Skip to content
Enforcement · AEPD (Spain) ·PS-00140-2025 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain

In October 2023, the controller suffered a personal data breach following a credential-stuffing attack.

Summary

Attackers accessed customer accounts by using login credentials that customers had reused on other services previously compromised. The breach affected 2,642 customers residing in Spain and exposed identity, contact and location data, images, genetic data, health data and data revealing ethnic origin. A sample of the data was published on an online forum, while a file containing the compromised data was offered for sale on the dark web. At the time of the breach, customers accessed their accounts using a username and password. Multi-factor authentication was available but optional. The controller had not established specific password-strength requirements or periodic password changes and had not implemented limits on access requests or downloads based on IP addresses. Once an account had been accessed, there were no additional controls limiting the viewing or downloading of sensitive data, including information relating to potential relatives. On 1 October 2023, the controller detected a Reddit post offering information allegedly belonging to its customers. On 5 October, it confirmed that one of the published records belonged to a customer. It published an alert on its website on 6 October, reported the incident to US authorities on 7 October and required customers to reset their passwords on 9 October. The controller informed all customers about the incident on 10 October. It identified 799 affected customers residing in Spain on 12 October and notified them on 13 October. It subsequently identified and notified another 1,843 customers residing in Spain on 24 October. However, the controller did not notify the DPA until 17 October 2023 and submitted additional information on 30 October. Holding — The DPA held that the GDPR applied pursuant to Article 3(2) GDPR because the controller, although not established in the EU, offered genetic testing and analysis services to data subjects in the Union. First, the DPA found a violation of Article 5(1)(f) GDPR. The controller had failed to process personal data in a manner ensuring appropriate integrity and confidentiality. The adequacy of its security measures had to be assessed in light of Articles 24(1) and 32 GDPR and the risk-based approach established by the GDPR. The DPA emphasised that the affected information included genetic data, health data and data revealing ethnic origin, which constitute special categories of personal data under Article 9 GDPR. Given the sensitivity of this information and the potential consequences of unauthorised disclosure, the controller was required to implement particularly robust security measures. Nevertheless, the controller did not impose specific password-strength requirements or require passwords to be changed periodically. Although it had implemented multi-factor authentication, its use remained optional. Moreover, it had not introduced additional controls or limits concerning account access, access requests or the downloading of sensitive information. These deficiencies made unauthorised access more difficult to detect and facilitated the extraction of the compromised data. The DPA rejected the suggestion that responsibility could be shifted to customers because they had reused their credentials. Although customers were responsible for using their credentials appropriately, the controller remained responsible for assessing the risks and implementing security measures appropriate to the nature of the processing. Credential theft was a well-known attack vector, particularly relevant where account access allowed users to view or download genetic and health information. Second, the DPA found a violation of Article 33 GDPR. It considered that the controller became aware of the personal data breach on 5 October 2023, when it confirmed that one of the records published online belonged to one of its customers. At that point, it had a reasonable degree of certainty that a security incident involving personal data had occurred. The controller’s subsequent actions, including publishing an alert, notifying US authorities and requiring password resets, further demonstrated that it was already aware of the breach. However, it did not notify the DPA until 17 October, substantially exceeding the 72-hour deadline. The DPA stressed that notification cannot be postponed until all affected individuals and all details of the incident have been identified. Article 33(4) GDPR expressly permits information to be provided in phases when it cannot be submitted simultaneously. The controller’s need to assess its notification obligations across several jurisdictions therefore did not justify the delay, particularly because the breach involved sensitive data posing a high risk to the affected individuals. The DPA imposed a total administrative fine of €2,400,000: - €2,000,000 for the violation of Article 5(1)(f) GDPR; - €400,000 for the violation of Article 33 GDPR.

How it connects

37 of 40 paragraphs apply legislation or carry a topic — see them in the full text ↓

Full text 40 findings

Paragraphs carrying a topic or an applied provision show those connections inline Original at the source →
§

: EXP202316010 SANCTIONING PROCEDURE RESOLUTION From the proceedings initiated by the Spanish Data Protection Agency and based on the following FACTS FIRST: On October 17, 2023, the company 23ANDME, INC (hereinafter, 23ANDME), with its registered address at 349 OYSTER POINT BLVD - 94080 SOUTH SAN FRANCISCO - CALIFORNIA notified this Agency of a security breach in which a violation of the security of personal data had occurred. According to the breach notification, made by the company Greenberg Traurig, LLP (hereinafter GREENBERG) as a representative of 23ANDME, on October 1, 2023, a confidentiality breach occurred due to a cyberattack that affected 799 people residing in Spain, customers of the company, in which identity, contact and location data, images, and genetic data were exposed. In the breach notification, 23ANDME includes the following description of the incident (unofficial translation made with the "Digital Europe Language Tools" tool): "(…)" On October 30, 2023, 23ANDME expands the information regarding the breach.

§

According to this new communication, the breach would have affected another 1,843 people in Spain and would have included, in addition to the previously mentioned data, data revealing ethnic origin. The description included in this second communication states the following (unofficial translation made with the "Digital Europe Language Tools" tool): "(…)" SECOND: As a result of the known facts, on October 31, 2023, the Director of the Spanish Data Protection Agency urged the Subdirection General of Data Inspection (SGID) to initiate the preliminary investigation proceedings referred to in Article 67 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD). es 2/24 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD. S. entity with no main establishment in Spain and the data breach affected residents in different States, on March 25, 2024, in accordance with Article 61 of the GDPR, a request was made, through the "Internal Market Information System" (regulated by the Regulation (EU) No 1024/2012 of the European Parliament and of the Council of October 25, 2012), information on the existence, if any, of the company's establishment in other States, confirming that the breach had been notified to other States and that no main establishment would be recorded in the European Union.

§

On March 27, 2024, a request for information was sent to 23ANDME, which was received on April 22, 2024, requesting additional information about the incident, risk assessment of the processing operations carried out, security measures adopted before and after the incident, and the reasons for the delay in notifying the breach to this supervisory authority. In response to the request, 23ANDME provides additional information about the incident, stating the following (unofficial translation made with the "Digital Europe Language Tools" tool): "(…)" Regarding the publication of the data on the Internet, it states the following (unofficial translation made with the "Digital Europe Language Tools" tool): "(…)" Regarding the security measures adopted before and after the breach, 23ANDME provides a copy of data protection impact assessments and states the following (unofficial translation made with the "Digital Europe Language Tools" tool): "(…)" Regarding the notification to this supervisory authority more than 72 hours after the requirement in Article 33 of the GDPR, 23ANDME states the following (unofficial translation using the "Digital Europe Language Tools" tool): "(…)" Along with its response, 23ANDME provides the texts of the communications it claims to have sent to its customers, which vary depending on the data exposed.

§

It also provides a copy of the impact assessments it has conducted. 1. es 3/24 diligenced in the file. In it, several updates are observed in which information is provided on the progress of the investigation and the measures that have been taken regarding user access. Likewise, on 03/26/2024, screenshots were entered into the file showing the website's privacy policy. com. This information is listed as updated on 12/14/2022 and indicates that it applies to all web pages owned and operated by 23ANDME. This policy includes references to the personal data of customers that are processed by 23ANDME, the source of the data processed, its use, and the circumstances under which it is disclosed to third parties. In the "security measures" section, the following is stated (unofficial translation made with the "Digital Europe Language Tools" tool): "Security Measures We implement physical, technical, and administrative measures designed to prevent unauthorized access to or disclosure of your personal information.

§

Our team regularly reviews and improves our security practices to help ensure the integrity of our systems and your personal information. For more information about our practices, visit our customer service guide. Please recognize that protecting your personal information is also your responsibility. Be mindful to keep your password and other authentication information safe from third parties, and immediately notify 23andMe of any unauthorized use of your login credentials. Your password is not visible to 23andMe staff, and we recommend that you do not share your password with 23andMe or with third parties. com/hc/en-us/articles/204712980-What-Countries-Do-You-Ship-To, which indicates the countries to which 23ANDME ships, among which is Spain. Finally, the record includes the document "23ANDME HOLDING CO. ANNUAL REPORT FISCAL 2023," published on the 23ANDME website and signed on 05/25/2023 by the President and CEO of 23ANDME as well as by other company officials.

§

This document provides information on various aspects of the company's activities. es 4/24 "We are committed to an ongoing effort of compliance and privacy oversight, also in relation to the requirements of numerous local, state, federal, and international laws, rules, and regulations related to the privacy and security of personally identifiable information, whether directly or indirectly (collectively, 'Protection Laws of data"). These data protection laws regulate the collection, storage, sharing, use, disclosure, processing, transfer, and protection of personal information, including genetic information, and frequently evolve in their scope and application. (…) Outside the United States, numerous countries have their own data protection laws, including, but not limited to, the Personal Information Protection and Electronic Documents Act ("PIPEDA") and the EU General Data Protection Regulation ("GDPR"), now also enacted in the United Kingdom ("UK GDPR").

§

(…) Internationally, we are subject to, among other data protection laws, the GDPR, the UK GDPR, and PIPEDA, which regulate the collection, storage, sharing, use, disclosure, and protection of personal information, and impose strict requirements with significant penalties and litigation risks for non-compliance. Like the United States, international data protection laws include national, state or provincial, and local laws, which means that compliance costs increase with each state, province, or locality to which we ship. 5 million or up to 4% of the offender's global annual revenue, whichever is greater. ) In addition, in the United States and internationally, companies are required to notify affected customers whose personal information has been disclosed as a result of a data breach. " On page 50 of said document, the following is stated regarding data breaches (unofficial translation made with the "Digital Europe Language Tools" tool): "The increase in global cybersecurity threats and more sophisticated and targeted cybercrime poses a risk to the security of our systems and networks and the confidentiality, availability, and integrity of our data.

§

es 5/24 unauthorized disclosure of confidential client information or other confidential information, as well as cyberattacks that involved the dissemination, theft, and destruction of corporate information, intellectual property, cash, or other valuable assets. There have also been several highly publicized cases in which hackers have demanded "ransom" payments in exchange for not disclosing confidential client information or other confidential information, or for not disabling the target company's computer or other systems. " Regarding 23ANDME's activity in Europe, on page 52 of the document, the following is stated (unofficial translation made with the "Digital Europe Language Tools" tool): "We plan to continue expanding our foreign operations where we have limited operational experience and may be subject to greater regulatory risks and local competition. If we are not successful in our efforts to expand internationally, our business may be harmed.

§

Regulations exist or are under consideration in countries outside the United States that limit or prevent the sale of direct-to-consumer genetic tests. Some countries, including Australia, require pre-market review by their regulatory body similar to that required in the United States by the FDA. Some countries, including Australia, Germany, France, and Switzerland, require a prescription for genetic tests that provide health information, thus limiting our offering in those countries to a ancestry-only test. Other countries require mandatory genetic counseling before genetic testing. These regulations limit the available market for our products and services and increase the costs associated with marketing our products and services where we can offer them. Legal developments in the EU have created a series of new compliance obligations regarding the transfer of personal data from the European Union to the United States, including GDPR and the UK GDPR, which apply to some of our activities related to the services we offer or may offer to individuals located in the EU.

§

Significant effort and expense will continue to be required to ensure compliance with the GDPR and the UK GDPR, and could require us to change our business practices. es 6/24 requirements under the GDPR and the UK GDPR may change periodically or may be modified by EU / UK and/or national legislation. " FOURTH: On April 23, 2025, and May 7, 2025, two communications were received from the entity OFFICE OF THE UNITED STATES TRUSTEE, regarding the bankruptcy proceedings of 23ANDME in the United States. FIFTH: On May 29, 2025, the Presidency of the Spanish Data Protection Agency decided to initiate an enforcement proceeding against the respondent, for the alleged violation of Articles 5(1)(f) and 33 of the GDPR, as typified in Article 83(5)(a) and Article 84(4)(a) of the GDPR, respectively. SIXTH: On June 24, 2025, the aforementioned opening decision was notified, in accordance with the certificate issued by Correos, pursuant to the provisions established in the Law 39/2015, of October 1, on the Common Administrative Procedure of the Public Administrations (hereinafter, LPACAP).

§

After the deadline for submitting arguments expired, it was determined that no arguments were received from the respondent. f) of the LPACAP—a provision that was communicated to the respondent party in the decision to initiate the procedure—stipulates that if no objections are filed within the prescribed period regarding the content of the opening decision, when it contains a precise determination of the liability attributed, it may be considered a draft resolution. In the present case, the opening decision of the administrative proceeding determined the facts constituting the charge, the GDPR violation attributed to the respondent, and the sanction that could be imposed. f) of the LPACAP, the aforementioned opening decision is considered a proposal for a resolution in this case. SEVENTH: In accordance with the document "23ANDME HOLDING CO. com/static-files/2f13f408-1924-4246-b3a9-ccb72af3a2ee), the company's revenue in 2023 amounted to $299,489,000.

