The agency slated to amass genetics testing enterprise 23andMe has moved rapidly to reassure prospects and regulators about its knowledge safety and privateness credentials.
Regeneron Prescription drugs stated in a press launch yesterday that it could purchase 23andMe’s Private Genome Service (PGS), Whole Well being and Analysis Companies enterprise traces, alongside its Biobank and related belongings, for $256m. Topic to chapter courtroom and regulatory approvals, the deal is anticipated to shut within the third quarter.
The agency stated it “intends to make sure compliance” with 23andMe’s shopper privateness insurance policies and any “relevant legal guidelines” relating to the dealing with of buyer knowledge. It added that it could define its proposed use of buyer knowledge, in addition to the privateness applications and safety controls it plans to place in place, for overview by an unbiased Buyer Privateness Ombudsman and different events.
The appointment of that ombudsman was ordered by a chapter decide in April – a move welcomed by privacy regulators the UK Info Commissioner’s Workplace (ICO) and the Workplace of the Privateness Commissioner of Canada (OPC).
Because the buyer genetic knowledge that 23andMe holds is classed as “particular class” knowledge, it’s thought of extremely delicate and topic to stricter guidelines below the GDPR and its Canadian equal (PIPEDA).
Within the US, there isn’t any uniform federal privateness regulation, however as a substitute varied relevant state legal guidelines. Well being knowledge safety regulation HIPAA doesn’t cowl direct-to-consumer firms like 23andMe.
“As a world chief in human genetics, Regeneron Genetics Middle is dedicated to and has a confirmed observe file of safeguarding the genetic knowledge of individuals throughout the globe, and, with their consent, utilizing this knowledge to pursue discoveries that profit science and society,” stated Aris Baras, SVP and head of the Regeneron Genetics Middle.
“We guarantee 23andMe prospects that we’re dedicated to defending the 23andMe dataset with our excessive requirements of knowledge privateness, safety and moral oversight and can advance its full potential to enhance human well being.”
Going Above and Past
The UK and Canadian knowledge safety regulators penned a joint letter earlier this month calling for the continued safety of 23andMe prospects’ knowledge, and warning that they “will take motion” if this doesn’t occur.
Any new knowledge safety controls deployed by Regeneron would in all probability want to supply additional safety assurances to regulators, given the major breach that occurred at 23andMe in 2023 by which knowledge on almost seven million people was compromised.
Hackers initially gained entry to a small variety of person accounts by way of beforehand compromised credentials, as a result of these accounts weren’t protected by multi-factor authentication (MFA). Nonetheless, they had been subsequently in a position to scrape knowledge from further customers who had registered with the DNA Family function by way of opt-in.
23andMe was criticized at the time for making an attempt in charge prospects for the incident.