23andMe changed its terms of service to prevent hacked customers from suing
23andMe is facing backlash after updating its terms of service to add binding arbitration and class‑action waivers shortly after a breach exposed data tied to millions of genetic testing customers. Commenters question the legality and enforceability of retroactive terms, share opt‑out instructions, and contrast weak U.S. consumer protections and arbitration norms with stricter EU rules. The incident also reignites broader concerns about commercial DNA testing, including the permanence and misuse of genetic data, versus its potential medical benefits.
ToS Change and Arbitration Clause
- 23andMe updated its Terms of Service shortly after the breach to strengthen binding arbitration, class‑action waivers, and add “mass arbitration” handling.
- Many see the timing as an attempt to limit liability for the recent hack; others note companies routinely change ToS and lawyers often advise silence during litigation.
Enforceability and Legal Debate
- Several argue retroactive limitation of rights is unlikely to hold for harms that occurred under the old ToS; courts would look at terms in force at time of breach.
- Others note the Federal Arbitration Act makes arbitration clauses hard to invalidate and warn against assuming courts will protect consumers.
- Some describe the change as potentially unconscionable, “fraud in the factum,” or even contractual fraud; others caution not to confuse “unjust” with “illegal.”
- A lawyer in the thread says adding a class waiver is legally possible; whether it applies to pre‑existing claims will be a live issue.
Opt‑Out Mechanics and User Actions
- New ToS deems users to have accepted changes unless they opt out within 30 days, typically by emailing [email protected] (addresses in emails/ToS vary).
- People share opt‑out email templates and advise sending to multiple addresses; some report bounces from legal@.
- Confusion and anger that consent can be implied via silence, especially if notices land in spam.
Data Breach, Security, and Scope
- Users ask what exactly was leaked; the thread cites names, locations, ancestry trees, family networks, and other profile data; underlying genetic data exposure is described as unclear.
- Some criticize password requirements and post‑breach measures as “security theater”; others counter that one breach doesn’t prove systemic incompetence.
- Several urge deleting accounts and requesting sample/data destruction, while noting prior sales/sharing or regulatory access can’t be undone.
Genetic Privacy vs. Utility
- Strong split: some always considered sending DNA to a startup obviously risky; others emphasize past optimism about “innovative” companies and health benefits.
- Pro‑testing side cites potential for precision medicine, disease markers, and ancestry discovery; some security professionals say they knowingly traded genomic privacy for health insight.
- Skeptical side highlights irreversibility of DNA exposure, potential future discrimination (e.g., insurance, employment, law‑enforcement), and spillover harms to relatives who never consented.
- Debate over whether DNA is currently “worse” than leaking email/phone; some see it as only mildly sensitive today, others argue future risks are unknown but potentially large.
US vs. EU / Consumer Protection
- Multiple comments contrast US adhesion contracts and unilateral ToS changes with stricter EU rules on unfair terms and surprise changes.
- EU posters suggest such automatic opt‑ins and arbitration clauses would likely be invalid or non‑binding for consumers there.
Class Actions, Mass Arbitration, and Remedies
- Some expect class actions and note existing filings; others point to “mass arbitration” as a new tactic that can become costly for companies despite arbitration clauses.
- There is interest from non‑customers whose relatives used the service; unclear if and how they can join suits based on derivative harm.