23ANDME, INC – Violation Found (Spain, 2025)

Violation Found
Agencia Española de Protección de Datos10 October 2025Spain
final
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

23andMe faced scrutiny after a data breach exposed sensitive information of over 2,600 customers in Spain. Hackers accessed accounts using stolen credentials, revealing personal details including genetic and health data. This incident underscores the need for stronger security measures to protect customer information.

What happened

A data breach at 23andMe allowed hackers to access the accounts of 2,642 customers in Spain, exposing sensitive personal data.

Who was affected

Customers of 23andMe residing in Spain whose accounts were compromised during the breach.

What the authority found

The Spanish data protection authority found that 23andMe failed to implement adequate security measures to protect customer data, violating GDPR requirements for data security and user consent.

Why this matters

This breach serves as a warning for companies to strengthen their data protection practices, especially regarding user authentication and security protocols. Small businesses should consider implementing multi-factor authentication and regular security audits.

GDPR Articles Cited

AI-verified

Art. 9(GDPR)
Art. 32(GDPR)
Art. 33(GDPR)
Art. 5(1)(f) GDPR
Art. 24(1) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 9(GDPR)
Art. 24(1) GDPR
Art. 32(GDPR)
Art. 33(GDPR)

Original data from scraper before AI verification against source document.

Source verified 25 July 2026
amount discrepancy
Full Legal Summary
Detailed

23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In October 2023, the controller suffered a personal data breach following a credential-stuffing attack. Attackers accessed customer accounts by using login credentials that customers had reused on other services previously compromised. The breach affected 2,642 customers residing in Spain and exposed identity, contact and location data, images, genetic data, health data and data revealing ethnic origin. A sample of the data was published on an online forum, while a file containing the compromised data was offered for sale on the dark web. At the time of the breach, customers accessed their accounts using a username and password. Multi-factor authentication was available but optional. The controller had not established specific password-strength requirements or periodic password changes and had not implemented limits on access requests or downloads based on IP addresses. Once an account had been accessed, there were no additional controls limiting the viewing or downloading of sensitive data, including information relating to potential relatives. On 1 October 2023, the controller detected a Reddit post offering information allegedly belonging to its customers. On 5 October, it confirmed that one of the published records belonged to a customer. It published an alert on its website on 6 October, reported the incident to US authorities on 7 October and required customers to reset their passwords on 9 October. The controller informed all customers about the incident on 10 October. It identified 799 affected customers residing in Spain on 12 October and notified them on 13 October. It subsequently identified and notified another 1,843 customers residing in Spain on 24 October. However, the controller did not notify the DPA until 17 October 2023 and submitted additional information on 30 October.

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Related Enforcement Actions (0)

No other enforcement actions found for 23ANDME, INC in ES

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

10 October 2025

Authority

Agencia Española de Protección de Datos

GDPRhub ID

gdprhub-10147

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. 23ANDME, INC - Spain (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: