may be adverse to our business. In addition, we are unable to predict what future tax reform may be proposed or enacted or what effect such changes would have on our business, but any changes, to the extent they are brought into tax legislation, regulations, policies, or practices, could increase our effective tax rates in the countries where we have operations and have an adverse effect on our overall tax rate, along with increasing the complexity, burden and cost of tax compliance, all of which could impact our business, financial condition, and results of operations.
Tax regulatory authorities may disagree with our positions and conclusions regarding certain tax positions resulting in unanticipated costs or non-realization of expected benefits.
A tax authority may disagree with tax positions that we have taken. For example, the Internal Revenue Service (“IRS”), or another tax authority could challenge our allocation of income by tax jurisdiction and the amounts paid between our affiliated companies pursuant to our intercompany arrangements and transfer pricing policies, including amounts paid with respect to our intellectual property in connection with our intercompany research and development cost sharing arrangement and legal structure. A tax authority may take the position that material income tax liabilities, interest, and penalties are payable by us, in which case, we expect that we might contest such assessment. Contesting such an assessment may be lengthy and costly and if we were unsuccessful in disputing the assessment, the implications could be materially adverse to us and affect our anticipated effective tax rate or operating income, and we could be required to pay substantial penalties and interest where applicable.
Catastrophic events may disrupt our business.
Our corporate headquarters and some of our suppliers and foundry vendors are located in areas that are in active earthquake zones or are subject to power outages, natural disasters, political, social, or economic unrest, and other potentially catastrophic events. In the event of a major earthquake, hurricane, flooding, or other catastrophic event such as fire, power loss, telecommunications failure, cyber-attack, war, terrorist attack, political, social, or economic unrest, or disease outbreak, such as the current COVID-19 pandemic, we may be unable to continue our operations and may endure system interruptions, reputational harm, delays in our product development, breaches of data security, or loss of critical data, any of which could have an adverse effect on our future results of operations.
State, federal, and foreign laws and regulations related to privacy, data use, and security could adversely affect us.
We are subject to state and federal laws and regulations related to privacy, data use, and security. In addition, in recent years, there has been a heightened legislative and regulatory focus on data security, including requiring consumer notification in the event of a data breach. Legislation has been introduced in Congress and there have been several Congressional hearings addressing these issues. From time to time, Congress has considered, and may do so again, legislation establishing requirements for data security and response to data breaches that, if implemented, could affect us by increasing our costs of doing business. In addition, several states have enacted privacy or security breach legislation requiring varying levels of consumer notification in the event of a security breach. For example, California passed the California Consumer Privacy Act (“CCPA”), which enhances consumer protection and privacy rights by granting consumers resident in California new rights with respect to the collection of their personal data and imposing new operational requirements on businesses, went into effect in January 2020. The CCPA includes a statutory damages framework and private rights of action against businesses that fail to comply with certain CCPA terms or implement reasonable security procedures and practices to prevent data breaches. Several other states are considering similar legislation.
Foreign governments are raising similar privacy and data security concerns. In particular, the European Union has enacted a General Data Protection Regulation (“GDPR”), which became effective in May 2018. It is unclear how compliance with GDPR will affect our business. China, Russia, Japan, and other countries in Latin
34