{"id":25340,"date":"2024-10-17T04:10:05","date_gmt":"2024-10-17T12:10:05","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/10\/17\/news-19070\/"},"modified":"2024-10-17T04:10:05","modified_gmt":"2024-10-17T12:10:05","slug":"news-19070","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/10\/17\/news-19070\/","title":{"rendered":"23andMe will retain your genetic information, even if you delete the account"},"content":{"rendered":"\n<p>Deleting your personal data from 23andMe is proving to be hard.<\/p>\n<p>There are good reasons for people wanting to delete their data from 23andMe: The DNA testing platform has a lot of problems, so let\u2019s start with a recap.<\/p>\n<p>A little over a year ago, cybercriminals put up information belonging to as many as <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2023\/10\/23andme\">seven million 23andMe customers<\/a> for sale on criminal forums following a credential stuffing attack against the genomics company.<\/p>\n<p>In December 2023, we <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2023\/12\/23andme-says-er-actually-some-genetic-and-health-data-might-have-been-accessed-in-recent-breach\">learned<\/a> that the attacker was able to directly access the accounts of roughly 0.1% of 23andMe\u2019s users, which is about 14,000 of its 14 million customers. So far not too many people affected, but with the breached accounts at their disposal, the attacker used 23andMe\u2019s opt-in DNA Relatives (DNAR) feature\u2014which matches users with their genetic relatives\u2014to access information about millions of other users.<\/p>\n<p>For a subset of these accounts, the stolen data contained health-related information based upon the user\u2019s genetics.<\/p>\n<p>In January 2024, 23andMe had the audacity to lay the <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/01\/23andme-blames-negligent-breach-victims-says-its-their-own-fault\">blame at the feet of victims<\/a> themselves in a letter to legal representatives of victims. 23andMe reasoned that the customers whose data was directly accessed re-used their passwords, gave permission to share data with other users on 23andMe\u2019s platform, and that the medical information was non-substantive.<\/p>\n<p>And in September 2024, we found out that the company would pay $30 million to settle a class action lawsuit, as that was all that 23andMe could afford to pay. And that\u2019s only because the expectation was that cyberinsurance would cover $25 million.<\/p>\n<p>As a result, the value of 23andMe plummeted. And last month the <a href=\"https:\/\/www.cnbc.com\/2024\/09\/17\/23andme-independent-directors-resign-from-board-read-the-ceo-memo.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">company said goodbye to all its board members<\/a> except for CEO Anne Wojcicki who stood by her plans to take the company private.<\/p>\n<p>This uncertainty about the future of the company and, with that, who will be the future holder of all the customer personal information, has caused a surge of users looking to close their accounts and delete their data.<\/p>\n<p>However, it turns out it&#8217;s not as easy as just asking for the data to be removed. You can delete your data from 23andMe , but 23andMe says it will retain some of that data (including genetic information) to comply with the company\u2019s legal obligations, according to its <a href=\"https:\/\/www.23andme.com\/en-eu\/legal\/privacy\/full-version\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">privacy policy<\/a>.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201c23andMe and\/or our contracted genotyping laboratory will retain your Genetic Information, date of birth, and sex as required for compliance with applicable legal obligations, including the federal Clinical Laboratory Improvement Amendments of 1988 (CLIA), California Business and Professions Code Section 1265 and College of American Pathologists (CAP) accreditation requirements, even if you chose to delete your account. 23andMe will also retain limited information related to your account and data deletion request, including but not limited to, your email address, account deletion request identifier, communications related to inquiries or complaints and legal agreements for a limited period of time as required by law, contractual obligations, and\/or as necessary for the establishment, exercise or defense of legal claims and for audit and compliance purposes.\u201d<\/p>\n<\/blockquote>\n<p>In addition, any information you previously provided and consented to be used in 23andMe research projects cannot be removed from ongoing or completed studies, although the company says it will not use it in any future ones.<\/p>\n<p>This is unfortunate, and is yet another reminder about how once you give information away you cannot always get it back. Let&#8217;s hope the policy gets changed and customers are allowed to fully delete their data soon.<\/p>\n<p>It&#8217;s still worth deleting as much as possible, though. So here&#8217;s how to do that.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-how-to-delete-most-of-your-data-from-23andme\">How to delete (most of) your data from 23andMe<\/h2>\n<ul>\n<li>Log into your account and navigate to&nbsp;<strong>Settings<\/strong>.<\/li>\n<li>Under&nbsp;<strong>Settings<\/strong>, scroll to the section titled&nbsp;<strong>23andMe data<\/strong>. Select&nbsp;<strong>View<\/strong>.<\/li>\n<li>It will ask you to enter your date of birth for extra security.\u00a0<\/li>\n<li>In the next section, you\u2019ll be asked which, if there is any, personal data you\u2019d like to download from the company (onto a personal, not public, computer). Once you\u2019re finished, scroll to the bottom and select&nbsp;<strong>Permanently delete data<\/strong>.<\/li>\n<li>You should then receive an email from 23andMe detailing its account deletion policy and requesting that you confirm your request. Once you confirm you\u2019d like your data to be deleted, the deletion will begin automatically, and you\u2019ll immediately lose access to your account.&nbsp;<\/li>\n<\/ul>\n<p>When you set up your 23andMe account, you had the options to either have the saliva sample that you sent to them securely destroyed or to have it stored for future testing. If you chose to store your sample but now want to delete your 23andMe account, the company says it will destroy the sample for you as part of the account deletion process.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-check-your-digital-footprint\">Check your digital footprint<\/h2>\n<p>If you want to find out if your personal data was exposed through the 23andMe breach, you can use our\u00a0<a href=\"https:\/\/www.malwarebytes.com\/digital-footprint\">free Digital Footprint scan<\/a>. Fill in the email address you\u2019re curious about (it\u2019s best to submit the one you used to register and 23andMe) and we\u2019ll send you a free report.<\/p>\n<div class=\"wp-block-malware-bytes-button mb-button\" id=\"mb-button-7ba16f0b-04e8-4679-9512-2f21a0971dcf\">\n<div class=\"mb-button__row u-justify-content-center\">\n<div class=\"mb-button__item mb-button-item-0\">\n<p class=\"btn-main\"><a href=\"https:\/\/www.malwarebytes.com\/digital-footprint?utm_source=blog&amp;utm_medium=social&amp;utm_campaign=b2c_pro_acq_fy25dfplaunch_171269600960&amp;utm_content=V1\"><\/a><a href=\"https:\/\/www.malwarebytes.com\/digital-footprint\">SCAN NOW<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\" \/>\n<p><strong>We don&#8217;t just report on threats &#8211; we help safeguard your entire digital identity<\/strong><\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Protect your\u2014and your family&#8217;s\u2014personal information by using <a href=\"https:\/\/www.malwarebytes.com\/identity-theft-protection\">identity protection<\/a>.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/10\/23andme-will-retain-your-genetic-information-even-if-you-delete-the-account\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Why should you and how can you delete your 23andMe account and why it does not result in a complete data removal <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[20260,16349,14958,32,17588,5897],"class_list":["post-25340","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-23andme","tag-account","tag-bankruptcy","tag-news","tag-personal-information","tag-privacy"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25340","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=25340"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25340\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=25340"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=25340"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=25340"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}