As we seek to build a trusted and secure platform for and to expand our network of customers and facilitate their transactions and interactions with their guests, we will increasingly be subject to laws and regulations relating to the collection, use, retention, privacy, security, and transfer of information, including the personal information of their employees and guests. Domestically, this includes federal as well as state-specific legislation, including but not limited to the CCPA. Additionally, a number of U.S. state-specific privacy laws have recently become effective or will become effective in 2024. As we expand internationally, international privacy laws pertaining to the processing and security of personal information become more relevant to our business, including but not limited to the GDPR, the United Kingdom GDPR and local privacy legislation, as well as Canadian privacy legislation, including Canada's Personal Information Protection and Electronic Documents Act and local provincial legislation. As with the other laws and regulations noted above, these laws and regulations may change or be interpreted and applied differently over time and from jurisdiction to jurisdiction, and it is possible they will be interpreted and applied in ways that will materially and adversely affect our business.
As noted above, many states in which we operate have laws that protect the privacy and security of sensitive and personal information. Certain state laws may be more stringent or broader in scope, or offer greater individual rights, with respect to sensitive and personal information than federal or other state laws, and such laws may differ from each other, which may complicate compliance efforts. For example, California enacted the CCPA, which initially went into effect in January 2020, with important amendments that went into effect in January 2023. The CCPA, as amended, requires companies covered by the legislation to provide disclosures to California consumers and afford such consumers rights with respect to their personal information, including the right to request deletion of their personal information, the right to receive the personal information on record for them, the right to know what categories of personal information generally are maintained about them, as well as the right to opt-out of certain sales of personal information and sharing personal information for certain advertising purposes. The CCPA also granted a new state agency, the California Privacy Protection Agency, powers to adopt and enforce regulations interpreting the CCPA, and the agency is continuing to adopt new rules that may require us to evolve and adapt our compliance strategies. The effects of the CCPA are potentially significant and may require us to modify our data collection or processing practices and policies and to incur substantial costs and expenses in an effort to comply and increase our potential exposure to regulatory enforcement and/or litigation. In addition, the CCPA provides for civil penalties for violations, as well as a private right of action for certain data breaches that result in the loss of personal information. This private right of action may increase the likelihood of, and risks associated with, data breach litigation.
Certain other states, such as Virginia, Colorado, Connecticut, and Utah, have passed and implemented consumer privacy laws that impose similar privacy obligations as the CCPA. Additional states have passed consumer privacy laws that will come into force over the next few years. We anticipate that more states may enact legislation similar to the CCPA and the forthcoming state privacy laws, which provide consumers with new privacy rights and increase the privacy and security obligations of entities handling certain personal information of such consumers. Moreover, states may pass consumer privacy laws that deviate from or exceed the requirements of the existing laws, or that regulate specific business practices. For example, Washington state's My Health My Data Act will come into effect in 2024 and will require regulated businesses to apply specific protections for consumer health data, which is defined broadly to include certain data categories that are not directly related to health, such as location information. These state privacy developments have prompted a number of proposals for new federal and state-level privacy legislation and regulation. Such proposed legislation and regulation, if enacted, may add additional complexity, variation in requirements, restrictions and potential legal risk, require additional investment of resources in compliance programs, impact strategies, and the availability of previously useful data, and could result in increased compliance costs and/or changes in business practices and policies.
The regulatory framework governing the collection, processing, storage, use, and sharing of certain information, particularly financial and other personal information, is rapidly evolving and is likely to continue to be subject to uncertainty and varying interpretations. It is possible that these laws may be interpreted and applied in a manner that is inconsistent with our existing data management practices or the features of our services and platform capabilities. Any failure or perceived failure by us, or any third parties with which we do business, to comply with our posted privacy statements or notices, changing consumer expectations, evolving laws, rules and regulations, industry standards, or contractual obligations to which we or such third parties are or may become subject, may result in actions or other claims against us by governmental entities or private actors, the expenditure of substantial costs, time, and other resources or the incurrence of significant fines, penalties, or other liabilities. In addition, any such action, particularly to the extent we were found to have engaged in violations or otherwise liable for damages, would damage our reputation and adversely affect our business, financial condition, and results of operations.
We cannot yet fully determine the impact these or future laws, rules, regulations, and industry standards may have on our business or operations. Any such laws, rules, regulations, and industry standards may be inconsistent among different jurisdictions, subject to differing interpretations or may conflict with our current or future practices. Additionally, our partners and our customers and their guests may be subject to differing privacy laws, rules, and legislation, which may mean that our partners or customers require us to be bound by varying contractual requirements applicable to certain other jurisdictions. If our customers fail to comply with such privacy laws, rules, or legislation, we could be exposed to liability and our business, financial condition, results of operations, and brand could be adversely affected. Adherence to contractual requirements imposed by our partners or customers may impact our collection, use, processing, storage, sharing, and disclosure of various types of information including financial information and other personal information, and may mean we become bound by, or voluntarily comply with, self-regulatory or other industry standards relating to these matters that may further change as laws, rules, and regulations evolve. Complying with these requirements and changing our policies and practices may be onerous and costly, and we may not be able to respond quickly or effectively to regulatory, legislative, and other developments. These changes may in turn impair our ability to offer our existing or planned features, products, and services, and/or increase our cost of doing business. As we expand our partnerships and our customer base, these requirements may vary from customer to customer, and from guest to guest, further increasing the cost of compliance and doing business.
We publicly post documentation regarding our practices concerning the collection, processing, use, and disclosure of information. Although we endeavor to comply with our published statements, notices, and documentation, we may at times fail to do so or be alleged to have failed to do so. Any failure or perceived failure by us to comply with our privacy statements, notices, or any applicable privacy, security, or data protection, information security, or consumer-protection related laws, regulations, orders, or industry standards could expose us to costly litigation, significant awards, fines or judgments, civil and/or criminal penalties, or negative publicity, and could materially and adversely affect our business, financial condition, and results of operations. The publication of our privacy statements, notices, and other documentation that provide promises and assurances about privacy and security can subject us to potential state and federal action if they are found to be deceptive, unfair, or misrepresentative of our actual practices, which could, individually or in the aggregate, materially and adversely affect our business, financial condition, and results of operations.
We have incurred, and may continue to incur, significant expenses to comply with evolving mandatory privacy and security standards and protocols imposed by law, regulation, industry standards, shifting customer and guest expectations, or contractual obligations, both in the U.S. and internationally. We post on our website our privacy statement and practices concerning the collection, use, and disclosure of information. In particular, with laws and regulations such as the CCPA and similar laws in the United States imposing new and relatively burdensome obligations, and with substantial uncertainty over the interpretation and application of these and other laws and regulations, we may face challenges in addressing their requirements and making necessary changes to our policies and practices and may incur significant costs and expenses in an effort to do so. This also applies in the context of international privacy legislation such as the GDPR, UK GDPR and applicable Canadian privacy legislation. Any failure, real or perceived, by us to comply with our posted privacy statements or notices, changing customer and guest expectations, or with any evolving regulatory requirements, interpretations, or orders, other local, state, federal, or international privacy, data protection, information security, or consumer protection-related laws and regulations, industry standards, or contractual obligations could cause our customers to reduce their use of our products and services, disrupt our supply chain or third-party vendor or developer partnerships, and materially and adversely affect our business.