In the course of our operations and the processing of consumer transactions, our businesses collect, use, store, disclose, transfer and otherwise process a large volume of personal information, including from our consumers, employees and third parties with whom we conduct business, and other user data. The collection, use, storage, disclosure, transfer and other processing of personal information is increasingly subject to a wide array of federal and state laws and regulations regarding data privacy and security, including the GLBA, that are intended to protect the privacy of personal information that is collected, used, stored, disclosed, transferred and otherwise processed in or from the governing jurisdiction. Some countries also are considering or have passed legislation requiring local storage and processing of data, or similar requirements, which could increase the cost and complexity of delivering our products and services. As we seek to expand our business, we are, and may increasingly become, subject to various laws, regulations and standards, as well as contractual obligations, relating to data use, privacy and security in the jurisdictions in which we operate. In many cases, these laws and regulations apply not only to third-party transactions, but also to transfers of information between or among us, our affiliates and other parties with whom we conduct business. These laws, regulations and standards may be interpreted and applied differently over time and from jurisdiction to jurisdiction, and it is possible that they will be interpreted and applied in ways that may have a material and adverse impact on our business, financial condition and results of operations. The regulatory framework for data privacy and security worldwide is continuously evolving and developing and, as a result, interpretation and implementation standards and enforcement practices are likely to remain uncertain for the foreseeable future.
In the United States, various federal and state regulators, including governmental agencies, like the CFPB and FTC, have adopted, or are considering adopting, laws and regulations concerning personal information and data privacy and security. This patchwork of legislation and regulation may give rise to conflicts or differing views of personal privacy rights. For example, certain state laws may be more stringent or broader in scope, or offer greater individual rights, with respect to personal information than federal, international or other state laws, and such laws may differ from each other, all of which may complicate compliance efforts. At the federal level, we are subject to the GLBA, which restricts certain collection, storage, use, disclosure and other processing by covered companies of certain personal information, requires notice to individuals of privacy practices and provides individuals with certain rights to prevent the use and disclosure of certain non-public or otherwise legally protected personal information. The GLBA also imposes requirements regarding the safeguarding and proper destruction of personal information through the issuance of data security standards or guidelines. In addition, many states in which we operate have laws that protect the privacy and security of personal information. For example, the California Consumer Privacy Act (the "CCPA"), as amended by the California Privacy Rights Act ("CPRA"), requires covered companies to, among other things, provide certain disclosures to California residents and provide such residents with certain data protection and privacy rights, including the ability to opt-out of certain sales of personal information. The CCPA provides for civil penalties for violations, as well as a private right of action for certain data breaches that result in the loss of certain personal information. This private right of action may increase the likelihood of, and risks associated with, data breach litigation. The CCPA and the CPRA contain several exemptions, including a provision to the effect that the CCPA and CPRA do not apply where the personal information is collected, processed, sold or disclosed pursuant to the GLBA. It is possible that further amendments to the CCPA and the CPRA will be enacted, but even in their current forms it remains unclear how various provisions of the CCPA and CPRA will be interpreted and enforced. Numerous other states also have enacted or are in the process of enacting state-level data privacy and security laws and regulations and there is discussion in Congress of a new federal data protection and privacy law to which we may become subject if it is enacted. All of these evolving compliance and operational requirements impose significant costs that are likely to increase over time, may require us to modify our data processing practices and policies, divert resources from other initiatives and projects, and could restrict the way products and services involving data are offered, all of which may have a material and adverse impact on our business, financial condition and results of operations.
Many regulatory and statutory requirements, both in the United States and abroad, include obligations for companies to notify individuals of data breaches involving certain personal information, which have in the past resulted from, and may in the future result from, breaches experienced by us or our external service providers. For example, laws in all 50 U.S. states require businesses to provide notice to consumers whose personal information has been disclosed as a result of a data breach. These laws are not consistent and compliance in the event of a widespread data breach is difficult and costly. Moreover, states have been frequently amending existing laws, requiring attention to changing regulatory requirements. We also may be contractually required to notify consumers or other third parties of a security breach. Although we may have contractual protections with our external service providers, actual or perceived security breaches have in the past resulted in, and may in the future result in, harm to our reputation and brand, exposure to potential liability or a need to expend significant resources on data security and in responding to any such actual or perceived breach. Any contractual protections we may have from our external service providers may not be sufficient to adequately protect us from any such liabilities and losses, and we may be unable to enforce any such contractual protections.
In addition to government regulation, privacy advocates and industry groups have and may in the future propose self-regulatory standards from time to time. These and other industry standards may legally or contractually apply to us, or we may elect to comply with such standards. We expect that there will continue to be new proposed laws and regulations concerning data privacy and security and we cannot yet determine the impact such future laws, regulations and standards may have on our business. New laws, amendments to or re-interpretations of existing laws, regulations, standards and other obligations may require us to incur additional costs and restrict our business operations. Because the interpretation and application of laws, regulations, standards and other obligations relating to data privacy and security are still uncertain, it is possible that these laws, regulations, standards and other obligations may be interpreted and applied in a manner that is inconsistent with our data processing practices and policies or the features of our products and services. If so, in addition to the possibility of fines, lawsuits, regulatory investigations, public censure, other claims and penalties, and significant costs for remediation and damage to our reputation, we could be materially and adversely affected if legislation or regulations are expanded to require changes in our data processing practices and policies or if governing jurisdictions interpret or implement their legislation or regulations in ways that negatively impact our business, financial condition and results of operations. We may be unable to make such changes and modifications in a commercially reasonable manner, or at all. Any inability to adequately address data privacy or security-related concerns, even if unfounded, or to comply with applicable laws, regulations, standards and other obligations relating to data privacy and security, could result in additional cost and liability to us, harm our reputation and brand, damage our relationships with consumers and have a material and adverse impact on our business, financial condition and results of operations.
We make public statements about our use and disclosure of personal information through our privacy policies, information provided on our website and press statements. Although we endeavor to comply with our public statements and documentation, we may at times fail to do so or be alleged to have failed to do so. The publication of our privacy policies and other statements that provide promises and assurances about data privacy and security can subject us to potential government or legal action if they are found to be deceptive, unfair or misrepresentative of our actual practices. Moreover, from time to time, concerns may be expressed about whether our products and services compromise the privacy of consumers and others. Any concerns about our data privacy and security practices, even if unfounded, could damage the reputation of our businesses, discourage potential users from our products and services and have a material and adverse impact on our business, financial condition and results of operations.
Any failure or perceived failure by us or our Network Partners or external service providers to comply with our posted privacy policies or with any applicable federal, state or foreign laws, regulations, standards, certifications or orders relating to data privacy or security or consumer protection, or any compromise of security that results in the theft, unauthorized access, acquisition, use, disclosure, or misappropriation of personal information or other user data, could result in fines or proceedings or litigation by governmental agencies or consumers, including class action privacy litigation in certain jurisdictions, which would subject us to significant awards, penalties or judgments, one or all of which could materially and adversely affect our business, financial condition and results of operations. In addition, if our practices are not consistent, or viewed as not consistent, with legal and regulatory requirements, including changes in laws, regulations and standards or new interpretations or applications of existing laws, regulations and standards, we may also become subject to audits, inquiries, whistleblower complaints, adverse media coverage, investigations, or severe criminal or civil sanctions, all of which may affect our financial condition, operating results and our reputation.