Canada: UK Information Commissioner’s Office issued provisional findings and proposed fine to 23andMe following joint investigation with Office of the Privacy Commissioner of Canada regarding compliance with cybersecurity regulations

Description

UK Information Commissioner’s Office issued provisional findings and proposed fine to 23andMe following joint investigation with Office of the Privacy Commissioner of Canada regarding compliance with cybersecurity regulations

On 24 March 2025, the UK Information Commissioner’s Office (ICO) issued provisional findings, a notice of intent to impose a fine of £4.59 million, and a preliminary enforcement notice to 23andMe. This action followed a joint investigation with the Office of the Privacy Commissioner of Canada (OPC) into a data breach reported by the company in October 2023. The breach involved sensitive personal data, including genetic information. The ICO stated that the findings are provisional and remain subject to representations from 23andMe, including in relation to the proposed penalty’s affordability. The regulator also confirmed that it is monitoring 23andMe’s Chapter 11 bankruptcy proceedings in the United States and noted that the company continues to be subject to obligations under the UK General Data Protection Regulation (UK GDPR).

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
other service provider
Implementation Level
bi- or plurilateral agreement
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2024-06-10
under deliberation

On 10 June 2024, the Office of the Privacy Commissioner of Canada (OPC) announced that they had lau…

2025-03-24
under investigation

On 24 March 2025, the UK Information Commissioner’s Office (ICO) issued provisional findings, a not…

We use cookies and other technologies to perform analytics on our website. By opting in, you consent to the use by us and our third-party partners of cookies and data gathered from your use of our platform. See our Privacy Policy to learn more about the use of data and your rights.