3 unchanged sentences
These risk factors, as well as our condensed consolidated financial statements and notes thereto and the other information appearing in this report, should be reviewed carefully for important information regarding risks that affect us.
+Added: CYBERSECURITY AND TECHNOLOGY RISKS
+Added: Cyberattacks and security vulnerabilities could result in serious harm to our reputation, business, and financial condition.
+Added: The techniques used to attempt to obtain unauthorized or illegal access to systems and information (including customers’ personal data), disable or degrade service, exploit vulnerabilities, or sabotage systems are constantly evolving.
+Added: In some circumstances, these attempts may not be recognized or detected until after they have been launched against a target.
+Added: Unauthorized parties will continue to attempt to gain access to our systems or facilities through various means, including through hacking into our systems or facilities or those of our customers, partners, or vendors, and attempting to fraudulently induce users of our systems (including employees, vendor and partner personnel and customers) into disclosing user names, passwords, payment card information, multi-factor authentication application access or other sensitive information used to gain access to such systems or facilities.
+Added: This information may, in turn, be used to access our customers’ confidential personal or proprietary information and financial instrument data that are stored on or accessible through our information technology systems and those of third parties with whom we partner.
+Added: This information may also be used to execute fraudulent transactions or otherwise engage in fraudulent actions.
+Added: Numerous and evolving cybersecurity threats, including advanced and persisting cyberattacks, cyberextortion, distributed denial-of-service attacks, ransomware, spear phishing and social engineering schemes, the introduction of computer viruses or other malware, and the physical destruction of all or portions of our information technology and infrastructure and those of third parties with whom we partner or that are part of our information technology supply chain, are becoming increasingly sophisticated and complex, may be difficult to detect, and could compromise the confidentiality, availability, and integrity of the data in our systems, as well as the systems themselves.
+Added: We believe that hostile actors, who may comprise individuals, coordinated groups, sophisticated organizations, or nation state supported entities may target PayPal due to our name, brand recognition, types of data (including sensitive payments- and identity-related data) that customers provide to us, and the widespread adoption and use of our products and services.
+Added: We have experienced from time to time, and may experience in the future, breaches of our security measures due to human error, deception, malfeasance, insider threats, system errors, defects, vulnerabilities, or other irregularities.
+Added: For example, in November 2017, we suspended the operations of TIO Networks (“TIO”) (acquired in July 2017) as part of an investigation of security vulnerabilities of the TIO platform, and in December 2017, we announced that we had identified evidence of unauthorized access to TIO’s network and the potential compromise of personally identifiable information for approximately 1.6 million TIO customers.
+Added: Any cyberattacks or data security breaches affecting the information technology or infrastructure of companies we acquire or of our customers, partners, or vendors (including data center and cloud computing providers) could have similar negative effects.
+Added: Under payment card network rules and our contracts with our payment processors, if there is a breach of payment card information stored by us or our direct payment card processing vendors, we could be liable to the payment card issuing banks, including for their cost of issuing new cards and related expenses.
+Added: Cybersecurity breaches and other exploited security vulnerabilities could subject us to significant costs and third-party liabilities, result in improper disclosure of data and violations of applicable privacy and other laws, require us to change our business practices, cause us to incur significant remediation costs, lead to loss of customer confidence in, or decreased use of, our products and services, damage our reputation and brands, divert the attention of management from the operation of our business, result in significant compensation or contractual penalties from us to our customers and their business partners as a result of losses to or claims by them, or expose us to litigation, regulatory investigations, and significant fines and penalties.
+Added: While we maintain insurance policies intended to help offset the financial impact we may experience from these risks, our coverage may be insufficient to compensate us for all losses caused by security breaches and other damage to or unavailability of our systems.
LEGAL, REGULATORY AND COMPLIANCE RISKS
56 unchanged sentences
The rapidly evolving regulatory landscape with respect to cryptocurrency may subject us to additional licensing and regulatory obligations or to inquiries or investigations from the SEC, other regulators and governmental authorities, and require us to make product changes, restrict or discontinue product offerings, implement additional and potentially costly controls, or take other actions.
−Removed: If we fail to comply with regulations, requirements, prohibitions or other obligations applicable to us, we could face regulatory or other enforcement actions, potential fines, and other consequences.
+Added: In August 2023, a third-party issuer with which we have partnered commercially (the “PYUSD Issuer”) launched a U.S.
+Added: dollar-denominated stablecoin named PayPal USD (“PYUSD”) for PayPal U.S.
+Added: customers and subsequently launched PYUSD for Venmo customers in September 2023.
+Added: These PayPal and Venmo customers may, if provisioned for external transfers and subject to our sanctions and anti-money laundering controls, send PYUSD to external wallets not controlled by PayPal.
+Added: The PYUSD Issuer may also allow institutional users to directly purchase PYUSD from the PYUSD Issuer (as per the PYUSD Issuer’s stablecoin terms and conditions).
+Added: The regulatory treatment of stablecoins is evolving and has drawn significant attention from legislative and regulatory bodies around the world, including the SEC.
