California AG Rob Bonta sues 23andMe, alleging it failed to protect sensitive user data in a 2023 breach that affected ~7M people across the US
California's attorney general sued the genetic testing company formerly known as 23andMe on Thursday, alleging it failed to protect sensitive user data …
Context & Ripple Effects
The 2023 breach has already produced a reported $30 million privacy settlement and criticism of 23andMe’s response to affected users. California’s action adds a state-enforcement track to litigation arising from the same incident.
The case arrives alongside broader concern over what happens to customers’ genetic information during 23andMe’s bankruptcy: 27 states and D.C. have challenged a sale of DNA data without direct customer consent, while California’s attorney general has urged users to delete their information.
First-order effects
- 23andMe must defend a California attorney general suit over safeguards for highly sensitive genetic and personal data, adding regulatory exposure to the aftermath of the breach.
- Affected California users gain a public-enforcement avenue focused on the company’s alleged security failures, separate from prior private litigation and settlement activity.
Second-order effects
- The suit increases pressure on any buyer or successor handling 23andMe customer data to demonstrate that security, consent, and retention practices will withstand state scrutiny.
- Other consumer-genetics services face a clearer warning that breach response and account-security design can draw attorney-general enforcement, not only customer claims.
Third-order effects
- If states continue to pair breach enforcement with challenges to transfers of genetic databases, genetic data may be treated less like an ordinary distressed-company asset and more like data whose movement requires meaningful customer control.
- The emerging fault line is whether legacy terms of service are sufficient for changes in ownership or use of DNA data; the related state actions suggest consent standards could become a central competitive and regulatory constraint.
The trend: Consumer genetic-data businesses are moving toward a stricter model in which cybersecurity failures and ownership changes both trigger scrutiny over consent and control of DNA information.