security, data storage, retention, transfer and deletion, technology protection, and personal information. Foreign data protection, data security, privacy, and other laws and regulations can impose different obligations or be more restrictive than those in the United States. These U.S. federal and state and foreign laws and regulations, which, depending on the regime, may be enforced by private parties or government entities, are constantly evolving and can be subject to significant change, and they are likely to remain uncertain for the foreseeable future. In addition, the application, interpretation, and enforcement of these laws and regulations are often uncertain, particularly in the new and rapidly evolving software and technology industry in which we operate, and may be interpreted and applied inconsistently from country to country and inconsistently with our current policies and practices. A number of proposals are pending before U.S. federal, state, and foreign legislative and regulatory bodies that could significantly affect our business. For example, legal challenges in Europe to the mechanisms allowing companies to transfer personal data from the European Economic Area to certain other jurisdictions, including the United States, could result in further limitations on the ability to transfer data across borders, particularly if governments are unable or unwilling to reach new or maintain existing agreements that permit cross-border data transfers. The California state legislature passed the California Consumer Privacy Act (“CCPA”) in 2018 and California voters approved a ballot measure subsequently establishing the California Privacy Rights Act (“CPRA”) in 2020, which will jointly regulate the processing of personal information of California residents and increase the privacy and security obligations of entities handling certain personal information of California residents, including requiring covered companies to provide new disclosures to California consumers, and affords such consumers new abilities to
opt-out
of certain sales of personal information. The CCPA came into effect on January 1, 2020, and the California Attorney General may bring enforcement actions, with penalties for violations of the CCPA. The CPRA will go into effect on January 1, 2023, instilling enforcement authority in a new dedicated regulatory body, the California Privacy Protection Agency, which will begin carrying out enforcement actions as soon as six months after the enactment date. While aspects of both the CCPA and CPRA and their interpretations remain to be determined in practice, we are committed to complying with their applicable obligations. More generally, some observers have noted the CCPA could mark the beginning of a trend toward more stringent privacy legislation in the United States, as observed with the subsequent Virginia Consumer Data Protection Act (“VCDPA”), enacted in March 2021 and scheduled to become effective on January 1, 2023, and the more recent Colorado Privacy Act (“CPA”), which was enacted in June 2021, will become effective on July 1, 2023. The VCDPA and CPA are comprehensive privacy laws that share similarities with the CCPA, the CPRA, and legislation proposed in other states. We cannot yet fully predict the impact of the CCPA, CPRA, VCDPA, CPA, and other new laws or regulations on our business or operations, but developments regarding these and all privacy and data protection laws and regulations around the world may require us to modify our data processing practices and policies and to incur substantial costs and expenses in an effort to maintain compliance on an ongoing basis. Outside of the United States, virtually every jurisdiction in which we operate has established its own legal framework relating to privacy, data protection, and information security matters with which we and/or our customers must comply. Laws and regulations in these jurisdictions apply broadly to the collection, use, storage, retention, disclosure, security, transfer, and other processing of data that identifies or may be used to identify or locate an individual. Some countries and regions, including the European Union, are considering or have passed legislation that imposes significant obligations in connection with privacy, data protection, and information security that could increase the cost and complexity of delivering our platforms and services, including the European General Data Protection Regulation (“GDPR”) which took effect in May 2018. Complying with the GDPR or other data protection laws, directives, and regulations as they emerge may cause us to incur substantial operational costs or require us to modify our data handling practices on an ongoing basis.
Non-compliance
with the GDPR specifically may result in administrative fines or monetary penalties of up to 4% of worldwide annual revenue in the preceding financial year or €20 million (whichever is higher) for the most serious infringements, and could result in proceedings against us by governmental entities or other related parties and may otherwise adversely impact our business, financial condition, and results of operations.