• About
  • Offices
  • Careers
  • News
  • Students
  • Alumni
  • Payments
  • EN | FR
Background Image
Bennett Jones Logo
  • People
  • Expertise
  • Knowledge
  • Search
  • FR Menu
  • Search Mobile
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
View all
Practices
Corporate Litigation Regulatory Tax View all
Industries
Energy Infrastructure Mining Private Equity & Investment Funds View all
Advisory
Crisis & Risk Management Public Policy
View Client Work
International Experience
Insights News Events Subscribe
Arbitration Angle Artificial Intelligence Insights Business Law Talks Podcast Class Actions: Looking Forward Class Action Quick Takes
Economic Outlook New Energy Economy Series Quarterly Fintech Insights Quarterly M&A Insights Sustainability & the CIO
People
Offices
About
Practices
Industries
Advisory Services
Client Work
Insights
News
Events
Careers
Law Students
Alumni
Payments
Search
Subscribe

Stay informed on the latest business and legal insights and events.

LinkedIn LinkedIn Twitter Twitter Vimeo Vimeo
 
Blog

23andMe's Data Breach: Key Takeaways

June 26, 2025

Written By Stephen Burns, Ruth Promislow, Sebastien Gittens, Matthew Flynn, Caroline Poirier, Kees de Ridder, Suzie Suliman, David Wainer, Emma Arnold-Fyfe and Sahej Toor

On June 17, 2025, the Office of the Privacy Commissioner of Canada (OPC) released a summary of its investigation findings regarding a data breach at 23andMe, which affected nearly seven million customers, including approximately 320,000 Canadians.

The compromised data included information which was derived from the individual's DNA or disclosed by the individual, and which was often deemed to be "sensitive" under Canadian privacy legislation, including: health details, race, ethnicity, information about relatives, date of birth, sex at birth and gender.

The data breach reportedly resulted from a credential-stuffing attack, where a threat actor exploited reused login credentials from unrelated breaches to gain unauthorized access to 23andMe’s platform.

Following a joint investigation, the OPC and the UK Information Commissioner’s Office (ICO) asserted there were deficiencies in 23andMe’s security practices. The authorities asserted that 23andMe:

  1. failed to implement appropriate controls to prevent unauthorized access to sensitive data;
  2. did not have effective systems in place to monitor, detect and respond to cyber threats; and
  3. did not investigate credible claims of a breach and did not adequately notify regulators or affected customers, as required under Canadian and UK privacy laws.

As a result, the OPC and ICO emphasized the need for organizations to take proactive steps to protect against cyber-attacks such as: multi-factor authentication; strong minimum password requirements; compromised password checks; and monitoring systems to detect abnormal activity.

They also remind organizations that:

  1. safeguards used in connection with sensitive personal information should be more robust given the heightened risk of harm; and
  2. safeguards must be prioritized and "built into the customer experience [of a web] design."

The ICO fined 23andMe £2.31 million under UK privacy law. Under Canadian federal privacy legislation, there is no penalty arising as a result of the findings made by the OPC. Accordingly, Privacy Commissioner Philippe Dufresne has called for modernized privacy legislation to enable stronger enforcement powers, aligning Canada with its international counterparts. 

The expectation among privacy professionals in Canada is that we will see the federal government bring forward legislation to update the federal private sector privacy regime which will include, among other things, penalties for non-compliance.  In the meantime, organizations should take note of the potential for substantial penalties under the Quebec private sector privacy regime.

This investigation highlights the need for controls, systems and processes, appropriate to the sensitivity of the information to be protected, to meet the obligations to safeguard personal information and manage risk.

For more information on privacy compliance and data protection, please contact one of our privacy and cybersecurity lawyers.

Please note that this publication presents an overview of notable legal trends and related updates. It is intended for informational purposes and not as a replacement for detailed legal advice. If you need guidance tailored to your specific circumstances, please contact one of the authors to explore how we can help you navigate your legal needs.

For permission to republish this or any other publication, contact Amrita Kochhar at kochhara@bennettjones.com.

Download PDF

Authors

  • Stephen D. Burns Stephen D. Burns, Partner, Trademark Agent
  • Ruth E. Promislow Ruth E. Promislow, Partner
  • J. Sébastien A. Gittens J. Sébastien A. Gittens, Partner, Trademark Agent
  • Matthew  Flynn Matthew Flynn, Partner
  • Caroline  Poirier Caroline Poirier, Partner
  • Kees  de Ridder Kees de Ridder, Associate, Patent Agent, Trademark Agent
  • Suzie  Suliman Suzie Suliman, Associate, Trademark Agent
  • David  Wainer David Wainer, Associate
  • Emma  Arnold-Fyfe Emma Arnold-Fyfe, Associate
  • Sahej  Toor Sahej Toor, Summer Student

Related Links

  • Insights
  • Media
  • Subscribe

Recent Posts

Blog

23andMe's Data Breach: Key Takeaways

June 26, 2025
       

Blog

The PE Briefing: Q2 2025

June 26, 2025
       

Blog

Requirements and Guidelines From Canadian Regulators, [...]

June 25, 2025
       

Blog

No Common Employer Means No Class Action—Ontario Court of Appeal

June 24, 2025
       

Blog

Canada Unveils Sweeping New Russia Sanctions Targeting [...]

June 20, 2025
       
Bennett Jones Centennial Footer
Bennett Jones Centennial Footer
About
  • Leadership
  • Diversity
  • Community
  • Innovation
  • Security
Offices
  • Calgary
  • Edmonton
  • Montréal
  • Ottawa
  • Toronto
  • Vancouver
  • New York
Connect
  • Insights
  • News
  • Events
  • Careers
  • Students
  • Alumni
Subscribe

Stay informed on the latest business and legal insights and events.

LinkedIn LinkedIn Twitter Twitter Vimeo Vimeo
© Bennett Jones LLP 2025. All rights reserved.
  • Privacy Policy
  • Disclaimer
  • Terms of Use
Logo Bennett Jones