Item 1A. Risk Factors
ITEM 1A: RISK FACTORS
We are subject to various risks and uncertainties, which could materially affect our business, results of operations, financial condition, future results, and the trading price of our common stock. You should read carefully the following information together with the information appearing in Part I, Item 1A, Risk Factors in our Annual Report on Form 10-K for the year ended December 31, 2023 as filed with the United States (“U.S.”) Securities and Exchange Commission (“SEC”) on February 8, 2024 (“2023 Form 10-K”). The following information supplements and, to the extent inconsistent, supersedes some of the information appearing in the Risk Factors section of our 2023 Form 10‑K. These risk factors, as well as our condensed consolidated financial statements and notes thereto and the other information appearing in this report, should be reviewed carefully for important information regarding risks that affect us.
CYBERSECURITY AND TECHNOLOGY RISKS
Cyberattacks and security vulnerabilities could result in serious harm to our reputation, business, and financial condition.
The techniques used to attempt to obtain unauthorized or illegal access to systems and information (including customers’ personal data), disable or degrade service, exploit vulnerabilities, or sabotage systems are constantly evolving. In some circumstances, these attempts may not be recognized or detected until after they have been launched against a target. Unauthorized parties continuously attempt to gain access to our systems or facilities through various means, including through hacking into our systems or facilities or those of our customers, partners, or vendors, and attempting to fraudulently induce users of our systems (including employees, vendor and partner personnel and customers) into disclosing user names, passwords, payment card information, multi-factor authentication application access or other sensitive information used to gain access to such systems or facilities. This information may, in turn, be used to access our customers’ confidential personal or proprietary information and financial instrument data that are stored on or accessible through our information technology systems and those of third parties with whom we partner. This information may also be used to execute fraudulent transactions or otherwise engage in fraudulent actions. Numerous and evolving cybersecurity threats, including advanced and persisting cyberattacks, cyberextortion, distributed denial-of-service attacks, ransomware, spear phishing and social engineering schemes, the introduction of computer viruses or other malware, and the physical destruction of all or portions of our information technology and infrastructure and those of third parties with whom we partner or that are part of our information technology supply chain, are becoming increasingly sophisticated and complex, may be difficult to detect, and could compromise the confidentiality, availability, and integrity of the data in our systems, as well as the systems themselves.
We believe that hostile actors, who may comprise individuals, coordinated groups, sophisticated organizations, or nation state supported entities may target PayPal due to our name, brand recognition, types of data (including sensitive payments- and identity-related data) that customers provide to us, and the widespread adoption and use of our products and services. We have experienced from time to time, and may experience in the future, cybersecurity incidents, including breaches of our security measures, network breaches, and compromise of personally identifiable customer information due to human error, deception, malfeasance, insider threats, system errors, defects, vulnerabilities, or other issues.
Any cybersecurity incidents, including cyberattacks or data security breaches affecting the information technology or infrastructure of companies we acquire or of our customers, partners, or vendors (including data center and cloud computing providers) could have similar negative effects.
64
Table of Contents
Under payment card network rules and our contracts with our payment processors, if there is a breach of payment card information stored by us or our direct payment card processing vendors, we could be liable to the payment card issuing banks, including for their cost of issuing new cards and related expenses. We have experienced, and may experience in the future, breaches involving customer information for which we have notified, and may notify, regulators, customers and other third parties. These or other cybersecurity breaches and other exploited security vulnerabilities have subjected us and could further subject us to significant costs and third-party liabilities, result in improper disclosure of data and violations of applicable privacy and other laws, require us to change our business practices, cause us to incur significant remediation costs, lead to loss of customer confidence in, or decreased use of, our products and services, damage our reputation and brands, divert the attention of management from the operation of our business, result in significant compensation or contractual penalties from us to our customers and their business partners as a result of losses to or claims by them, or expose us to litigation, regulatory investigations, and significant fines and penalties. While we maintain insurance policies intended to help offset the financial impact we may experience from these risks, our coverage may be insufficient to compensate us for all losses caused by security breaches and other damage to or unavailability of our systems.
