[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCQcWpmGdE-GymGsHbYexVN7kDcGHQzjfnlj-yRnPYYg":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"6a70a9fc-a8ac-4f34-bb47-47725363ddd0","AEPD (Spain) - PS-00140-2025","aepd-spain-ps-00140-2025-93862a","← Older revision Revision as of 10:55, 29 July 2026 Line 100: Line 100: }} }} The DPA fined a genomics and biotechnology company €2.4 million for failing to adequately protect sensitive genetic and health data and for notifying a personal data breach after the 72-hour deadline. The DPA fined a genomics and biotechnology company €2.4 million for failing to adequately protect sensitive genetic and health data and for notifying the DPA about a personal data breach after the 72-hour deadline. == English Summary == == English Summary == Line 122: Line 122: First, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(f) GDPR]]. The controller had failed to process personal data in a manner ensuring appropriate integrity and confidentiality. The adequacy of its security measures had to be assessed in light of Articles 24(1) and 32 GDPR and the risk-based approach established by the GDPR. First, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(f) GDPR]]. The controller had failed to process personal data in a manner ensuring appropriate integrity and confidentiality. The adequacy of its security measures had to be assessed in light of Articles 24(1) and 32 GDPR and the risk-based approach established by the GDPR. The DPA emphasised that the affected information included genetic data, health data and data revealing ethnic origin, which constitute special categories of personal data under [[Article 9 GDPR|Article 9 GDPR]]. Given the sensitivity of this information and the potential consequences of unauthorised disclosure, the controller was required to implement particularly robust security measures. The DPA emphasised that the affected information included genetic data, health data and data revealing ethnic origin, which constitute special categories of personal data under [[Article 9 GDPR]]. Given the sensitivity of this information and the potential consequences of unauthorised disclosure, the controller was required to implement particularly robust security measures. Nevertheless, the controller did not impose specific password-strength requirements or require passwords to be changed periodically. Although it had implemented multi-factor authentication, its use remained optional. Moreover, it had not introduced additional controls or limits concerning account access, access requests or the downloading of sensitive information. These deficiencies made unauthorised access more difficult to detect and facilitated the extraction of the compromised data. Nevertheless, the controller did not impose specific password-strength requirements or require passwords to be changed periodically. Although it had implemented multi-factor authentication, its use remained optional. Moreover, it had not introduced additional controls or limits concerning account access, access requests or the downloading of sensitive information. These deficiencies made unauthorised access more difficult to detect and facilitated the extraction of the compromised data. Line 130: Line 130: Although customers were responsible for using their credentials appropriately, the controller remained responsible for assessing the risks and implementing security measures appropriate to the nature of the processing. Credential theft was a well-known attack vector, particularly relevant where account access allowed users to view or download genetic and health information. Although customers were responsible for using their credentials appropriately, the controller remained responsible for assessing the risks and implementing security measures appropriate to the nature of the processing. Credential theft was a well-known attack vector, particularly relevant where account access allowed users to view or download genetic and health information. Second, the DPA found a violation of [[Article 33 GDPR|Article 33 GDPR]]. It considered that the controller became aware of the personal data breach on 5 October 2023, when it confirmed that one of the records published online belonged to one of its customers. At that point, it had a reasonable degree of certainty that a security incident involving personal data had occurred. Second, the DPA found a violation of [[Article 33 GDPR]]. It considered that the controller became aware of the personal data breach on 5 October 2023, when it confirmed that one of the records published online belonged to one of its customers. At that point, it had a reasonable degree of certainty that a security incident involving personal data had occurred. The controller’s subsequent actions, including publishing an alert, notifying US authorities and requiring password resets, further demonstrated that it was already aware of the breach. However, it did not notify the DPA until 17 October, substantially exceeding the 72-hour deadline. The controller’s subsequent actions, including publishing an alert, notifying US authorities and requiring password resets, further demonstrated that it was already aware of the breach. However, it did not notify the DPA until 17 October, substantially exceeding the 72-hour deadline. Line 138: Line 138: The DPA imposed a total administrative fine of €2,400,000: The DPA imposed a total administrative fine of €2,400,000: - €2,000,000 for the violation of [[Article 5 GDPR|Article 5(1)(f) GDPR]]; - €2,000,000 for the violation of [[Article 5 GDPR|Article 5(1)(f) GDPR]]; - €400,000 for the violation of [[Article 33 GDPR|Article 33 GDPR]]. - €400,000 for the violation of [[Article 33 GDPR]].","Spain's Data Protection Agency (AEPD) has fined a genomics and biotechnology company €2.4 million for failing to implement adequate security measures for sensitive genetic and health data. The company also violated GDPR by notifying the AEPD of a personal data breach after the mandatory 72-hour deadline. The AEPD highlighted deficiencies in password policies and optional multi-factor authentication as contributing factors.","Spain's AEPD fines a genomics company €2.4M for data protection and breach notification failures.","Help AEPD (Spain) - PS-00140-2025: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 14:28, 24 July 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators228 editsm Tag: Visual edit: Switched← Older edit Latest revision as of 10:55, 29 July 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators228 editsTag: Visual edit Line 100: Line 100: }}}} The DPA fined a genomics and biotechnology company €2.4 million for failing to adequately protect sensitive genetic and health data and for notifying a personal data breach after the 72-hour deadline.The DPA fined a genomics and biotechnology company €2.4 million for failing to adequately protect sensitive genetic and health data and for notifying the DPA about a personal data breach after the 72-hour deadline. == English Summary ==== English Summary == Line 122: Line 122: First, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(f) GDPR]]. The controller had failed to process personal data in a