Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document references separate regional privacy notices for EEA, UK, and Switzerland users, indicating that the full privacy framework for these user populations is governed by documents beyond this Privacy Statement.
This analysis describes what 23andMe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision indicates that the privacy terms applicable to EU, UK, and Swiss users are contained in separate regional notices, which means this Privacy Statement alone does not constitute the complete disclosure for those populations. Compliance assessment for these regions requires review of the referenced regional notices.
Interpretive note: The content of the referenced regional notices is not included in this document, and a complete compliance assessment for EU, UK, and Swiss users requires review of those separate documents.
The updated privacy statement no longer explicitly directs users to a separate Medical Record Privacy Notice for telehealth services or explains that medical information collected through telehealth is governed by different privacy rules. Previously, the policy stated that users choosing telehealth services coordinated through 23andMe would find healthcare privacy protections described in a separate notice. That reference is now absent from the main privacy statement. Users seeking privacy information specific to telehealth services will need to determine independently whether a separate notice exists or contact 23andMe directly using the provided contact information.
View change record →The updated privacy statement no longer explicitly discloses a separate Medical Record Privacy Notice that previously described how medical information is used, disclosed, and maintained for telehealth services. Users who receive telehealth services coordinated through 23andMe may now lack clear notice of which privacy framework governs their medical records, since the reference to that parallel notice has been removed. The organizational scope change from '23andMe Research Institute' to '23andMe' narrows the explicitly named entities responsible for the policy, though operational impact depends on how these entities actually function.
View change record →Under this architecture, EU, UK, and Swiss users are subject to separate privacy notices that may contain additional rights, mechanisms, or disclosures beyond those described in this Privacy Statement. Users in those regions should review the applicable regional notice to understand the full scope of their data rights.
Cross-platform context
See how other platforms handle Regional Privacy Notices for EEA, UK, and Switzerland and similar clauses.
Compare across platforms →Monitoring
23andMe has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Quick links US Privacy How we use information Cookie Policy EEA, UK and Switzerland Privacy Notice Transparency Report Full Privacy StatementExcerpt from 23andMe's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision implicates GDPR (EU/EEA), UK GDPR, and the Swiss Federal Act on Data Protection. Each framework imposes distinct requirements on notice content, data subject rights, consent mechanisms, and cross-border data transfer safeguards. The referenced regional notices must satisfy the transparency requirements of each applicable framework. (2) GOVERNANCE EXPOSURE: Medium. A layered notice architecture is a recognized approach under GDPR but requires that each layer be consistent with the others and that all required information is disclosed at the appropriate layer. Inconsistencies between the global Privacy Statement and regional notices create compliance exposure. (3) JURISDICTION FLAGS: Heightened exposure exists for EU/EEA users under GDPR, UK users under UK GDPR following Brexit, and Swiss users under the revised Swiss Federal Act on Data Protection. Each jurisdiction has distinct enforcement authorities and may require specific disclosures or mechanisms not present in the global notice. (4) CONTRACT AND VENDOR IMPLICATIONS: Cross-border data transfers from EU/EEA to the US must be covered by appropriate transfer mechanisms (Standard Contractual Clauses, adequacy decisions, or similar). Legal teams should verify that transfer mechanisms are in place and disclosed in the regional notices. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a full cross-document audit of all regional notices against this Privacy Statement to confirm consistency, completeness, and compliance with each applicable regional framework. Transfer mechanism documentation should be reviewed and updated as required.
This provision indicates that the privacy terms applicable to EU, UK, and Swiss users are contained in separate regional notices, which means this Privacy Statement alone does not constitute the complete disclosure for those populations. Compliance assessment for these regions requires review of the referenced regional notices.
Under this architecture, EU, UK, and Swiss users are subject to separate privacy notices that may contain additional rights, mechanisms, or disclosures beyond those described in this Privacy Statement. Users in those regions should review the applicable regional notice to understand the full scope of their data rights.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by 23andMe.