23andWho? The fate of your DNA data after the 23andMe bankruptcy

Consumers have been trading their DNA for a personal genetic history lesson with 23andMe since 2007.

The company has since become extremely popular and has collected a trove of genetic information relating to more than 14 million people. But in March 2025, 23andMe filed for Chapter 11 bankruptcy due to ongoing financial struggles and data privacy concerns after the company experienced a major data breach involving approximately 6.9 million customers and resulting in a $30 million settlement.

Now, the company and its assets could potentially be sold to an entity that has a different agenda for millions of individuals’ genetic information. In that event, genetic information could be used for research on genetic diseases, identification of individuals in law enforcement actions, and other applications that consumers may not have contemplated when they provided their genetic information to 23andMe.

The fate of 23andMe raises questions such as what laws, if any, protect this information, and what can customers do to protect their data?

Data privacy laws

All 50 states have data breach notification laws that require data owners to notify individuals if certain personal information was subject to unauthorized access or acquisition. However, the acquisition of data through the sale of a bankruptcy estate does not mean that the acquisition of data is unauthorized. It is likely that the bankruptcy estate would be considered the “owner” of the data with authorization to sell it without the consent of the individuals who provided the data. And, in turn, the buyer’s subsequent use of the data would be “authorized.”

It should also be noted that states define personal information differently, and only a small number of states protect biometric information such as genetic information. State laws generally do not govern the processing of the data. Thus, in the event that the acquirer of the data experiences a data breach, 23andMe, or a future acquirer, may be required to inform individuals of a breach but will not necessarily be required to disclose how their information is being used.

Federal laws also do not offer much help here. The Health Insurance Portability and Accountability Act applies only to certain types of health care entities and their vendors. 23andMe, or a subsequent purchaser, is not likely to fall under this classification. Further, to qualify as protected health information under HIPAA, the information generally needs to be transmitted electronically and related to a person’s health condition, or to the provision of, or payment for the provision of, health care. Therefore, data collected by 23andMe would not qualify as protected health information. Although the federal Genetic Information Nondiscrimination Act prohibits employers and health insurance companies from discriminating based on an individual’s genetic information, among other things, it presumably would not protect against other uses of the information.

What can 23andMe customers do?

Currently, customers are still able to delete their data and profiles from 23andMe. Customers should also consider requesting destruction of their saliva samples and cancellation of any further use of their genetic information. Additionally, it is a best practice to review the privacy policies of companies to which consumers divulge personal information. Privacy policies typically explain what third parties, if any, will receive the information and how the information is processed.

The Constangy Cyber Team assists businesses of all sizes and industries with compliance needs. If you would like additional information about state or federal data privacy laws, please contact us at cyber@constangy.com.

The Constangy Cyber Advisor posts regular updates on legislative developments, data privacy, and information security trends. Our blog posts are informed through the Constangy Cyber Team's experience managing thousands of data breaches, providing robust compliance advisory services, and consultation on complex data privacy and security litigation. 

Search

Get Updates By Email

Subscribe

Archives

Jump to Page

Constangy, Brooks, Smith & Prophete, LLP Cookie Preference Center

Your Privacy

When using this website, Constangy and certain third parties may collect and use cookies or similar technologies to enhance your experience. These technologies may collect information about your device, activity on our website, and preferences. Some cookies are essential to site functionality, while others help us analyze performance and usage trends to improve our content and features.

Please note that if you return to this website from a different browser or device, you may need to reselect your cookie preferences.

For more information about our privacy practices, including your rights and choices, please see our Privacy Policy. 

Strictly Necessary Cookies

Always Active

Strictly Necessary Cookies are essential for the website to function, and cannot be turned off. We use this type of cookie for purposes such as security, network management, and accessibility. You can set your browser to block or alert you about these cookies, but if you do so, some parts of the site will not work. 

Functionality Cookies

Always Active

Functionality Cookies are used to enhance the functionality and personalization of this website. These cookies support features like embedded content (such as video or audio), keyword search highlighting, and remembering your preferences across pages—for example, your cookie choices or form inputs during submission.

Some of these cookies are managed by third-party service providers whose features are embedded on our site. These cookies do not store personal information and are necessary for certain site features to work properly.

Performance Cookies

Performance cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek