AEPD (Spain) - PS-00140-2025

From GDPRhub
AEPD - PS-00140-2025
Authority: AEPD (Spain)
Jurisdiction: Spain
Relevant Law: Article 5(1)(f) GDPR
Article 9 GDPR
Article 24(1) GDPR
Article 32 GDPR
Article 33 GDPR
Type: Investigation
Outcome: n/a
Started: 29.05.2025
Decided: 10.10.2025
Published: 16.07.2026
Fine: n/a
Parties: 23ANDME, INC
National Case Number/Name: PS-00140-2025
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Spanish
Original Source: AEPD (in ES)
Initial Contributor: bms

The DPA fined a genomics and biotechnology company €2.4 million for failing to adequately protect sensitive genetic and health data and for notifying the DPA about a personal data breach after the 72-hour deadline.

English Summary

Facts

23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain.

In October 2023, the controller suffered a personal data breach following a credential-stuffing attack. Attackers accessed customer accounts by using login credentials that customers had reused on other services previously compromised. The breach affected 2,642 customers residing in Spain and exposed identity, contact and location data, images, genetic data, health data and data revealing ethnic origin. A sample of the data was published on an online forum, while a file containing the compromised data was offered for sale on the dark web.

At the time of the breach, customers accessed their accounts using a username and password. Multi-factor authentication was available but optional. The controller had not established specific password-strength requirements or periodic password changes and had not implemented limits on access requests or downloads based on IP addresses. Once an account had been accessed, there were no additional controls limiting the viewing or downloading of sensitive data, including information relating to potential relatives.

On 1 October 2023, the controller detected a Reddit post offering information allegedly belonging to its customers. On 5 October, it confirmed that one of the published records belonged to a customer. It published an alert on its website on 6 October, reported the incident to US authorities on 7 October and required customers to reset their passwords on 9 October.

The controller informed all customers about the incident on 10 October. It identified 799 affected customers residing in Spain on 12 October and notified them on 13 October. It subsequently identified and notified another 1,843 customers residing in Spain on 24 October. However, the controller did not notify the DPA until 17 October 2023 and submitted additional information on 30 October.


Holding

The DPA held that the GDPR applied pursuant to Article 3(2) GDPR because the controller, although not established in the EU, offered genetic testing and analysis services to data subjects in the Union.

First, the DPA found a violation of Article 5(1)(f) GDPR. The controller had failed to process personal data in a manner ensuring appropriate integrity and confidentiality. The adequacy of its security measures had to be assessed in light of Articles 24(1) and 32 GDPR and the risk-based approach established by the GDPR.

The DPA emphasised that the affected information included genetic data, health data and data revealing ethnic origin, which constitute special categories of personal data under Article 9 GDPR. Given the sensitivity of this information and the potential consequences of unauthorised disclosure, the controller was required to implement particularly robust security measures.

Nevertheless, the controller did not impose specific password-strength requirements or require passwords to be changed periodically. Although it had implemented multi-factor authentication, its use remained optional. Moreover, it had not introduced additional controls or limits concerning account access, access requests or the downloading of sensitive information. These deficiencies made unauthorised access more difficult to detect and facilitated the extraction of the compromised data.

The DPA rejected the suggestion that responsibility could be shifted to customers because they had reused their credentials.

Although customers were responsible for using their credentials appropriately, the controller remained responsible for assessing the risks and implementing security measures appropriate to the nature of the processing. Credential theft was a well-known attack vector, particularly relevant where account access allowed users to view or download genetic and health information.

Second, the DPA found a violation of Article 33 GDPR. It considered that the controller became aware of the personal data breach on 5 October 2023, when it confirmed that one of the records published online belonged to one of its customers. At that point, it had a reasonable degree of certainty that a security incident involving personal data had occurred.

The controller’s subsequent actions, including publishing an alert, notifying US authorities and requiring password resets, further demonstrated that it was already aware of the breach. However, it did not notify the DPA until 17 October, substantially exceeding the 72-hour deadline.

The DPA stressed that notification cannot be postponed until all affected individuals and all details of the incident have been identified. Article 33(4) GDPR expressly permits information to be provided in phases when it cannot be submitted simultaneously. The controller’s need to assess its notification obligations across several jurisdictions therefore did not justify the delay, particularly because the breach involved sensitive data posing a high risk to the affected individuals.

The DPA imposed a total administrative fine of €2,400,000: - €2,000,000 for the violation of Article 5(1)(f) GDPR; - €400,000 for the violation of Article 33 GDPR.


Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Catalan; Valencian original. Please refer to the Catalan; Valencian original for more details.

1/24




  Case No.: EXP202316010



 SANCTIONING PROCEDURE RESOLUTION

From the proceedings initiated by the Spanish Data Protection Agency and based on the following

FACTS


FIRST: On October 17, 2023, the company 23ANDME, INC (hereinafter, 23ANDME), with its registered address at 349 OYSTER POINT BLVD - 94080 SOUTH
SAN FRANCISCO - CALIFORNIA notified this Agency of a security breach in which a violation of the security of personal data had occurred.

According to the breach notification, made by the company Greenberg Traurig, LLP (hereinafter GREENBERG) as a representative of 23ANDME, on October 1, 2023, a confidentiality breach occurred due to a

cyberattack that affected 799 people residing in Spain, customers of the company, in which identity, contact and location data, images, and genetic data were exposed.

In the breach notification, 23ANDME includes the following description of the incident (unofficial translation made with the "Digital Europe Language Tools" tool):

"(…)"

On October 30, 2023, 23ANDME expands the information regarding the breach. According to this new communication, the breach would have affected another 1,843 people in Spain and would have included, in addition to the previously mentioned data, data revealing ethnic origin.

The description included in this second communication states the following

(unofficial translation made with the "Digital Europe Language Tools" tool):

 "(…)"

SECOND: As a result of the known facts, on October 31, 2023, the Director of the Spanish Data Protection Agency urged the Subdirection

General of Data Inspection (SGID) to initiate the preliminary investigation proceedings referred to in Article 67 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter, LOPDGDD).


THIRD: The Sub-Directorate General of Data Inspection proceeded to conduct preliminary investigation proceedings to clarify the facts in question, in virtue of the functions assigned to supervisory authorities in Article 57.1 and the powers granted in Article 58.1 of Regulation (EU)


C/ Jorge Juan, 6 www.aepd.es
C/ Jorge Juan, 6 www.aepd.es 28001 – Madrid sedeapd.gob.es 2/24




2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of Title VIII of the LOPDGDD.


Since 23ANDME is a U.S. entity with no main establishment in Spain and the data breach affected residents in different States, on March 25, 2024, in accordance with Article 61 of the GDPR, a request was made, through the "Internal Market Information System" (regulated by the
Regulation (EU) No 1024/2012 of the European Parliament and of the Council of October 25, 2012), information on the existence, if any, of the company's establishment in other States, confirming that the breach had been notified to other States and that no main establishment would be recorded in the European Union.

On March 27, 2024, a request for information was sent to 23ANDME, which was received on April 22, 2024, requesting additional information about the incident,

risk assessment of the processing operations carried out, security measures adopted before and after the incident, and the reasons for the delay in notifying the breach to this supervisory authority.

In response to the request, 23ANDME provides additional information about the incident, stating the following (unofficial translation made with the "Digital Europe Language Tools" tool):

"(…)"

Regarding the publication of the data on the Internet, it states the following (unofficial translation made with the "Digital Europe Language Tools" tool):

"(…)"

Regarding the security measures adopted before and after the breach, 23ANDME provides a copy of data protection impact assessments and states the following (unofficial translation made with the "Digital Europe Language Tools" tool):

"(…)"


Regarding the notification to this supervisory authority more than 72 hours after the requirement in Article 33 of the GDPR, 23ANDME states the following (unofficial translation using the "Digital Europe Language Tools" tool):

"(…)"


Along with its response, 23ANDME provides the texts of the communications it claims to have sent to its customers, which vary depending on the data exposed.
It also provides a copy of the impact assessments it has conducted.


As part of the preliminary investigation, the publication of a blog post on the company's website regarding the incident was confirmed at the URL ***URL.1. The post was created on 10/06/2023 and last updated on 12/05/2023, as can be seen

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 3/24




diligenced in the file. In it, several updates are observed in which information is provided on the progress of the investigation and the measures that have been taken regarding user access.

Likewise, on 03/26/2024, screenshots were entered into the file showing the website's privacy policy.
https://www.23andme.com. This information is listed as updated on 12/14/2022 and indicates that it applies to all web pages owned and operated by 23ANDME.

This policy includes references to the personal data of customers that are processed by 23ANDME, the source of the data processed, its use, and the circumstances under which it is disclosed to third parties. In the "security measures" section, the following is stated (unofficial translation made with the "Digital Europe Language Tools" tool):


       "Security Measures

 We implement physical, technical, and administrative measures designed to
 prevent unauthorized access to or disclosure of your personal information.
 Our team regularly reviews and improves our security practices
 to help ensure the integrity of our systems and your personal information.

 For more information about our practices, visit
 our customer service guide.

       Please recognize that protecting your personal information is also your responsibility. Be mindful to keep your password and other authentication information safe from third parties, and immediately notify 23andMe of any unauthorized use of your login credentials. Your password is not visible to 23andMe staff, and we recommend that you do not share your password with 23andMe or with third parties. 23andMe cannot protect Personal Information that you disclose on your own or that you request us to disclose."


Also on record in the case file is the affidavit of January 8, 2025, with printouts of screenshots
of the screen of the webpage https://eu.customercare.23andme.com/hc/en-us/articles/204712980-What-Countries-Do-You-Ship-To, which indicates the countries to which 23ANDME ships, among which is Spain.

Finally, the record includes the document "23ANDME HOLDING CO. ANNUAL

REPORT FISCAL 2023," published on the 23ANDME website and signed on
05/25/2023 by the President and CEO of 23ANDME as well as by other
company officials. This document provides information on various aspects of the company's activities.


On page 13 of this document, under the heading "Privacy and Security Regulation"
(Privacy and Security Regulation), among other information, states the following
(unofficial translation made with the "Digital Europe Language Tools" tool):



C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 4/24








       "We are committed to an ongoing effort of compliance and privacy oversight, also in relation to the requirements of numerous local, state, federal, and international laws, rules, and regulations related to the privacy and security of personally identifiable information, whether directly or indirectly (collectively, 'Protection Laws of

       data"). These data protection laws regulate the collection, storage, sharing, use, disclosure, processing, transfer, and protection of personal information, including genetic information, and frequently evolve in their scope and application.

 (…)


       Outside the United States, numerous countries have their own data protection laws, including, but not limited to, the Personal Information Protection and Electronic Documents Act ("PIPEDA") and the EU General Data Protection Regulation ("GDPR"), now also enacted in the United Kingdom ("UK GDPR").

 (…)

       Internationally, we are subject to, among other data protection laws, the GDPR, the UK GDPR, and PIPEDA, which regulate the collection, storage, sharing, use, disclosure, and protection of personal information, and impose strict requirements with significant penalties and litigation risks for non-compliance. Like the United States, international data protection laws include national, state or provincial, and local laws, which means that compliance costs increase with each state, province, or locality to which we ship. Non-compliance with the GDPR (and the UK's GDPR) can result in fines of up to €20 million / £17.5 million or up to 4% of the offender's global annual revenue, whichever is greater. 

       (...)


 In addition, in the United States and internationally, companies are required to notify affected customers whose personal information has been disclosed as a result of a data breach. Many countries and/or states require companies to maintain safeguards and take certain measures in response to a data breach and may be required to notify applicable regulatory authorities as well."


On page 50 of said document, the following is stated regarding data breaches (unofficial translation made with the "Digital Europe Language Tools" tool):


       "The increase in global cybersecurity threats and more sophisticated and targeted
cybercrime poses a risk to the security of our systems and networks and the confidentiality, availability, and integrity
of our data. There have been several recent, highly publicized cases in which organizations of various types and sizes have reported the non-

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 5/24




unauthorized disclosure of confidential client information or other confidential
 information, as well as cyberattacks that involved the dissemination, theft, and
 destruction of corporate information, intellectual property, cash, or other

valuable assets.

       There have also been several highly publicized cases in which hackers have demanded "ransom" payments in exchange for not disclosing confidential client information or other confidential information, or for not disabling the target company's computer or other systems. A breach

       security or privacy breach that results in the unauthorized disclosure or loss of unauthorized use or modification or that prevents access to or otherwise affects the confidentiality, security, or integrity of sensitive, confidential, or proprietary information that we or our third-party service provider maintain or process, could require us to comply with

       with breach notification laws and subject us to significant remediation costs, fines, penalties, notification to individuals, the media, and government authorities, implementing measures to repair or replace systems or technologies, and to prevent future incidents, potential increases in insurance premiums, and security audits or forensic investigations."


Regarding 23ANDME's activity in Europe, on page 52 of the document, the following is stated (unofficial translation made with the "Digital Europe Language Tools" tool):


 "We plan to continue expanding our foreign operations where we have limited operational experience and may be subject to greater regulatory risks and local competition.

       If we are not successful in our efforts to expand internationally, our business may be harmed. Regulations exist or are under consideration in countries outside the United States that limit or prevent the sale of direct-to-consumer genetic tests. Some countries, including Australia, require pre-market review by their regulatory body similar to that required in the United States by the FDA. Some countries, including Australia, Germany, France, and Switzerland, require

       a prescription for genetic tests that provide health information, thus limiting our offering in those countries to a ancestry-only test. Other countries require mandatory genetic counseling before genetic testing. These regulations limit the available market for our products and services and increase the costs associated with marketing our products and services where we can offer them. Legal developments in the EU have created a series of new compliance obligations regarding the transfer of personal data from the European Union to the United States, including GDPR and the UK GDPR, which apply to some of our activities

       related to the services we offer or may offer to individuals located in the EU. Significant effort and expense will continue to be required to ensure compliance with the GDPR and the UK GDPR, and could require us to change our business practices. In addition, the

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 6/24




requirements under the GDPR and the UK GDPR may change periodically or may be modified by EU / UK and/or national legislation. The GDPR and the UK GDPR impose strict

       compliance obligations with respect to the handling of personal data and have resulted in the issuance of significant financial penalties for non-compliance, including potential fines of up to 4% of global annual turnover for the previous financial year or €20 million / £17.5 million (whichever is greater) for the most serious violations."


FOURTH: On April 23, 2025, and May 7, 2025, two communications were received from the entity OFFICE OF THE UNITED STATES TRUSTEE, regarding the bankruptcy proceedings of 23ANDME in the United States.

FIFTH: On May 29, 2025, the Presidency of the Spanish Data Protection Agency decided to initiate an enforcement proceeding against the respondent, for the alleged violation of Articles 5(1)(f) and 33 of the GDPR, as typified in Article 83(5)(a) and Article 84(4)(a) of the GDPR, respectively.

SIXTH: On June 24, 2025, the aforementioned opening decision was notified, in accordance with the certificate issued by Correos, pursuant to the provisions established in the Law

39/2015, of October 1, on the Common Administrative Procedure of the Public Administrations (hereinafter, LPACAP). After the deadline for submitting arguments expired, it was determined that no arguments were received from the respondent.


Article 64.2.f) of the LPACAP—a provision that was communicated to the respondent party in the decision to initiate the procedure—stipulates that if no objections are filed within the prescribed period regarding the content of the opening decision, when it contains a precise determination of the liability attributed, it may be considered a draft resolution. In the present case, the opening decision of the administrative proceeding determined the facts constituting the charge, the GDPR violation attributed to the respondent, and the sanction that could be imposed. Therefore, taking into consideration that the respondent has not filed objections to the opening decision and in accordance with Article 64.2.f) of the LPACAP, the aforementioned opening decision is considered a proposal for a resolution in this case.


SEVENTH: In accordance with the document "23ANDME HOLDING CO. ANNUAL REPORT FISCAL 2023" (page 80), published on the 23ANDME website
(https://investors.23andme.com/static-files/2f13f408-1924-4246-b3a9-ccb72af3a2ee), the company's revenue in 2023 amounted to $299,489,000.

(approximately 263 million euros).

In light of all the proceedings, the following are considered proven facts by the Spanish Data Protection Agency in this proceeding,



 PROVEN FACTS



6 Jorge Juan Street www.aepd.es
28001 – Madrid sedeaepd.gob.es 7/24




FIRST: On October 17, 2023, the company 23ANDME, INC notified this Agency of a security breach in which a personal data security violation had occurred, information on which it expanded in a new notification dated

10/30/2023.

SECOND: The breach occurred due to a cyberattack that affected 2,642 people residing in Spain, customers of the company, in which identity, contact and location data, images, health data, genetic data, and data revealing the individuals' ethnic origin were exposed. A sample of this data was published on an internet forum and a file with the data was put up for sale on the dark web.

THIRD: The origin of the breach was access to certain customer accounts, known as "credential stuffing," in cases where customers had used the same login credentials for their 23ANDME account as they had for other websites at other organizations that had already been compromised.

FOURTH: At the time of the breach, 23ANDME customers accessed their accounts, which allowed access to their personal data and, in some cases, that of potential relatives, using a username and password. Multifactor authentication was offered, but it was optional. Additionally, 23ANDME had not implemented limits on data access, requests, or downloads per IP address.

FIFTH: On October 1, 2023, 23ANDME detected a post on Reddit offering for sale information allegedly belonging to its customers, and on October 5, 2023, it confirmed that one of the published data points belonged to one of its customers. 

SIXTH: On October 6, 2023, 23ANDME published an alert on its website.

SEVENTH: On October 7, 2023, 23ANDME notified the U.S. authorities of the breach.

EIGHTH: On October 10, 2023, 23ANDME sent an email to all its customers informing them of the incident.

NINTH: On October 12, 2023, 23ANDME confirmed the identities of 799 customers affected by the breach in Spain.


TENTH: On October 13, 2023, 23ANDME notified the 799 affected individuals residing in Spain who were initially located.

ELEVENTH: On October 24, 2023, 23ANDME notified the 1,843 affected individuals residing in Spain who were subsequently located.


                          LEGAL GROUNDS


 I


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 8/24








                                     Jurisdiction

In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and as established in Articles 47, 48.1, 64.2, and 68.1 of the
Organic Law 3/2018, of December 5, on the Protection of Personal Data and
Guarantee of Digital Rights (hereinafter, LOPDGDD), the Presidency of the Spanish Data Protection

Agency is competent to resolve this procedure.

Furthermore, Article 63.2 of the LOPDGDD provides that: "Procedures handled by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, this organic law, the regulations issued in its development, and, to the extent they do not conflict with them, as a subsidiary basis, by the general rules on administrative procedures."

 II
 Preliminary Issues


Article 4.1) of the GDPR defines "personal data" as: "any information relating to an identified or identifiable natural person ('the data subject'); an identifiable natural person is one whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or

various elements of the physical, physiological, genetic, psychological, economic, cultural, or social identity of said person."

Article 4.2) of the GDPR defines "processing" as: "any operation or set of operations performed on personal data or sets of personal data, whether or not automated, such as collection, recording,

organization, structuring, storage, adaptation or alteration, extraction, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or interconnection, restriction, erasure or destruction."

Article 4(7) of the GDPR defines the "controller" or "responsable"

as: "the natural or legal person, public authority, service or other body which, alone or jointly with others, determines the purposes and means of the processing; if the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be laid down by Union or Member State law."


In the present case, in accordance with the provisions of Articles 4.1 and 4.2 of the GDPR, the processing of personal data is established, since 23ANDME carries out, among other processing activities, the collection, storage, and disclosure of personal data of natural persons, the company's clients, including identifying data, contact and location data, images, genetic data, data on

health and data revealing their ethnic origin.

23ANDME carries out this activity in its capacity as the controller, since, pursuant to Article 4.7 of the GDPR, it is the one that determines the purposes and means of the processing.

6 Jorge Juan Street www.aepd.es
28001 – Madrid sedeaepd.gob.es 9/24




For its part, Article 3 of the GDPR regulates its territorial scope of application,
establishing in its second paragraph the following:




Article 3. Territorial scope

 (…)


       2. This Regulation applies to the processing of personal data of data subjects who are residents in the Union by a controller or processor not established in the Union, where the processing activities are related to:
 a) the offering of goods or services, irrespective of whether a payment of the data subjects is required, to such data subjects in the Union,

       regardless of whether payment is required from them, or
 b) the monitoring of their behavior, to the extent that this takes place in the
 Union.

In the present case, 23ANDME is a controller not established in the Union

European that carries out processing activities related to offering services to data subjects in the Union, specifically the services consisting of conducting genetic tests and analyzing the data obtained. Therefore, the obligations imposed by the GDPR on the controller apply to this processing.


 III
 Failed Obligation. Integrity and Confidentiality

Article 5.1(f) of the GDPR provides:


 "1. Personal data shall be:
 (…)
 f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures ('integrity and confidentiality')."

In the present case, a confidentiality breach has occurred in the personal data of the

       of appropriate technical or organizational measures ('integrity and confidentiality')."

In the present case, a confidentiality breach has occurred in the personal data of 23ANDME's customers. Information regarding this breach is contained in the information communicated by 23ANDME in the breach notification of October 17, 2023, and in its update of October 30, 2023, as well as the additional information provided by the company in response to the request made by the SGID as part of the preliminary investigation proceedings.

According to the notifications and 23ANDME's response, the breach affected the company's customer data, 2,642 of whom are believed to be data subjects in Spain. The compromised data includes identifying, contact, and location data; images; genetic data; health data; and data revealing the affected individuals' ethnic origin. A


6 Jorge Juan Street, www.aepd.es
28001 – Madrid sedeaepd.gob.es 10/24




A sample of said data was published on an internet forum and a file with the data was put up for sale on the dark web.


It is therefore necessary to determine whether, in accordance with the obligation established by Article 5.1(f) of the GDPR, 23ANDME, as the data controller, implemented appropriate technical and organizational measures to ensure an adequate level of security for the data against incidents like the one that occurred.

In this analysis, it should be noted, first, that part of the data that were

were special category data, in accordance with Article 9 of the GDPR. Specifically, genetic data, which was analyzed to obtain information about the health and ethnic origin of 23ANDME's clients by comparing it with that of other clients of the company, potential family members, as set forth in the privacy policy reproduced in the background facts.


The fact that these are special category data is relevant to this proceeding, as the GDPR provides special protection for this type of data and establishes, as a general principle regarding the obligations of data controllers, a risk-based approach. In accordance with this approach, the type of data being processed and the potential consequences for data subjects of a loss of confidentiality are of particular relevance.

In this regard, Recital 51 of the GDPR states the following:

"(51) Special protection should be afforded to personal data which, by its nature, is particularly sensitive in relation to fundamental rights and freedoms, as the context of its processing could entail significant risks for fundamental rights and freedoms. Such personal data should include personal data revealing racial or ethnic origin."


Article 24.1 of the GDPR specifically mentions risks when it refers to the controller's obligation to implement appropriate measures:

       "1. Taking into account the nature, scope, context and purposes of the processing as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller shall implement appropriate technical and organizational measures to ensure and be able to demonstrate that the processing is in compliance with this Regulation. These measures shall be reviewed and updated as necessary."


For its part, Article 32, regarding the security of processing, refers to the "risks of varying probability and severity for rights and freedoms," establishing the following:

       1. Taking into account the state of the art, the costs of implementation, and the

 nature, scope, context, and purposes of processing, as well as the risks
 of varying probability and severity for the rights and freedoms of
 natural persons, the controller and the processor shall implement


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 11/24




appropriate technical and organizational measures to ensure a level of
 security appropriate to the risk, which in its case includes, among others:
 a) the pseudonymization and encryption of personal data;

       b) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
 c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
 d) a process for regularly verifying, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the

 processing. 

       2. In assessing the adequacy of the level of security, particular consideration shall be given to the risks presented by the processing of data, in particular as a result of the accidental or unlawful destruction, loss, or alteration of personal data transmitted, stored, or otherwise processed, or the unauthorized disclosure of or access to such data.

Likewise, Article 35 of the GDPR establishes the obligation to have a data protection impact assessment (hereinafter, DPIA) prior to processing when it is likely to result in a high risk to the rights and freedoms of individuals. In implementation of paragraph 4 of this article, the AEPD published a list of types of processing that require a DPIA in 2019, which specifically included "processing involving the use of genetic data for any purpose."


Ultimately, in accordance with the GDPR, the controller's adoption of measures must take into account, among other things, the type of data being processed and, consequently, the risk that a potential loss of confidentiality poses to the data subjects. In the present case, given that some of the data are particularly sensitive (genetic data, health data, and data that

reveal ethnic origin), special diligence would be required in establishing measures for the processing. Within this framework, it is necessary to analyze whether the measures implemented by 23ANDME were adequate.

