We are subject to laws and regulations related to, among other things, privacy, data protection, information security and consumer protection across different markets where we conduct our business. Such laws and regulations are constantly evolving and changing and are likely to remain uncertain for the foreseeable future. Our actual or perceived failure to comply with such obligations could have an adverse effect on our business, operating results and financial operations. Complying with these numerous, complex, and often changing regulations is expensive and difficult, and failure to comply with any privacy laws or data security laws or any security incident or breach involving the potential or actual misappropriation, loss or other unauthorized processing, use or disclosure of sensitive or confidential patient, consumer or other personal information, whether by us, one of our collaborators or another third party, could adversely affect our business, financial condition, and results of operations, including but not limited to investigation costs, material fines and penalties, compensatory, special, punitive, and statutory damages, litigation, consent orders regarding our privacy and security practices, requirements that we provide notices, credit monitoring services, and/or credit restoration services or other relevant services to impacted individuals, adverse actions against our licenses to do business, reputational damage and injunctive relief.
European data collection is also governed by restrictive regulations governing the use, processing and cross-border transfer of personal information. The collection, use, storage, disclosure, transfer, or other processing of personal data regarding individuals in Europe, including personal health data, is subject to the EU General Data Protection Regulation ("GDPR"), which imposes strict requirements for processing the personal data of individuals within the European Economic Area (the "EEA"), such as Norway, Iceland and Liechtenstein. The GDPR is directly applicable in each EU member state and is extended to the EEA. The GDPR is wide-ranging in scope and imposes numerous requirements on companies that process personal data, including requirements relating to processing health and other sensitive data, obtaining consent of the individuals to whom the personal data relates, providing information to individuals regarding data processing activities, implementing safeguards to protect the security and confidentiality of personal data, providing notification of data breaches, and taking certain measures when engaging third-party processors. The GDPR implements more stringent operational requirements than its predecessor legislation. Compliance with the GDPR will be a rigorous and time-intensive process that may increase our cost of doing business or require us to change our business practices, and despite those efforts, there is a risk that we may be subject to fines and penalties, litigation, and reputational harm in connection with our European activities. For example, the GDPR applies extraterritorially, requires us to make more detailed disclosures to data subjects, requires disclosure of the legal basis on which we can process personal data, makes it harder for us to obtain valid consent for collecting and processing personal data (including data from clinical trials), requires the appointment of data protection officers, such as when sensitive personal data, such as health data, is processed on a large scale, provides more robust rights for data subjects, including far reaching information rights and the right to erasure, introduces mandatory data breach notification through the EU, imposes additional obligations on us when contracting with service providers and requires us to adopt appropriate privacy governance, including policies, procedures, training, and data audit. The GDPR provides that EU member states and EEA countries may establish their own laws and regulations that go beyond the GDPR in certain areas, such as regarding the mandatory appointment of data protection officers or further limiting the processing of personal data, including genetic, biometric, or health data, which could limit our ability to use and share personal data or could cause our costs to increase. Among other requirements, the GDPR regulates transfers of personal data subject to the GDPR to third countries that have not been found to provide adequate protection to such personal data, including the United States, and the efficacy and longevity of current transfer mechanisms between the EU and the United States remains uncertain. For example, in 2016, the EU and the United States agreed to a transfer framework for data transferred from the EU to the United States, called the Privacy Shield, but the Privacy Shield was invalidated in July 2020 by the Court of Justice of the European Union ("CJEU"). While the CJEU upheld the adequacy of the standard contractual clauses (a standard form of contract approved by the European Commission as an adequate personal data transfer mechanism, and potential alternative to the Privacy Shield), it made clear that reliance on them alone may not necessarily be sufficient in all circumstances. Use of the standard contractual clauses must now be assessed on a case-by-case basis taking into account the legal regime applicable in the destination country, in particular applicable surveillance laws and rights of individuals and additional measures and/or contractual provisions may need to be put in place, however, the nature of these additional measures is currently uncertain. After Brexit the United Kingdom is also a third country from an EU perspective, but the EU Commission adopted adequacy decisions for the United Kingdom on June 28, 2021 largely permitting the free flow of data from the EU to the United Kingdom. However, for the first time, the adequacy decisions include a so-called "sunset clause" and, therefore, will automatically expire four years after their entry into force.
We cannot assure you that our third-party service providers with access to our or our customers', suppliers', trial patients' and employees' personally identifiable and other sensitive or confidential information will not breach contractual obligations imposed by us, or that they will not experience data security breaches or attempts thereof, which could have a corresponding effect on our business, including putting us in breach of our obligations under privacy laws and regulations and/or which could in turn adversely affect our business, results of operations, and financial condition. We cannot assure you that our contractual measures and our own privacy and security-related safeguards will protect us from the risks associated with the third-party processing, use, storage, and transmission of such information. Any of the foregoing could have a material adverse effect on our business, financial condition, results of operations, and prospects.