§

(approximately 263 million euros). es 7/24 FIRST: On October 17, 2023, the company 23ANDME, INC notified this Agency of a security breach in which a personal data security violation had occurred, information on which it expanded in a new notification dated 10/30/2023. SECOND: The breach occurred due to a cyberattack that affected 2,642 people residing in Spain, customers of the company, in which identity, contact and location data, images, health data, genetic data, and data revealing the individuals' ethnic origin were exposed. A sample of this data was published on an internet forum and a file with the data was put up for sale on the dark web. THIRD: The origin of the breach was access to certain customer accounts, known as "credential stuffing," in cases where customers had used the same login credentials for their 23ANDME account as they had for other websites at other organizations that had already been compromised.

§

FOURTH: At the time of the breach, 23ANDME customers accessed their accounts, which allowed access to their personal data and, in some cases, that of potential relatives, using a username and password. Multifactor authentication was offered, but it was optional. Additionally, 23ANDME had not implemented limits on data access, requests, or downloads per IP address. FIFTH: On October 1, 2023, 23ANDME detected a post on Reddit offering for sale information allegedly belonging to its customers, and on October 5, 2023, it confirmed that one of the published data points belonged to one of its customers. SIXTH: On October 6, 2023, 23ANDME published an alert on its website. S. authorities of the breach. EIGHTH: On October 10, 2023, 23ANDME sent an email to all its customers informing them of the incident. NINTH: On October 12, 2023, 23ANDME confirmed the identities of 799 customers affected by the breach in Spain.

§

TENTH: On October 13, 2023, 23ANDME notified the 799 affected individuals residing in Spain who were initially located. ELEVENTH: On October 24, 2023, 23ANDME notified the 1,843 affected individuals residing in Spain who were subsequently located. 1 of the Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to resolve this procedure. 2 of the GDPR, the processing of personal data is established, since 23ANDME carries out, among other processing activities, the collection, storage, and disclosure of personal data of natural persons, the company's clients, including identifying data, contact and location data, images, genetic data, data on health and data revealing their ethnic origin. 7 of the GDPR, it is the one that determines the purposes and means of the processing.

§

es 9/24 For its part, Article 3 of the GDPR regulates its territorial scope of application, establishing in its second paragraph the following: Article 3. Territorial scope (…) 2. This Regulation applies to the processing of personal data of data subjects who are residents in the Union by a controller or processor not established in the Union, where the processing activities are related to: a) the offering of goods or services, irrespective of whether a payment of the data subjects is required, to such data subjects in the Union, regardless of whether payment is required from them, or b) the monitoring of their behavior, to the extent that this takes place in the Union. In the present case, 23ANDME is a controller not established in the Union European that carries out processing activities related to offering services to data subjects in the Union, specifically the services consisting of conducting genetic tests and analyzing the data obtained.

§

Therefore, the obligations imposed by the GDPR on the controller apply to this processing. III Failed Obligation. 1(f) of the GDPR provides: "1. " In the present case, a confidentiality breach has occurred in the personal data of 23ANDME's customers. Information regarding this breach is contained in the information communicated by 23ANDME in the breach notification of October 17, 2023, and in its update of October 30, 2023, as well as the additional information provided by the company in response to the request made by the SGID as part of the preliminary investigation proceedings. According to the notifications and 23ANDME's response, the breach affected the company's customer data, 2,642 of whom are believed to be data subjects in Spain. The compromised data includes identifying, contact, and location data; images; genetic data; health data; and data revealing the affected individuals' ethnic origin.

§

es 10/24 A sample of said data was published on an internet forum and a file with the data was put up for sale on the dark web. 1(f) of the GDPR, 23ANDME, as the data controller, implemented appropriate technical and organizational measures to ensure an adequate level of security for the data against incidents like the one that occurred. In this analysis, it should be noted, first, that part of the data that were were special category data, in accordance with Article 9 of the GDPR. Specifically, genetic data, which was analyzed to obtain information about the health and ethnic origin of 23ANDME's clients by comparing it with that of other clients of the company, potential family members, as set forth in the privacy policy reproduced in the background facts. The fact that these are special category data is relevant to this proceeding, as the GDPR provides special protection for this type of data and establishes, as a general principle regarding the obligations of data controllers, a risk-based approach.

§

In accordance with this approach, the type of data being processed and the potential consequences for data subjects of a loss of confidentiality are of particular relevance. In this regard, Recital 51 of the GDPR states the following: "(51) Special protection should be afforded to personal data which, by its nature, is particularly sensitive in relation to fundamental rights and freedoms, as the context of its processing could entail significant risks for fundamental rights and freedoms. 1 of the GDPR specifically mentions risks when it refers to the controller's obligation to implement appropriate measures: "1. Taking into account the nature, scope, context and purposes of the processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organizational measures to ensure and be able to demonstrate that the processing is in compliance with this Regulation.

