Complex local, state, national, foreign, and international laws and regulations apply to the collection, use, retention, protection, disclosure, transfer, and other processing of personal data. These privacy laws and regulations are quickly evolving, with new or modified laws and regulations proposed and implemented frequently and existing laws and regulations subject to new or different interpretations. In addition, our legal and regulatory obligations in jurisdictions outside of the U.S. are subject to unexpected changes, including the potential for regulatory or other governmental entities to enact new or additional laws or regulations, to issue rulings that invalidate prior laws or regulations, or to increase penalties significantly. Complying with these laws and regulations can be costly and can impede the development and offering of new products and services. For example, the E.U. General Data Protection Regulation (GDPR), which became effective in May 2018, imposes stringent data protection requirements and provides for significant penalties for noncompliance. Additionally, California enacted legislation, the California Consumer Privacy Act (CCPA), which became effective January 1, 2020. The CCPA requires, among other things, covered companies to provide new disclosures to California consumers, and allow such consumers new abilities to opt-out of certain sales of personal data. The CCPA also provides for civil penalties for violations, as well as a private right of action for data breaches that may increase data breach litigation. Several state privacy laws became effective in 2023, including the California Privacy Rights Act (expanding the CCPA to provide for certain obligations with respect to California employee's sensitive personal data and an expansion of rights, including the right to limit, correct and request deletion of certain sensitive personal data), the Virginia Consumer Data Protection Act, the Utah Consumer Privacy Act, the Colorado Privacy Act and the Connecticut Data Privacy Act. Additional state privacy laws become effective in 2024, including the Montana Consumer Data Privacy Act, Oregon Consumer Data Privacy Act and Texas Data Privacy and Security Act, and a number of other states have passed laws that will go into effect in the next few years, including Delaware, Kentucky, Maryland, Minnesota, Nebraska, New Hampshire, New Jersey, Rhode Island, Tennessee, Indiana and Iowa and many more that are considering similar laws. The new state privacy laws will impose additional data protection obligations on covered businesses, including additional consumer rights, limitations on data uses, new audit requirements for higher risk data, and opt outs for certain uses of sensitive data. The new and proposed privacy laws may result in further uncertainty and would require us to incur additional expenditures to comply. These regulations and legislative developments have potentially far-reaching consequences and may require us to modify our data management practices and incur substantial compliance expense.
Our failure to comply with applicable laws and regulations or other obligations to which we may be subject relating to personal data, or to protect personal data from unauthorized access, use, or other processing, could result in enforcement actions and regulatory investigations against us, claims for damages by customers and other affected individuals, fines, damage to our reputation, and loss of goodwill, any of which could have a material adverse effect on our operations, financial performance, and business.