Rockley is subject to U.S. and foreign anti-corruption and anti-money laundering laws and regulations. Rockley can face criminal liability and other serious consequences for violations, which can harm its business.
Rockley is subject to the U.S. Foreign Corrupt Practices Act of 1977, as amended, the U.S. domestic bribery statute contained in 18 U.S.C. § 201, the U.S. Travel Act, the USA PATRIOT Act, the U.K. Bribery Act of 2010, and possibly other anti-bribery and anti-money laundering laws in countries in which Rockley conducts activities. Anti-corruption laws are interpreted broadly and prohibit companies and their employees, agents, contractors, and other collaborators from authorizing, promising, offering, or providing, directly or indirectly, improper payments or anything else of value to recipients in the public or private sector. Rockley can be held liable for the corrupt or other illegal activities of its employees, agents, contractors, and other collaborators, even if Rockley does not explicitly authorize or have actual knowledge of such activities. Any violations of the laws and regulations described above may result in substantial civil and criminal fines and penalties, imprisonment, the loss of export or import privileges, debarment, tax reassessments, breach of contract and fraud litigation, reputational harm, and other consequences.
Failures, or perceived failures, to comply with privacy, data protection, and information security requirements in the variety of jurisdictions in which Rockley operates may adversely impact its business, and such legal requirements are evolving, uncertain, and may require improvements in, or changes to, Rockley’s policies and operations.
Rockley’s current and potential future operations and sales are subject to laws and regulations addressing privacy and the collection, use, storage, disclosure, transfer, and protection of a variety of types of data. For example, the European Commission has adopted the General Data Protection Regulation and California recently enacted the California Consumer Privacy Act of 2018, both of which provide for potentially material penalties for non-compliance. These regimes may, among other things, impose data security requirements, disclosure requirements, and restrictions on data collection, uses, and sharing that may impact Rockley’s operations and the development of its business. Rockley has limited access to collect, store, process, or share certain information collected by its products, and Rockley’s products may evolve to collect additional information. Therefore, the full impact of these privacy regimes on Rockley’s business is rapidly evolving across jurisdictions and remains uncertain at this time.
Rockley may also be affected by cyber-attacks and other means of gaining unauthorized access to its products, systems, and data. For instance, cyber criminals or insiders may target Rockley or third parties with which it has business relationships to obtain data, or in a manner that disrupts Rockley’s operations or compromises its products or the systems into which its products are integrated.
Rockley is assessing the continually evolving privacy and data security regimes and measures it believes are appropriate in response. Since these data security regimes are evolving, uncertain, and complex, especially for a global business like Rockley, Rockley may need to update or enhance its compliance measures and these updates or enhancements may require implementation costs. In addition, Rockley may not be able to monitor and react to all developments in a timely manner. The compliance measures Rockley does adopt may prove ineffective. Any failure, or perceived failure, by Rockley to comply with current and future regulatory or customer-driven privacy, data protection, and information security requirements, or to prevent or mitigate security breaches, cyber-attacks, or improper access to, use of, or disclosure of data, or any security issues or cyber-attacks affecting Rockley, could result in significant liability, costs (including the costs of mitigation and recovery), and a material loss of revenue resulting from the adverse impact on its reputation and brand, loss of proprietary information and data, disruption to its business and relationships, and diminished ability to retain or attract customers and business partners. Such events may result in governmental enforcement actions and prosecutions, private litigation, fines, and penalties or adverse publicity, and could cause customers and business partners to lose trust in Rockley, which could have an adverse effect on its reputation and business.
35