California Barred from Damages in 23andMe 2023 Data Breach Case

A recent U.S. bankruptcy court ruling has blocked California’s pursuit of monetary damages from the successor of 23andMe following a significant 2023 data breach that exposed personal genetic information. This decision, issued on July 10 by U.S. Bankruptcy Judge Brian Walsh in St. Louis, holds profound implications for how states can enforce consumer protection laws against companies undergoing Chapter 11 reorganization.
The Court’s Decisive Stance on Monetary Claims
Judge Brian Walsh’s ruling emphatically states that California is precluded from seeking monetary relief against Chrome Holding Co—the entity formerly known as 23andMe—and its affiliate, stemming from the fallout of the 2023 data breach. This pivotal judgment mandates that California either dismiss its May 28 lawsuit in San Francisco Superior Court within 14 days or revise its complaint to eliminate all claims for financial compensation. The initial lawsuit accused 23andMe of having disregarded clear warnings about system vulnerabilities and subsequently minimizing the severity of the intrusion.
The breach, which came to light in 2023, compromised genetic and other sensitive personal details belonging to an estimated 6.9 million customers. Can a corporate reorganization effectively shield a company from accountability for such a widespread privacy violation? While the state is barred from monetary recovery, the door remains open for non-monetary remedies, although their specific nature and potential impact have yet to be fully defined. This distinction highlights a critical juncture in data privacy litigation, raising questions about the scope of state-level consumer protection in an era of complex corporate financial maneuvers.
“Because the state was a party to the Chapter 11 case and was given a fair chance to challenge this court’s subject-matter jurisdiction, the state cannot challenge it now by pursuing its lawsuit.”
The state’s legal challenge sought potentially millions of dollars in civil fines, a significant sum intended to penalize the alleged negligence and deter future breaches. Yet, the bankruptcy court’s preclusion order appears to nullify this financial avenue for the state. This legal landscape suggests a powerful mechanism for companies to compartmentalize liabilities, potentially at the expense of robust state enforcement actions. Is this an equitable outcome for millions of affected individuals?
California’s Unsuccessful Challenge and AG Bonta’s Concerns
California Attorney General Rob Bonta vehemently opposed the preclusion, arguing that the U.S. Congress never intended to grant bankruptcy judges the authority to prohibit state law-based enforcement actions in state courts. Bonta expressed deep concern that allowing such preclusions would permit bankruptcy courts to become nothing short of “a haven for wrongdoers.” His office has not yet publicly commented on the latest ruling, signaling a moment of significant recalibration for the state’s legal strategy.
Judge Walsh, however, directly countered Bonta’s assertion, stating that 23andMe’s reorganization plan did not, in fact, create such a haven. Furthermore, Walsh asserted that even if it had, California was a party to the Chapter 11 case and had ample opportunity to challenge the court’s subject-matter jurisdiction previously. This procedural detail proved fatal to the state’s current bid for financial recompense. Considering the sensitive nature of genetic data, which can reveal deeply personal health information and ancestry, does this legal interpretation adequately protect consumers?
The precedent set here could have far-reaching implications, potentially influencing how other states approach data breaches when the offending company enters bankruptcy. Historically, data breaches have often led to substantial fines and legal actions, particularly in California, a state known for its stringent privacy laws. This ruling starkly contrasts with many past cases, where state attorneys general have successfully leveraged civil penalties to compel corporate compliance and secure consumer restitution. The ability of a Chapter 11 process to limit punitive damages raises fundamental questions about the balance of power between state regulatory authority and federal bankruptcy jurisdiction.
The Bankruptcy Backdrop and Customer Compensation
The legal battle over the 2023 data breach unfolds against the backdrop of 23andMe’s Chapter 11 bankruptcy filing in March 2025. This filing for protection from creditors fundamentally reshaped the landscape for addressing claims against the company. Crucially, Judge Walsh had previously approved the creation of a fund aimed at resolving the majority of U.S. customer claims arising from the breach.
This fund was established roughly four months before California initiated its lawsuit in San Francisco. On Tuesday, a payment of $32.46 million was authorized from this fund, adding to a prior disbursement of $14.29 million, bringing the total payout to affected customers to an aggregate of $46.75 million. Are these payouts truly commensurate with the long-term risks associated with compromised genetic data, especially when considering the potential for identity theft or targeted discrimination? The financial restitution provided through this channel remains separate from the monetary fines sought by the state, illustrating distinct legal pathways.
Further to the restructuring, TTAM Research Institute, a nonprofit organization controlled by 23andMe co-founder Anne Wojcicki, acquired 23andMe’s assets for $305 million in July 2025. This acquisition underscores the strategic moves made during the bankruptcy process to redefine the company’s financial and operational structure. The question remains: how effectively do these financial and legal mechanisms serve the millions of individuals whose most intimate personal data was exposed in the 2023 data breach?
The Last Thing You Need to Know About the 2023 Data Breach Fallout
This ruling marks a pivotal moment, effectively limiting California’s ability to levy financial penalties against a company emerging from Chapter 11 bankruptcy for a prior data security lapse. While the state can still pursue non-monetary remedies—such as requiring enhanced data security protocols or other injunctive actions—the inability to seek direct civil fines diminishes its punitive power. For individuals affected by the 2023 data breach, this underscores that relief channels often channel through bankruptcy settlements or class-action lawsuits rather than state-initiated punitive actions.
The case highlights a growing tension between state efforts to hold corporations accountable for data privacy failures and the protective mechanisms offered by federal bankruptcy law. What does this mean for the future of consumer privacy, particularly as more companies collect and manage highly sensitive personal data? It emphasizes the intricate interplay of legal jurisdictions and corporate restructuring in determining the ultimate recourse for data breach victims. Investors and consumers alike must recognize the complexities inherent in seeking justice when corporate liabilities are redefined through the bankruptcy process.
Genetic Data Breach Legal Implications – Disclaimer
This article offers an economic and legal analysis of the 23andMe data breach and subsequent court ruling, not financial or legal advice. The information is for informational purposes only and does not replace consultation with a qualified legal professional regarding individual circumstances or specific data breach claims. Outcomes in legal cases can vary widely based on unique facts and applicable laws. Always seek expert advice for your particular situation.




