23andMe · Trust Center

23Andme Trust Center

Trust center

23andMe maintains a public trust center documenting HIPAA Compliance, ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27018, Genetic Information Nondiscrimination Act (GINA), General Data Protection Regulation (GDPR), State Consumer Privacy & Health Privacy Laws (U.S.), FDA Authorization, and Common Rule compliance.

CompanyHealth TechGeneticsGenomicsDNA TestingAncestryConsumer HealthBioinformaticsPrecision MedicinePharmacogenomicsTelehealthHealth Research
Trust center: https://www.23andme.org/trust-center/

Certifications & Compliance

HIPAA ComplianceISO/IEC 27001ISO/IEC 27701ISO/IEC 27018Genetic Information Nondiscrimination Act (GINA)General Data Protection Regulation (GDPR)State Consumer Privacy & Health Privacy Laws (U.S.)FDA AuthorizationCommon Rule

Source

Trust Center

23andme-trust-center.yml Raw ↑
generated: '2026-08-15'
method: searched
probe: true
source: https://www.23andme.org/trust-center/
url: https://www.23andme.org/trust-center/
note: >-
  Upgraded on 2026-08-15 from the live first-party Trust Center. The prior record
  pointed at trust.23andme.com, which now 301s to trust.23andme.org and answers a
  Cloudflare managed challenge (403) to anonymous requests. The certification list
  below was read verbatim from the "Compliance — Certifications, Regulations and
  Standards" section of the canonical Trust Center page.
certifications:
- HIPAA Compliance
- ISO/IEC 27001
- ISO/IEC 27701
- ISO/IEC 27018
- Genetic Information Nondiscrimination Act (GINA)
- General Data Protection Regulation (GDPR)
- State Consumer Privacy & Health Privacy Laws (U.S.)
- FDA Authorization
- Common Rule
lab_accreditations:
- CLIA-certified U.S. laboratories (genotyping and exome sequencing)
- CAP-accredited (Total Health exome processing)
audit:
  scheme: ISO/IEC 27001 / 27701 / 27018
  systems:
  - Information Security Management System (ISMS)
  - Privacy Information Management System (PIMS)
  cadence: annual
  auditor: accredited third party
  quote: >-
    "23andMe's ISMS and PIMS are audited by an accredited third party on an annual
    basis."
  penetration_testing: >-
    "we hire outside experts to perform extensive annual penetration tests on our
    systems."
superseded:
  previous_url: https://trust.23andme.com/
  previous_status: 301
  redirects_to: https://trust.23andme.org/
  redirect_status: 403
  removed_claim: PCI DSS
  removed_claim_note: >-
    A prior pass recorded PCI DSS from the legacy trust portal. It is NOT among the
    nine certifications named on the current first-party Trust Center and could not be
    re-verified on 2026-08-15, so it has been moved to conformance/ as `unknown`
    rather than carried forward.
evidence:
- source: https://www.23andme.org/trust-center/
  status: 200
  keywords:
  - hipaa compliance
  - iso/iec 27001
  - iso/iec 27701
  - iso/iec 27018
  - fda authorization
  - common rule
- source: https://www.23andme.org/security/
  status: 200
  keywords:
  - certified under the global iso/iec 27001, 27701, and 27018 standards
  - information security management system
  - privacy information management system