In the ordinary course of business, we collect and process personal data, including proprietary and confidential business data, intellectual property, and other third-party data. For example, we process personal data about our customers' consumers, content creators, and other social media users that interact with our customers' social media pages. Our data collection and processing activities subject us to numerous data privacy and security obligations, such as various laws, regulations, guidance, industry standards, external and internal privacy and security policies, contracts, and other obligations that govern the processing of personal data by us and on our behalf. While we contractually prohibit our customers from using our platform to process, store, or collect sensitive information (such as personal health information or credit card information), our customers may breach these use prohibitions and cause us to inadvertently violate laws, rules, or regulations regarding the use and protection of personal data, which in turn may adversely impact our business.
In the United States, federal, state, and local governments have enacted numerous data privacy and security laws, including data breach notification laws, personal data privacy laws, and consumer protection laws (e.g., Section 5 of the Federal Trade Commission Act), and other similar laws (e.g., wiretapping laws). For example, the CCPA imposes certain obligations on businesses and service providers with respect to collecting and processing personal data of consumers, business representatives, and employees who are California residents. These obligations include, but are not limited to, providing specific disclosures in privacy notices and affording California residents with certain rights related to their personal data. The CCPA allows for statutory fines for noncompliance of up to $7,500 per violation. In addition, the CPRA amends and expands the CCPA and establishes a new California Privacy Protection Agency to implement and enforce the CPRA, which increases the risk of an enforcement action. Other states, like Virginia, Colorado, and Oregon, have also enacted or proposed data privacy laws that may differ from the CCPA. If we are or become subject to these laws and/or new or amended data privacy laws, the risk of enforcement actions against us could increase because we may be subject to additional obligations under applicable regulatory frameworks, and the number of individuals or entities that could initiate actions against us may increase, in addition to further complicating our compliance efforts.
Additionally, under various privacy laws and other obligations, we may be required to obtain certain consents to process personal data. For example, some of our data processing practices may be challenged under wiretapping laws, if we obtain consumer information from third parties through various methods, including chatbot and session replay providers, or via third-party marketing pixels. These practices may be subject to increased challenges by class action plaintiffs. Our inability or failure to obtain consent for these practices could result in adverse consequences, including class action litigation and mass arbitration demands.
Outside the United States, an increasing number of laws, regulations, and industry standards apply to data privacy and security. For example, the EU GDPR and the equivalent law in the UK GDPR impose strict requirements for processing the personal data of individuals. Under the EU GDPR, government regulators may impose temporary or definitive bans on data processing, as well as fines of up to 20 million euros or 4% of annual global revenue, whichever is greater. Similar processing penalties and fines exist under the UK GDPR, and the variations in the application of GDPR in the UK following Brexit has increased the complexity of our compliance efforts. Further, individuals may initiate litigation related to our processing of their personal data. As another example, Brazil's General Data Protection Law (Lei Geral de Proteção de Dados Pessoais, or "LGPD") (Law No. 13,709/2018) may apply to our operations. The LGPD broadly regulates processing of personal data of individuals in Brazil and imposes compliance obligations and penalties comparable to those of the EU GDPR. In Canada, the Personal Information Protection and Electronic Documents Act ("PIPEDA") may apply to our operations. We may also process personal data about our customers' consumers in Asia and therefore, may become subject to new and emerging data privacy regimes in Asia, including China's Personal Information Protection Law, Japan's Act on the Protection of Personal Information, and Singapore's Personal Data Protection Act.
Certain jurisdictions have enacted data localization laws and cross-border personal data transfer laws. For example, absent appropriate safeguards or other circumstances, the EU GDPR, UK GDPR, and laws in Switzerland generally restrict the transfer of personal data to countries that these jurisdictions consider to not provide an adequate level of personal data protection. Although there are currently various mechanisms that may be used to transfer personal data from the EEA and UK to the United States in compliance with law, such as the EEA's standard contractual clauses, the UK's International Data Transfer Agreement / Addendum, and the EU-U.S. Data Privacy Framework and the UK extension thereto (which allows for transfers to relevant U.S.-based organizations who self-certify compliance and participate in the Framework), these mechanisms are subject to legal challenges, and there is no assurance that we can satisfy or rely on these measures to lawfully transfer personal data to the United States.