§

" For its part, Article 32, regarding the security of processing, refers to the "risks of varying probability and severity for rights and freedoms," establishing the following: 1. es 11/24 appropriate technical and organizational measures to ensure a level of security appropriate to the risk, which in its case includes, among others: a) the pseudonymization and encryption of personal data; b) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; d) a process for regularly verifying, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing. 2. In assessing the adequacy of the level of security, particular consideration shall be given to the risks presented by the processing of data, in particular as a result of the accidental or unlawful destruction, loss, or alteration of personal data transmitted, stored, or otherwise processed, or the unauthorized disclosure of or access to such data.

§

Likewise, Article 35 of the GDPR establishes the obligation to have a data protection impact assessment (hereinafter, DPIA) prior to processing when it is likely to result in a high risk to the rights and freedoms of individuals. " Ultimately, in accordance with the GDPR, the controller's adoption of measures must take into account, among other things, the type of data being processed and, consequently, the risk that a potential loss of confidentiality poses to the data subjects. In the present case, given that some of the data are particularly sensitive (genetic data, health data, and data that reveal ethnic origin), special diligence would be required in establishing measures for the processing. Within this framework, it is necessary to analyze whether the measures implemented by 23ANDME were adequate. According to 23ANDME's response to the request made by this supervisory authority, reproduced in the factual background, the origin of the breach was the access to certain customer accounts, known as "credential stuffing," in cases where customers had used the same login credentials for their website as for other websites at other organizations that had already been compromised.

§

It is therefore necessary to analyze what technical and organizational measures 23ANDME had adopted, in particular, with respect to its customers' access to their accounts. According to 23ANDME's response, customers accessed their accounts, which allowed access to their personal data and, in some cases, that of their potential relatives, using a username and password. es 12/24 The information submitted by 23ANDME does not indicate that there was any specific requirement regarding the password's format in terms of its strength, nor any requirement to change it periodically. In 23ANDME's privacy policy, published on its website and reproduced in the background information, there is only one reference to account login credentials, in the following terms: "Please recognize that protecting your personal information is also your responsibility. Be aware of keeping your password and other authentication information safe from third parties, and immediately notify 23andMe of any unauthorized use of your login credentials.

§

Your password is not visible to 23andMe staff, and we recommend that you do not share your password with 23andMe or with third parties. " From the above, it can be concluded that the measures adopted by 23ANDME regarding customer access to their accounts were not adequate to the level of risk for the rights and freedoms of the individuals whose data is processed. User credential theft is one of the most common cyberattacks. For example, the report from the European Union Agency for Cybersecurity (ENISA), which annually documents the main security threats, can be cited. In its 2022 report, "ENISA THREAT LANDSCAPE 2022" (the one prior to the breach at issue in this proceeding), it notes that the use of stolen credentials is the main attack vector in the case of data breaches, accounting for 40% of cases. In its section on security recommendations and standards, it specifically refers to the use of unique and robust passwords, the use of multi-factor authentication (MFA) to strengthen the authentication process, and user awareness.

§

For its part, 23ANDME also refers to data breaches in its investor report, which was published on its website prior to the breach and is partially reproduced in the background materials, when it refers to the increase in security threats and the risk of access to and disclosure of its clients' confidential information. In this context, 23ANDME was processing particularly sensitive data, for which the application of especially strengthened measures would have been required. Regarding user credentials, a known attack vector in data breaches that, in the case of 23ANDME accounts, provides access to viewing and downloading genetic, health, and data revealing the ethnic origin of its clients, the measures that could be considered adequate would necessarily involve an analysis of the access policy and related security measures. However, the information provided by 23ANDME and published on its website makes it clear that there were no specific requirements for the establishment of strong passwords, nor for their periodic change.

§

The security and privacy policy published on its website states that the company does not require users to create strong passwords, nor does it require them to be changed periodically. es 13/24 strong passwords, nor for their periodic change. The security and privacy policy published on its website also lacks instructions or recommendations beyond reminding users of their responsibility in using their credentials. According to the information provided by 23ANDME, it had implemented a multi-factor authentication system on its website, which shows that 23ANDME was aware that it could be an adequate security measure. However, it was configured as non-mandatory for users, so 23ANDME did not guarantee an enhanced level of security for its clients with it. On the other hand, the responsible use of credentials involves the user, as indicated by the previously reproduced 23ANDME privacy policy.

