Federal Trade Commission Chairman Andrew N. Ferguson issued a letter to the U.S. Trustee overseeing the 23andMe bankruptcy proceeding, expressing concerns about the potential sale or transfer of consumers' personal genetic data. The letter underscores the importance of companies honoring their privacy promises to consumers, particularly regarding sensitive information, during bankruptcy proceedings.
In-house legal teams should review vendor agreements involving data sharing, customer terms of service, and data processing addendums for clauses related to data assignment, consent for transfers, and privacy policy integration. Specific attention should be paid to provisions governing asset sales in bankruptcy, ensuring that privacy promises are binding on successors and that consumer consent is obtained before transferring sensitive genetic data. Consider amending contracts to include explicit restrictions on data sales without user approval, audit rights for data handling, and clear breach notification procedures for genetic information.
Entity
23andMe, Inc.
Also known as: 23andMe
Industry
HealthcareOfficial Press Release
https://www.ftc.gov/news-events/news/press-releases/2025/03/federal-trade-commission-chairman-andrew-n-ferguson-issues-letter-23andme-bankruptcy-impact
chairman ferguson letter regarding 23andme
https://www.ftc.gov/legal-library/browse/cases-proceedings/staff-letters/chairman-ferguson-letter-regarding-23andme
Federal Trade Commission Enforcement Page
https://www.ftc.gov/enforcement
"23andMe"
"Many Americans are concerned about the impact of a potential sale of their personal data"
"Today, Federal Trade Commission Chairman Andrew N Ferguson issued a letter to the U.S. Trustee regarding the 23andMe bankruptcy proceeding, expressing the concerns American consumers have with the potential sale or transfer of their 23andMe data."
$18.0M
Attorney General Jennifer Davenport joined a bipartisan coalition of 42 attorneys general in announcing a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised genetic data of 6.9 million people worldwide, including nearly 150,000 in New Jersey. The settlement provides $18 million to states from available bankruptcy funds, plus enhanced data security and consumer deletion rights for the successor entity, 23andMe Research Institute.
$18.0M
A coalition of 42 state attorneys general settled with the bankruptcy trustee for 23andMe over a 2023 data breach that exposed genetic data of 6.9 million customers. The states will receive $18 million from bankruptcy funds, and 23andMe agreed to enhanced data security requirements and consumer deletion rights as part of the asset sale to TTAM Research Institute.
$18.0M
A coalition of 42 state attorneys general reached a settlement with the bankruptcy trustee for 23andMe over a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement provides $18 million from bankruptcy funds, with Minnesota receiving $514,871, and imposes data security requirements on the successor entity, 23andMe Research Institute.
New York Attorney General Letitia James, joined by 27 other state attorneys general and the District of Columbia, filed a lawsuit against 23andMe to block the company’s planned sale of 15 million customers’ genetic and health data without their consent or knowledge. The coalition argues 23andMe must comply with state laws requiring express informed consent for the sale or transfer of sensitive genetic data. The lawsuit seeks to prevent misuse, exposure in future breaches, and unauthorized use of customers’ private genetic information.
$750K
The FTC finalized an order against Vanilla Chip LLC (doing business as TruHeight) and its principals for deceptively advertising height-enhancing supplements for children and teens without scientific evidence. The company also used fake reviews and incentivized 5-star ratings. The order requires a $750,000 payment and prohibits false health claims and deceptive review practices.
$2.3M
The FTC alleged that RentGrow, a tenant screening company, violated the Fair Credit Reporting Act (FCRA) by failing to use reasonable procedures to ensure the accuracy of its reports, including by reporting duplicate records and failing to disclose data sources. RentGrow agreed to pay a $2.25 million penalty and is prohibited from further FCRA violations and from misrepresenting dispute outcomes.