United States where we conduct our activities. Anti-corruption and anti-bribery laws have been enforced aggressively in recent years and are interpreted to prohibit companies, their employees, agents, representatives, business partners and third-party intermediaries from authorizing, offering or providing, directly or indirectly, improper payments or benefits to recipients in the public or private sector.
We sometimes leverage third parties to sell our products and conduct our business abroad. Exodus, our team members, agents, representatives, business partners and third-party intermediaries may have direct or indirect interactions with officials and employees of government agencies, or state-owned or affiliated entities and we may be held liable for the corrupt or other illegal activities of such parties even if we do not explicitly authorize such activities. As we increase our international sales and business, our risks under these laws may increase.
Any allegations or violation of the FCPA or other applicable anti-bribery and anti-corruption laws could result in whistleblower complaints, sanctions, settlements, prosecution, enforcement actions, fines, damages, adverse media coverage, investigations, loss of export privileges, severe criminal or civil sanctions, suspension or debarment from government contracts, all of which may have an adverse effect on our reputation, business, results of operations and prospects. Responding to any investigation or action will likely result in a materially significant diversion of management’s attention and resources, significant defense costs and other professional fees.
Furthermore, we rely on third parties for our KYC and other compliance obligations. If these third parties fail to effectively provide these services, we may be subject to adverse consequences as described above.
Privacy concerns and laws or other domestic or foreign regulations may reduce the effectiveness of our platform and adversely affect our business.
We may be subject to a variety of foreign laws and regulations that involve matters central to our business. Although we believe we are operating in compliance with the laws of jurisdictions in which Exodus exists, these laws and regulations are evolving, may impose inconsistent or conflicting standards among jurisdictions, can be subject to significant change and may result in ever-increasing regulatory and public scrutiny and escalating levels of enforcement and sanctions.
Aspects of the General Data Protection Regulation (“GDPR”), California Consumer Privacy Act (“CCPA”), Swiss Secretariat for Economic Affairs (“SECO”) and other laws, regulations, industry standards and other obligations related to privacy, data protection and data security remain uncertain. As such, compliance may require us to incur additional costs, modify our data handling practices and restrict our business operations. It is also possible that these laws, regulations, industry standards and other obligations may be interpreted and applied in a manner that is, or is alleged to be, inconsistent with our policies and procedures, the Exodus Platform or our services. If so, in addition to the possibility of fines, lawsuits and other claims, we could be required to modify the Exodus Platform or services or make changes to our business activities and practices. We may be unable to make such changes and modifications in a commercially reasonable manner, or at all, and our ability to develop new offerings and features could be limited.
We expect that there will continue to be new proposed laws, regulations and standards relating to privacy and data protection in various jurisdictions, and we cannot determine the impact such laws, regulations and standards may have on our business.
We are subject to export control, import and sanctions laws and regulations that could impair our ability to compete in international markets or subject us to liability if we violate such laws and regulations.
Under U.S. export control and sanctions laws and regulations, including the U.S. Department of Commerce’s Export Administration Regulations (“EAR”) and various economic and trade sanctions administered by the USDT Office of Foreign Assets Control (“OFAC”), our business activities are subject to various restrictions related to the sale or supply of certain products and services to U.S. embargoed or sanctioned countries, governments, persons and entities and require authorization for the export of certain encryption items. Although we take precautions to prevent our software and services from being accessed or provided in violation of such laws, we may have previously allowed our software to be downloaded by individuals or entities potentially located in countries or territories subject to U.S. trade embargoes, potentially in violation of U.S. sanctions laws. In December 2018, we received an administrative subpoena issued by OFAC seeking information regarding potential transactions with individuals in Iran. In response, we conducted a comprehensive review that covered all countries and territories subject to U.S. trade embargoes administered by OFAC. We submitted a voluntary self-disclosure and subpoena responses regarding potential