§

However, the risk analysis and adoption of appropriate security measures to protect its clients' personal data is a requirement for 23ANDME as the data controller, and this responsibility cannot be exclusively shifted to the user. On the other hand, once the user had accessed the account, there were no additional limits or controls implemented for accessing or downloading the particularly sensitive data, as the response from 23ANDME makes clear, in which it is indicated that this type of limitation was incorporated after the breach: (…) This fact made it difficult to detect accesses to the accounts and facilitated the download of the information that was the subject of the breach. For all of the foregoing, it is considered that the proven facts constitute an infringement attributable to 23ANDME for violating the article quoted above. 2 of the GDPR must be observed, which state: "1. Each supervisory authority shall ensure that the imposition of administrative fines under this Article for the infringements of this Regulation referred to in paragraphs 4, 9 and 6 is, in each individual case, effective, proportionate and dissuasive.

§

2. Administrative fines shall be imposed, based on the circumstances of each individual case, in addition to or in lieu of the measures provided for in Article 58, paragraphs 2(a) to (h) and (j). " For its part, Article 76 "Sanctions and corrective measures" of the LOPDGDD provides: "1. The sanctions provided for in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the criteria for determining the level of the fine established in paragraph 2 of the said article. 2. In accordance with Article 83(2)(k) of Regulation (EU) 2016/679, the following may also be taken into account: a) The ongoing nature of the infringement. b) The link between the infringer's activities and the processing of personal data. c) The benefits obtained as a result of the commission of the infringement. d) The possibility that the data subject's conduct may have induced the commission of the infringement.

§

e) The existence of a merger by absorption after the commission of the infringement, which cannot be attributed to the absorbing entity. f) The impact on the rights of minors. g) Having a data protection officer, when not mandatory. " In the present case, considering the severity of the possible infringement, and taking special account of the consequences its commission causes the affected individuals, the imposition of a fine would be appropriate. 1 of the GDPR. To ensure these principles, the volume of business of 23ANDME's business volume was $299,489,000 (approximately 263 million euros) in 2023. To decide on the imposition of an administrative fine and its amount, the sanction to be imposed must be graduated in accordance with the following circumstances, contemplated in the provisions cited above. es 16/24 that have suffered (Article 83(2)(a) of the GDPR). In the present case, what stands out is not only the high number of affected individuals, which amounts to 2,642 data subjects in Spain.

§

2(g) of the GDPR). In the present case, in addition to identifying, contact, and location data, the breach has affected particularly sensitive personal data, such as genetic data, health data, and data revealing the ethnic origin of the affected individuals, which poses a high risk to their rights and freedoms. 2(b) of the LOPDGDD). 23ANDME's activity consisted in large part of processing its clients' especially sensitive personal data as part of the service the company offered, which involved conducting genetic tests and analyzing their results. 00 euros. VI Failure to comply with the obligation. Notification of a personal data security breach to the competent supervisory authority Article 33 of the GDPR states the following: "1. In the event of a personal data breach, the controller shall notify the competent supervisory authority pursuant to Article 55 without undue delay and, where feasible, no later than 72 hours after becoming aware of it, unless the personal data breach is unlikely to result in a risk for the rights and freedoms of natural persons.

§

If the notification to the supervisory authority does not take place within 72 hours, it must be accompanied by an indication of the reasons for the delay. 2. The processor shall without undue delay notify the controller of the personal data breaches of which it becomes aware. 3. es 17/24 c) describe the likely consequences of the personal data security breach; d) describe the measures taken or proposed by the controller to address the personal data security breach, including, where appropriate, the measures taken to mitigate the potential negative effects. 4. If it is not possible to provide the information simultaneously, and to the extent that it is not, the information shall be provided in a gradual manner without undue delay. 5. The controller shall document any personal data security breach, including the facts relating to it, its effects, and the remedial action taken. " First, it should be noted that the obligation to notify a breach is not a mere formal requirement, but a measure of proactive accountability linked to the damages that personal data security breaches can cause for the affected individuals.

