Our handling and storage of the data we collect from some of our customers, vendors and employees, and our processing of data, which may include confidential or personally identifiable information, through the services we provide, may be subject to a variety of laws and regulations, which have been adopted by various federal, state and foreign governments to regulate the collection, distribution, use and storage of personal information of individuals. Several foreign countries in which we conduct business, including the European Economic Area ("EEA") and Canada, currently have in place or have recently proposed, laws or regulations concerning privacy, data protection and information security, which are more restrictive than those imposed in the United States. Some of these laws are in their early stages and we cannot yet determine the impact these revised laws and regulations, if implemented, may have on our business. However, any failure or perceived failure by us to comply with these privacy laws, regulations, policies or obligations or any security incident that results in the unauthorized release or transfer of personally identifiable information or other customer data in our possession, could result in government enforcement actions, litigation, fines and penalties and/or adverse publicity, all of which could have an adverse effect on our reputation and business.
For example, the EEA wide General Data Protection Regulation ("GDPR") became applicable on May 25, 2018, replacing the data protection laws of each EEA member state. The GDPR implemented more stringent operational requirements for processors and controllers of personal data, including, for example, expanded disclosures about how personal information is to be used, limitations on retention of information, increased requirements to erase an individual's information upon request, mandatory data breach notification requirements and higher standards for data controllers to demonstrate that they have obtained valid consent for certain data processing activities. It also significantly increases penalties for non-compliance, including where we act as a service provider (e.g. data processor). If our privacy or data security measures fail to comply with applicable current or future laws and regulations, we may be subject to litigation, regulatory investigations, enforcement notices requiring us to change the way we use personal data or our marketing practices, fines, for example, of up to 20 million Euros or up to 4% of the total worldwide annual turnover of the preceding financial year (whichever is higher) under the GDPR, or other liabilities, as well as negative publicity and a potential loss of business.
Data protection regulation remains an area of increased focus in all jurisdictions and data protection regulations continue to evolve. There is no assurance that we will be able to meet new requirements that may be imposed on the transfer of personally identifiable information from the EU to the United States without incurring substantial expense or at all. European and/or multi-national customers may be reluctant to purchase or continue to use our services due to concerns regarding their data protection obligations. In addition, we may be subject to claims, legal proceedings or other actions by individuals or governmental authorities if they have reason to believe that our data privacy or security measures fail to comply with current or future laws and regulations.
Moreover, we must ensure that certain vendors and customers who have access to such information also have the appropriate privacy policies, procedures and protections in place. Although we take customary measures to protect such information, the continued occurrence of high-profile data breaches provides evidence of an external environment increasingly hostile to information security. If our security measures are breached as a result of third-party action, employee or subcontractor error, malfeasance or otherwise, and, as a result, someone obtains unauthorized access to customer data, our reputation may be damaged, our business may suffer and we could incur significant liability. Techniques used to obtain unauthorized access or to sabotage systems change frequently and are growing increasingly sophisticated. As a result, we may be unable to anticipate these techniques or to implement adequate preventative measures.
This environment demands that we continuously improve our design and coordination of security controls throughout our business. Despite these efforts, it is possible that our security controls over data, training and other practices we follow may not prevent the improper disclosure of personally identifiable or other confidential information.
If an actual or perceived breach of our security occurs, we could be liable under laws and regulations that protect personal or other confidential data resulting in increased costs or loss of revenues and the market perception of our services could be harmed.