In the ordinary course of our business, we collect and store sensitive data, including protected health information, or PHI, personally identifiable information, genetic information, credit card information, intellectual property and proprietary business information owned or controlled by ourselves or our customers, payers and other parties. We manage and maintain our applications and data utilizing a combination of on-site systems, managed data center systems and cloud-based systems. We also communicate PHI and other sensitive patient data through our various customer tools and platforms. In addition to storing and transmitting sensitive data that is subject to multiple legal protections, these applications and data encompass a wide variety of business-critical information including research and development information, commercial information, and business and financial information. We face a number of risks relative to protecting this critical information, including loss of access risk, inappropriate disclosure, inappropriate modification, and the risk of our being unable to adequately monitor and modify our controls over our critical information. Any technical problems that may arise in connection with our data and systems, including those that are hosted by third-party providers, could result in interruptions to our business and operations or exposure to security vulnerabilities. These types of problems may be caused by a variety of factors, including infrastructure changes, intentional or accidental human actions or omissions, software errors, malware, viruses, security attacks, ransomware fraud, spikes in customer usage and denial of service issues. There continues to be a significant level of ransomware and cyber security attacks related to the ongoing conflict between Russia and Ukraine, which could result in substantial harm to internal systems necessary for running our critical operations and revenue generating services.
The secure processing, storage, maintenance and transmission of this critical information are vital to our operations and business strategy, and we devote significant resources to protecting such information. Although we take what we believe to be reasonable and appropriate measures, including a formal, dedicated enterprise security program, to protect sensitive information from various compromises (including unauthorized access, disclosure, or modification or lack of availability), our information technology and infrastructure may be vulnerable to attacks by hackers or viruses or breached due to employee error, malfeasance or other disruptions. For example, we have been subject to phishing incidents in the past, and we may experience additional incidents in the future. Any such breach or interruption could compromise our networks, and the information stored therein could be accessed by unauthorized parties, altered, publicly disclosed, lost or stolen.
Unauthorized access, loss or dissemination could also disrupt our operations including our ability to conduct our analyses, provide test results, bill payers or patients, process claims and appeals, provide customer assistance, conduct research and development activities, collect, process and prepare company financial information, provide information about our tests and other patient and physician education and outreach efforts through our website, and manage the administrative aspects of our business.
In addition to data security risks, we face privacy risks. Should we actually violate, or be perceived to have violated, any privacy commitments we make to patients or consumers, we could be subject to a complaint from an affected individual or interested privacy regulator, such as the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR), the FTC, a state Attorney General, an EU Member State Data Protection Authority, or a data protection authority in another international jurisdiction. This risk is heightened given the sensitivity of the data we collect.
Any security compromise that causes an apparent privacy violation could also result in legal claims or proceedings and liability and penalties under federal, state, foreign, or multinational laws that regulate the privacy, security, or breach of personal information, such as but not limited to HIPAA, HITECH, the FTC Act, state UDAP data security and data breach notification laws, the GDPR and the UK Data Protection Act of 2018.
There has been unprecedented activity in the development of data protection regulation around the world. As a result, the interpretation and application of consumer, health-related and data protection laws in the United States, Europe and elsewhere are often uncertain, contradictory and in flux. The GDPR took effect in May 2018. The GDPR applies to any entity established in the EU as well as extraterritorially to any entity outside the EU that offers goods or services to, or monitors the behavior of, individuals who are located in the EU. Among other requirements, the GDPR imposes strict rules on controllers and processors of personal data, including enhanced protections for "special categories" of personal data, which includes sensitive information such as health and genetic information of data subjects. Maximum penalties for violations of the GDPR are capped at 20.0 million euros or 4% of an organization's annual global revenue, whichever is greater.
Additionally, the implementation of GDPR has led other jurisdictions to either amend or propose legislation to amend their existing data privacy and cybersecurity laws to resemble the requirements of GDPR. For example, in June 2018, California adopted the California Consumer Privacy Act of 2018, or the CCPA. The CCPA, is a comprehensive consumer privacy law that took effect in January 2020 and was further amended as of January 1, 2023. The CCPA regulates how certain for-profit businesses that meet one or more CCPA applicability thresholds collect, use, and disclose the personal information of natural persons who reside in California. The CCPA does not apply to personal information that is PHI under HIPAA. The CCPA also does not apply to a HIPAA-regulated entity to the extent that the entity maintains patient information in the same manner as PHI. In addition, de-identified data as defined under HIPAA is also exempt from the CCPA. Accordingly, we do not have CCPA compliance obligations with respect to most genetic testing and patient information we collect and process. However, we are required to comply with the CCPA insofar as we collect other categories of California consumers' personal information.
Several other states in the United States have either recently enacted or are currently considering similar consumer data privacy laws, which could impact our operations if enacted. Some observers have noted that the CCPA could mark the beginning of a trend toward more stringent privacy legislation in the United States, which could increase our potential liability and adversely affect our business, results of operations, and financial condition.
It is possible the GDPR, CCPA and other emerging United States and international data protection laws may be interpreted and applied in a manner that is inconsistent with our practices. If so, this could result in government-imposed fines or orders requiring that we change our practices, which could adversely affect our business. In addition, these privacy laws and regulations may differ from country to country and state to state, and our obligations under these laws and regulations vary based on the nature of our activities in the particular jurisdiction, such as whether we collect samples from individuals in the local jurisdiction, perform testing in the local jurisdiction, or process personal information regarding employees or other individuals in the local jurisdiction. Complying with these various laws and regulations could cause us to incur substantial costs or require us to change our business practices and compliance procedures in a manner adverse to our business. We can provide no assurance that we are or will remain in compliance with diverse privacy and data security requirements in all of the jurisdictions in which we do business. Failure to comply with privacy and data security requirements could result in a variety of consequences, including civil or criminal penalties, litigation, or damage to our reputation, any of which could have a material adverse effect on our business.