We receive, store and process various types of data, including personal data, from and about customers, including third-party reseller customers, partners, end users of our services, and in limited cases, end consumers, as well as data from and about our personnel and service providers. In connection with future feature offerings, we may receive, store and process additional types of data, including personal data. Our processing of data is subject to a variety of laws and regulations, including regulation by various government agencies, such as the U.S. Federal Trade Commission, or FTC, and various state, local and foreign agencies. Our data processing is also subject to contractual obligations and industry standards.
The U.S. federal and various state governments have adopted requirements related to the collection, distribution, use, storage, and security of personal data, including unique online identifiers. For example, the California Consumer Privacy Act of 2018, or CCPA, originally became effective January 1, 2020 and an amended version became effective on January 1, 2023. The amended CCPA requires covered businesses to, among other things, make new disclosures to consumers about their data collection, use, and sharing practices, and allows consumers to opt out of certain data sharing with third parties. Under the amended CCPA, consumers include individuals that interact with us in a professional or employment capacity. The CCPA provides a limited private cause of action for certain data breaches. Numerous other states have proposed, and in many cases, enacted, privacy legislation. The effects of such state privacy laws are potentially significant and may require us to incur substantial costs and expenses in an effort to comply and increase our potential exposure to regulatory enforcement and/or litigation. We expect additional states may continue to enact data protection legislation that may be similar to or different from the state privacy laws already adopted.
Additionally, the FTC and many state attorneys general are interpreting federal and state consumer protection laws as imposing standards for the collection, use, dissemination, and security of personal data. We may be required to incur costs and expenses to stay in compliance with these interpretations, and if we were found to have violated consumer protection laws, we may face enforcement actions which could adversely affect our business. We also may be subject to laws and rules implemented and enforced by the FTC, the Federal Communications Commission, or FCC, and potentially other federal agencies, as well as state, local or international laws and regulations related to marketing, advertising, commercial electronic mail and other messages. Compliance with these requirements may limit our ability to engage in certain marketing and advertising activities. If we were found to have violated such requirements, we may face enforcement actions and/or face civil penalties, either of which could adversely affect our business.
Several foreign countries and governmental bodies, including the European Union, Switzerland and the United Kingdom have laws and regulations dealing with the processing of personal data obtained about their residents, which in certain cases are more restrictive than those in the United States. We expect that additional jurisdictions may enact similar requirements. Laws and regulations in these jurisdictions can apply broadly to the collection, use, storage, disclosure and security of various types of data, including personal data, such as names, email addresses and in some jurisdictions, unique online identifiers like Internet Protocol, or IP, addresses.
In particular, in the European Union, the GDPR became effective in May 2018. The GDPR includes stringent operational requirements for processors and controllers of personal data and imposes significant penalties for non-compliance. The United Kingdom has implemented data protection laws that substantially align with requirements under the GDPR and provide for similar penalties. The United Kingdom's decision to adopt a separate data protection regime after its exit from the European Union, known as Brexit, has created uncertainty and the potential for differing regulations as compared to the European Union, which in turn may delay or deter transactions with customers that transfer personal data to and from the United Kingdom.
In addition, there remains uncertainty regarding transfers of certain personal data from the European Economic Area, Switzerland, and the United Kingdom following Brexit as well as the invalidation of both the EU-U.S. Privacy Shield and Swiss-U.S. Privacy Shield. While alternative transfer mechanisms, such as Standard Contractual Clauses, are available to Yext and its customers for such transfers, the use of these transfer mechanisms, in addition to related developments and uncertainty, could require us to implement additional contractual and technical safeguards for personal data transferred out of the European Economic Area, Switzerland, and the United Kingdom, which may increase compliance and related costs and risks, lead to increased regulatory scrutiny or liability, necessitate additional contractual negotiations, and adversely impact our business, operating results and financial condition. Customers and potential customers may hesitate or refuse to purchase and use our products and services due to the potential risk associated with cross-border data transfers or may view alternative data transfer mechanisms as being too costly, burdensome or uncertain. Our ability to attract and retain customers may therefore be impaired. In addition, other mechanisms that we use or may use in the future in an effort to legitimize cross-border data transfers may be challenged or invalidated or may evolve such that they do not function as appropriate means for us to transfer certain personal data from the European Economic Area, Switzerland, and the United Kingdom to the United States.
These domestic and foreign laws and regulations relating to privacy and information security are evolving, can be subject to significant change and may result in ever-increasing regulatory and public scrutiny and escalating levels of enforcement and sanctions. Interpretation of certain requirements remains unclear and may evolve, in particular for laws and regulations that have recently been enacted. Application of laws and regulations may be inconsistent or may conflict among jurisdictions resulting in additional complexity and increased legal risk. In addition, these requirements have increased our compliance costs and may impair our ability to grow our business or offer our service in some locations, may subject us to liability for non-compliance, may require us to modify our data processing and transferring practices and policies and may strain our technical capabilities. In addition as we, our customers and potential customers evaluate the impact of new laws and regulations, sales cycles have lengthened and transaction costs have increased as customers conduct additional diligence and as contractual obligations under the new regulations are negotiated.
To protect the personal data that we process, including payment card information, we have implemented technical and organizational measures in an effort to preserve and protect our data and our customers' data against loss, misuse, corruption, destruction, or misappropriation caused by systems failures, unauthorized access or other misuse. Notwithstanding these measures, we could experience security incidents, fail to handle personal data correctly or be subject to liability claims relating to information security by individuals and customers whose data resides in our databases. We are also required to comply with applicable industry standards with respect to our handling of payment card information. If we fail to meet appropriate compliance levels for payment card data specifically, this could negatively impact our ability to utilize payment cards as a method of payment, and/or collect and store payment card information, which could disrupt our business.
As our products are applied to new uses and in new verticals, we may become subject to additional regulations or legal risks. For example, we have begun selling our platform to government entities. Risks associated with sales to government entities include adherence to complex procurement regulations and other government-specific contractual requirements. We may be subject to audits and investigations relating to our government contracts and any violations could result in various civil and criminal penalties and administrative sanctions, including termination of contracts, payment of fines, and suspension or debarment from future government business, as well as harm to our reputation and financial results. Sales to government entities can be highly competitive, expensive and time consuming, often requiring significant upfront time and expense without any assurance that we will successfully complete a sale. As another example, in order to offer our products to certain customers in the health care industry we have implemented certain security and privacy measures and related procedures to comply with the Health Insurance Portability and Accountability Act of 1996, or HIPAA, and the Health Information Technology for Economic and Clinical Health Act, or HITECH. We may execute HIPAA business associate agreements, or BAAs, with certain customers that are "covered entities" under HIPAA, which would subject us to additional liabilities, penalties and fines in the event we fail to comply with the terms of such agreements. The storage of such information may require us to modify and enhance our platform at a significant cost.
Any failure or perceived failure by us to comply with laws, regulations, policies, legal or contractual obligations, industry standards, or regulatory guidance relating to privacy or information security may result in governmental investigations and enforcement actions, litigation, fines and penalties, consumer actions, and/or adverse publicity, and could cause our customers and partners to lose trust in us, which could have an adverse effect on our reputation and business. This could materially affect our business, operating results, and financial condition. Furthermore, our third-party reseller customers, over which we have more limited control, may not comply with the laws, regulations, and policies described above, which may damage our reputation or subject us to costly legal or regulatory inquiries and liability or to contractual liability.
We expect that there will continue to be new proposed laws, regulations and industry standards relating to privacy, data protection, marketing, advertising communications, information security and cross-border data transfer in the United States, the European Union and other jurisdictions, and we cannot determine the impact such future laws, regulations and standards may have on our business. Future laws, regulations, standards and other obligations or any changed interpretation of existing laws or regulations could impair our ability to develop and market new features and maintain and grow our customer base and increase revenue. Future restrictions on the collection, use, sharing or disclosure of data or additional requirements placed upon us, our customers, partners or end consumers in connection with the use and disclosure of such information could require us to incur additional costs or modify our platform or other aspects of our products and services, possibly in a material manner, and could increase the complexity and cost of developing and deploying new products or limit our ability to develop new products and features altogether.