23andMe data breach under ICO investigation: What it means for you

The UK’s Information Commissioner’s Office (ICO) will investigate 23andMe over its recent data breach. This means the data watchdog thinks the genetic testing company has questions to answer over how it handled its customer’s private data.  

The investigation is good news for people who have joined a legal action against 23andMe, as it will help establish exactly what happened.

What do we know about the 23andMe data breach?

In October 2023, hackers accessed the accounts of around 14,000 23andMe customers.` Here’s what we know so far:  

  • The criminals used emails and passwords stolen in other breaches to login to the accounts of some 23andMe customers 
  • The security failure exposed a range of sensitive data 
  • 23andMe has a feature called ‘DNA Relatives’ that lets people share data with users they are related to. The hackers exploited this to access the data of around seven million people. 

The ICO will work alongside its Canadian counterpart, the Office of the Privacy Commissioner of Canada (OPC). Together, they will look at: 

  • The scope of information that was exposed by the breach 
  • The potential harm to affected people 
  • Whether 23andMe had adequate safeguards to protect the highly sensitive information within its control 
  • Whether the company provided adequate notification about the breach to the two regulators and affected people as required under Canadian and UK data protection laws. 

Are you affected by the 23andMe data hack? 

Millions of people are affected by the 23andMe data breach, including many in the UK. However, while the joint investigation is welcome, even if found guilty, the ICO and OPC does not award compensation to data breach victims.
 
The only way to get justice and compensation for the hack is make a lawsuit against 23andMe.

Join the Claim connects consumers with SRA-regulated lawyers. Visit the claim page to check your eligibility if a claim is open with one of our trusted legal partners. If a group action has not yet been launched, you can register your interest and we’ll keep you informed if a partner firm decides to take a claim forward.  

This information is for general guidance only and does not constitute legal or financial advice.

Found this helpful? Share it

Facebook
Twitter
WhatsApp
LinkedIn
Email

Or

You may also like:

BMW faces legal action over emissions-cheating software. Learn what the scandal involves, who is affected, and what it means for UK diesel car owners.
Capita’s data breach exposed pension holders’ personal data. Stay updated on the latest legal action, investigations, and regulatory responses.
Confused about Jaguar Land Rover DPF claims vs. Dieselgate? Learn the key differences, legal actions, and how to check if you qualify for compensation.

Latest news & insights

Discover 10 essential facts about group litigation for first-time claimants. Learn how joining a group...
Delayed 3+ hours or had a cancelled flight? You could claim up to £520 under...
Massive UK collective actions could return billions to consumers, yet awareness remains low. Discover the...

Did you know we have a newsletter?

Sign up for our newsletter to stay up to date.