us with the most current version of such software, modify their products, standards or terms of use in a manner that degrades the functionality or performance of our platform or is otherwise unsatisfactory to us or gives preferential treatment to competitive products or services, we may be required to seek comparable software from other sources, which may be more expensive and/or inferior, or might not be available at all. Any of these events could adversely affect our business, financial condition and results of operations.
We may incur increased costs to comply with privacy and data protection laws, regulations, and industry standards and, to the extent we fail to comply, we could be subject to government enforcement actions, private claims and litigation, and adverse publicity.
As part of our day-to-day business operations and the services we provide, including through our website and mobile application, we receive, collect, store, process, transmit, share, and use various kinds of personal information pertaining to our employees, members and other travelers, aircraft owners and buyers, and business partners. A variety of federal, state, local, and foreign laws, regulations, and industry standards apply, or could in the future apply as our business grows and expands, to our processing of that information. The California Consumer Privacy Act of 2018, for example, requires covered companies that process personal information about California residents to make specific disclosures about their data collection, use, and sharing practices, and to allow consumers to opt out of certain types of data sharing with third parties, among other obligations. We are required to comply with the Payment Card Industry Data Security Standard (“PCI DSS”), a set of technical and operating requirements issued by payment card brands designed to protect cardholder data because we accept debit and credit cards for payment.
These laws, regulations, and industry standards are continually evolving and are subject to potentially differing interpretations, including as to their scope and applicability to our business. The interpretation of these laws, regulations, and standards can be uncertain, and they may be applied inconsistently from one jurisdiction to another or may conflict with other rules or our practices. As a result, our practices might not have complied or might not comply in the future with all such laws, regulations, and industry standards.
Compliance with current and future privacy and data protection laws, regulations, and industry standards can be costly and time-consuming, and may necessitate changes to our business practices with respect to the collection, use, and disclosure of personal information, which may adversely affect our business and financial condition. Any failure, or perceived failure, by us to comply with these laws, regulations, and industry standards could have a materially adverse impact to our reputation and brand, and may result in government investigations and enforcement actions, as well as claims for damages and other forms of relief by affected individuals, business partners, and other third parties. Any such investigations, enforcement actions, or claims could require us to change our operations, incur substantial costs and expenses in an effort to comply, force us to incur significant expenses in defense of such proceedings, distract our management, increase our costs of doing business, result in a loss of customers and vendors, result in the imposition of monetary penalties, and otherwise adversely affect our business, financial condition, and results of operations.
Any failure to maintain the security of personal or other confidential information that is stored in our information technology systems or by third parties on our behalf, whether as the result of cybersecurity breaches or otherwise, could damage our reputation, result in litigation or other legal actions against us, cause us to incur substantial additional costs, and materially adversely affect our business and operating results.
Our information technology systems, and those of our third-party service providers and business partners, contain personal financial and other sensitive information relating to our customers, employees, and other parties, as well as proprietary and other confidential information related to our business. Attacks against these systems, including but not limited to ransomware, malware, and phishing attacks, create a risk of data breaches and other cybersecurity incidents. Some of our systems and third-party service providers’ systems have experienced security incidents or breaches, and although those incidents did not have a material adverse effect on our operating results, there can be no assurance of a similar result in the future.
17