The regulatory framework for the collection, use, safeguarding, sharing, transfer, and other processing of information worldwide is rapidly evolving and is likely to remain uncertain for the foreseeable future. Globally, virtually every jurisdiction in which we operate has established its own data security and privacy frameworks with which we must comply. For example, the collection, use, disclosure, transfer, or other processing of personal data regarding individuals in the European Union, including personal health data, is subject to the EU General Data Protection Regulation (the "GDPR"), which took effect across all member states of the European Economic Area (the "EEA") in May 2018. The GDPR is wide-ranging in scope and imposes numerous requirements on companies that process personal data, including requirements relating to processing health and other sensitive data, obtaining consent of the individuals to whom the personal data relates, providing information to individuals regarding data processing activities, implementing safeguards to protect the security and confidentiality of personal data, providing notification of data breaches, and taking certain measures when engaging third-party processors. The GDPR increases our obligations with respect to clinical trials conducted in the EEA by expanding the definition of personal data to include coded data and requiring changes to informed consent practices and more detailed notices for clinical trial subjects and investigators. In addition, the GDPR imposes strict rules on the transfer of personal data to countries outside the European Union, including the United States, and, as a result, increases the scrutiny that clinical trial sites located in the EEA should apply to transfers of personal data from such sites to countries that are considered to lack an adequate level of data protection, such as the United States. The GDPR also permits data protection authorities to require destruction of improperly gathered or used personal information and/or impose substantial fines for violations of the GDPR, which can be up to four percent of global revenues or 20 million Euros, whichever is greater, and it also confers a private right of action on data subjects and consumer associations to lodge complaints with supervisory authorities, seek judicial remedies, and obtain compensation for damages resulting from violations of the GDPR. In addition, the GDPR provides that European Union member states may make their own further laws and regulations limiting the processing of personal data, including genetic, biometric or health data.
Further, Brexit has led to, and could continue to lead to legislative and regulatory changes, which may increase our compliance costs. As of January 1, 2021 and the expiry of transitional arrangements agreed to between the United Kingdom and the European Union, data processing in the United Kingdom is governed by a United Kingdom version of the GDPR (combining the GDPR and the Data Protection Act 2018), exposing us to two parallel regimes, each of which authorizes similar fines and other potentially divergent enforcement actions for certain violations. On June 28, 2021, the European Commission adopted an Adequacy Decision for the United Kingdom, allowing for the relatively free exchange of personal information between the European Union and the United Kingdom, however, the European Commission may suspend the Adequacy Decision if it considers that the United Kingdom no longer provides for an adequate level of data protection. A bill to amend the existing UK framework has been reintroduced (in a different form) by the new UK Government and was announced as a bill which will be introduced into Parliament at the King's Speech on July 17, 2024. At this time, there is no specific clarity on the provisions of the bill, or the extent to which it will amend the UK framework, beyond general descriptions on its intended purpose. Other jurisdictions outside the European Union are similarly introducing or enhancing privacy and data security laws, rules and regulations.
Similar actions are either in place or under way in the United States. There are a broad variety of data protection laws that are applicable to our activities, and a wide range of enforcement agencies at both the state and federal levels that can review companies for privacy and data security concerns based on general consumer protection laws. The Federal Trade Commission and state Attorneys General all are aggressive in reviewing privacy and data security protections for consumers. New laws also are being considered at both the state and federal levels and several states have passed comprehensive privacy laws. For example, the California Consumer Privacy Act - which went into effect on January 1, 2020 - is creating similar risks and obligations as those created by the GDPR, though the California Consumer Privacy Act does exempt certain information collected as part of a clinical trial subject to the Federal Policy for the Protection of Human Subjects (the Common Rule). As of January 1, 2023, the California Consumer Privacy Act (as amended and expanded by the California Privacy Rights Act) is in full effect, with enforcement by California's dedicated privacy enforcement agency expected to start later in 2023. While California was first among the states in adopting comprehensive data privacy legislation similar to the GDPR, many other states are following suit. Similar laws passed in Virginia, Colorado, Connecticut, and Utah took effect in 2023. Additionally, Delaware, Florida, Indiana, Iowa, Montana, Oregon, Tennessee, Texas and others have adopted privacy laws, which take effect from July 1, 2024 through 2026. Some state laws also minimize what data can be collected from consumers and how businesses may use and disclose it. These state privacy laws also require businesses to make disclosures to consumers about data collection, use and sharing practices. In addition, some of these laws (including the California Privacy Rights Act), along with other standalone health privacy laws, subject health-related information to additional safeguards and disclosures and some specifically regulate consumer health data, such as the Washington My Health My Data Act, which became effective in 2023 and 2024. Additionally, a broad range of legislative measures also have been introduced at the federal level. Accordingly, failure to comply with federal and state laws (both those currently in effect and future legislation) regarding privacy and security of personal information could expose us to fines and penalties under such laws. There also is the threat of consumer class actions related to these laws and the overall protection of personal data. This is particularly true with respect to data security incidents, and sensitive personal information, including health and biometric data. Even if we are not determined to have violated these laws, government investigations into these issues typically require the expenditure of significant resources and generate negative publicity, which could harm our reputation and business.
Given the breadth and depth of changes in data protection obligations, preparing for and complying with these requirements is rigorous and time intensive and requires significant resources and a review of our technologies, systems and practices, as well as those of any third-party collaborators, service providers, contractors or consultants that process or transfer personal data collected in the European Union. The GDPR, new state privacy laws and other changes in laws or regulations associated with the enhanced protection of certain types of sensitive data, such as healthcare data or other personal information from our clinical trials, could require us to change our business practices and put in place additional compliance mechanisms, may interrupt or delay our development, regulatory and commercialization activities and increase our cost of doing business, and could lead to government enforcement actions, private litigation and significant fines and penalties against us and could have a material adverse effect on our business, financial condition and results of operations.