In addition to the foregoing, any breach of privacy laws or data security laws, particularly resulting in a significant security incident or breach involving the misappropriation, loss or other unauthorized use or disclosure of sensitive or confidential patient or consumer information, could have a material adverse effect on our business, reputation and financial condition. As a data controller, we will be accountable for any third-party service providers we engage to process personal data on our behalf, including our CROs. We attempt to mitigate the associated risks but there is no assurance that privacy and security-related safeguards will protect us from all risks associated with the third-party processing, storage and transmission of such information.
New legislation proposed or enacted in Illinois, Massachusetts, Nevada, New Jersey, New York, Rhode Island, Washington and other states, and a proposed right to privacy amendment to the Vermont Constitution, imposes, or has the potential to impose, additional obligations on companies that collect, store, use, retain, disclose, transfer and otherwise process confidential, sensitive and personal information, and will continue to shape the data privacy environment nationally. State laws are changing rapidly and there is discussion in Congress of a new federal data protection and privacy law to which we would become subject if it is enacted. All of these evolving compliance and operational requirements, including the requirement to comply with GDPR, CCPA, CPRA, CDPA, CPA, or other laws, regulations, amendments to or re-interpretations of existing laws and regulations, and contractual or other obligations relating to privacy, data protection, data transfers, data localization, or information security may impose significant costs that are likely to increase over time, may require us to modify our data processing practices and policies, divert resources from other initiatives and projects, modify our data practices and policies, restrict our business operations, and could restrict the way products and services involving data are offered, all of which could significantly harm our business, financial condition, results of operations and prospects. Further, certain state laws may be more stringent or broader in scope, or offer greater individual rights, with respect to confidential, sensitive and personal information than federal, international or other state laws, and such laws may differ from each other, which may complicate compliance efforts. Any actual or perceived failure by us to comply with these laws, regulations, or other obligations may lead to significant fines, penalties, regulatory investigations, lawsuits, significant costs for remediation, damage to our reputation, or other liabilities.
Many statutory requirements, both in the United States and abroad, include obligations for companies to notify individuals of security breaches involving certain personal information, which could result from breaches experienced by us or our third-party service providers. For example, laws in all 50 U.S. states and the District of Columbia require businesses to provide notice to consumers whose personal information has been disclosed as a result of a data breach. These laws are not consistent, and compliance in the event of a widespread data breach is difficult and may be costly. Moreover, states have been frequently amending existing laws, requiring attention to changing regulatory requirements. We also may be contractually required to notify customers or other counterparties of a security breach. Although we may have contractual protections with our third-party service providers, contractors and consultants, any actual or perceived security breach could harm our reputation and brand, expose us to potential liability or require us to expend significant resources on data security and in responding to any such actual or perceived breach. Any contractual protections we may have from our third-party service providers, contractors or consultants may not be sufficient to adequately protect us from any such liabilities and losses, and we may be unable to enforce any such contractual protections.
We expect that there will continue to be new proposed laws and regulations concerning data privacy and security, and we cannot yet determine the impact such future laws, regulations and standards may have on our business. New laws, amendments to or re-interpretations of existing laws, regulations, standards and other obligations may require us to incur additional costs and restrict our business operations. Because the interpretation and application of health-related and data protection laws, regulations, standards and other obligations are still uncertain, and often contradictory and in flux, it is possible that the scope and requirements of these laws may be interpreted and applied in a manner that is inconsistent with our practices and our efforts to comply with the evolving data protection rules may be unsuccessful. If so, this could result in government-imposed fines or orders requiring that we change our practices, which could adversely affect our business. In addition, these privacy regulations may differ from country to country, and may vary based on whether testing is performed in the United States or in the local country and our operations or business practices may not comply with these regulations in each country.