Item 1A. Risk Factors
ITEM 1A: RISK FACTORS
We are subject to various risks and uncertainties, which could materially affect our business, results of operations, financial condition, future results, and the trading price of our common stock. You should read carefully the following information together with the information appearing in Part I, Item 1A, Risk Factors in our Annual Report on Form 10-K for the year ended December 31, 2020 as filed with the SEC on February 5, 2021 (“2020 Form 10-K”). The following information supplements and, to the extent inconsistent, supersedes some of the information appearing in the Risk Factors section of our 2020 Form 10 ‑ K. These risk factors, as well as our condensed consolidated financial statements and notes thereto and the other information appearing in this report, should be reviewed carefully for important information regarding risks that affect us.
LEGAL, REGULATORY AND COMPLIANCE RISKS
Our business is subject to extensive government regulation and oversight. Our failure to comply with extensive, complex, overlapping, and frequently changing rules, regulations, and legal interpretations could materially harm our business.
Lending Regulation
PayPal’s U.S. consumer short-term installment loan product is subject to federal law, as well as state lending laws (some of which require licensure and/or state regulator notification), federal and state debt collection laws, as well as compliance with the Equal Credit Opportunity Act and Regulation B as implemented by the Consumer Financial Protection Bureau (“CFPB”) and other applicable laws and regulations. In addition, we hold a number of U.S. state lending licenses. Increased global regulatory focus on short-term installment products could result in laws or regulations requiring changes to our policies, procedures, operations, and product offerings. We could be subject to fines, other enforcement action, and litigation if we are found to violate any aspects of applicable law or regulations.
Cryptocurrency Regulation
The regulation of cryptocurrency is still an evolving area, and we expect that it could become subject to additional regulations and licensing requirements, including as a result of our cryptocurrency offerings expanding and the number of jurisdictions in which we provide these offerings increasing. The evolving regulatory landscape may require us to make product changes, restrict product offerings in certain jurisdictions, or implement additional and potentially costly controls. If we fail to comply with regulations, requirements, or prohibitions applicable to us, we could face regulatory or other enforcement actions and potential fines and other consequences.
In addition, financial and third party risks related to our cryptocurrency offerings, such as inappropriate access and theft of cryptocurrency assets held by our custodian, insufficient insurance coverage by the custodian to reimburse us for all such losses, the custodian’s failure to maintain effective controls over the custody and settlement services provided to us, the custodian’s inability to purchase or liquidate cryptocurrency holdings, and default on financial or performance obligations by counterparty financial institutions, could materially and adversely affect our financial performance and significantly harm our business.
Consumer Protection
Violations of federal and state consumer protection laws and regulations, including the Electronic Fund Transfer Act (“EFTA”) and Regulation E as implemented by the CFPB, could result in the assessment of significant actual damages or statutory damages or penalties (including treble damages in some instances) and plaintiffs’ attorneys’ fees. We are subject to, and have paid amounts in settlement of, lawsuits containing allegations that our business violated the EFTA and Regulation E or otherwise advance claims for relief relating to our business practices (e.g., that we improperly held consumer funds or otherwise improperly limited consumer accounts).
61
Table of Contents
The CFPB issued a final rule on prepaid accounts that came into effect on April 1, 2019. We have implemented certain changes to comply with the final rule and made substantial changes to the design of certain U.S. consumer accounts and their operability, which could lead to unintended customer confusion and dissatisfaction, discourage customers from opening new accounts, require us to reallocate resources, and increase our costs, which could negatively affect our business. In October 2021, the CFPB issued an order pursuant to its market-monitoring authority requiring the Company to provide extensive information on its payment products, including with respect to the collection, use of, and access to data and consumer protections, among other items.
PayPal principally offers its services in the European Economic Area (“EEA”) countries through a “passport” notification process through the Luxembourg regulator (in the case of PayPal (Europe)) to regulators in other EEA member states in accordance with EU regulations. Regulators in these countries could notify us of local consumer protection laws that apply to our business, in addition to Luxembourg consumer protection laws, and could also seek to persuade the local regulator to order PayPal to conduct its activities in the local country directly or through a branch office. These or similar actions by these regulators could increase the cost of, or delay, our ability to expand our business in Europe.
