23andMe Bankruptcy Highlights Urgent Need for Genetic Privacy Reform

23andMe’s bankruptcy amid a major data breach highlights the urgent need for stronger federal genetic privacy laws and clearer compliance strategies for companies.

Key points:

  • 23andMe’s bankruptcy follows a major data breach that exposed sensitive genetic information.
  • The incident spotlights growing legal, ethical, and national security concerns around genetic privacy.
  • Experts urge stronger federal legislation and standardized compliance strategies for companies handling genetic data.

Direct-to-consumer genetic testing company 23andMe has filed for Chapter 11 bankruptcy, a move driven in part by a severe loss of consumer trust following a 2023 security breach that compromised the genetic data of millions. The incident has refocused attention on the urgent need for robust genetic privacy protections and consistent regulatory standards, especially as companies across industries—from health care to AI—leverage sensitive genomic data in increasingly complex ways.

The bankruptcy underscores the unique risks posed by genetic information, which unlike other forms of personal data, is permanent, deeply intimate, and impossible to change if compromised. As Bloomberg Law reports, misuse of such data can lead to discrimination in insurance and employment, identity fraud, and even national security threats if foreign actors weaponize U.S. genetic data.

While federal laws like the Genetic Information Nondiscrimination Act (GINA), HIPAA, and the Affordable Care Act provide a baseline of protection, these laws leave major gaps. GINA, for example, bars genetic discrimination in health insurance and employment, but does not cover life or disability insurance. Enforcement is largely reactive and does not address the broader consumer privacy risks associated with widespread data sharing and resale.

States have tried to fill in the gaps with their own laws. California’s Genetic Information Nondiscrimination Act extends protections into housing and education, while states like Maryland and Washington have adopted strict rules around informed consent, data security, and bans on the sale of genetic data. But this patchwork of state laws creates a complex and often confusing compliance landscape for companies operating nationally.

To navigate these challenges, businesses handling genetic information should implement clear compliance strategies, including:

  • Publishing detailed privacy notices about how genetic data is collected, used, stored, and shared.
  • Providing consumer controls for accessing, deleting, or modifying their genetic data and accounts.
  • Obtaining explicit, purpose-specific consent before using genetic data, with easy revocation options.
  • Implementing strong data security systems and performing regular risk assessments and audits.
  • Conducting data protection impact assessments to identify and mitigate emerging privacy and security risks.

Still, experts warn that industry compliance alone isn’t enough. The 23andMe fallout demonstrates that even de-identified data can be re-identified using public databases and genomic software, raising new risks for both individuals and national security. Advocates are calling for the Trump administration and Congress to prioritize comprehensive federal legislation that would impose consistent standards for consent, data minimization, breach notification, and restrictions on resale of genetic data.

“The 23andMe bankruptcy is a wake-up call,” the report concludes. Without urgent regulatory action and stronger compliance, companies risk not only legal consequences, but permanent reputational damage in an era of growing privacy expectations and geopolitical threats.

Customer Stories

See how leading enterprise in-house teams have scaled smarter with Legal.io's high-caliber flex talent.

More from Legal.io


Legal Issue Series - What to do about Delayed OPT Extensions
Legal Issue Series - What to do about Delayed OPT Extensions

For many foreign students on F-1 visas, the practical American training they receive is just as important as their education.

Aug 19, 2015
Read More
February 24, 2023 Edition #147
February 24, 2023 Edition #147

Published weekly on Friday, the Legal.io Newsletter covers the latest in legal, talent & tech

Feb 24, 2023
Read More
Top U.S. Firms Curb Hiring Amid Growth Slowdown
Top U.S. Firms Curb Hiring Amid Growth Slowdown

Firms prioritize productivity over recruitment.

Feb 01, 2024
Read More
Allen & Overy Announces Legal AI Product - Harvey
Allen & Overy Announces Legal AI Product - Harvey

The AI product will eventually become available to all A&O firms worldwide.

Feb 17, 2023
Read More
Breaking the Chains: How In-House Legal Teams Can Overcome the Perception of Being a Roadblock
Breaking the Chains: How In-House Legal Teams Can Overcome the Perception of Being a Roadblock

The State of Collaboration in Corporate Legal Departments reports on in-house counsel perceptions

Oct 22, 2023
Read More
Ready to hire?

Schedule a free consultation to discuss your hiring needs.

Free 15-min consultation
Legal.io Platform
5 star reviews
Hiring made smarter

Easy-to-use platform for hiring legal talent, managing spend, and optimizing your panel — plus an average savings of 50%.

Need Immediate Help?

Submit a hiring request and let our experts handle the entire process for you.