In the ordinary course of our business, we and the third parties upon which we rely collect, receive, store, or otherwise process personal data, including information we may collect about participants in our clinical trials. Our data processing activities subject us to numerous, evolving privacy and data security obligations, such as various laws, regulations, guidance, industry standards, external and internal privacy and security policies, contractual requirements, and other obligations relating to privacy and data security.
The legislative and regulatory framework for the processing of personal data worldwide is rapidly evolving in a manner that is increasingly stringent and, globally, this legal and regulatory framework is likely to remain uncertain for the foreseeable future. In the United States, numerous federal, state and local laws and regulations, including federal health information privacy laws, state information security and data breach notification laws, federal consumer protection laws (e.g., Section 5 of the Federal Trade Commission Act), state consumer protection and privacy laws, and other similar laws (e.g., wiretapping and communications interception laws) govern the processing of health-related and other personal data.
At the state level, numerous U.S. states have enacted comprehensive privacy laws that impose certain obligations on covered businesses, including providing specific disclosures in privacy notices and affording individuals certain rights concerning their personal data. Similar laws are being considered in several other states, as well as at the federal and local levels, and we expect more states to pass similar laws in the future. While existing state comprehensive privacy laws exempt some data processed in the context of clinical trials, these developments may further complicate compliance efforts, and increase legal risk and compliance costs for us and the third parties upon whom we rely.
Additionally, we may be subject to new laws governing the privacy of consumer health data. These various privacy and data security laws may impact our business activities, including our identification of research subjects, relationships with business partners and ultimately the marketing and distribution of our products.
Regulators and legislators in the U.S. are increasingly scrutinizing and restricting certain personal data transfers and transactions involving foreign countries. For example, the Biden Administration's executive order Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern as implemented by Department of Justice regulations issued in December 2024, prohibits data brokerage transactions involving certain sensitive personal data categories, including health data, genetic data, and biospecimens, to countries of concern, including China. The regulations also restrict certain investment agreements, employment agreements and vendor agreements involving such data and countries of concern, absent specified cybersecurity controls. Actual or alleged violations of these regulations may be punishable by criminal and/or civil sanctions, and may result in exclusion from participation in federal and state programs.
Outside the United States, an increasing number of laws, regulations, and industry standards may govern privacy, data security, and the transfer of personal data between jurisdictions. For example, the European Union's General Data Protection Regulation ("EU GDPR") and the United Kingdom's General Data Protection Regulation ("UK GDPR", together with the EU GDPR, "GDPR") impose strict requirements for processing personal data including relating to processing of sensitive data (such as health data), ensuring there is a legal basis or condition to justify the processing of personal data, where required requirements relating to obtaining consent of individuals, disclosures about how personal data is to be used, limitations on retention of information, implementing safeguards to protect the security and confidentiality of personal data, where required providing notification of data breaches, maintaining records of processing activities and documenting data protection impact assessments where there is high risk processing and taking certain measures when engaging third-party processors. Under GDPR, companies may face temporary or definitive bans on data processing and other corrective activities, fines of up to €20 million (£17.5 million GBP) or 4% of annual global revenues, whichever is greater, and private litigation related to processing of personal data brought by classes of data subjects or consumer protection organizations authorized at law to represent their interests. Non-compliance could also result in a material adverse effect on our business, financial position and results of operations.
In addition, we may be unable to transfer personal data from Europe and other jurisdictions to the United States or other countries due to data localization requirements or limitations on cross-border data flows. Europe and other jurisdictions have enacted laws requiring data to be localized or limiting the transfer of personal data to other countries. In particular, the European Economic Area ("EEA") and the UK have significantly restricted the transfer of personal data to the United States and other countries. Other jurisdictions may adopt similarly stringent interpretations of their data localization and cross-border data transfer laws. Although there are currently various mechanisms that may be used to transfer personal data from the EEA and UK to the United States in compliance with law, such as the EEA's standard contractual clauses, the UK's International Data Transfer Agreement / Addendum, and the EU-U.S. Data Privacy Framework ("Framework") and the UK extension thereto (which allows for transfers to relevant U.S.-based organizations who self-certify compliance and participate in the Framework), these mechanisms are subject to legal challenges, and there is no assurance that we can satisfy or rely on these measures to lawfully transfer personal data to the United States. If there is no lawful manner for us to transfer personal data from the EEA, the UK, or other jurisdictions to the United States (or other countries), or if the requirements for a legally-compliant transfer are too onerous, we could face significant adverse consequences, including the interruption or degradation of our operations, the need to relocate part of or all of our business or data processing activities to other jurisdictions (such as Europe) at significant expense, increased exposure to regulatory actions, substantial fines and penalties, the inability to transfer data and work with partners, vendors and other third parties, and injunctions against our processing or transferring of personal data necessary to operate our business. Additionally, companies that transfer personal data out of the EEA and UK to other jurisdictions, particularly to the United States, are subject to increased scrutiny from regulators, individual litigants, and activities activist groups. Some European regulators have ordered certain companies to suspend or permanently cease certain transfers of personal data out of Europe for allegedly violating the GDPR's cross-border data transfer limitations.
