Consent Did Not Survive Bankruptcy

The 23andMe bankruptcy is not just a privacy story. It is a warning about what happens when permanent biological data sits inside a temporary corporate structure.

Avihu Marom · · 6 MIN READ

23andMe DNA collection kit, saliva tube, Chapter 11 bankruptcy filing, and confidential genetic data folders on a legal review desk.

Consent Did Not Survive Bankruptcy

The Break

Genetic data does not become less sensitive when the company holding it runs out of money.

It becomes more exposed.

That is the 23andMe signal.

Not a failed consumer DNA company.

Not another startup that lost demand after a hyped public listing.

The real story is what happens when permanent biological information sits inside a temporary corporate structure.

23andMe filed for Chapter 11 bankruptcy in March 2025. Reuters reported that the company held genetic data from about 15 million customers and was seeking a buyer. The FTC warned the bankruptcy court about consumer concerns over any sale or transfer of that data. More than 25 states pushed for stronger oversight, and the court approved a consumer protection ombudsman to review data handling and any sale implications.

The uncomfortable point is simple.

Consent was given in one business context.

Bankruptcy moved the data into another.

The Hidden Pattern

The asset was not only the database. The asset was the control environment around the database.

That distinction matters.

People usually think about sensitive data through privacy policies, consent checkboxes, account settings, and deletion rights.

Those mechanisms assume the company remains stable enough to honor the original relationship.

Financial distress changes the map.

Once a company enters bankruptcy, the data does not sit inside a normal customer relationship anymore.

It enters a creditor process, an auction process, a buyer-review process, and a court-supervised restructuring process.

The customer remains genetically exposed.

The company’s incentives change.

That is the gap.

23andMe said its bankruptcy would not change how it stores, manages, or protects customer data.

That may be true at the policy level.

It does not remove the structural problem.

A distressed company has to preserve value.

For a genetics company, value lives in the dataset, the biological samples, the research permissions, the customer relationships, and the future ability to use those assets under a new owner.

That is why the oversight response escalated.

Reuters reported that U.S. national security agencies warned a sale to a foreign buyer could require CFIUS review, especially if the buyer had ties to adversary countries such as China, Russia, or Iran.

That moves the case out of ordinary privacy territory.

Genetic data can become a national-security asset because it can support population-level research, targeting, coercion, discrimination, and intelligence analysis.

Then came the state-level fight.

AP reported that 27 states and Washington, D.C. sued to block any sale of 23andMe personal genetic data without explicit customer consent.

Their argument was blunt: genetic and health data should not be treated like ordinary bankruptcy assets.

Regeneron initially agreed to buy 23andMe for $256 million and said it would maintain privacy policies and comply with existing law.

Later, Anne Wojcicki’s nonprofit TTAM Research Institute won with a $305 million bid and committed to maintain privacy protections and adopt additional safeguards.

That sequence proves the real issue.

Even when the buyer promises safeguards, the customer has already lost something.

Control timing.

The customer is no longer deciding whether to enter a genetics service.

The customer is reacting to a court process after the data already exists.

That is not consent.

That is damage control.

The 2023 breach adds another layer.

Reuters reported that 23andMe agreed to settle litigation over a breach that exposed data of millions of customers. The UK Information Commissioner later fined 23andMe £2.31 million after finding failures to implement appropriate security measures for UK users following the 2023 cyberattack.

Read those two events together.

First, the data was exposed through security failure.

Then, the remaining data entered a bankruptcy sale environment.

That is the lifecycle risk most boards still do not map.

They ask whether sensitive data is secure today.

They do not ask what happens if the company holding it collapses tomorrow.

The Uncomfortable Truth

A privacy promise is only as strong as the corporate structure behind it.

That is the part most data-heavy companies avoid.

The privacy team can write strong language.

The product team can design consent flows.

The security team can harden systems.

The legal team can document retention rules.

But if the company has no distress protocol for sensitive data, the whole trust architecture depends on financial health.

That is not enough.

This applies far beyond genetic testing.

Any company holding biometric, health, location, children’s, behavioral, workplace, fertility, mental-health, or identity data has the same problem.

The data may be collected under one promise and transferred under another pressure environment.

  • A funding crunch changes incentives.
  • A merger changes access.
  • A bankruptcy changes control.
  • A creditor process changes leverage.
  • A buyer changes future use.
  • A foreign bidder changes national-security exposure.

This is the board-level lesson.

Data governance cannot stop at compliance while the business is healthy.

It needs a collapse plan.

  • Who controls the data if the company is sold?
  • Who can bid for it?
  • Which data categories are non-transferable without renewed consent?
  • What happens to biological samples?
  • What happens to research permissions?
  • How fast can customers delete data and samples?
  • Who verifies deletion?
  • What restrictions survive a bankruptcy sale?

These are not theoretical questions.

23andMe forced regulators, courts, customers, and bidders to fight those questions in public.

That is failure of design.

Not because every actor behaved badly.

Because the original trust model did not fully account for corporate mortality.

The Hard Stop

The real risk was not that people gave genetic data to 23andMe.

The real risk was that they gave permanent biological information to a temporary company.

That is the operating failure.

Sensitive data needs a death plan.

Without one, consent does not survive distress.

It becomes an asset schedule.