manner ensuring appropriate integrity and confidentiality. The adequacy of its security measures had to be assessed in light of Articles 24(1) and 32 GDPR and the risk-based approach established by the GDPR.First, the DPA found a violation of [[Article 5 GDPR|Article 5(1)(f) GDPR]]. The controller had failed to process personal data in a manner ensuring appropriate integrity and confidentiality. The adequacy of its security measures had to be assessed in light of Articles 24(1) and 32 GDPR and the risk-based approach established by the GDPR. The DPA emphasised that the affected information included genetic data, health data and data revealing ethnic origin, which constitute special categories of personal data under [[Article 9 GDPR|Article 9 GDPR]]. Given the sensitivity of this information and the potential consequences of unauthorised disclosure, the controller was required to implement particularly robust security measures.The DPA emphasised that the affected information included genetic data, health data and data revealing ethnic origin, which constitute special categories of personal data under [[Article 9 GDPR]]. Given the sensitivity of this information and the potential consequences of unauthorised disclosure, the controller was required to implement particularly robust security measures. Nevertheless, the controller did not impose specific password-strength requirements or require passwords to be changed periodically. Although it had implemented multi-factor authentication, its use remained optional. Moreover, it had not introduced additional controls or limits concerning account access, access requests or the downloading of sensitive information. These deficiencies made unauthorised access more difficult to detect and facilitated the extraction of the compromised data.Nevertheless, the controller did not impose specific password-strength requirements or require passwords to be changed periodically. Although it had implemented multi-factor authentication, its use remained optional. Moreover, it had not introduced additional controls or limits concerning account access, access requests or the downloading of sensitive information. These deficiencies made unauthorised access more difficult to detect and facilitated the extraction of the compromised data. Line 130: Line 130: Although customers were responsible for using their credentials appropriately, the controller remained responsible for assessing the risks and implementing security measures appropriate to the nature of the processing. Credential theft was a well-known attack vector, particularly relevant where account access allowed users to view or download genetic and health information.Although customers were responsible for using their credentials appropriately, the controller remained responsible for assessing the risks and implementing security measures appropriate to the nature of the processing. Credential theft was a well-known attack vector, particularly relevant where account access allowed users to view or download genetic and health information. Second, the DPA found a violation of [[Article 33 GDPR|Article 33 GDPR]]. It considered that the controller became aware of the personal data breach on 5 October 2023, when it confirmed that one of the records published online belonged to one of its customers. At that point, it had a reasonable degree of certainty that a security incident involving personal data had occurred.Second, the DPA found a violation of [[Article 33 GDPR]]. It considered that the controller became aware of the personal data breach on 5 October 2023, when it confirmed that one of the records published online belonged to one of its customers. At that point, it had a reasonable degree of certainty that a security incident involving personal data had occurred. The controller’s subsequent actions, including publishing an alert, notifying US authorities and requiring password resets, further demonstrated that it was already aware of the breach. However, it did not notify the DPA until 17 October, substantially exceeding the 72-hour deadline.The controller’s subsequent actions, including publishing an alert, notifying US authorities and requiring password resets, further demonstrated that it was already aware of the breach. However, it did not notify the DPA until 17 October, substantially exceeding the 72-hour deadline. Line 138: Line 138: The DPA imposed a total administrative fine of €2,400,000:The DPA imposed a total administrative fine of €2,400,000: - €2,000,000 for the violation of [[Article 5 GDPR|Article 5(1)(f) GDPR]];- €2,000,000 for the violation of [[Article 5 GDPR|Article 5(1)(f) GDPR]]; - €400,000 for the violation of [[Article 33 GDPR|Article 33 GDPR]].- €400,000 for the violation of [[Article 33 GDPR]]. Latest revision as of 10:55, 29 July 2026 AEPD - PS-00140-2025 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 5(1)(f) GDPR Article 9 GDPR Article 24(1) GDPR Article 32 GDPR Article 33 GDPR Type: Investigation Outcome: n\u002Fa Started: 29.05.2025 Decided: 10.10.2025 Published: 16.07.2026 Fine: n\u002Fa Parties: 23ANDME, INC National Case Number\u002FName: PS-00140-2025 European Case Law Identifier: n\u002Fa Appeal: Unknown Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: bms The DPA fined a genomics and biotechnology company €2.4 million for failing to adequately protect sensitive genetic and health data and for notifying the DPA about a personal data breach after the 72-hour deadline. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In October 2023, the controller suffered a personal data breach following a credential-stuffing attack. Attackers accessed customer accounts by using login credentials that customers had reused on other services previously compromised. The breach affected 2,642 customers residing in Spain and exposed identity, contact and location data, images, genetic data, health data and data revealing ethnic origin. A sample of the data was published on an online forum, while a file containing the compromised data was offered for sale on the dark web. At the time of the breach, customers accessed their accounts using a username and password. Multi-factor authentication was available but optional. The controller had not established specific password-strength requirements or periodic password changes and had not implemented limits on access requests or downloads based on IP addresses. Once an account had been accessed, there were no additional controls limiting the viewing or downloading of sensitive data, including informa","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_PS-00140-2025&diff=52546&oldid=52492","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F5\u002F59\u002FLogoES.jpg","2026-07-29T10:55:18+00:00","2026-07-29T12:00:19.778395+00:00",7,[18],{"name":19,"type":20},"AEPD","vendor","53f9c4b6-8bc6-4964-9169-d09e5cd41d72",{"id":21,"icon":23,"name":24,"slug":25},null,"Compliance","compliance",[27,32,37,42],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":38},{"id":39,"icon":23,"name":40,"slug":41},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":43},{"id":44,"icon":23,"name":45,"slug":46},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]