There has been heightened legislative and regulatory focus on data privacy and cybersecurity in the U.S., the EU, China and elsewhere, particularly with respect to critical infrastructure providers, including those in the transportation sector. As a result, we must comply with a proliferating and fast-evolving set of legal requirements in this area, including substantive data privacy and cybersecurity standards as well as requirements for notifying regulators and affected individuals in the event of a data security incident. This regulatory environment is increasingly challenging and may present material obligations and risks to our business, including significantly expanded compliance burdens, costs and enforcement risks. For example, in May 2018, the EU’s General Data Protection Regulation, commonly referred to as GDPR, came into effect, which imposes a host of data privacy and security requirements, imposing significant costs on us and carrying substantial penalties for non-compliance.
In addition, many of our commercial partners, including credit card companies, have imposed data security standards that we must meet. In particular, we are required by the Payment Card Industry Security Standards Council, founded by the credit card companies, to comply with their highest level of data security standards. While we continue our efforts to meet these standards, new and revised standards may be imposed that may be difficult for us to meet and could increase our costs.
Significant cybersecurity incidents involving us or one of our AAdvantage partners or other business partners have in the past and may in the future result in a range of potentially material negative consequences for us, including unauthorized access to, disclosure, modification, misuse, loss or destruction of company systems or data; theft of sensitive, regulated or confidential data, such as personal information or our intellectual property; the loss of functionality of critical systems through ransomware, denial of service or other attacks; a diminished ability to retain or attract new customers; a deterioration in our relationships with business partners and other third parties; interruptions or failures in our payment related systems; and business delays, service or system disruptions, damage to equipment and injury to persons or property. The methods used to obtain unauthorized access, disable or degrade service or sabotage systems are constantly evolving and may be difficult to anticipate or to detect for long periods of time. The constantly changing nature of the threats means that we cannot and have not been able to prevent all data security breaches or misuse of data. Similarly, we depend on the ability of our key commercial partners, including AAdvantage partners, other business partners, our regional carriers, distribution partners and technology vendors, to conduct their businesses in a manner that complies with applicable security standards and assures their ability to perform on a timely basis. A security failure, including a failure to meet relevant payment security standards, breach or other significant cybersecurity incident affecting one of our partners, interruptions or failures in our payment related systems, could result in potentially material negative consequences for us, including loss of critical data, service interruptions and the potential for fines, restrictions and expulsion from card acceptance programs. In addition, we use third-party service providers to help us deliver services to customers. These service providers may store personal information, credit card information and/or other confidential information. Such information may be the target of unauthorized access or subject to security breaches because of third-party action, employee error, malfeasance or otherwise. Any of these could (a) result in the loss of information, litigation, indemnity obligations, expensive and inconsistent cybersecurity incident and data breach notification requirements, damage to our reputation, regulatory scrutiny, and other liability, or (b) have a material adverse effect on our business, financial condition and results of operations.
The costs and operational consequences of defending against, preparing for, responding to and remediating an incident of cybersecurity breach may be substantial. As cybersecurity threats become more frequent, intense and sophisticated, costs of proactive defense measures are increasing. Further, we could be exposed to litigation, regulatory enforcement or other legal action as a result of an incident, carrying the potential for damages, fines, sanctions or other penalties, as well as injunctive relief and enforcement actions requiring costly compliance measures. A significant number of recent privacy and data security incidents, including those involving other large airlines, have resulted in very substantial adverse financial consequences to those companies. A cybersecurity incident could also impact our brand, including that of the AAdvantage program, harm our reputation and adversely impact our relationship with our customers, employees and stockholders. The increased regulatory focus on data privacy practices apart from how personal data is secured, such as how personal data is collected, used for marketing purposes, and shared with third parties, also may require changes to our processes and increase compliance costs. There is also an increased risk to our business in the event of a significant data privacy violation, including additional compliance costs, reputational harm, disruption to the manner in which we provide our services, including the geographies we service, and being subject to complaints and/or regulatory investigations, significant monetary liability, fines, penalties, regulatory enforcement, individual or class action lawsuits, public criticism, loss of customers, loss of goodwill or other additional liabilities, such as claims by industry groups or other third parties. Accordingly, failure to appropriately address data privacy and cybersecurity issues could result in material financial and other liabilities and cause significant reputational harm to our company.