We collect, store, process, and use personal information and other customer data, and we rely in part on third parties that are not directly under our control to manage certain of these operations. For example, we rely on encryption, storage and processing technology developed by third parties to securely transmit, operate on and store such information. Due to the volume and sensitivity of the personal information and data we and these third parties manage and expect to manage in the future, as well as the nature of our customer base, the security features of our information systems are critical. We expend significant resources to protect against security breaches and may need to expend more resources in the event we need to address problems caused by potential breaches. Any failure or perceived failure to maintain the security of personal and other data that is provided to us by customers and vendors could harm our reputation and brand and expose us to a risk of loss or litigation and possible liability, any of which could adversely affect our business, financial condition and results of operations. Additionally, concerns about our practices with regard to the collection, use or disclosure of personal information or other privacy-related matters, even if unfounded, could harm our business, financial condition and results of operations.
We have in the past experienced security vulnerabilities, though such vulnerabilities have not had a material impact on our operations. While we have implemented security procedures and virus protection software, intrusion prevention systems, access control and emergency recovery processes to mitigate risks like these with respect to information systems that are under our control, they are not fail-safe and may be subject to breaches. Further, we cannot ensure that third parties upon whom we rely for various services will maintain sufficient vigilance and controls over their systems. Our inability to use or access those information systems at critical points in time, or unauthorized releases of personal or confidential information, could unfavorably impact the timely and efficient operation of our business, including our results of operations, and our reputation, as well as our relationships with our customers, employees or other individuals whose information may have been affected by such cybersecurity incidents.
There are numerous federal, state and local laws regarding privacy and the collection, processing, storing, sharing, disclosing, using and protecting of personal information and other data, the scope of which are changing and expanding as we move into new markets, subject to differing interpretations, and which may be costly to comply with, inconsistent between jurisdictions or conflicting with other rules. We are also subject to specific contractual requirements contained in third-party agreements governing our use and protection of personal information and other data. We generally seek to comply with industry standards and are subject to the terms of our privacy policies and the privacy- and security-related obligations to third parties. We strive to comply with applicable laws, policies, legal obligations and industry codes of conduct relating to privacy and data protection, to the extent possible. However, it is possible that these obligations may be interpreted and applied in new ways or in a manner that is inconsistent from one jurisdiction to another and may conflict with other rules or our practices. Additionally, new regulations could be enacted with which we are not familiar. Any failure or perceived failure by us to comply with our privacy policies, our privacy-related obligations to customers or other third parties, or our privacy-related legal obligations or any compromise of security that results in the unauthorized release or transfer of sensitive information, which may include personally identifiable information or other customer data, may result in governmental enforcement actions, litigation or public statements against us by consumer advocacy groups or others and could cause customers, vendors and receivable-purchasers to lose trust in us, which could have a material adverse effect on our business, financial condition and results of operations. Additionally, if vendors, developers or other third parties that we work with violate applicable laws or our policies, such violations may also put customers' or vendors' information at risk and could in turn harm our business, financial condition and results of operations.
We expect that new industry standards, laws and regulations will continue to be proposed and implemented regarding privacy, data protection and information security where we do business. For example, the California Consumer Privacy Act (the "CCPA"), which went into effect on January 1, 2020, gives California residents expanded rights to access and delete their personal information, opt out of certain personal information sharing, and receive detailed information about how their personal information is used. The CCPA provides for civil penalties for violations, as well as a private right of action for data breaches that is expected to increase data breach litigation. The CCPA may increase our compliance costs and potential liability. Some observers have noted that the CCPA could mark the beginning of a trend toward more stringent state privacy legislation in the U.S., which could increase our potential liability and adversely affect our business. Further, if individual U.S. states pass data privacy laws that place different obligations or limitations on the processing of personal data of individuals in those states, it will become more complex to comply with these laws and our compliance costs may increase.
A significant data breach or any failure, or perceived failure, by us to comply with any federal, state or local privacy or consumer protection-related laws, regulations or other principles or orders to which we may be subject or other legal obligations relating to privacy or consumer protection could adversely affect our reputation, brand and business, and may result in claims, investigations, proceedings or actions against us by governmental entities or others or other penalties or liabilities or require us to change our operations and/or cease using certain data sets. Depending on the nature of the information compromised, we may also have obligations to notify users, law enforcement or payment companies about the incident and may need to provide some form of remedy, such as refunds, for the individuals affected by the incident.