← IoT Privacy Database

23andMe

23andMe, Inc. · Genetic Testing

✓ Reviewed

6.4Surveillance
Index
Policy — what its policy permitsD
Evidence — what research provesF

23andMe holds the single most sensitive and permanent category of personal data: your genome. From a saliva sample it derives ancestry composition, ethnicity estimates, carrier status and health-predisposition reports, and — through the DNA Relatives feature — maps your biological family network, exposing data about relatives who never consented. It also collects self-reported health surveys, and historically shared de-identified genetic data with pharmaceutical research partners (e.g. GSK). Your DNA cannot be changed or reissued if it leaks.

Why this rating

Deductions: collection of genetic and health data is maximally sensitive (-15); research-partner and pharma data-sharing plus a bankruptcy/M&A transfer clause create broker-style disclosure and unilateral-transfer risk (-15 / -5); the company added a forced-arbitration clause to its terms after the 2023 breach (-5); indefinite retention and vague processing language (-8 / -7). Users can opt out of research and request deletion, which prevents deeper cuts.

What it is

Manufacturer
23andMe, Inc.
Category
Genetic Testing
Model years
2007-present
Market status
Current
Companion app
23andMe

The evidence 3

Independent research, regulatory action, lawsuits, breaches and journalism about this device — the "what actually happens" axis. Each links to its source.

  1. Journalism · NBC News · 2025-03

    23andMe's 2025 Chapter 11 filing put its genetic database up for sale, prompting multiple state attorneys general to urge users to delete their DNA before a new owner could acquire it.

    Why it matters here: Shows the durable risk that this service's DNA archive changes hands through corporate insolvency.

  2. Breach report · HIPAA Journal · 2023-12

    A credential-stuffing attack on ~14,000 accounts cascaded through the DNA Relatives feature to expose personal and ancestry data of about 6.9 million users, including targeted datasets of Ashkenazi Jewish and Chinese users.

    Why it matters here: Directly exposed this service's users; genetic-relative data is immutable and cannot be reset like a password.

  3. Regulatory action · Cybernews · 2026-07

    A bipartisan coalition of 42 state attorneys general secured an $18M settlement over the 2023 breach, faulting 23andMe's lack of MFA, login rate-limiting and compromised-credential screening.

    Why it matters here: Multistate regulatory action specifically over this company's security failures.

Descriptive, cited, not legal advice; ratings are versioned and corrections create a new version. Data from the IoT Info Grabber DB research project, CC BY-SA 4.0.

← Back to the IoT Privacy Database