+Added: There are uncertainties on how ongoing changes to federal, state, and international laws and regulations would apply to stablecoins in practice, and we and the PYUSD Issuer may face substantial costs to operationalize and comply with any additional or changed requirement.
+Added: If we or the PYUSD Issuer fail to comply with regulations, requirements, prohibitions or other obligations applicable to us, we could face regulatory or other enforcement actions, potential fines, and other consequences.
+Added: In addition, we could face reputational harm through our relationship with the PYUSD Issuer if the PYUSD Issuer were to face regulatory scrutiny or if PYUSD is deemed to be a security.
We hold our customers’ cryptocurrency assets through one or more third-party custodians.
−Removed: Financial and third-party risks related to our customer cryptocurrency offerings, such as inappropriate access to, theft, or destruction of cryptocurrency assets held by our custodians, insufficient insurance coverage by a custodian to reimburse us for all such losses, a custodian’s failure to maintain effective controls over the custody and settlement services provided to us, a custodian’s inability to purchase or liquidate cryptocurrency holdings, and defaults on financial or performance obligations by a custodian, or counterparty financial institutions, could expose our customers and us to loss, and therefore significantly harm our business, financial performance, and reputation.
−Removed: We have selected custodian partners, and may in the future select additional custodian partners, that are subject to regulatory oversight, capital requirements, maintenance of audit and compliance industry certifications, and cybersecurity procedures and policies.
−Removed: Nevertheless, operational disruptions at any such custodian, or such custodian’s failure to safeguard cryptocurrency holdings could result in losses of customer assets, expose us to customer claims, reduce consumer confidence and materially impact our operating results and our cryptocurrency product offerings.
+Added: Financial and third-party risks related to our customer cryptocurrency offerings, such as inappropriate access to, theft, or destruction of cryptocurrency assets held by our custodians, insufficient insurance coverage by a custodian to reimburse us for all such losses, a custodian’s failure to maintain effective controls over the custody and settlement services provided to us, a custodian’s inability to purchase or liquidate cryptocurrency holdings, the failure of the PYUSD Issuer to maintain sufficient reserve assets backing PYUSD, and defaults on financial or performance obligations by a custodian, banks with which the PYUSD Issuer maintains reserve assets, or counterparty financial institutions, could expose our customers and us to loss, and therefore significantly harm our business, financial performance, and reputation.
+Added: We have selected custodian partners and the PYUSD Issuer, and may in the future select additional custodian partners and stablecoin issuing entities, that are subject to regulatory oversight, capital requirements, maintenance of audit and compliance industry certifications, and cybersecurity procedures and policies.
+Added: Nevertheless, operational disruptions at any such custodian or issuer, or such custodian’s or issuer's failure to safeguard cryptocurrency holdings (or reserve assets) could result in losses of customer assets, expose us to customer claims, reduce consumer confidence and materially impact our operating results and our cryptocurrency product offerings.
Custodial arrangements to safeguard cryptocurrency assets involve unique risks and uncertainties in the event of a custodian’s bankruptcy.
62 unchanged sentences
and European BNPL loan portfolio held on PayPal (Europe)’s balance sheet at the closing of the transaction and a forward-flow arrangement for the sale of future originations of eligible loans.
−Removed: The closing of the transaction and the sale of future receivables are subject to certain conditions.
−Removed: If these conditions are not satisfied or waived or if the parties are unable to fulfill their obligations under these arrangements, the sale of these receivables could be delayed or not take place at all and we may not realize the expected benefits of this arrangement.
+Added: The closing of the transaction and the sale of future eligible receivables are subject to certain conditions.
+Added: If these conditions are not satisfied or waived or if the parties are unable to fulfill their obligations under these arrangements, the sale of these receivables could be delayed and we may not realize the expected benefits of this arrangement.
From time to time, we may consider other third-party sources of funding (including asset sales, warehouse facilities, forward-flow arrangements, securitizations, partnerships or other funding structures) for our credit portfolio or other receivables.
1 unchanged sentence
If we are unable to fund our credit products or the purchase of the receivables related to our credit products and offerings adequately or in a cost-effective manner, the growth of our credit products and our results of operations and financial condition could be materially and adversely impacted.
+Added: Failure to deal effectively with fraud, abusive behaviors, bad transactions, and negative customer experiences may increase our loss rate and could negatively impact our business and severely diminish merchant and consumer confidence in and use of our services.
+Added: We expect that third parties will continue to attempt to abuse access to and misuse our payments services to commit fraud by, among other things, creating fictitious PayPal accounts using stolen or synthetic identities or personal information, making transactions with stolen financial instruments, abusing or misusing our services for financial gain, or fraudulently inducing users of our systems into engaging in fraudulent transactions.
+Added: Due to the nature of PayPal’s digital payments services, third parties may seek to engage in abusive schemes or fraud attacks that are often difficult to detect and may be deployed at a scale that would otherwise not be possible in physical transactions.
+Added: Measures to detect and reduce the risk of fraud and abusive behavior are complex, require continuous improvement, and may not be effective in detecting and preventing fraud, particularly new and continually evolving forms of fraud or in connection with new or expanded product offerings.
+Added: If these measures are not effective, our business could be negatively impacted.
