
PIPEDA Findings #2025-001: Joint investigation into a data breach at 23andMe by the Privacy Commissioner of Canada and the UK Information Commissioner
The Office of the Privacy Commissioner of Canada (OPC) and the UK Information Commissioner (ICO) jointly investigated a data breach at 23andMe Inc., a direct-to-consumer genetic testing company, which affected almost 7 million customers globally, including 319,000 in Canada. The investigation focused on the adequacy of 23andMe's security safeguards and its breach notification practices following a credential stuffing attack. The OPC found that 23andMe failed to implement appropriate safeguards, such as mandatory multi-factor authentication, robust compromised-password checks, and effective detection systems, given the highly sensitive nature of genetic and health information. Additionally, 23andMe's breach notifications to the OPC and affected individuals were deemed inadequate in content and timing, as they initially omitted crucial details like raw DNA data compromise and the data being offered for sale. However, 23andMe subsequently implemented significant security enhancements and updated its notification processes. Consequently, the OPC concluded both issues were well-founded but resolved due to the satisfactory corrective measures taken by the company. This report also highlighted the ongoing bankruptcy proceedings of 23andMe and the Commissioners' commitment to ensuring privacy obligations are met if customer data is transferred.
- 1Whether 23andMe had appropriate safeguards to protect highly sensitive personal information under its control, specifically against credential stuffing attacks.
- 2Whether 23andMe's prevention measures, including mandatory Multi-factor Authentication (MFA), compromised-password checks, and minimum password requirements, were adequate.
- 3Whether 23andMe's detection measures, including detection systems, digital fingerprinting, and device history, were adequate to identify ongoing attacks.
- 4Whether 23andMe adequately investigated anomalies and claims of breach prior to public disclosure.
- 5Whether 23andMe's breach response, including the timeliness of disabling active user sessions, disabling raw DNA download features, and implementing mandatory MFA, was adequate.
- 6Whether 23andMe adequately notified the OPC about the breach, including the completeness of information provided and timeliness.
- 7Whether 23andMe adequately notified affected individuals about the breach, including the completeness of information provided and timeliness.
- 8Whether the data breach created a real risk of significant harm to affected individuals, triggering notification obligations.
- 9Whether 23andMe's methodology for identifying and notifying individuals whose raw DNA was downloaded by the Threat Actor was adequate.
- Security safeguards: Found inadequate but resolved
- Breach notification content: Found inadequate but resolved
- Breach notification timing: Found inadequate but resolved
Complaint well-founded and resolved for both safeguard and breach notification issues.
The OPC found that 23andMe contravened PIPEDA provisions related to safeguards and breach notifications, but the company implemented satisfactory corrective measures during the investigation to address these deficiencies.
23andMe implemented significant security enhancements, including increasing minimum password length, implementing mandatory email-based two-factor authentication, enhancing protection for sensitive data downloads, conducting regular attack simulations, and updating monitoring and detection tools, as well as organizational security processes.
- Principle 4.7 of Schedule 1 of PIPEDA
- section 10.1 of PIPEDA
- sections 2 and 3 of the Breach of Safeguards Regulations
This summary is for informational purposes only and not legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro