Privacy Commissioner launches investigation into 23andMe data breach

Privacy Commissioner launches investigation into 23andMe data breach

On June 10, 2024, the Privacy Commissioners of Canada and the United Kingdom announced that they have begun their joint investigation into the 23andMe (a direct-to-consumer genetic testing company) data breach that was discovered in October, 2023.

That is, Privacy Commissioner of Canada Philippe Dufresne and UK Information Commissioner John Edwards will be examining three main things:

  • The scope of information that was exposed by the breach and potential harms to affected individuals.
  • Whether 23andMe had adequate safeguards to protect the highly sensitive information within its control.
  • Whether the company provided adequate notification about the breach to the two regulators and affected individuals as required under Canadian and UK privacy and data protection laws.

Both regulators are well aware that genetic information is highly sensitive personal information that can reveal information about an individual and their family members (including health, ethnicity, and biological relationships).

Canada’s Privacy Commissioner, Dufresne, stated, “In the wrong hands, an individual’s genetic information could be misused for surveillance or discrimination…Ensuring that personal information is adequately protected against attacks by malicious actors is an important focus for privacy authorities in Canada and around the world.”

What exactly happened with this breach? Apparently, a statement from the company said that hackers gained access to roughly 6.9 million profiles on the site (nearly half its client base). Essentially, those profiles had delicate personal data ranging from birth year, geographic location, health information, and the percentage of DNA that users shared with their relatives.

Privacy expert, Professor Teresa Scassa, had the following to say after the breach’s discovery for those who are considering doing the tests: “I would not do it and if anyone asked me, I would say, ‘do not do it’.” It is easy to see that there may be concern because people are basically giving them a raw code of themselves. That is not all—the hackers have accessed family tree profile information for about 1.4 million customers.

The Privacy Commissioners of Canada and the UK have created a memorandum of understanding that sets out the terms of their arrangement. The memorandum highlighted the applicable laws, the Personal Information Protection and Electronic Documents Act (PIPEDA) and the Data Protection Act of UK (DPA)
are the main instruments that will be referred to.

In fact, in the memorandum signed in 2019 and 2020 by Commissioners Therrien and Denham respectively (as they then were), the Commissioners acknowledged that it was in their common interests to collaborate, namely to share experiences, implement joint research projects, exchange information (but not personal information), conduct joint investigations, have bilateral meetings and similar activities.

As the current Privacy Commissioner just said at the Canada Privacy Symposium, “…protecting privacy is one of the paramount challenges of our time.”

Let us consider this an invitation to Canadians to get involved in privacy advocacy, education, promotion, and enforcement.

Meanwhile, a class action commenced in British Columbia seeking damages against 23andMe for breaches of privacy and consumer laws, breach of contract, and negligence. We will keep you posted on the investigation and results of any class actions.

Share

Related Posts

Imagen 1

Employees with disabilities – accommodation strategies (Part I)

Accommodating employees with disabilities to the point of undue hardship under human rights legislation can be a complicated task. It’s important to make sure the accommodation process goes smoothly and the employee can focus on working as efficiently as possible, but employers may not be sure about what kinds of questions to ask disabled employees in order to meet their needs.

Christina Catenacci, BA, LLB, LLM, PhD

Read more
Imagen 1

Slaw: Canadian Human Rights Commission’s controversial ‘anti-hate’ policy

The Canadian Human Rights Commission recently posted a policy on its website concerning how it interprets and applies section 13 of the Canadian Human Rights Act (CHRA) when it receives an inquiry or complaint. The purpose of section 13 of the Act is to balance Canadians’ rights to equality and freedom of expression with respect to hate messages, as protected by the Canadian Charter of Rights and Freedoms. The parliamentary record indicates that section 13 was initially included in the legislation to address activities of individuals and groups who used the telephone system to disseminate hate messages. In December 2001, parliament amended the CHRA by adding section 13(2), which makes it clear that Internet hate messages come under the jurisdiction of the commission.

Read the whole article on Slaw.ca.

Marie-Yosie Saint-Cyr, LL.B. Managing Editor

Read more
Imagen 1

The new age of workplace gossip – TMI!

I’ve discussed workplace gossip here before, and what bosses can do to prevent it or at least reduce the potential harm, but there are a couple of hyper-modern developments that I didn’t get into: reality television and the Internet. These two things have created a culture of “sharing”, for lack of a better word, that encourages people at play or work to divulge the most mundane and private details of their lives to others—the kind of information that one previously might only have shared with family or best friends.

Adam Gorley

Read more