our operations, as well as additional reporting obligations and oversight if we become subject to a corporate integrity agreement or other agreement to resolve allegations of non-compliance with these laws. Any action for violation of these laws, even if successfully defended, could cause a pharmaceutical manufacturer to incur significant legal expenses and divert management’s attention from the operation of the business. Prohibitions or restrictions on sales or withdrawal of future marketed products could materially affect business in an adverse way.
Failure to comply with health and data protection laws and regulations could lead to government enforcement actions (which could include civil or criminal penalties), private litigation, and/or adverse publicity and could negatively affect our operating results and business.
We, our CROs, and any potential collaborators may be subject to federal, state, and foreign data protection laws and regulations (i.e., laws and regulations that address privacy and data security). In the U.S., numerous federal and state laws and regulations, including federal health information privacy laws, state data breach notification laws, state health information privacy laws, and federal and state consumer protection laws (e.g., Section 5 of the Federal Trade Commission Act), that govern the collection, use, disclosure and protection of health-related and other personal information could apply to our operations or the operations of our CROs and collaborators. In addition, we may obtain health information from third parties (including research institutions from which we obtain clinical trial data) that are subject to privacy and security requirements under HIPAA, as amended by HITECH. Depending on the facts and circumstances, we could be subject to civil, criminal, and administrative penalties if we knowingly obtain, use, or disclose individually identifiable health information maintained by a HIPAA-covered entity in a manner that is not authorized or permitted by HIPAA.
Compliance with U.S. and international data protection laws and regulations could require us to take on more onerous obligations in our contracts, restrict our ability to collect, use and disclose data, or in some cases, impact our ability to operate in certain jurisdictions. Failure to comply with these laws and regulations could result in government enforcement actions (which could include civil, criminal and administrative penalties), private litigation, and/or adverse publicity and could negatively affect our operating results and business. Moreover, clinical trial subjects, employees and other individuals about whom we or our potential collaborators obtain personal information, as well as the providers who share this information with us, may limit our ability to collect, use and disclose the information. Claims that we have violated individuals’ privacy rights, failed to comply with data protection laws, or breached our contractual obligations, even if we are not found liable, could be expensive and time-consuming to defend and could result in adverse publicity that could harm our business.
We have conducted our TOPAZ Phase 2 clinical trial of apitegromab in the European Economic Area (“EEA”), may conduct future clinical trials in the EEA and therefore may be subject to additional privacy laws. The General Data Protection Regulation, (EU) 2016/679 (“GDPR”) became effective on May 25, 2018, and deals with the collection, use, storage, disclosure, transfer or other processing of personal data and on the free movement of such data. The GDPR imposes a broad range of strict requirements on companies subject to the GDPR, including requirements relating to having legal bases for processing personal information relating to identifiable individuals and transferring such information outside the EEA, including to the U.S., providing details to those individuals regarding the processing of their personal information, keeping personal information secure, having data processing agreements with third parties who process personal information, responding to individuals’ requests to exercise their rights in respect of their personal information, reporting security breaches involving personal data to the competent national data protection authority and affected individuals, appointing data protection officers, conducting data protection impact assessments, and record-keeping. The GDPR increases substantially the penalties to which we could be subject in the event of any non-compliance, including fines of up to 10,000,000 Euros or up to 2% of our total worldwide annual turnover for certain comparatively minor offenses, or up to 20,000,000 Euros or up to 4% of our total worldwide annual turnover for more serious offenses. The GDPR also confers a private right of action on data subjects and consumer associations to lodge complaints with supervisory authorities, seek judicial remedies, and obtain compensation for damages resulting from violations of the GDPR. In addition, the GDPR includes restrictions on cross-border data transfers.
The GDPR may increase our responsibility and liability in relation to personal data that we process where such processing is subject to the GDPR, and we may be required to put in place additional mechanisms to ensure compliance with the GDPR, including as implemented by individual countries. Given the new law, we face uncertainty as to the exact interpretation of the new requirements and we may be unsuccessful in implementing all measures required by data