23andMe
23andMe, Inc. · Genetic Testing
✓ Reviewed
Index
23andMe holds the single most sensitive and permanent category of personal data: your genome. From a saliva sample it derives ancestry composition, ethnicity estimates, carrier status and health-predisposition reports, and — through the DNA Relatives feature — maps your biological family network, exposing data about relatives who never consented. It also collects self-reported health surveys, and historically shared de-identified genetic data with pharmaceutical research partners (e.g. GSK). Your DNA cannot be changed or reissued if it leaks.
Why this rating
Deductions: collection of genetic and health data is maximally sensitive (-15); research-partner and pharma data-sharing plus a bankruptcy/M&A transfer clause create broker-style disclosure and unilateral-transfer risk (-15 / -5); the company added a forced-arbitration clause to its terms after the 2023 breach (-5); indefinite retention and vague processing language (-8 / -7). Users can opt out of research and request deletion, which prevents deeper cuts.
What it is
- Requires a cloud account
- Manufacturer
- 23andMe, Inc.
- Category
- Genetic Testing
- Model years
- 2007-present
- Market status
- Current
- Companion app
- 23andMe
The evidence 3
Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.
-
23andMe's 2025 Chapter 11 filing put its genetic database up for sale, prompting multiple state attorneys general to urge users to delete their DNA before a new owner could acquire it.
Why it matters here: Shows the durable risk that this service's DNA archive changes hands through corporate insolvency.
-
A credential-stuffing attack on ~14,000 accounts cascaded through the DNA Relatives feature to expose personal and ancestry data of about 6.9 million users, including targeted datasets of Ashkenazi Jewish and Chinese users.
Why it matters here: Directly exposed this service's users; genetic-relative data is immutable and cannot be reset like a password.
-
A bipartisan coalition of 42 state attorneys general secured an $18M settlement over the 2023 breach, faulting 23andMe's lack of MFA, login rate-limiting and compromised-credential screening.
Why it matters here: Multistate regulatory action specifically over this company's security failures.
Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.