Back to Explorer
UK GDPRHealthcare

23andMe

Data Subject Rights

Authority

ICO

Country

United Kingdom

Date Issued

June 4, 2025

Industry

Healthcare

Summary

The UK Information Commissioner's Office issued a monetary penalty to 23andMe for GDPR violations related to inadequate data protection practices and failure to properly handle data subject rights requests.

Violation Types

Data Subject RightsSecurityConsent

Articles Violated

Avoid enforcement risk with automated compliance

IQWorks helps organizations automate UK GDPR compliance before regulators come knocking.

Talk to an Expert