So after posting this story this morning, I got a number of enquiries about how one can delete their 23andMe data. I did some looking around and I found that The Verge has excellent instructions on how to delete your data.
That’s the good news. Here’s the bad news. Deleting your data may not matter. Here’s why:
One of the notable issues is that this process also won’t delete all of your data — according to 23andMe’s privacy disclosure, your genetic information, date of birth, and sex will be retained for an undisclosed amount of time to comply with the company’s legal obligations, alongside “limited information related to your account,” such as your email address and communications around your data deletion request.
As I said this morning, the DNA or related genetic information is going to be super valuable to any company that wants to buy 23andMe, or what’s left of it. So It doesn’t surprise me that this verbiage exists. And it means that anyone who took a 23andMe test will have their data floating around in some form for a very long time, if not forever.
The take away from this whole episode is that perhaps you need to think twice before you use one of these services as this could be the end result.
UPDATE: Ensar Seker, CISO at SOCRadar had this comment:
“With 23andMe facing bankruptcy, there are serious concerns about what happens to millions of users’ genetic and personal health information (PHI). This isn’t just a typical data set; it includes deeply sensitive, immutable biological data that can be tied to individuals and their families for generations. Unlike a password or credit card number, you can’t change your DNA.”
“The most immediate risk is that this highly valuable dataset could be sold during bankruptcy proceedings, either to repay creditors or as part of asset acquisition. While regulations such as HIPAA and data use agreements exist, bankruptcy can complicate consent, data retention, and transfer policies, especially if the company is acquired by a foreign entity or a data broker.”
“From a security perspective, if proper safeguards and access controls aren’t maintained during this uncertain period, there’s a high risk that this data could be exfiltrated, sold on the dark web, or used in nation-state-level surveillance and profiling operations. It could even be leveraged in advanced identity fraud, blackmail, or discriminatory practices, especially if combined with breached data from other sources.”
“Additionally, given the military, political, and economic interest some governments have in genomic data, there’s also a strategic threat vector here. DNA data can reveal not just ancestry but predispositions to diseases, behavioral traits, and vulnerabilities, information that could be abused in both commercial and geopolitical contexts.”
“The bottom line is that 23andMe’s bankruptcy shouldn’t just be seen as a business failure. It’s a data stewardship crisis. Regulators, privacy watchdogs, and even national security agencies should step in to ensure that this dataset doesn’t fall into the wrong hands. Transparency, oversight, and ethical responsibility are now more important than ever.”
Chris Hauk, Consumer Privacy Champion at Pixel Privacy follows with this:
“23andMe is based in South San Francisco, California, so the company’s data is subject to the stricter privacy protections enforced in California. The bankruptcy is Chapter 11, meaning the company will likely continue operating until a new buyer is found. This means 23andme customers do still have time to request that the company delete all of their data, including their genetic data. I strongly recommend that affected customers make a deletion request as soon as possible, to ensure that your data is not sold.”
Paul Bischoff, Consumer Privacy Advocate at Comparitech adds this:
“The privacy policy that 23andMe customers agreed to may no longer apply if another company acquires it or its assets. Furthermore, genetic data is not considered medical info in the USA, and 23andMe is not considered a healthcare provider, so it’s not subject to HIPAA protections. Whoever acquires 23andMe will be free to change the privacy policy. I recommend deleting your 23andMe account immediately and requesting your personal data be deleted. Given the company’s data breach and compliance with law enforcement, this should be a no-brainer for privacy.”
Brian Higgins, Security Specialist at Comparitech offers this:
“It really depends on where the company is registered. In the case of a U.K. bankruptcy, according to the Insolvency Service, “The official receiver will become the data controller for personal data held by the bankrupt.” This at least gives some confidence to those customers affected by the failure of the company as regulations regarding storage, security and access ought to be maintained.”
“If 23andme were incorporated/registered elsewhere then it would be worth checking the data protection regulations of the jurisdiction concerned as there are some major differences in provision across the globe.”
Martin Jartelius, CISO at Outpost24 provided this:
“When any organization goes under, it will be harder to maintain privacy and control of information. We do not know who will pick it up, we do not know if sunsetting will be needed and we do not know how said sunsetting would work. The cyber element of personal data is generally related to credibility, such as the ability to refer to a relationship or bond to instigate an action of others, or simply the use of information related to the platform for the purposes of fraud or extortion – none of those are immediate and none are disastrous.”
SafeBreach Launches Enhanced MSSP Program for Advanced Security Validation
Posted in Commentary with tags SafeBreach on March 26, 2025 by itnerdSafeBreach today announced the launch of its enhanced Managed Security Service Provider (MSSP) program, an expanded element of the company’s successful “Elevate” partner initiative that was unveiled in 2024. The new MSSP program is specifically designed to support service providers who host, manage, or resell SafeBreach’s continuous security validation solutions, enabling them to deliver greater value to their clients while accelerating their own business growth.
Following the recent launch of the SafeBreach exposure validation platform in February, this new MSSP program represents the company’s continued commitment to empowering partners with the tools, resources, and support needed to address the evolving cybersecurity challenges that organizations face today.
The enhanced MSSP program builds on the strengths of SafeBreach’s previous partner framework, incorporating industry best practices to enhance growth, scalability, and reliability. The program provides a clear framework for partners to establish consistent client engagement expectations, ensuring successful deployment and ongoing management of SafeBreach’s security validation solutions.
SafeBreach empowers partners to accelerate business growth by expanding their client services portfolio with advanced, continuous security validation. Through scalable and automated simulations, partners can help their clients better understand, detect, and defend against cyber threats.
Key benefits of the enhanced MSSP program include:
With traditional, point-in-time security control validation tactics like penetration testing and red teaming proving insufficient, organizations increasingly need comprehensive and continuous views of security performance combined with prioritized remediation of gaps. The SafeBreach exposure validation platform addresses this need with an innovative combination of breach and attack simulation (BAS) and attack path validation that provides enterprises with deeper insight into threat exposure and a more holistic view of cyber risk.
Through this enhanced MSSP program, SafeBreach partners can now more effectively help their clients combat the ongoing challenges of an evolving threat landscape. “The updates to the SafeBreach MSSP program and strategy build on the strengths of our previous program to position our partners as trusted advisors,” added Wilkinson. “As a result, they can better help their clients select, validate, and implement a comprehensive security validation platform.”
For more information on the Elevate MSSP program, visit https://www.safebreach.com/partners/.
Leave a comment »