Brexit, has created uncertainty with regard to data protection regulation in the United Kingdom. In particular, it is unclear how data transfers to and from the United Kingdom will be regulated.
In addition, California recently enacted the California Consumer Privacy Act (CCPA), which creates new individual privacy rights for California consumers (as defined in the law) and places increased privacy and security obligations on entities handling personal data of consumers or households. The CCPA will require covered companies to provide new disclosure to consumers about such companies’ data collection, use and sharing practices, provide such consumers new ways to opt-out of certain sales or transfers of personal information, and provide consumers with additional causes of action. The CCPA went into effect on January 1, 2020, and the California Attorney General may bring enforcement actions for violations beginning July 1, 2020. The CCPA was amended on September 23, 2018, and it remains unclear what, if any, further modifications will be made to this legislation or how it will be interpreted. As currently written, the CCPA may impact our business activities and exemplifies the vulnerability of our business to the evolving regulatory environment related to personal data and protected health information.
Compliance with U.S. and international data protection laws and regulations could require us to take on more onerous obligations in our contracts, restrict our ability to collect, use and disclose data, or in some cases, impact our ability to operate in certain jurisdictions. Failure to comply with U.S. and international data protection laws and regulations could result in government enforcement actions (which could include civil or criminal penalties), private litigation or adverse publicity and could negatively affect our operating results and business. Moreover, clinical trial subjects about whom we or our potential collaborators obtain information, as well as the providers who share this information with us, may contractually limit our ability to use and disclose the information. Claims that we have violated individuals’ privacy rights, failed to comply with data protection laws, or breached our contractual obligations, even if we are not found liable, could be expensive and time consuming to defend and could result in adverse publicity that could harm our business.
If we experience security or data privacy breaches or other unauthorized or improper access to, use of, or destruction of our proprietary or confidential data, employee data or personal data, we may face costs, significant liabilities, harm to our brand and business disruption.
In connection with our discovery platform and efforts, we may collect and use a variety of personal data, such as name, mailing address, email addresses, phone number and clinical trial information. Although we have extensive measures in place to prevent the sharing and loss of patient data in our sample collection process associated with our discovery platform, any failure to prevent or mitigate security breaches or improper access to, use of, or disclosure of our clinical data or patients’ personal data could result in significant liability under state (e.g., state breach notification laws), federal (e.g., HIPAA, as amended by HITECH), and international law (e.g., the GDPR). Any failure to prevent or mitigate security breaches or improper access to, use of, or disclosure of our clinical data or patients’ personal data may cause a material adverse impact to our reputation, affect our ability to conduct new studies and potentially disrupt our business. We may also rely on third-party service providers to host or otherwise process some of our data and that of users, and any failure by such third party to prevent or mitigate security breaches or improper access to or disclosure of such information could have similarly adverse consequences for us. If we are unable to prevent or mitigate the impact of such security or data privacy breaches, we could be exposed to litigation and governmental investigations, which could lead to a potential disruption to our business.
We depend on sophisticated information technology systems to operate our business and a cyber-attack or other breach of these systems could have a material adverse effect on our business.
We rely on information technology systems that we or our third-party vendors operate to process, transmit and store electronic information in our day-to-day operations. The size and complexity of our information technology systems makes them vulnerable to a cyber-attack, malicious intrusion, breakdown, destruction, loss of data privacy or other significant disruption. A successful attack could result in the theft or destruction of intellectual property, data, or other misappropriation of assets, or otherwise compromise our confidential or proprietary information and disrupt our operations. Cyber-attacks are becoming more sophisticated and frequent. We have invested in our systems and the protection and recoverability of our data to reduce the risk of an intrusion or interruption, and we monitor and test our systems on an ongoing basis for any current or potential threats. There can be no assurance that these measures and