/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

23andMe changed its TOS to prevent lawsuits days after its October data breach; to opt out, customers must email the company that they disagree within 30 days

Axios Jacob Knutson

Context & Ripple Effects

The October breach put 23andMe's handling of highly sensitive customer information under immediate scrutiny. This terms update added a legal-process layer to the company’s response, requiring customers who objected to act affirmatively within a short window.

Later coverage shows that the dispute did not end with the revised terms: 23andMe was reported to have reached a $30M privacy-breach settlement, while states later challenged the prospect of DNA-data sales without direct consent.

First-order effects

  • Customers seeking to preserve their ability to pursue claims outside the new terms must send an email objection within 30 days; those who do not act face a more constrained path to litigate.
  • 23andMe gains an immediate mechanism to steer post-breach disputes toward the contractual process it has set, rather than leaving every affected customer on the same litigation footing.

Second-order effects

  • The change raises the operational importance of breach notices, account communications, and recordkeeping: disputes can turn on whether customers received and acted on an opt-out instruction.
  • The later privacy settlement indicates that contractual protections do not eliminate the financial and reputational exposure created by a large breach, particularly where privacy claims persist.

Third-order effects

  • If companies routinely revise dispute terms after security incidents, regulators and courts may scrutinize whether consent was meaningful and whether affected users had a practical opportunity to opt out.
  • For genetic-data businesses, breach governance is likely to remain intertwined with downstream control of customer data, as reflected in the later multistate challenge to DNA-data sales without direct consent.

The trend: The story is one instance of sensitive-data companies using contract design alongside security response, while regulators and consumers increasingly contest the limits of that approach.

Discussion

  • @chris Chris Messina on threads
    Beware. @23andme is trying to pull a fast one. https://www.axios.com/...
  • @microh.bsky.social MicRoh on bluesky
    We fucked up and lied about it and now you agree we're cool.  [embedded post]
  • @sgrant525 Sergio Grant on x
    This is one major reason why folks don't trust genetic testing companies. Also, they give police access to your private genetic data, & some don't even require a warrant to compel access. @axios
  • @brettcallow Brett Callow on x
    Days after a data breach allowed hackers to steal 6.9 million 23andMe users' personal details, the genetic testing company changed its terms of service to prevent customers from suing the firm or pursuing class-action lawsuits against it. #23andMe https://www.axios.com/...
  • @tosdr @tosdr on x
    23andMe just updated their terms of service limiting the time in which users can take legal action and adding a class action waver. If you are a 23andMe user you have 30 days to opt-out. This comes after millions of user data including DNA was leaked. https://www.23andme.com/...
  • @onekade @onekade on x
    23andMe is hacked and subsequently informs users they have 30 days to opt out of new arbitration terms. Incredible shit. https://www.wired.com/... [image]
  • @mattbc @mattbc on x
    “What measures has @23andMe announced to mitigate the tremendous harm their negligence has caused? If you guessed, ‘updating their Terms of Service to force customers...into binding arbitration’ you'd be correct.” Limited time to opt-out, act now. https://www.patreon.com/...
  • @jeffseibert Jeff Seibert on x
    Get hacked, change your terms to prevent class action lawsuits? Wow @23andMe this is a really bad look. https://arstechnica.com/...
  • @agingsloth @agingsloth on x
    The suits at @23andMe have sent an email about changes to their arbitration terms before letting me know if my information has been compromised #classaction #23andme [image]