According to 23ANDME's response to the request made by this supervisory authority, reproduced in the factual background, the origin of the breach

was the access to certain customer accounts, known as "credential stuffing," in cases where customers had used the same login credentials for their website as for other websites at other organizations that had already been compromised. It is therefore necessary to analyze what technical and organizational measures 23ANDME had adopted, in particular, with respect to its customers' access to their accounts.

According to 23ANDME's response, customers accessed their accounts, which allowed access to their personal data and, in some cases, that of their potential relatives, using a username and password. At the time the breach occurred, 23ANDME offered the option to use multi-factor authentication, but on a voluntary basis:

       "(…)"

6 Jorge Juan Street, www.aepd.es
28001 – Madrid sedeaepd.gob.es 12/24









The information submitted by 23ANDME does not indicate that there was any specific requirement regarding the password's format in terms of its strength, nor any requirement to change it periodically.

In 23ANDME's privacy policy, published on its website and reproduced in the background information, there is only one reference to account login credentials, in the following terms:


       "Please recognize that protecting your personal information is also your
 responsibility. Be aware of keeping your password and other authentication
 information safe from third parties, and immediately notify 23andMe of
 any unauthorized use of your login credentials. Your password is not visible to 23andMe staff, and we recommend that you

       do not share your password with 23andMe or with third parties. 23andMe cannot protect the Personal Information that you disclose on your own or that you request us to disclose."

From the above, it can be concluded that the measures adopted by 23ANDME regarding customer access to their accounts were not adequate to the level of risk for

the rights and freedoms of the individuals whose data is processed.

User credential theft is one of the most common cyberattacks. For example, the report from the European Union Agency for Cybersecurity (ENISA), which annually documents the main security threats, can be cited. In its 2022 report, "ENISA THREAT LANDSCAPE 2022" (the one prior to the breach at issue in this proceeding), it notes that the use of stolen credentials is the main attack vector in the case of data breaches, accounting for 40% of cases. In its section on security recommendations and standards, it specifically refers to the use of unique and robust passwords, the use of multi-factor authentication (MFA) to strengthen the authentication process, and user awareness.

For its part, 23ANDME also refers to data breaches in its investor report, which was published on its website prior to the breach and is partially reproduced in the background materials, when it refers to the increase in security threats and the risk of access to and disclosure of its clients' confidential information.

In this context, 23ANDME was processing particularly sensitive data, for which the application of especially strengthened measures would have been required.

Regarding user credentials, a known attack vector in data breaches that, in the case of 23ANDME accounts, provides access to viewing and downloading genetic, health, and data revealing the ethnic origin of its clients, the measures that could be considered adequate would necessarily involve an analysis of the access policy and related security measures.

However, the information provided by 23ANDME and published on its website makes it clear that there were no specific requirements for the establishment of strong passwords, nor for their periodic change. The security and privacy policy published on its website states that the company does not require users to create strong passwords, nor does it require them to be changed periodically. C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 13/24




strong passwords, nor for their periodic change. The security and privacy policy published on its website also lacks instructions or recommendations beyond reminding users of their responsibility in using their credentials.

According to the information provided by 23ANDME, it had implemented a multi-factor authentication system on its website, which shows that 23ANDME was aware that it could be an adequate security measure. However, it was configured as non-mandatory for users, so 23ANDME did not guarantee an enhanced level of security for its clients with it.

On the other hand, the responsible use of credentials involves the user, as indicated by the previously reproduced 23ANDME privacy policy. However, the risk analysis and adoption of appropriate security measures to protect its clients' personal data is a requirement for 23ANDME as the data controller, and this responsibility cannot be exclusively shifted to the user.

On the other hand, once the user had accessed the account, there were no additional limits or controls implemented for accessing or downloading the particularly sensitive data, as the response from 23ANDME makes clear, in which it is indicated that this type of limitation was incorporated after the breach:

 (…)


This fact made it difficult to detect accesses to the accounts and facilitated the download of the information that was the subject of the breach.

For all of the foregoing, it is considered that the proven facts constitute an infringement attributable to 23ANDME for violating the article quoted above.

IV
   Typification of the infringement of Article 5.1.f) of the GDPR and classification for the purposes of

 prescription

Article 83.5 of the GDPR typifies as an administrative offense the violation of the
following article, which shall be penalized, in accordance with paragraph 2, with
administrative fines of up to 20,000,000 EUR or, in the case of an undertaking, of

an amount equivalent to a maximum of 4% of the total annual worldwide business turnover of the previous financial year, whichever is higher:

 "a) the basic principles for processing, including the conditions for consent in accordance with Articles 5, 6, 7 and 9;"


For its part, the LOPDGDD in its Article 71, Offenses, states that:

"Offenses are constituted by the acts and conduct referred to in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this organic law."

6 Jorge Juan Street, www.aepd.es
28001 – Madrid sedeaepd.gob.es 14/24




For the sole purpose of the statute of limitations, Article 72.1 of the LOPDGDD provides the following:


       "In accordance with Article 83.5 of Regulation (EU) 2016/679, the following are considered very serious violations and will become time-barred after three years: violations that constitute a substantial breach of the articles mentioned in that provision, and in particular, the following:
a) Processing personal data in violation of the principles and guarantees

       established in Article 5 of Regulation (EU) 2016/679."



 V

 Penalty for violation of Article 5.1(f) of the GDPR

In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR must be observed, which state:


       "1. Each supervisory authority shall ensure that the imposition of administrative fines under this Article for the infringements of this Regulation referred to in paragraphs 4, 9 and 6 is, in each individual case, effective, proportionate and dissuasive. 

       2. Administrative fines shall be imposed, based on the circumstances of each individual case, in addition to or in lieu of the measures provided for in Article 58, paragraphs 2(a) to (h) and (j). In deciding whether to impose an administrative fine and its amount in each individual case, due regard shall be had to:
       a) the nature, gravity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing in question as well as the number of data subjects affected and the level of damage and harm they have suffered;
 b) the intentionality or negligence in the infringement;
 c) any measures taken by the controller or processor

       to remedy the damage suffered by the data subjects;
 d) the degree of responsibility of the controller or processor, taking into account the technical or organizational measures they have applied pursuant to Articles 25 and 32;
 e) any previous infringements committed by the controller or processor;

       f) the degree of cooperation with the supervisory authority in order to remedy the breach and mitigate the possible adverse effects of the breach;
 g) the categories of personal data affected by the breach;
 h) the manner in which the supervisory authority became aware of the breach, in particular whether the controller or processor notified the breach and, if so, to what extent;
       i) when the measures indicated in Article 58(2) have previously been ordered against the controller or processor concerned in relation to the same matter, compliance with those measures;

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 15/24








       j) adherence to codes of conduct under Article 40 or to certification mechanisms approved in accordance with Article 42, and
 k) any other aggravating or mitigating factor applicable to the circumstances of the

 case, such as the financial benefits obtained or losses avoided, directly
 or indirectly, through the infringement."

For its part, Article 76 "Sanctions and corrective measures" of the LOPDGDD provides:


 "1. The sanctions provided for in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679 shall be applied taking into account the criteria for determining the level of the fine established in paragraph 2 of the said article.

         2. In accordance with Article 83(2)(k) of Regulation (EU) 2016/679, the following may also be taken into account:
 a) The ongoing nature of the infringement.
 b) The link between the infringer's activities and the processing of personal data.
 c) The benefits obtained as a result of the commission of the infringement.
 d) The possibility that the data subject's conduct may have induced the commission of the infringement.
 e) The existence of a merger by absorption after the commission of the infringement, which cannot be attributed to the absorbing entity.
 f) The impact on the rights of minors.
 g) Having a data protection officer, when not mandatory.
 h) The voluntary submission by the controller or processor to alternative dispute resolution mechanisms, in those cases where disputes exist between them and any interested party."


In the present case, considering the severity of the possible infringement, and taking special account of the consequences its commission causes the affected individuals, the imposition of a fine would be appropriate.

The fine imposed must, in each case, be individual, effective, proportionate, and dissuasive, in accordance with what is established in Article 83.1 of the GDPR. To ensure these principles, the volume of business of
23ANDME's business volume was $299,489,000 (approximately 263 million euros) in 2023.

To decide on the imposition of an administrative fine and its amount,

the sanction to be imposed must be graduated in accordance with the following circumstances,
contemplated in the provisions cited above.

First, it is determined that the infringement would be serious, to the extent that the following circumstances are present:


 • The nature, severity, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage and prejudice

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 16/24




that have suffered (Article 83(2)(a) of the GDPR). In the present case,
 what stands out is not only the high number of affected individuals, which amounts to 2,642 data subjects in Spain.

     • The categories of personal data affected by the

 breach (Article 83.2(g) of the GDPR). In the present case, in addition to identifying, contact, and location data, the breach has affected particularly sensitive personal data, such as genetic data, health data, and data revealing the ethnic origin of the affected individuals, which poses a high risk to their rights and freedoms.


Additionally, the link between the offender's activity and the processing of personal data is considered an aggravating factor (Article 76.2(b) of the LOPDGDD). 23ANDME's activity consisted in large part of processing its clients' especially sensitive personal data as part of the service the company offered, which involved conducting genetic tests and analyzing their results.


The balance of the circumstances set forth in Article 83.2 of the GDPR and Article 76.2 of the LOPDGDD, with respect to the infringement committed by violating the provisions of Article 5.1.f) of the GDPR, allows for the imposition of an administrative fine of 2,000,000.00 euros.


                                           VI
    Failure to comply with the obligation. Notification of a personal data security breach to the
    competent supervisory authority



Article 33 of the GDPR states the following:

 "1. In the event of a personal data breach, the controller shall notify the competent supervisory authority pursuant to Article 55 without undue delay and, where feasible, no later than 72 hours after becoming aware of it, unless the personal data breach is unlikely to result in a risk for the rights and freedoms of natural persons. If the notification to the
 supervisory authority does not take place within 72 hours, it must be

 accompanied by an indication of the reasons for the delay.

 2. The processor shall without undue delay notify the controller
 of the personal data breaches of which it becomes aware.


       3. The notification referred to in paragraph 1 shall, at a minimum:
 a) describe the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects concerned, and the categories and approximate number of

       of personal data records affected;
 b) communicate the name and contact details of the data protection officer or another contact point where more information can be obtained;

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 17/24








       c) describe the likely consequences of the personal data security breach;
 d) describe the measures taken or proposed by the controller to address the personal data security breach, including, where appropriate, the measures taken to mitigate the potential negative effects.

       4. If it is not possible to provide the information simultaneously, and to the extent that it is not, the information shall be provided in a gradual manner without undue delay.

 5. The controller shall document any personal data security breach, including the facts relating to it, its effects, and the remedial action taken. Such documentation

       will allow the supervisory authority to verify compliance with the provisions of this article."

First, it should be noted that the obligation to notify a breach is not a mere formal requirement, but a measure of proactive accountability linked to the damages that personal data security breaches can cause

for the affected individuals. In this regard, Recital 85 of the GDPR emphasizes the need to notify the breach without delay "unless the controller can demonstrate, in accordance with the principle of proactive accountability, the improbability that the personal data security breach is likely to result in a risk to the rights and freedoms of natural persons." 


Likewise, in recital 87 of the GDPR, the need for the supervisory authority to verify that such notification has been made is stated, in the following terms:


       (87) It should be verified whether all appropriate technological protection measures have been applied and the necessary organizational measures have been taken to determine immediately if a personal data security breach has occurred and to inform the supervisory authority and the data subject without undue delay.
       It must be verified that the notification has been made without undue delay, taking into account, in particular, the nature and gravity of the personal data security breach and its consequences and adverse effects for the data subject. Such notification may result in an intervention by the supervisory authority in accordance with the tasks and powers established by this Regulation.


In this case, according to the information provided by 23ANDME in the breach notification and in its response to the SGID's request during the preliminary investigation proceedings, previously transcribed in the factual background, the chronology of the incident, the actions taken by 23ANDME, and its notification to this supervisory authority have been as follows:


    -   10/01/2023, 23ANDME detects a message on Reddit offering for sale
 information allegedly belonging to its customers


6 Jorge Juan Street, www.aepd.es
28001 – Madrid sedeaepd.gob.es 18/24








    -   10/05/2023, confirms that one of the published data items belongs to one of its
 customers

    -   10/06/2023, publishes an alert on its website


 -   10/07/2023, notifies US authorities of the breach

 -   10/09/2023, logs clients out and forces password resets

    -   10/10/2023, sends an email to all its customers informing them of the incident

 -   12/10/2023, confirms the identity of the customers affected by the breach


 -   13/10/2023, notifies the 799 affected individuals residing in Spain who were initially located

    -   10/17/2023, GREENBERG TRAURIG, on behalf of 23ANDME, notifies the AEPD of the breach

 -   10/24/2023, 23ANDME notifies the 1,843 affected individuals located subsequently


    - 10/30/2023, GREENBERG TRAURIG expands the information on the breach

According to this timeline, the notification, from the moment it is known that a breach affecting personal data has occurred, significantly exceeds the 72-hour deadline established in Article 33 of the GDPR.


Regarding the notification to this supervisory authority after the 72 hours required by Article 33 of the GDPR, in the expansion of the breach notification made on 10/30/2023, transcribed in the factual background, the following is stated (unofficial translation made with the "Digital Europe Language Tools" tool):

 (…)


On the other hand, in its response to the SGID's request, 23ANDME states the following (unofficial translation made with the "Digital Europe Language Tools" tool):

 (…)


Regarding this justification, it is first necessary to identify the moment at which 23ANDME would have had the obligation to notify the data breach.

In this regard, it should be noted that the notification obligation established in Article 33 of the GDPR has been developed by the European Data Protection Committee (hereinafter, EDPB) through Guidelines 9/2022 on the notification of personal data security breaches under the GDPR.


C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 19/24








These Guidelines refer in particular to the moment when the controller "becomes aware" of the breach and, therefore, has the obligation to notify a personal data breach. Thus, in their sections 31 and 32, they state the following:


       31. As explained above, the GDPR provides that, in the event of a breach, the controller shall notify it without undue delay and, where feasible, no later than seventy-two hours after becoming aware of it. This may raise the question of when a controller can be considered to have "become aware" of a

breach. The CEPD is of the opinion that the controller should be considered to be "aware" when it has a reasonable degree of certainty that a security incident affecting personal data has occurred.


Following the Guidelines, in the present case, on 10/05/2023, 23ANDME became aware of the existence of a breach, as it confirmed that one of the published data items belonged to one of its customers. It therefore had a reasonable degree of certainty that the incident compromised personal data from the processing for which it was responsible. In the same vein, the fact that the next day, 10/06/2023, 23ANDME published an alert on its website, the

On October 7, 2023, it notified the breach to U.S. authorities and on October 9, 2023, it closed all of its customers' sessions and required them to reset their passwords as a reactive security measure. Furthermore, on October 12, 2023, it was already aware that there were affected individuals in Spain. However, it did not proceed with the notification to this supervisory authority until October 17, 2023.


The need for immediacy in notification is not trivial, but is related to the effectiveness of this measure in relation to the damages that a breach can cause for the affected individuals. In this regard, Article 33 of the GDPR expressly provides that at first, not all information about what happened may be available and that it can be provided gradually.

In this regard, the 9/2022 Guidelines from the EDPB are again worth citing, when they state the following:

35. Once the controller becomes aware of a reportable breach, it must be notified without undue delay and, where feasible, no later than seventy-two hours. During this period, the
 controller must assess the potential risk to individuals in order to determine if the notification requirement applies, as well as the
 necessary measures to address the breach.


 (…)

 40. Consequently, it must be clear that the controller is obligated to act on any initial alert and to determine whether or not a
 breach has occurred. This short period allows for some investigation and for the data controller to gather evidence and other relevant details. However, once the data controller has established with a reasonable degree of certainty that a breach has occurred,

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 20/24




If a data controller fails to act quickly and it becomes evident that a breach has occurred, this could be considered a failure to notify in accordance with Article 33 of the GDPR.

On the other hand, 23

       If a controller does not act quickly and it becomes evident that a breach has occurred, this could be considered a failure to notify in accordance with Article 33 of the GDPR.

On the other hand, 23ANDME notes that, once the customers whose profiles had been affected were identified, "23andMe immediately began to determine the

breach notification obligations in the 62 jurisdictions where affected customers are located." This statement would reveal a lack of due diligence regarding the obligations of data controllers to whom the GDPR applies.


The notification obligation, as stated, is a measure linked to the security of personal data and must be carried out immediately. The statement that only after the affected individuals have been identified are they beginning to determine what obligations exist in each country, since from the day
10/12/23 was aware of the existence of affected individuals residing in Spain and the notification obligation, in accordance with section 73 of the aforementioned Guidelines, "the breach must be notified to all supervisory authorities in whose Member State the affected data subjects reside."

This is especially true when it involves a high-risk processing, as it includes genetic, health, and ethnic origin data of the affected individuals, as the controller itself indicates in the DPIA that accompanies its response. A breach of such data would, in any case, trigger a notification obligation, as it entails a high risk to the rights and freedoms of the affected individuals.


On the other hand, 23ANDME was aware of the need to comply with data protection regulations in the European Union and the obligations imposed by the GDPR on data controllers. This is made clear by the document "23ANDME HOLDING CO. ANNUAL REPORT FISCAL 2023," published on the 23ANDME website. In this document, which predates the breach, reference is made to the company's activities in countries where the GDPR applies, and it contains various references to the GDPR, as set forth in the factual background, and even expressly mentions the possibility that the company could be fined in the event of a violation. 

In this regard, the CEPD's Guidelines 9/2022 are again worth citing, which state the following regarding controllers not established in the European Union:

72. When a controller not established in the EU is subject to the provisions of Article 3(2) or (3) of the GDPR and becomes aware of a breach, it will still be required to comply with the notification obligations set out in Articles 33 and 34 of the GDPR. Article 27 of the GDPR requires that the controller (and the processor)
       designate a representative in the EU when Article 3(2) of the GDPR applies.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 21/24









Therefore, the proven facts are considered to constitute an infringement attributable to 23ANDME for violating the aforementioned article.

 VII
 Typification of the infringement of Article 33 of the GDPR and classification for the purposes of

 prescription

Article 83.4 of the GDPR classifies as an administrative offense the violation of the following article, which shall be subject to a fine, in accordance with paragraph 2, of up to 10,000,000 EUR or, in the case of an enterprise, an amount equivalent to up to 2% of the total annual worldwide business turnover of the previous financial year, whichever is higher:

       "a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39, 42, and 43;"


For its part, the LOPDGDD in its Article 71, Offenses, states that:

 "Offenses are constituted by the acts and conduct referred to in
 paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those
 that are contrary to this organic law."


