from committing a bribery offense. We and our commercial partners operate in a number of jurisdictions that pose a high risk of potential Bribery Act or FCPA violations, and we participate in collaborations and relationships with third parties whose corrupt or illegal activities could potentially subject us to liability under the Bribery Act, FCPA or local anti-corruption laws, even if we do not explicitly authorize or have actual knowledge of such activities. In addition, we cannot predict the nature, scope or effect of future regulatory requirements to which our international operations might be subject or the manner in which existing laws might be administered or interpreted.
We are also subject to other laws and regulations governing our international operations, including regulations administered by the governments of the United Kingdom and the United States, and authorities in the European Union, including applicable export control regulations, economic sanctions and embargoes on certain countries and persons, anti-money laundering laws, import and customs requirements and currency exchange regulations, collectively referred to as the Trade Control laws.
There is no assurance that we will be completely effective in ensuring our compliance with all applicable anti-corruption laws, including the Bribery Act, the FCPA or other legal requirements, including Trade Control laws. If we are not in compliance with the Bribery Act, the FCPA and other anti-corruption laws or Trade Control laws, we may be subject to criminal and civil penalties, disgorgement and other sanctions and remedial measures, and legal expenses, which could have an adverse impact on our business, financial condition, results of operations and liquidity. Likewise, any investigation of any potential violations of the Bribery Act, the FCPA, other anti-corruption laws or Trade Control laws by the United Kingdom, United States or other authorities could also have an adverse impact on our reputation, our business, results of operations and financial condition.
We are subject to stringent and evolving U.S. and foreign laws, regulations, rules, contractual obligations, policies and other obligations related to data privacy and security. Our actual or perceived failure to comply with such obligations could lead to regulatory investigations or actions, litigation, fines and penalties, disruptions of our business operations, reputational harm, loss of revenue or profits, and other adverse business consequences.
In the ordinary course of business, we collect, receive, store, process, generate, use, transfer, disclose, make accessible, protect, secure, dispose of, transmit, and share (collectively, processing) personal data and other sensitive information, including proprietary and confidential business data, trade secrets, intellectual property, data we collect about trial participants in connection with clinical trials, and sensitive third-party data. Our data processing activities may subject us to numerous data privacy and security obligations, such as various laws, regulations, guidance, industry standards, external and internal privacy and security policies, contractual requirements, and other obligations relating to data privacy and security.
In the United States, federal, state, and local governments have enacted numerous data privacy and security laws, including data breach notification laws, personal data privacy laws, consumer protection laws (e.g., Section 5 of the Federal Trade Commission Act), and other similar laws. For example, HIPAA, as amended by HITECH, imposes specific requirements relating to the privacy, security, and transmission of individually identifiable health information. Additionally, various U.S. states, including California, Virginia and Colorado, have passed comprehensive privacy laws, and similar laws are being considered in several other states, as well as at the federal and local levels. These developments may further complicate compliance efforts, and increase legal risk and compliance costs for us and the third parties upon whom we rely.
Outside of the U.S., an increasing number of laws, regulations, and industry standards may govern data privacy and security. For example, the European Union’s General Data Protection Regulation, or EU GDPR, and the United Kingdom’s GDPR, or UK GDPR, impose strict requirements for processing personal data. For example, under the EU GDPR, companies may face temporary or definitive bans on data processing and other corrective actions; fines of up to 20 million Euros or 4% of annual global revenue, whichever is greater; or private litigation related to processing of personal data brought by classes of data subjects or consumer protection organizations authorized at law to represent their interests.
In the ordinary course of business, we transfer personal data from the United Kingdom (UK) to the United States or other countries. The UK has enacted laws requiring data to be localized or limiting the transfer of personal data