LEGAL, REGULATORY AND COMPLIANCE RISKS
Our business is subject to extensive government regulation and oversight. Our failure to comply with extensive, complex, overlapping, and frequently changing rules, regulations, and legal interpretations could materially harm our business.
Privacy and Protection of Customer Data
The legal and regulatory environment relating to privacy and data protection laws continues to develop and evolve in ways we cannot predict, including with respect to technologies such as cloud computing, (generative) artificial intelligence, machine learning, cryptocurrency, and blockchain technology. Any failure or alleged failure by us to comply with our privacy policies as communicated to customers or with privacy and data protection laws relating to our collection, use, storage, transfer, or sharing of customer data with third parties could result in proceedings or actions against us by data protection authorities, other government agencies, or others, which could subject us to significant fines, penalties, judgments, and negative publicity, require us to change our business practices, increase the costs and complexity of compliance, result in reputational harm, and materially harm our business. Compliance with inconsistent privacy and data protection laws may also restrict or limit our ability to provide products and services to our customers.
PayPal relies on a variety of compliance methods to transfer personal data of Europe Economic Area individuals to the U.S., including Binding Corporate Rules for internal transfers of certain types of personal data and Standard Contractual Clauses (“SCCs”) as approved by the European Commission for transfers to and from third parties. While PayPal intends to continue to rely on Binding Corporate Rule and SCCs and will evaluate the circumstances under which additional mechanisms, such as the Data Privacy Framework may be leveraged for transfers of personal data to the U.S., we may be subject to regulatory enforcement actions if our approach is deemed to be noncompliant.
Many jurisdictions in which we operate globally have enacted, or are in the process of enacting, data privacy legislation or regulations aimed at creating and enhancing individual privacy rights. For example, numerous U.S. states have enacted or are in the process of enacting state level data privacy laws and regulations governing the collection, use, and retention of their residents’ personal information. The continued proliferation of privacy laws in the jurisdictions in which we operate is likely to result in a disparate array of privacy rules with unaligned or conflicting provisions, accountability requirements, individual rights, and national or local enforcement powers, which may subject us to increased regulatory scrutiny and business costs and could lead to unintended consumer confusion.
Our credit products expose us to additional risks.
We offer credit products to a wide range of consumers and merchants in the U.S. and various international markets. The financial success of these products depends largely on the effective management of related risk. The credit decision-making process for our consumer credit products uses proprietary methodologies and credit algorithms and other analytical techniques designed to analyze the credit risk of specific consumers based on, among other factors, their past purchase and transaction history with PayPal or Venmo and their credit scores. Similarly, proprietary risk models and other indicators are applied to assess merchants who desire to use our merchant financing offerings to help predict their ability to repay. These risk models may not accurately predict the creditworthiness of a consumer or merchant due to inaccurate assumptions, including those related to the particular consumer or merchant, market conditions, economic environment, or limited transaction history or other data. The accuracy of these risk models and the ability to manage credit risk related to our credit products may also be affected by legal or regulatory requirements, changes in consumer behavior, changes in the economic environment, issuing bank policies, and other factors.
65
Table of Contents
We generally rely on the activities and charters of unaffiliated financial institutions to provide PayPal and Venmo branded consumer credit and merchant financing offerings to our U.S. customers. As a service provider to these unaffiliated financial institutions, which are federally supervised U.S. financial institutions, we are subject from time to time to examination by their federal banking regulators. In the event of any termination or interruption in a partner bank’s ability or willingness to lend, our ability to offer consumer credit and merchant financing products could be interrupted or limited, which could materially and adversely affect our business. We may be unable to reach a similar arrangement with another unaffiliated financial institution on favorable terms or at all. Obtaining and maintaining the lending licenses required for us to originate such loans ourselves would be a costly, time-consuming and uncertain process, and would subject us to additional laws and regulatory requirements, which could significantly increase our costs and compliance obligations and require us to change our business practices.
