Key Takeaways
- Spanish regulator AEPD fined 23andMe €2.4 million ($2.7 million) for GDPR violations tied to an April 2023 data breach.
- The breach exposed genetic data of roughly 6.9 million users worldwide, including more than 2,600 Spaniards.
- 23andMe waited 12 days after discovering the breach before notifying Spanish authorities, contravening the GDPR’s “immediate notification” requirement.
- Poor cybersecurity practices—missing multifactor authentication, no IP‑based access limits, and weak password policies—were cited as primary causes.
- The company’s own May 2023 fiscal report acknowledged rising cyber threats, yet its safeguards fell short of the standards it proclaimed.
- Separately, 23andMe settled with a coalition of 42 U.S. state attorneys general for $18 million, committing to stronger data‑protection measures at its research institute.
Background of the Breach
In April 2023, threat actors obtained a copy of 23andMe’s customer data through a credential‑stuffing attack. The compromised information included names, email addresses, dates of birth, genetic ancestry results, and, for some users, raw genetic data. The breach remained undetected until a sample of the stolen data appeared for sale on Reddit, prompting internal investigation and eventual disclosure to regulators.
Regulatory Action by the AEPD
Spain’s Agencia Española de Protección de Datos (AEPD) issued an enforcement decision on Friday, levying a €2.4 million ($2.7 million) fine against 23andMe. The decision concluded that the company violated several GDPR provisions, notably the obligation to protect personal data with appropriate technical and organizational measures and to report breaches without undue delay.
Scope of the Impact
The AEPD determined that more than 2,600 Spanish residents were affected by the incident, which ultimately impacted approximately 6.9 million 23andMe users worldwide. The regulator emphasized that the genetic nature of the data heightened the potential harm, as such information is considered a special category of data under GDPR.
Delayed Notification
According to the AEPD’s findings, 23andMe learned of the breach internally but did not notify Spanish authorities until 12 days later. The regulator characterized this delay as “not trivial,” stressing that prompt notification is essential for enabling affected individuals to take protective steps and for allowing authorities to coordinate mitigation efforts.
Inadequate Security Controls
The decision highlighted multiple shortcomings in 23andMe’s cybersecurity posture. Most notably, the firm did not enforce mandatory multifactor authentication (MFA) for user accounts, a gap that facilitated the credential‑stuffing attack. Additionally, 23andMe placed no limits on the number of data requests or downloads originating from a single IP address, enabling attackers to harvest large volumes of information with minimal resistance.
Weak Password Policies
23andMe’s privacy policy contained only a single reference to account access credentials and failed to specify any requirements for password strength or periodic renewal. The AEPD pointed out that this lack of guidance left users vulnerable to credential reuse and brute‑force attacks, further undermining the security of the platform.
Contrast with Public Statements
Despite these deficiencies, 23andMe’s May 2023 fiscal report—available on the company’s website—extensively discussed the rising threat of ransomware and other cybercrimes. The report warned that a security breach could trigger costly remediation, regulatory penalties, higher insurance premiums, and the need for forensic audits. The AEPD noted the disconnect between the company’s acknowledged risk awareness and its actual protective measures.
Financial and Operational Consequences
Beyond the European fine, 23andMe faced parallel scrutiny in the United States. In July 2023, the company agreed to an $18 million settlement with a coalition of 42 state attorneys general. As part of the agreement, 23andMe committed to implementing enhanced data‑protection safeguards at the 23andMe Research Institute, a nonprofit spin‑off led by former CEO Anne Wojcicki. The settlement also required regular third‑party security assessments and improved incident‑response procedures.
Broader Implications for Genetic‑Data Handlers
The AEPD’s decision serves as a stark reminder that firms handling highly sensitive genetic information must meet stringent GDPR standards, particularly regarding authentication, access controls, and breach notification timelines. Regulators worldwide are increasingly vigilant about the unique privacy risks posed by genomic data, and non‑compliance can result in substantial financial penalties and reputational harm.
Lessons for Companies and Consumers
For organizations, the case underscores the necessity of aligning public risk disclosures with concrete security practices—such as enforcing MFA, imposing rate‑based access limits, and mandating strong, regularly updated passwords. Consumers, meanwhile, should remain cautious about reusing credentials across services and consider enabling any available security features offered by providers of personal data services. Continued regulatory oversight and proactive self‑assessment will be critical to safeguarding the privacy of genetic information in an increasingly threat‑laden digital landscape.