In addition to European restrictions on cross-border transfers of personal data, other jurisdictions, such as China's Personal Information Protection Law and Brazil's LGPD, have enacted or are considering similar cross-border personal data transfer laws and local personal data residency laws, any of which could increase the cost and complexity of doing business in foreign jurisdictions. If we cannot implement valid compliance mechanisms for cross-border personal data transfers, we may face increased exposure to regulatory actions, substantial fines, and injunctions against processing or transferring personal data from Europe or elsewhere. The inability to import personal data to the United States could significantly and negatively impact our business operations; limit our ability to collaborate with parties that are subject to European and other data privacy and security laws; or require us to increase our personal data processing capabilities and infrastructure in Europe and/or elsewhere at significant expense.
We publish privacy policies, marketing materials, and other statements, such as compliance with certain certifications or self-regulatory principles, regarding data privacy and security. If these policies, materials or statements are found to be deficient, lacking in transparency, deceptive, unfair, or misrepresentative of our practices, we may be subject to investigation, enforcement actions by regulators, or other adverse consequences.
Our obligations related to data privacy and security are quickly changing in an increasingly stringent fashion, creating some uncertainty as to the effective future legal framework. These obligations may be subject to differing applications and interpretations, which may be inconsistent or in conflict among jurisdictions. As our platform and products evolve and the ways we use personal data change to meet the complex needs of our customer base, we continue to become subject to additional privacy and security obligations. Even if we believe we have satisfied compliance requirements in our activities, regulators may disagree with our compliance posture and issue high penalties and fines for noncompliance. Additionally, our sales cycles may increase due to increasingly rigorous privacy and security assessments that must be completed prior to purchasing our platform and products as a result of increased regulation. Preparation for and compliance with these obligations require us to devote significant resources (including, without limitation, financial and time-related resources). For example, the increased consumer control over the sharing of their personal data afforded by the CCPA may affect our customers' ability to share such personal data with us or may require us to delete or remove consumer information from our records or data sets, which may result in considerable costs for our organization. Further, these obligations may necessitate changes to our information technologies, systems, and practices and to those of any third parties that process personal data on our behalf. In addition, these obligations may require us to change our business model or our products. For example, social media networks (which are integral third-party services to our platform) are under heightened scrutiny from international regulators as well as individuals seeking to bring claims for alleged non-compliance. If the interpretation or application of data privacy or security laws or regulations adversely impact social media networks, this may change the APIs and data made available to us from the social media networks. Although we endeavor to comply with all applicable data privacy and security obligations, we may at times fail (or be perceived to have failed) to do so. Despite our efforts, our personnel or third parties upon whom we rely may fail to comply with such obligations, which could negatively impact our business operations and compliance posture. For example, any failure by a third-party that processes personal data on our behalf to comply with applicable law, regulations, or contractual obligations could result in adverse effects, including inability to operate our business and proceedings against us by governmental entities or others.
If we fail, or are perceived to have failed, to address or comply with data privacy and security obligations, we could face significant consequences. These consequences may include, but are not limited to, government enforcement actions (e.g., investigations, fines, penalties, audits, inspections, and similar); litigation (including class-related claims); additional reporting requirements and/or oversight; bans on collecting or processing personal data; and orders to destroy or not use personal data. Any of these events could have a material adverse effect on our reputation, business, or financial condition, including but not limited to, loss of customers; interruptions or stoppages in our business operations; inability to process personal data or to operate in certain jurisdictions; limited ability to develop or commercialize our platform and services; expenditure of time and resources to defend any claim or inquiry; adverse publicity; or revision or restructuring of our operations.
The public's increasing concerns about data privacy and the use of social media may negatively affect the use or popularity of social media networks, and, in turn, adversely affect our business. For example, negative publicity surrounding particular forums of social media may have an adverse effect on our customers' and prospective customers' perceived value of our solution and willingness to purchase subscriptions or expand such subscriptions to more users or additional departments across their organizations. Similarly, enhanced scrutiny may lead to an increase in regulation of social media, which in turn could change the data or the manner in which data is shared by social media networks to social media management providers and other developers. Any change to the data we receive from social media networks or other third parties may negatively affect the functionality of our platform and products.