§

" Likewise, in recital 87 of the GDPR, the need for the supervisory authority to verify that such notification has been made is stated, in the following terms: (87) It should be verified whether all appropriate technological protection measures have been applied and the necessary organizational measures have been taken to determine immediately if a personal data security breach has occurred and to inform the supervisory authority and the data subject without undue delay. It must be verified that the notification has been made without undue delay, taking into account, in particular, the nature and gravity of the personal data security breach and its consequences and adverse effects for the data subject. Such notification may result in an intervention by the supervisory authority in accordance with the tasks and powers established by this Regulation. es 18/24 - 10/05/2023, confirms that one of the published data items belongs to one of its customers - 10/06/2023, publishes an alert on its website - 10/07/2023, notifies US authorities of the breach - 10/09/2023, logs clients out and forces password resets - 10/10/2023, sends an email to all its customers informing them of the incident - 12/10/2023, confirms the identity of the customers affected by the breach - 13/10/2023, notifies the 799 affected individuals residing in Spain who were initially located - 10/17/2023, GREENBERG TRAURIG, on behalf of 23ANDME, notifies the AEPD of the breach - 10/24/2023, 23ANDME notifies the 1,843 affected individuals located subsequently - 10/30/2023, GREENBERG TRAURIG expands the information on the breach According to this timeline, the notification, from the moment it is known that a breach affecting personal data has occurred, significantly exceeds the 72-hour deadline established in Article 33 of the GDPR.

§

Regarding the notification to this supervisory authority after the 72 hours required by Article 33 of the GDPR, in the expansion of the breach notification made on 10/30/2023, transcribed in the factual background, the following is stated (unofficial translation made with the "Digital Europe Language Tools" tool): (…) On the other hand, in its response to the SGID's request, 23ANDME states the following (unofficial translation made with the "Digital Europe Language Tools" tool): (…) Regarding this justification, it is first necessary to identify the moment at which 23ANDME would have had the obligation to notify the data breach. In this regard, it should be noted that the notification obligation established in Article 33 of the GDPR has been developed by the European Data Protection Committee (hereinafter, EDPB) through Guidelines 9/2022 on the notification of personal data security breaches under the GDPR.

§

es 19/24 These Guidelines refer in particular to the moment when the controller "becomes aware" of the breach and, therefore, has the obligation to notify a personal data breach. Thus, in their sections 31 and 32, they state the following: 31. As explained above, the GDPR provides that, in the event of a breach, the controller shall notify it without undue delay and, where feasible, no later than seventy-two hours after becoming aware of it. This may raise the question of when a controller can be considered to have "become aware" of a breach. The CEPD is of the opinion that the controller should be considered to be "aware" when it has a reasonable degree of certainty that a security incident affecting personal data has occurred. Following the Guidelines, in the present case, on 10/05/2023, 23ANDME became aware of the existence of a breach, as it confirmed that one of the published data items belonged to one of its customers.

§

It therefore had a reasonable degree of certainty that the incident compromised personal data from the processing for which it was responsible. S. authorities and on October 9, 2023, it closed all of its customers' sessions and required them to reset their passwords as a reactive security measure. Furthermore, on October 12, 2023, it was already aware that there were affected individuals in Spain. However, it did not proceed with the notification to this supervisory authority until October 17, 2023. The need for immediacy in notification is not trivial, but is related to the effectiveness of this measure in relation to the damages that a breach can cause for the affected individuals. In this regard, Article 33 of the GDPR expressly provides that at first, not all information about what happened may be available and that it can be provided gradually. In this regard, the 9/2022 Guidelines from the EDPB are again worth citing, when they state the following: 35.

§

Once the controller becomes aware of a reportable breach, it must be notified without undue delay and, where feasible, no later than seventy-two hours. During this period, the controller must assess the potential risk to individuals in order to determine if the notification requirement applies, as well as the necessary measures to address the breach. (…) 40. Consequently, it must be clear that the controller is obligated to act on any initial alert and to determine whether or not a breach has occurred. This short period allows for some investigation and for the data controller to gather evidence and other relevant details. es 20/24 If a data controller fails to act quickly and it becomes evident that a breach has occurred, this could be considered a failure to notify in accordance with Article 33 of the GDPR. On the other hand, 23 If a controller does not act quickly and it becomes evident that a breach has occurred, this could be considered a failure to notify in accordance with Article 33 of the GDPR.

§

" This statement would reveal a lack of due diligence regarding the obligations of data controllers to whom the GDPR applies. The notification obligation, as stated, is a measure linked to the security of personal data and must be carried out immediately. " This is especially true when it involves a high-risk processing, as it includes genetic, health, and ethnic origin data of the affected individuals, as the controller itself indicates in the DPIA that accompanies its response. A breach of such data would, in any case, trigger a notification obligation, as it entails a high risk to the rights and freedoms of the affected individuals. On the other hand, 23ANDME was aware of the need to comply with data protection regulations in the European Union and the obligations imposed by the GDPR on data controllers. This is made clear by the document "23ANDME HOLDING CO. ANNUAL REPORT FISCAL 2023," published on the 23ANDME website.

§

In this document, which predates the breach, reference is made to the company's activities in countries where the GDPR applies, and it contains various references to the GDPR, as set forth in the factual background, and even expressly mentions the possibility that the company could be fined in the event of a violation. In this regard, the CEPD's Guidelines 9/2022 are again worth citing, which state the following regarding controllers not established in the European Union: 72. When a controller not established in the EU is subject to the provisions of Article 3(2) or (3) of the GDPR and becomes aware of a breach, it will still be required to comply with the notification obligations set out in Articles 33 and 34 of the GDPR. Article 27 of the GDPR requires that the controller (and the processor) designate a representative in the EU when Article 3(2) of the GDPR applies. es 21/24 Therefore, the proven facts are considered to constitute an infringement attributable to 23ANDME for violating the aforementioned article.

§

4 of Regulation (EU) 2016/679, the following are considered serious violations and will be subject to a two-year statute of limitations: violations that substantially affect the articles referred to in that provision and, in particular, the following: r) Failure to notify the supervisory authority of a personal data security breach in accordance with Article 33 of Regulation (EU) 2016/679. 2 of the GDPR and Article 76 of the LOPDGDD, which were transcribed above in the third ground, must be observed. In the present case, considering the severity of the potential infringement, and taking special consideration of the consequences its commission causes the affected individuals, the imposition of a fine is appropriate. 1 of the GDPR. To ensure these principles, the business volume of 23ANDME, which was $299,489,000 in 2023, is taken into account. es 22/24 In order to decide on the imposition of an administrative fine and its amount, the sanction to be imposed must be graduated in accordance with the following circumstances, as contemplated in the provisions cited above.

§

2(a) of the GDPR): In the present case, the high number of affected individuals, which amounts to 2,642 people in Spain, is notable. 2(g) of the GDPR): In addition to identifying, contact, and location data, the breach has affected personal data of a particularly sensitive nature, such as genetic data, health data, and data revealing the ethnic origin of the affected individuals, which constitutes a high risk to their rights and freedoms. 2, letter b), of the LOPDGDD): 23ANDME's activity consisted in large part of processing its clients' especially sensitive personal data as part of the service the company offered, which included conducting genetic tests and analyzing their results. 00 euros. es 23/24 SECOND: NOTIFY this resolution to 23ANDME, INC. THIRD: This resolution will become effective once the period for filing the optional appeal has expired (one month from the day following the notification of this resolution) without the interested party having exercised this right.

§

b) of Law 39/2015, of October 1, on the Common Administrative Procedure of the Public Administrations (hereinafter LPACAP), within the voluntary payment period established in Article 68 of the General Collection Regulation, approved by Royal Decree 939/2005 Public Administrations (hereinafter LPACAP), within the voluntary payment period established in Article 68 of the General Collection Regulation, approved by Royal Decree 939/2005, of July 29, in relation to Article 62 of Law 58/2003, of December 17, December, by depositing it, indicating the NIF of the offender and the procedure number that appears at the heading of this document, into the restricted account no. A.. Otherwise, collection will proceed in the enforcement phase. Upon receipt of the notification and once it becomes effective, if the effective date falls between the 1st and 15th of each month, inclusive, the deadline for voluntary payment will be the 20th of the following month or the next business day, and if it falls between the 16th and the last day of each month, inclusive, the payment deadline will be until the 5th of the second following month or the next business day.

§

4 of the LOPDGDD, and since the amount of the imposed fine is greater than one million euros, information identifying the offender, the offense committed, and the amount of the fine will be published in the Official State Gazette. In accordance with Article 50 of the LOPDGDD, this Resolution will be made public. The publication will be carried out once it has been notified to the interested parties. Against this resolution, which exhausts administrative remedies in accordance with Art. 1 of the aforementioned Law. 3(a) of the LPACAP, the final administrative resolution may be provisionally suspended if the interested party expresses their intention to file a contentious-administrative appeal. 4 of the aforementioned Law 39/2015, of October 1. You must also submit to the Agency the documentation proving the effective filing of the administrative lawsuit. If the Agency is not notified of the filing of the administrative lawsuit within two months from the day after this resolution is notified, the precautionary suspension will be terminated. es