Such a withdrawal from the EU is unprecedented, and it is unclear how the United Kingdom’s access to the European single market for goods, capital, services and labor, and the wider commercial, legal and regulatory environment, will impact our business, and in particular our business in Belgium and planned operations in the EU, non-EU European nations and the United Kingdom.
We are subject to certain U.S. and foreign anti-corruption, anti-money laundering, export control, sanctions, and other trade laws and regulations, violations of which can have serious negative consequences for our business.
U.S. and foreign anti-corruption, anti-money laundering, export control, sanctions, and other trade laws and regulations (collectively, “Trade Laws”), prohibit, among other matters, companies and their employees, agents, clinical research organizations, legal counsel, accountants, consultants, contractors, and other partners from authorizing, promising, offering, providing, soliciting, or receiving directly or indirectly, corrupt or improper payments or anything else of value to or from recipients in the public or private sector. Violations of Trade Laws can result in substantial criminal fines and civil penalties, imprisonment, the loss of trade privileges, debarment, tax reassessments, breach of contract and fraud litigation, and reputational harm, among other consequences. We routinely have direct or indirect interactions with officials and employees of government agencies or government-affiliated hospitals, universities, and other organizations, and we expect our non-U.S. activities to increase in time. We plan to engage third parties for clinical trials and/or obtain necessary permits, licenses, patent registrations, and other regulatory approvals from such officials, employees and government agencies and affiliates and we may be held liable for any corrupt or other illegal activities of our personnel, agents, or partners, even if we do not explicitly authorize or have prior knowledge of such activities.
Failure to comply with current or future federal, state and foreign laws and regulations and industry standards relating to privacy and data protection laws could lead to government enforcement actions, which could include civil or criminal penalties, private litigation, and/or adverse publicity and could negatively affect our operating results and business.
We and our partners may be subject to federal, state and foreign data privacy and security laws and regulations. Failure by us or our third-party vendors, collaborators, contractors and consultants to comply with any of these laws and regulations could result in notification obligations or enforcement actions against us, which could result in, among other things, fines, claims for damages by affected individuals, damage to our reputation and loss of goodwill, any of which could have a material adverse effect on our business, financial condition, results of operations or prospects. These laws, rules and regulations evolve frequently and their scope may continually change, through new legislation, amendments to existing legislation and changes in enforcement, and may be inconsistent from one jurisdiction to another. The interpretation and application of consumer, health-related and data protection laws in the United States, the EU and elsewhere, are often uncertain, contradictory and in flux. As a result, implementation standards and enforcement practices are likely to remain uncertain for the foreseeable future. As our operations and business grow, we may become subject to or affected by new or additional data protection laws and regulations and face increased scrutiny or attention from regulatory authorities.
In the United States, numerous federal and state laws and regulations, including federal health information privacy laws, state data breach notification laws, state health information privacy laws and federal and state consumer protection laws (e.g., Section 5 of the Federal Trade Commission Act), which govern the collection, use, disclosure and protection of health-related and other personal information could apply to our operations or the operations of our collaborators. In addition, we may obtain health information from third parties (including research institutions from which we obtain clinical trial data) that are subject to privacy and security requirements under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the Health Information Technology for Economic and Clinical Health Act. Depending on the facts and circumstances, we could be subject to criminal penalties if we knowingly obtain, use, or disclose individually identifiable health information maintained by a HIPAA-covered entity in a manner that is not authorized or permitted by HIPAA.
Many states have also adopted comparable privacy and security laws and regulations, some of which may be more stringent than HIPAA. Such laws and regulations will be subject to interpretation by various courts and other governmental authorities, thus creating potentially complex compliance issues for us and our future customers and strategic partners. In addition, California recently enacted the CCPA, which became effective on January 1, 2020. The CCPA, among other things, requires new disclosures to California consumers and affords such consumers new abilities to access and delete their personal information, opt-out of certain sales of personal information and receive detailed information about how their personal information is used. The CCPA provides for civil penalties for violations, as well as a private right of action for data breaches that is expected to increase the frequency of data breach litigation. In the event that we are subject to or affected by HIPAA, the CCPA or other domestic privacy and data protection laws, any liability from failure to comply with the requirements of these laws could adversely affect our financial condition.
We currently operate in countries outside of the United States, including Belgium and Australia, where laws may in some cases be more stringent than the requirements in the United States. For example, in Europe, the European Union General Data Protection Regulation (the “GDPR”) went into effect in May 2018 and imposes strict requirements for the collection, storage, use, disclosure, transfer and other processing of the personal data of individuals within the European Economic
71