For the sole purpose of the statute of limitations, Article 73 of the LOPDGDD establishes the following:

 "In accordance with what is established in Article 83.4 of Regulation (EU) 2016/679, the following are considered serious violations and will be subject to a two-year statute of limitations: violations that

       substantially affect the articles referred to in that provision and, in particular, the following:
r) Failure to notify the supervisory authority of a personal data security breach in accordance with Article 33 of Regulation (EU) 2016/679.


                                           VIII
Sanction for non-compliance with Article 33 of the GDPR

In order to determine the administrative fine to be imposed, the provisions of Articles 83.1 and 83.2 of the GDPR and Article 76 of the LOPDGDD, which were transcribed above in the third ground, must be observed.

In the present case, considering the severity of the potential infringement, and taking special
consideration of the consequences its commission causes the affected individuals,

the imposition of a fine is appropriate.

The fine imposed must, in each case, be individual, effective, proportionate, and
deterrent, in accordance with what is established in Article 83.1 of the GDPR. To ensure these principles, the business volume of 23ANDME, which was $299,489,000 in 2023, is taken into account.

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 22/24









In order to decide on the imposition of an administrative fine and its amount, the sanction to be imposed must be graduated in accordance with the following circumstances, as contemplated in the provisions cited above.

First, it is determined that the infringement would be serious, to the extent that the following circumstances are present:

• The nature, severity, and duration of the infringement, taking into account the

     nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damage and prejudice they have suffered (Article 83.2(a) of the GDPR): In the present case, the high number of affected individuals, which amounts to 2,642 people in Spain, is notable.

     • The categories of personal data affected by the

 breach (Article 83.2(g) of the GDPR): In addition to identifying, contact, and location data, the breach has affected personal data of a particularly sensitive nature, such as genetic data, health data, and data revealing the ethnic origin of the affected individuals, which constitutes a high
     risk to their rights and freedoms.

Likewise, the link between the offender's activity and the processing of personal data is considered an aggravating factor (Article 76.2, letter b), of the LOPDGDD): 23ANDME's activity consisted in large part of processing its clients' especially sensitive personal data as part of the service the company offered, which included conducting genetic tests and analyzing their results.


The balance of the circumstances considered in Article 83.2 of the GDPR and 76.2 of
the LOPDGDD, with respect to the infringement committed by violating the provisions of Article 33 of the GDPR, allows for the imposition of an administrative fine of 400,000.00 euros.



Therefore, in accordance with applicable law and after weighing the sanction graduation criteria that have been established, the Presidency of the Spanish Data Protection Agency


RESOLVES:


FIRST: TO IMPOSE on 23ANDME, INC, for the alleged violations of Articles 5.1(f) and 33 of the GDPR, typified, respectively, in Articles 83.5 and

83.4 of the GDPR, an administrative fine of TWO MILLION FOUR HUNDRED THOUSAND EUROS (€2,400,000.00), corresponding to the following infringements:

- For the infringement of Article 5.1(f) of the GDPR, typified in Article 83.5, a fine of
€2,000,000.00
- For the infringement of Article 33 of the GDPR, as typified in Article 83.4, a fine of

400,000.00 euros

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 23/24








SECOND: NOTIFY this resolution to 23ANDME, INC.

THIRD: This resolution will become effective once the period for filing the optional appeal has expired (one month from the day following the notification of this resolution) without the interested party having exercised this right.

The sanctioned party is hereby notified that they must pay the imposed sanction once this resolution becomes final, in accordance with Article 98.1.b) of Law 39/2015, of October 1, on the Common Administrative Procedure of the Public Administrations (hereinafter LPACAP), within the voluntary payment period established in Article 68 of the General Collection Regulation, approved by Royal Decree 939/2005
Public Administrations (hereinafter LPACAP), within the voluntary payment period established in Article 68 of the General Collection Regulation, approved by Royal Decree 939/2005, of July 29, in relation to Article 62 of Law 58/2003, of December 17,

December, by depositing it, indicating the NIF of the offender and the procedure number that appears at the heading of this document, into the restricted account no. IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code:
CAIXESBBXXX), opened in the name of the Spanish Data Protection Agency at the bank CAIXABANK, S.A.. Otherwise, collection will proceed in the enforcement phase.

Upon receipt of the notification and once it becomes effective, if the effective date falls between the 1st and 15th of each month, inclusive, the deadline for voluntary payment will be the 20th of the following month or the next business day, and if it falls between the 16th and the last day of each month, inclusive, the payment deadline

will be until the 5th of the second following month or the next business day.

In accordance with Article 76.4 of the LOPDGDD, and since the amount of the imposed fine is greater than one million euros, information identifying the offender, the offense committed, and the amount of the fine will be published in the Official State Gazette.


In accordance with Article 50 of the LOPDGDD, this Resolution will be made public. The publication will be carried out once it has been notified to the interested parties.

Against this resolution, which exhausts administrative remedies in accordance with Art. 48.6 of the

LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, the
interested parties may, as a matter of discretion, file an appeal for reconsideration before the
the Presidency of the Spanish Data Protection Agency within one month from the day following the notification of this resolution, or directly an administrative appeal before the Administrative Court of the National Court of Appeals, in accordance with the provisions of Article 25 and paragraph 5 of

the Fourth Additional Provision of Law 29/1998, of July 13, regulating the Jurisdiction of the Administrative Court, within two months from the day following the notification of this act, as provided for in Article 46.1 of the aforementioned Law.


Finally, it is noted that in accordance with Article 90.3(a) of the LPACAP, the final administrative resolution may be provisionally suspended if the interested party expresses their intention to file a contentious-administrative appeal.
If this is the case, the interested party must formally communicate this fact in writing to the Spanish Data Protection Agency, submitting it through

C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeaepd.gob.es 24/24









of the Agency's Electronic Registry [https://sedeaepd.gob.es/sede-electronica-web/], or through any of the other registries provided for in Article 16.4 of the aforementioned Law 39/2015, of October 1. You must also submit to the Agency the documentation proving the effective filing of the administrative lawsuit. If the Agency is not notified of the filing of the administrative lawsuit within two months from the day after this resolution is notified, the precautionary suspension will be terminated.



 938-101025
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency




















































6 Jorge Juan Street, www.aepd.es
28001 – Madrid sedeaepd.gob.es