The agreement states that 23andMe accounts are protected with two-factor authentication as a standard security measure.
This analysis describes what 23andMe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes two-factor authentication as a baseline account security control for a platform holding sensitive genetic and health-related data, which is relevant to regulatory expectations under GDPR Article 32 and FTC data security guidelines.
Interpretive note: The document does not specify the type of two-factor authentication implemented, which affects the strength and verifiability of this security representation.
This new provision highlights security measures as a standalone disclosure, building transparency around account protection mechanisms.
View full change record →Under this provision, all 23andMe accounts are described as protected by two-factor authentication, providing a baseline security layer for accounts holding genetic and personal health information.
How other platforms handle this
You and your organization's administrator can access several types of Service Data directly from Google Cloud, including your account information, billing contact information, payment and transaction information, as well as product and communication settings and configurations.
If you registered to use Notion's Services with such an email address, but you do not use the Services in connection with your organization...you may transfer your account to a different email address.
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
"You create your online account and password. Your account is protected with 2-factor authentication.Excerpt from 23andMe's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision engages GDPR Article 32 (technical measures for data security), FTC guidelines on reasonable data security practices, and California CCPA/CPRA provisions that require reasonable security procedures for personal information.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes two-factor authentication as a baseline account security control for a platform holding sensitive genetic and health-related data, which is relevant to regulatory expectations under GDPR Article 32 and FTC data security guidelines.
Under this provision, all 23andMe accounts are described as protected by two-factor authentication, providing a baseline security layer for accounts holding genetic and personal health information.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by 23andMe.