Privacy and Protection of Customer Data
The legal and regulatory environment relating to “privacy and data protection laws” (as defined in “Item 1. Business— Government Regulation” in our 2020 Form 10-K) continues to develop and evolve in ways we cannot predict, including with respect to technologies such as cloud computing, artificial intelligence, cryptocurrency, and blockchain technology. Any failure, or perceived failure, by us to comply with our privacy policies as communicated to users or with privacy and data protection laws could result in proceedings or actions against us by data protection authorities, government entities, or others. Such proceedings or actions could subject us to significant fines, penalties, judgments, and negative publicity which may require us to change our business practices, increase the costs and complexity of compliance, and materially harm our business. In addition, compliance with inconsistent privacy and data protection laws may restrict our ability to provide products and services to our customers. For further information regarding data protection and information security, see “Item 1. Business—Government Regulation” in our 2020 Form 10-K.
PayPal relies on a variety of compliance methods to transfer personal data of European Economic Area (“EEA”) individuals to the U.S., including Binding Corporate Rules (“BCRs”) for internal transfers of certain types of personal data and Standard Contractual Clauses (“SCCs”) as approved by the European Commission for transfers to and from third parties. We continue to monitor and respond to changes in the requirements for cross-border transfers of data. In June 2021, the European Commission imposed new SCC requirements which impose new contract and operational requirements on PayPal, its merchants, and vendors in order to adhere to certain affirmative duties, including requirements related to government access transparency, enhanced data subject rights, and broader third party assessments to ensure safeguards necessary to protect personal data exported from PayPal’s EEA customers and/or employees to countries outside the EEA. To the extent PayPal relies on SCCs, such engagements will require new contractual arrangements under the updated requirements to avoid limitation on PayPal’s ability to process EEA data in third countries.
In the wake of the California Consumer Privacy Act (“CCPA”) passed in 2018, multiple US states have proposed similar legislation to protect consumers in their states. California passed the Consumer Privacy Rights Act of 2020 (the “CPRA”, an amendment to the CCPA), Virginia has passed the Virginia Consumer Data Protection Act (signed into law March 2, 2021) and Colorado has passed the Colorado Privacy Act (signed into law July 7, 2021). The continued increase in state-level privacy laws is likely to result in a disparate array of privacy rules with unaligned provisions, accountability requirements, individual rights, and state enforcement powers. In the absence of federal legislation, the state-level privacy terrain is likely to become increasingly complex and may add to increased regulatory scrutiny, business cost and consumer confusion.
Use of our payments services for illegal purposes could harm our business.
Our payment system is susceptible to potentially illegal or improper uses, including money laundering, terrorist financing, sanctions evasion, illegal online gambling, fraudulent sales of goods or services, illegal sales of prescription medications or controlled substances, piracy of software, movies, music, and other copyrighted or trademarked goods (in particular, digital goods), bank fraud, child pornography, human trafficking, prohibited sales of alcoholic beverages or tobacco products, securities fraud, pyramid or ponzi schemes, or the facilitation of other illegal or improper activity. The use of our payment system for illegal or improper uses has subjected us, and may subject us in the future, to claims, individual and class action lawsuits, and government and regulatory requests, inquiries, or investigations that could result in liability and harm our reputation. For example, government enforcement or regulatory authorities could seek to impose additional restrictions or liability on us arising from the use of our payment system for illegal activity and our failure to detect or prevent such use.
62
Table of Contents
Moreover, certain activity that may be legal in one jurisdiction may be illegal in another jurisdiction, and a merchant may be found responsible for intentionally or inadvertently importing or exporting illegal goods, resulting in liability for us. Owners of intellectual property rights or government authorities may seek to bring legal action against providers of payments solutions, including PayPal, that are peripherally involved in the sale of infringing or allegedly infringing items. Any threatened or resulting claims could result in reputational harm, and any resulting liabilities, loss of transaction volume, or increased costs could harm our business.
63
Table of Contents
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.