Merchant loans under our U.S. PayPal Working Capital (“PPWC”) and PayPal Business Loan (“PPBL”) products and certain U.S. installment loan products are provided by a state-chartered industrial bank under a program agreement with us, and we acquire the receivables generated by those loans from the state-chartered bank after origination. In June 2020, the Federal Deposit Insurance Corporation (“FDIC”) approved a final rule clarifying that loans validly originated by state-chartered banks or insured branches of foreign banks remain valid throughout the lifetime of the loan, reflecting a similar rule finalized by the Office of the Comptroller of Currency (“OCC”) in May 2020 for nationally chartered banks. The final rule reaffirms and codifies the so-called “valid-when-made doctrine,” which provides that the permissibility of an interest rate for a loan is determined when the loan is made and will not be affected by subsequent events such as sale, assignment, or other transfer. While a number of state attorneys general have unsuccessfully challenged these FDIC and OCC rules, there remains some uncertainty whether non-bank entities purchasing loan receivables originated by FDIC-insured, state-chartered banks may rely on federal preemption of state usury laws and other state laws. An adverse outcome of these or similar challenges, or changes to applicable laws and regulations or regulatory policy, could materially impact our U.S. PPWC, PPBL, certain installment products, and our business.
We are subject to the risk that account holders who use our credit products will default on their payment obligations. The non-payment rate among account holders may increase due to, among other factors, changes to underwriting standards, risk models not accurately predicting the creditworthiness of a user, worsening economic conditions, such as a recession or government austerity programs, increases in prevailing interest rates, and high unemployment rates. Account holders who miss payments often fail to repay their loans, and account holders who file for protection under the bankruptcy laws generally do not repay their loans. Further, laws or regulations may limit the assessment of late fees or penalties on certain credit products, which could negatively impact our revenue share arrangement with an independent chartered financial institution with respect to our U.S. consumer credit products. Any deterioration in the performance of loans facilitated through our platform or unexpected losses on such loans may increase the risk of potential charge-offs, increase our allowance for loans and interest receivable, negatively impact our revenue share arrangement with an independent chartered financial institution with respect to our U.S. consumer credit products, and materially and adversely affect our financial condition and results of operations .
We currently purchase receivables related to our U.S. PayPal-branded merchant financing offerings and certain U.S. consumer installment loan products and extend credit for our consumer and merchant products outside the U.S. through our international subsidiaries. In June 2023, we entered into a multi-year agreement to sell up to €40 billion of U.K. and European buy now, pay later (“BNPL”) loan receivables originated by PayPal (Europe) and PayPal U.K., consisting of the sale of a substantial majority of the U.K. and European BNPL loan portfolio held on PayPal (Europe)’s balance sheet at the closing of the transaction and a forward-flow arrangement for the sale of future originations of eligible loans, and in October 2023, we began selling those receivables. The sale of future eligible receivables is subject to certain conditions. If these conditions are not satisfied or waived or if the parties are unable to fulfill their obligations under these arrangements, the sale of these receivables could be delayed and we may not realize the expected benefits of this arrangement.
From time to time, we may consider other third-party sources of funding (including asset sales, warehouse facilities, forward-flow arrangements, securitizations, partnerships or other funding structures) for our credit portfolio or other receivables. The availability of such third-party funding is subject to a number of factors, including economic conditions and interest rates, and there can be no assurance that any such funding arrangements can be obtained on favorable terms or at all. If we are unable to fund our credit products or the purchase of the receivables related to our credit products and offerings adequately or in a cost-effective manner, the growth of our credit products and our results of operations and financial condition could be materially and adversely impacted.
66
Table of Contents
Text extracted from the filing as submitted to EDGAR. Formatting, tables and exhibits are simplified for reading; the original document is authoritative for anything you rely on.