23andMe changed its TOS to prevent lawsuits days after its October data breach; to opt out, customers must email the company that they disagree within 30 days
Days after a data breach allowed hackers to steal 6.9 million 23andMe users' personal details, the genetic testing company changed …
Context & Ripple Effects
The terms change followed disclosure that attackers accessed a small share of accounts but exposed personal details tied to millions of customers through the October incident. The company’s own account of the breach later placed unauthorized access across April-to-September 2023.
The move put contractual dispute terms at the center of the response while the underlying incident was still being investigated. Subsequent coverage of a $30 million privacy settlement shows that changing terms did not eliminate the breach’s legal and reputational consequences.
First-order effects
- Customers who want to reject the revised dispute terms must take a time-limited, affirmative step: email 23andMe within 30 days.
- 23andMe immediately improves its ability to channel post-breach disputes through the newly revised terms, rather than leaving all customers under the prior agreement.
Second-order effects
- The opt-out-by-email design can reduce the number of customers who preserve an alternative path to bring claims, raising the procedural burden for affected users.
- The change makes breach response a combined security-and-legal exercise: remediation communications and terms updates can shape liability exposure at the same time.
Third-order effects
- If this approach becomes common, consumer data companies may increasingly use terms updates after incidents to manage collective legal exposure, intensifying scrutiny of whether notice and opt-out mechanisms are meaningful.
- For sensitive-data services, security failures may be judged not only by the intrusion itself but by the fairness and accessibility of the remedies offered afterward.
The trend: Data-intensive consumer platforms are increasingly treating contract design as a core part of breach response and privacy-risk management.