+Added: We also incur substantial losses from erroneous transactions and situations where funding instruments used for legitimate transactions are closed or have insufficient funds to satisfy payments, or the payment is initiated to an unintended recipient in error.
+Added: Numerous and evolving fraud schemes and misuse of our payments services could subject us to significant costs and liabilities, require us to change our business practices, cause us to incur significant remediation costs, lead to loss of customer confidence in, or decreased use of, our products and services, damage our reputation and brands, divert the attention of management from the operation of our business, and result in significant compensation or contractual penalties from us to our customers and their business partners as a result of losses or claims.
+Added: While we actively seek to recover transaction losses where possible, such recoveries may be insufficient to compensate us for such losses.
+Added: Our Purchase and Seller Protection Programs (“protection programs”) are intended to reduce the likelihood of losses for consumers and merchants from unauthorized and fraudulent transactions.
+Added: The Purchase Protection Program also protects consumers who do not receive the item ordered or who receive an item that is significantly different from its description.
+Added: We incur substantial losses from our protection programs as a result of disputes filed by our customers.
+Added: We seek to recover losses from our protection programs from the merchant, but may not be able to fully recover our losses (for example, if the merchant is unwilling or unable to pay, the transaction involves a fraudulent merchant, or the merchant provides sufficient evidence that the item was delivered).
+Added: In addition, consumers who pay through PayPal or Venmo may have reimbursement rights from their payment card issuer, which in turn will seek recovery from us.
+Added: If losses incurred by us related to payment card transactions become excessive, we could lose the ability to accept payment cards for payment, which would negatively impact our business.
+Added: Regulators and card networks may also adapt error resolution and chargeback requirements to account for evolving forms of fraud, which could increase PayPal’s exposure to fraud losses and impact the scope of coverage of our protection programs.
+Added: Increases in our loss rate, including as a result of changes to the scope of transactions covered by our protection programs, could negatively impact our business.
+Added: See “Note 13—Commitments and Contingencies—Protection Programs” to our consolidated financial statements.
+Added: Failure to effectively monitor and evaluate the financial condition of our merchants may expose PayPal to losses.
+Added: In the event of the bankruptcy, insolvency, business failure, or other business interruption of a merchant that sells goods or services in advance of the date of their delivery or use (e.g., airline, cruise, or concert tickets, custom-made goods, and subscriptions), we could be liable to the buyers of such goods or services, including through our Purchase Protection Program or through chargebacks on payment cards used by customers to fund their purchase.
+Added: Allowances for transaction losses that we have established may be insufficient to cover incurred losses.
Global and regional economic conditions could harm our business.
4 unchanged sentences
The U.K.’s departure from the EU could harm our business, financial condition, and results of operations.
−Removed: Following the departure of the U.K.
−Removed: from the EU and the EEA on January 31, 2020 (commonly referred to as “Brexit”) and the expiration of the transition period on December 31, 2020, there continues to be uncertainty over the practical consequences of Brexit, including the potential for greater restrictions on the supply and availability of goods and services between the U.K.
−Removed: and EEA region, and a general deterioration in consumer sentiment and credit conditions leading to overall negative economic growth and increased risk of merchant default.
−Removed: The consequences of Brexit have brought legal uncertainty and increased complexity for financial services firms, which could continue as national laws and regulations in the U.K.
−Removed: differ from EU laws and regulations and additional authorization requirements come into effect.
−Removed: These developments have led and could lead in the future to additional regulatory costs and challenges for us.
−Removed: Specifically, PayPal currently operates in the U.K.
−Removed: within the scope of its passport permissions (as they existed at the end of the transition period) pursuant to the Temporary Permissions Regime pending the grant of new authorizations by the U.K.
−Removed: financial regulators.
−Removed: If we are unable to obtain the required authorizations before the expiry of the longstop dates set by the U.K.
−Removed: regulators under the Temporary Permissions Regime, our European operations could lose their ability to offer services within the U.K.
−Removed: market, or into the U.K.
−Removed: market on a cross-border basis.
−Removed: Our European operations may also be required to comply with legal and regulatory requirements in the U.K.
−Removed: that may be in addition to, or inconsistent with, those of the EEA, in each case, leading to increased complexity and costs.
+Added: In connection with the departure of the U.K.
+Added: from the EU and the EEA on January 31, 2020 (commonly referred to as “Brexit”) and the expiration of the transition period on December 31, 2020, there continues to be legal and economic uncertainty over developments related to Brexit.
+Added: PayPal has operated in the U.K.
+Added: within the scope of its passport permissions pursuant to the Temporary Permissions Regime pending the grant of new authorizations by the U.K.
+Added: Financial Conduct Authority (“FCA”).
+Added: On October 31, 2023, PayPal’s U.K.
+Added: subsidiary received authorizations from the FCA as an electronic money institution and consumer credit firm, and registration as a cryptoasset business, subject to certain conditions that will require further implementation action by us.
+Added: If we are unable to meet these requirements, our U.K.
+Added: business and operations may be impacted and we may be subject to enforcement actions.
If one or more of our counterparty financial institutions default on their financial or performance obligations to us or fail, we may incur significant losses.
13 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.