Item 1A. Risk Factors
ITEM 1A: RISK FACTORS
We are subject to various risks and uncertainties, which could materially affect our business, results of operations, financial condition, future results, and the trading price of our common stock. You should read carefully the following information together with the information appearing in Part I, Item 1A, Risk Factors in our Annual Report on Form 10-K for the year ended December 31, 2020 as filed with the SEC on February 5, 2021 (“2020 Form 10-K”). The following information supplements and, to the extent inconsistent, supersedes some of the information appearing in the Risk Factors section of our 2020 Form 10-K. These risk factors, as well as our condensed consolidated financial statements and notes thereto and the other information appearing in this report, should be reviewed carefully for important information regarding risks that affect us.
LEGAL, REGULATORY AND COMPLIANCE RISKS
Our business is subject to extensive government regulation and oversight. Our failure to comply with extensive, complex, overlapping, and frequently changing rules, regulations, and legal interpretations could materially harm our business.
Cryptocurrency Regulation
The regulation of cryptocurrency is still an evolving area, and we expect that it could become subject to additional regulations and licensing requirements, including as a result of our cryptocurrency offerings expanding and the number of jurisdictions in which we provide these offerings increasing. The evolving regulatory landscape may require us to make product changes, restrict product offerings in certain jurisdictions, or implement additional and potentially costly controls. If we fail to comply with regulations, requirements, or prohibitions applicable to us, we could face regulatory or other enforcement actions and potential fines and other consequences.
In addition, financial and third party risks related to our cryptocurrency offerings, such as inappropriate access and theft of cryptocurrency assets held by our custodian, insufficient insurance coverage by the custodian to reimburse us for all such losses, the custodian’s failure to maintain effective controls over the custody and settlement services provided to us, the custodian’s inability to purchase or liquidate cryptocurrency holdings, and default on financial or performance obligations by counterparty financial institutions, could materially and adversely affect our financial performance and significantly harm our business.
Privacy and Protection of Customer Data
The legal and regulatory environment relating to “privacy and data protection laws” (as defined in “Item 1. Business— Government Regulation” in our 2020 Form 10-K) continues to develop and evolve in ways we cannot predict, including with respect to technologies such as cloud computing, artificial intelligence, cryptocurrency, and blockchain technology. Any failure, or perceived failure, by us to comply with our privacy policies as communicated to users or with privacy and data protection laws could result in proceedings or actions against us by data protection authorities, government entities, or others. Such proceedings or actions could subject us to significant fines, penalties, judgments, and negative publicity which may require us to change our business practices, increase the costs and complexity of compliance, and materially harm our business. In addition, compliance with inconsistent privacy and data protection laws may restrict our ability to provide products and services to our customers. For further information regarding data protection and information security, see “Item 1. Business—Government Regulation” in our 2020 Form 10-K.
60
Table of Contents
PayPal relies on a variety of compliance methods to transfer personal data of European Economic Area (“EEA”) individuals to the U.S., including Binding Corporate Rules (“BCRs”) for internal transfers of certain types of personal data and Standard Contractual Clauses (“SCCs”) as approved by the European Commission for transfers to and from third parties. We continue to monitor and respond to changes in the requirements for cross-border transfers of data. In June 2021, the European Commission imposed new SCC requirements which impose new contract and operational requirements on PayPal, its merchants, and vendors in order to adhere to certain affirmative duties, including requirements related to government access transparency, enhanced data subject rights, and broader third party assessments to ensure safeguards necessary to protect personal data exported from PayPal’s EEA customers and/or employees to countries outside the EEA. To the extent PayPal relies on SCCs, such engagements will require new contractual arrangements under the updated requirements to avoid limitation on PayPal’s ability to process EEA data in third countries.
In the wake of the California Consumer Privacy Act (“CCPA”) passed in 2018, multiple US states have proposed similar legislation to protect consumers in their states. California passed the Consumer Privacy Rights Act of 2020 (the “CPRA”, an amendment to the CCPA), Virginia has passed the Virginia Consumer Data Protection Act (signed into law March 2, 2021) and Colorado has passed the Colorado Privacy Act (signed into law July 7, 2021). The continued increase in state-level privacy laws is likely to result in a disparate array of privacy rules with unaligned provisions, accountability requirements, individual rights, and state enforcement powers. In the absence of federal legislation, the state-level privacy terrain is likely to become increasingly complex and may add to increased regulatory scrutiny, business cost and consumer confusion.
61
Table of Contents
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.