In March 2025, 23andMe filed for Chapter 11 protection under US bankruptcy law. Its genetic database did not evaporate with the company: it became an asset to sell, acquired in July by a nonprofit foundation founded and led by the company's co-founder.
The right to erasure applied throughout. It did not stop the database from changing hands: to have any effect, it had to have been exercised, one person at a time, beforehand.
GDPR is a procedure: it opens remedies against someone. An architecture decides what exists at all. A remedy needs a counterparty; a lock does not.
What article 9 prohibits, and the door people walk through anyway
GDPR article 9 places data concerning health in the special categories. The principle is stronger than most people assume: processing is prohibited. Not regulated, not subject to authorisation. Prohibited by default.
The same article then lists ten situations that lift the prohibition. The first is your explicit consent, the one you give at signup, and it is sufficient on its own. Nothing abnormal about that: it is the intended mechanism, and it is what allows an app to be useful to you at all.
But it moves the subject. The law does not guard the door, it sets the conditions under which you hand over the key.
Your sleep and your stack are health data
The French regulator lists three families: data that is health data by nature, data that becomes health data by combination with other data, and data that becomes health data through the medical use made of it. The second is the underestimated one: the example given is a weight measurement combined with a step count and calorie intake. Nothing medical line by line, and the sensitive data regime applies to the result all the same.
A sleep log, a supplement list with doses and timings, and three months of blood panels clear that bar comfortably. It is a medical file rebuilt by accumulation, with no doctor involved at any point.
Three places where the right runs out
Access, portability, rectification and erasure are real rights. They share one dependency: someone has to be there, able to answer, and reachable by a regulator.
When the company changes hands
In June 2025 the UK data protection authority issued a £2.31 million fine against 23andMe, following a joint investigation with its Canadian counterpart: no mandatory multi-factor authentication, and no proper access controls over raw genetic data.
The attack dated back to 2023. Credential stuffing, meaning mass attempts using passwords stolen in earlier unrelated breaches. The result: access to the information of 155,592 UK residents, including ethnicity, family trees and health reports. The company only opened a full investigation in October, when an employee found the stolen data advertised for sale on Reddit.
« Unlike usernames, passwords and e-mail addresses, you can't change your genetic makeup when a data breach occurs. »
A person affected by the breach, quoted by the ICO, June 2025
The penalty was heavy. It did not restore the confidentiality of what had left, and it did not stop the database from being sold the following month. A fine punishes. It does not repair.
When the host is European and the law is not
«Hosted in Europe» has become a sales argument. It answers a question about location, not a question about jurisdiction.
The US CLOUD Act, passed in 2018, lets American authorities compel a provider subject to US law to disclose the data it holds, wherever the servers sit. The European Data Protection Board and the European Data Protection Supervisor took a position in July 2019: such an order alone is not a valid basis for transfer under GDPR, whose article 48 points to an international agreement.
The two texts say different things, and the provider sits in between. Where the servers sit and which law the operating company answers to are two separate facts, and only the second decides who can compel disclosure.
When «anonymised» does not mean anonymous
Genuinely anonymous data falls outside GDPR. That explains why the word appears in almost every privacy policy.
Removing the name is not enough. A 2019 study in Nature Communications estimates that 99.98% of Americans would be correctly re-identified in any dataset from 15 demographic attributes. Even heavily sampled, the authors conclude, such datasets are unlikely to meet GDPR's anonymisation standard.
Fifteen attributes is not many on a health profile. Age, sex, postcode, height, weight, and the list is already half done.
| Situation | What GDPR provides | What execution depends on |
|---|---|---|
| Data breach | Notification to the authority within 72 hours | The breach being detected, and dated |
| Acquisition or bankruptcy | Rights follow the database to the buyer | The buyer honouring them and staying reachable |
| Foreign disclosure order | Article 48: an international agreement is required | Which law the company answers to |
| «Anonymised» reuse | Anonymous data falls outside the regulation | The anonymisation actually being one |
| Erasure | Reply within one month, no justification needed | The reference copy sitting with them |
The protection that needs no exercising
There is one category of data on which no right needs to be exercised: the data that never left.
The French regulator notes it about mobile health apps: the rules do not apply the same way when data is collected exclusively on the device, with no outside connection and for strictly personal purposes. No controller, no transfer, no processor, because there is nothing to process elsewhere.
That is what local-first means, stripped of the engineering vocabulary: your data is written on your phone first and stays there by default. No central database to breach, and erasure is immediate because the reference copy is already yours.
Questions to ask before handing over your blood work
- 1
Which law does the company answer to?
Not where the servers are: who owns the company, and under which jurisdiction.
- 2
What happens to the database if it is sold?
If the words «merger» or «asset sale» appear nowhere in the privacy policy, nobody thought about it.
- 3
Which processors have access?
The list must be public and current. An analytics vendor has no business inside a biomarker database.
- 4
How long after the account is closed?
A stated duration is expected, per category. «As long as necessary» is not a duration.
- 5
Is the data used for advertising?
If the answer is not a plain no, it is a yes with intermediate steps.
- 6
Is there a reachable DPO and a public register?
A dedicated address and an online register are worth more than any trust badge, and take thirty seconds to check.
What this article does not say
- That GDPR is useless. Without it the UK fine would not exist and no processor list would be public anywhere.
- That European hosting is pointless. It removes an entire class of transfer problems, not the jurisdiction question.
- That local-first is free. Losing your phone without a backup means losing the history. Sharing with a doctor takes an explicit step instead of a link.
- That this is legal advice. It is the reading of someone who has to make these architecture decisions, texts in hand, and would rather show his work.
« Data sovereignty is not a legal checkbox, it is an architecture decision. »
Where Helix stands
Helix is built in Europe, with European hosting and a public processing register: processors, purposes and retention periods are readable without creating an account. Granular consent for anything not required by the service. No advertising, no resale.
Sensitive data stays local-first on your device. That choice is expensive and makes sync harder. It has one advantage, and it is enough: there is no central database whose sale could one day appear in a bankruptcy filing.
Check what is collected, by whom and for how long, before creating an account.
Read the processing register