Although the UK is regarded as a third country under the EU GDPR, the European Commission has adopted an adequacy decision in favor of the UK, a decision recognizing the UK as providing adequate protection under the EU GDPR and enabling data transfers from EU Member States to the UK without additional safeguards. However, the UK adequacy decision will automatically expire in June 2025 unless the European Commission re-assesses and renews or extends that decision and remains under review by the Commission during this period. The EU GDPR and the UK GDPR currently impose substantially similar obligations. However, it is possible that the respective provisions, interpretations and enforcement of the EU GDPR and U.K. GDPR may further diverge in the future and create additional regulatory challenges and uncertainties. In October 2024, the UK Government introduced its Data Use and Access Bill, or UK Bill, into the UK legislative process. If passed, the final version of the UK Bill will have the effect of further altering the similarities between the UK and EEA data protection regime and threaten the UK adequacy decision from the European Commission. This may lead to additional compliance costs and could increase our overall risk.
Additionally in the EEA, the NIS 2 Directive ("NIS 2") is replacing the cybersecurity legal framework under the current NIS framework, aiming to ensure a high level of cybersecurity in the region. NIS 2 brings new medium and large organizations providing services in the EEA within scope of the legal framework. It extends to additional sectors and expands the list of in-scope healthcare organizations, including to certain providers engaged in research and development of medicinal products. The new regime imposes direct obligations on management in respect of an in-scope organization's compliance with NIS 2, requires covered organizations to put in place certain cyber risk management measures, strengthens incident reporting requirements and provides supervisory authorities with a greater oversight. The majority of obligations will come into force when national legislation implementing NIS 2 becomes effective in the relevant EU Member State. EU Member States had until 17 October 2024 to transpose NIS 2 into national legislation, although many countries have still not completed the transposition. As such, the cybersecurity regulatory landscape in the EEA is currently fragmented and uncertain. To the extent we are subject to NIS 2, we will require additional investment of our resources in compliance programs. Under NIS 2 companies may be subject to administrative fines of up to the higher amount of €10 million or 2% of worldwide turnover.
In addition to privacy and data security laws, we are contractually subject to industry standards adopted by industry groups and may become subject to such obligations in the future. We are also bound by other contractual obligations related to privacy and data security, and our efforts to comply with such obligations may not be successful.
We publish privacy policies and other statements, such as compliance with certain certifications or self-regulatory principles, regarding privacy and data security. If these policies, materials or statements are found to be deficient, lacking in transparency, deceptive, unfair, or misrepresentative of our practices, we may be subject to investigation, enforcement actions by regulators, or other adverse consequences.
Obligations related to privacy and data security are quickly changing, becoming increasingly stringent, and creating uncertainty. Additionally, these obligations may be subject to differing applications and interpretations, which may be inconsistent or conflict among jurisdictions. Preparing for and complying with these obligations requires us to devote significant resources and may necessitate changes to our services, information technologies, systems, and practices and to those of any third parties that process personal data on our behalf.
We may at times fail in our efforts to comply with our privacy and data security obligations. Moreover, despite our efforts, our personnel or third parties on whom we rely may fail to comply with such obligations, which could negatively impact our business operations. If we or the third parties on which we rely fail, or are perceived to have failed, to address or comply with applicable privacy and data security obligations, we could face significant consequences, including but not limited to: government enforcement actions (e.g., investigations, fines, penalties, audits, inspections, and similar); litigation (including class-action claims), and mass arbitration demands; additional reporting requirements and/or oversight; bans on processing personal data; and orders to destroy or not use personal data. In particular, plaintiffs have become increasingly more active in bringing privacy-related claims against companies, including class claims and mass arbitration demands. Some of these claims allow for the recovery of statutory damages on a per violation basis, and, if viable, carry the potential for significant statutory damages, depending on the volume of data and the number of violations. Any of these events could have a material adverse effect on our reputation, business, financial condition, results of operations and growth prospects, including but not limited to: loss of customers; interruptions or stoppages in our business operations (including, as relevant, clinical trials); inability to process personal data or to operate in certain jurisdictions; limited ability to develop or commercialize our products; expenditure of time and resources to defend any claim or inquiry; adverse publicity; or substantial changes to our business model or operations.