The Spanish authority imposes a 2.4 million euro fine on 23ANDME for a serious personal data breach
Facts and context
The Spanish Data Protection Authority (AEPD) today published a sanction decision against 23ANDME, INC (including the imposition of a fine of €2,400,000) for failures related to data security and the notification of a personal data breach.
The case originated from the company's notification of a data breach resulting from a cyberattack that exposed sensitive data, including genetic and ethnic origin data, concerning 2,642 residents in Spain.
Grounds for the decision
The authority found two infringements against the data controller:
- Obligation to ensure the integrity and confidentiality of personal data (Article 5(1)(f) of the GDPR): The authority considered that the technical and organizational measures implemented by 23ANDME were not appropriate to guarantee a level of security suitable for the high risk presented by the processing of genetic, health, and ethnic origin data. The breach was made possible by a "credential stuffing" attack, exploiting users' reuse of compromised passwords on other sites. The authority noted that the company did not enforce any strong password policy, that multi-factor authentication was only optional, and that no additional control or limit was in place for access to or downloading of sensitive data once logged in.
- Obligation to notify a data breach to the supervisory authority (Article 33 of the GDPR): The company detected the breach on October 1, 2023, but only notified the AEPD on October 17, 2023, far exceeding the 72-hour deadline. The authority recalled, relying on Recitals 85 and 87 of the GDPR, that this notification must be made without undue delay. The company's argument that it first had to determine its obligations in 62 different jurisdictions was rejected and qualified as a lack of diligence, also citing the European Data Protection Board (EDPB) Guidelines 9/2022 on personal data breach notification.
Authority's decision
Consequently, the authority imposed a fine of €2,400,000 on 23ANDME, INC., broken down into €2,000,000 for the violation of Article 5(1)(f) of the GDPR and €400,000 for the violation of Article 33 of the GDPR.
Lessons learned
This decision reminds that:
- The optional nature of multi-factor authentication is deemed insufficient to secure accounts granting access to particularly sensitive data.
- The absence of a password policy imposing robustness and periodic renewal requirements constitutes a security failure.
- Failing to implement additional controls (e.g., limitations or alerts) for access to or downloading of sensitive data after initial authentication weakens overall security.
- The 72-hour deadline to notify a breach is strict, and the need to analyze legal obligations in multiple jurisdictions does not justify a delay.
- A controller not established in the Union offering services to persons in the Union must be prepared to comply with its GDPR obligations, including notification, without delay.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire