23ANDME, INC – Violation Found (Spain, 2025)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
23andMe faced scrutiny after a data breach exposed sensitive information of over 2,600 customers in Spain. Hackers accessed accounts using stolen credentials, revealing personal details including genetic and health data. This incident underscores the need for stronger security measures to protect customer information.
What happened
A data breach at 23andMe allowed hackers to access the accounts of 2,642 customers in Spain, exposing sensitive personal data.
Who was affected
Customers of 23andMe residing in Spain whose accounts were compromised during the breach.
What the authority found
The Spanish data protection authority found that 23andMe failed to implement adequate security measures to protect customer data, violating GDPR requirements for data security and user consent.
Why this matters
This breach serves as a warning for companies to strengthen their data protection practices, especially regarding user authentication and security protocols. Small businesses should consider implementing multi-factor authentication and regular security audits.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In October 2023, the controller suffered a personal data breach following a credential-stuffing attack. Attackers accessed customer accounts by using login credentials that customers had reused on other services previously compromised. The breach affected 2,642 customers residing in Spain and exposed identity, contact and location data, images, genetic data, health data and data revealing ethnic origin. A sample of the data was published on an online forum, while a file containing the compromised data was offered for sale on the dark web. At the time of the breach, customers accessed their accounts using a username and password. Multi-factor authentication was available but optional. The controller had not established specific password-strength requirements or periodic password changes and had not implemented limits on access requests or downloads based on IP addresses. Once an account had been accessed, there were no additional controls limiting the viewing or downloading of sensitive data, including information relating to potential relatives. On 1 October 2023, the controller detected a Reddit post offering information allegedly belonging to its customers. On 5 October, it confirmed that one of the published records belonged to a customer. It published an alert on its website on 6 October, reported the incident to US authorities on 7 October and required customers to reset their passwords on 9 October. The controller informed all customers about the incident on 10 October. It identified 799 affected customers residing in Spain on 12 October and notified them on 13 October. It subsequently identified and notified another 1,843 customers residing in Spain on 24 October. However, the controller did not notify the DPA until 17 October 2023 and submitted additional information on 30 October.
Outcome
Violation Found
The DPA found a violation but did not impose a fine.
Related Enforcement Actions (0)
No other enforcement actions found for 23ANDME, INC in ES
This is the only recorded action for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. 23ANDME, INC - Spain (2025). Retrieved from cookiefines.eu
Last updated: