Back to Feed
GDPRJul 24, 2026

AEPD (Spain) - PS-00140-2025

AEPD fines 23andMe €2.4M for inadequate genetic data protection and delayed breach notification.

Summary

Spain's AEPD (Data Protection Authority) issued a €2.4 million fine to 23andMe for failing to implement adequate security measures protecting sensitive genetic, health, and ethnic origin data of 2,642 Spanish customers affected by an October 2023 credential-stuffing attack. The company also violated GDPR Article 33 by notifying the authority on 17 October, seven days after detecting the breach, rather than within the mandated 72-hour window. The breach exposed customer identities, contacts, locations, images, genetic data, and health information, which was subsequently published on forums and offered for sale on the dark web.

Full text

Help AEPD (Spain) - PS-00140-2025: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 14:26, 24 July 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators221 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 14:26, 24 July 2026 AEPD - PS-00140-2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 5(1)(f) GDPR Article 9 GDPR Article 24(1) GDPR Article 32 GDPR Article 33 GDPR Type: Investigation Outcome: n/a Started: 29.05.2025 Decided: 10.10.2025 Published: 16.07.2026 Fine: n/a Parties: 23ANDME, INC National Case Number/Name: PS-00140-2025 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Catalan; Valencian Original Source: AEPD (in CA) Initial Contributor: bms The DPA fined a genomics and biotechnology company €2.4 million for failing to adequately protect sensitive genetic and health data and for notifying a personal data breach after the 72-hour deadline. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In October 2023, the controller suffered a personal data breach following a credential-stuffing attack. Attackers accessed customer accounts by using login credentials that customers had reused on other services previously compromised. The breach affected 2,642 customers residing in Spain and exposed identity, contact and location data, images, genetic data, health data and data revealing ethnic origin. A sample of the data was published on an online forum, while a file containing the compromised data was offered for sale on the dark web. At the time of the breach, customers accessed their accounts using a username and password. Multi-factor authentication was available but optional. The controller had not established specific password-strength requirements or periodic password changes and had not implemented limits on access requests or downloads based on IP addresses. Once an account had been accessed, there were no additional controls limiting the viewing or downloading of sensitive data, including information relating to potential relatives. On 1 October 2023, the controller detected a Reddit post offering information allegedly belonging to its customers. On 5 October, it confirmed that one of the published records belonged to a customer. It published an alert on its website on 6 October, reported the incident to US authorities on 7 October and required customers to reset their passwords on 9 October. The controller informed all customers about the incident on 10 October. It identified 799 affected customers residing in Spain on 12 October and notified them on 13 October. It subsequently identified and notified another 1,843 customers residing in Spain on 24 October. However, the controller did not notify the DPA until 17 October 2023 and submitted additional information on 30 October. Holding The DPA held that the GDPR applied pursuant to Article 3(2) GDPR because the controller, although not established in the EU, offered genetic testing and analysis services to data subjects in the Union. First, the DPA found a violation of Article 5(1)(f) GDPR. The controller had failed to process personal data in a manner ensuring appropriate integrity and confidentiality. The adequacy of its security measures had to be assessed in light of Articles 24(1) and 32 GDPR and the risk-based approach established by the GDPR. The DPA emphasised that the affected information included genetic data, health data and data revealing ethnic origin, which constitute special categories of personal data under Article 9 GDPR. Given the sensitivity of this information and the potential consequences of unauthorised disclosure, the controller was required to implement particularly robust security measures. Nevertheless, the controller did not impose specific password-strength requirements or require passwords to be changed periodically. Although it had implemented multi-factor authentication, its use remained optional. Moreover, it had not introduced additional controls or limits concerning account access, access requests or the downloading of sensitive information. These deficiencies made unauthorised access more difficult to detect and facilitated the extraction of the compromised data. The DPA rejected the suggestion that responsibility could be shifted to customers because they had reused their credentials. Although customers were responsible for using their credentials appropriately, the controller remained responsible for assessing the risks and implementing security measures appropriate to the nature of the processing. Credential theft was a well-known attack vector, particularly relevant where account access allowed users to view or download genetic and health information. Second, the DPA found a violation of Article 33 GDPR. It considered that the controller became aware of the personal data breach on 5 October 2023, when it confirmed that one of the records published online belonged to one of its customers. At that point, it had a reasonable degree of certainty that a security incident involving personal data had occurred. The controller’s subsequent actions, including publishing an alert, notifying US authorities and requiring password resets, further demonstrated that it was already aware of the breach. However, it did not notify the DPA until 17 October, substantially exceeding the 72-hour deadline. The DPA stressed that notification cannot be postponed until all affected individuals and all details of the incident have been identified. Article 33(4) GDPR expressly permits information to be provided in phases when it cannot be submitted simultaneously. The controller’s need to assess its notification obligations across several jurisdictions therefore did not justify the delay, particularly because the breach involved sensitive data posing a high risk to the affected individuals. The DPA imposed a total administrative fine of €2,400,000: - €2,000,000 for the violation of Article 5(1)(f) GDPR; - €400,000 for the violation of Article 33 GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Catalan; Valencian original. Please refer to the Catalan; Valencian original for more details. 1/24  Case No.: EXP202316010 SANCTIONING PROCEDURE RESOLUTION From the proceedings initiated by the Spanish Data Protection Agency and based on the following FACTS FIRST: On October 17, 2023, the company 23ANDME, INC (hereinafter, 23ANDME), with its registered address at 349 OYSTER POINT BLVD - 94080 SOUTH SAN FRANCISCO - CALIFORNIA notified this Agency of a security breach in which a violation of the security of personal data had occurred. According to the breach notification, made by the company Greenberg Traurig, LLP (hereinafter GREENBERG) as a representative of 23ANDME, on October 1, 2023, a confidentiality breach occurred due to a cyberattack that affected 799 people residing in Spain, customers of the company, in which identity, contact and location data, images, and genetic data were exposed. In the breach notification, 23ANDME includes the following description of the incident (unofficial translation made with the "Digital Europe Language Tools" tool): "(…)" On October 30, 2023, 23ANDME expands the information regarding the breach. According to this new communication, the breach would have affected another 1,843 people in Spain and would have included, in addition to the previously mentioned data, data revealing ethnic origin. The description included in this second communication states the following

Indicators of Compromise

  • malware — credential-stuffing attack

Entities

23andMe (vendor)AEPD (Spain) (vendor)