implemented in a manner that is inconsistent with our current business practices and that require changes to these practices, the design of our games, game features, or our privacy policy. These platform providers may dictate rules, conduct or technical features that do not properly comply with federal, state, local and foreign laws, regulations and regulatory codes and guidelines governing data privacy, data protection and security, including with respect to the collection, storage, use, processing, transmission, sharing and protection of personal information and other consumer data. In addition, these platforms may dictate rules, conduct or technical features relating to the collection, storage, use, transmission, sharing and protection of personal information and other consumer data, which may result in substantial costs and may necessitate changes to our business practices, which in turn may compromise our growth strategy,adversely affect our ability to attract, monetize or retain players, and otherwise adversely affect our business, reputation, legal exposures, financial condition and results of operations. Any failure or perceived failure to comply with these platform-dictated rules, conduct or technical features may result in platform-led investigations or enforcement actions, litigation, or public statements against us, which in turn could result in significant liability or temporary or permanent suspension of our business activities with these platforms, cause our players to lose trust in us, and otherwise compromise our growth strategy, adversely affect our ability to attract, monetize or retain players, and otherwise adversely affect our business, reputation, legal exposures, financial condition and results of operations.
Player interaction with our games is subject to our privacy policy and terms of service. If we fail to comply with our posted privacy policy or terms of service or if we fail to comply with existing privacy-related or data protection laws and regulations, it could result in proceedings or litigation against us by governmental authorities or others, which could result in fines or judgments against us, damage our reputation, impact our financial condition and harm our business. If regulators, the media or consumers raise any concerns about our privacy and data protection or consumer protection practices, even if unfounded, this could also result in fines or judgments against us, damage our reputation, and negatively impact our financial condition and damage our business.
In the area of information security and data protection, many jurisdictions have passed laws requiring notification when there is a security breach involving personal data or requiring the adoption of minimum information security standards that are often vaguely defined and difficult to implement. Our security measures and standards may not be sufficient to protect personal information and we cannot guarantee that our security measures will prevent security breaches. A security breach that compromises personal information could harm our reputation and result in a loss of player and/or employee confidence in our games and ultimately in a loss of players, which could adversely affect our business and impact our financial condition. A security breach could also involve loss or unavailability of business-critical data and could require us to spend significant resources to mitigate and repair the breach, which in turn could compromise our growth and adversely affect our ability to attract, monetize or retain players. These risks could also subject us to liability under applicable security breach-related laws and regulations and could result in additional compliance costs, costs related to regulatory inquiries and investigations, and an inability to conduct our business.
In addition, Brazil's passage of the Lei Geral de Protecao de Dados Pessoais, or LGPD, became effective September 2020 and created new privacy rights for consumers residing in Brazil.
Compliance with the GDPR, LGPD, CCPA, CPRA, and similar legal requirements has required us to devote significant operational resources and incur significant expenses. We expect the number of jurisdictions adopting their own data privacy laws to increase, which will require us to devote additional significant operational resources and incur additional significant expenses and will also increase our exposure to risks of claims by our players that we have not complied with all applicable data privacy laws.
All of our games are subject to our online privacy policy and our terms of service accessible through our platform providers' storefronts, from our games, and on our corporate website. While we strive to comply with such policies and all applicable laws, regulations, other legal and contractual obligations, and certain industry standards and codes of conduct relating to data privacy and data protection, these obligations may be interpreted and applied in a manner that is inconsistent from one jurisdiction to another and may conflict with other rules or our practices. It is also possible that new laws, regulations, other legal obligations or industry codes of conduct may be adopted, or existing laws, regulations, other legal obligations or industry codes of conduct may be interpreted in such a way that results in us having to take further compliance steps and/or could prevent us from being able to offer services to citizens of a certain jurisdiction or makes it costlier or more difficult for us to do so.
Any failure or perceived failure by us to comply with our privacy policy and terms of service, or our data privacy-related legal obligations including those to our players or other third parties, or any compromise of security that results in the unauthorized release or transfer of personal information, including personal information about our players, may result in regulatory investigations, governmental enforcement actions, and significant fines, which, as an example, can be up to 20 million euros or up to 4% of the annual global revenue of the noncompliant undertaking, whichever is greater, for violations of certain requirements of the GDPR. The UK GDPR mirrors the fines under the GDPR. In addition to the foregoing, we may suffer reputational damage, orders to cease or change our processing of our data, civil claims including representative actions and other class action type litigation (where individuals have suffered harm), potentially amounting to significant compensation or damages liabilities, or public statements against us by consumer advocacy groups or others which could cause our players to lose trust in us, any of which could have an adverse effect on our business, financial condition, or results of operations. Additionally, if third parties we work with such as our players or vendors violate applicable laws or our policies, such violations may also put personal information at risk and expose us to potential liability and reputational harm. Further, public scrutiny of, or complaints about, technology companies or their data handling or data protection practices,even if unrelated to our business, industry, or operations, may lead to increased scrutiny of technology companies, including us, and may cause government agencies to enact additional regulatory requirements, or to modify their enforcement or investigation activities. Any of the foregoing could have an adverse effect on our business, financial condition, or results of operations.