Section 363(b)(1) protects your data only if the company promised not to transfer it. 23andMe's policy promised the opposite, so the brake was never armed. The law worked as written.
On 3 March 2025 the Internet Archive took a copy of 23andMe's full privacy statement. Under a heading that reads "Commonly owned entities, affiliates and change of ownership," it says: "If we are involved in a bankruptcy, merger, acquisition, reorganization, or sale of assets, your Personal Information may be accessed, sold or transferred as part of that transaction and this Privacy Statement will apply to your Personal Information as transferred to the new entity."
Eighteen days later, on 21 March, California's attorney general issued a consumer alert telling the company's customers to delete their genetic data and ask for their saliva samples to be destroyed. Two days after that, on 23 March, 23andMe filed for Chapter 11 in the Eastern District of Missouri. In May a drug company won the auction for the business at $256 million. In June the founder's nonprofit reopened the bidding and won at $305 million. Twenty-seven states and the District of Columbia sued to stop the data of roughly 15 million customers changing hands without fresh consent. A court-appointed privacy ombudsman wrote 211 pages recommending that consent be obtained. On 27 June the judge approved the sale anyway.
I want to explain why that outcome was not a failure of the law. The law worked as written. The sentence that decided the case was the one from 3 March, and the people it governed had never negotiated it.
The Bankruptcy Code does contain a protection for personal data in an asset sale. Section 363(b)(1) says that if a debtor, in offering a product or service, "discloses to an individual a policy prohibiting the transfer of personally identifiable information about individuals to persons that are not affiliated with the debtor," and that policy is in force on the day the case begins, then the trustee may not sell that information unless the sale is consistent with the policy, or unless a consumer privacy ombudsman is appointed and the court approves the sale after a hearing.
Read the trigger slowly. The protection attaches when the company promised not to transfer. 23andMe's policy promised the opposite: your information "may be accessed, sold or transferred." The brake was installed for a policy that says no, and the policy said yes. So the branch of the statute that everyone argued about in June, the ombudsman and the hearing, was the fallback, and even the fallback sets its bar low. The court may approve on "finding that no showing was made" that the sale would violate other law. Not a finding that the sale complies. A finding that nobody proved otherwise.
That is what happened. Judge Brian C. Walsh, in approving the sale to TTAM Research Institute on 27 June 2025, wrote that the deal "involves a sale of customer data only in a technical sense," and that while selling genetic data "is a scary proposition," lawmakers had not banned it. The states had argued that biological samples, DNA data and health records are too sensitive to be sold without each person's express, informed consent. The ombudsman, Professor Neil Richards of Washington University, had recommended "separate and affirmative" consent before any sale to either bidder. Both were overruled, and on 14 July TTAM completed the acquisition.
None of this was unlawful, and the buyer is accused of nothing here. That is the point. The consumer-protection branch of a federal statute was switched off years before the case by a boilerplate sentence, written by the company the statute was meant to constrain, that appears in nearly every privacy policy you have ever clicked through.
Section 332 of the Code describes the fallback in more detail than the coverage did. The court orders the ombudsman appointed "not later than 7 days before the commencement of the hearing." The ombudsman may present the debtor's privacy policy, the potential losses or gains of privacy to consumers, the costs and benefits, and alternatives that would mitigate privacy losses. The ombudsman "shall not disclose any personally identifiable information."
One disinterested person, appointed a week before the hearing, to represent the privacy interest of everyone in the database, and forbidden from disclosing what they see. That is not a criticism of Professor Richards, whose report ran to 211 pages and took more than a month. It is the resourcing the statute specifies. His report drew on messages from customers, many of whom described the difficulty of deleting their own accounts and the accounts of relatives who had died. Deleting a dead relative's genome is, it turns out, not a personal act either.
The database went to the buyer. So did the brand. What stayed behind is visible on the docket kept by Kroll, the court's claims agent. By an order dated 11 September 2025, the debtors were renamed: 23andMe Holding Co. became Chrome Holding Co., 23andMe, Inc. became ChromeCo, Inc., and 23andMe Pharmacy Holdings became Chrome Pharmacy Holdings. All the cases were closed on 21 January 2026 except Chrome Holding Co.
The docket also carries a "Notice of Deadline for Filing Cyber Security Incident Proofs of Claims." That deadline is the tail of the breach that started the collapse. Between April and September 2023 an attacker ran a credential-stuffing campaign against the site, logging in with passwords reused from other breaches. About 14,000 accounts were entered that way. Through the relative-matching features those accounts opened onto the profiles of roughly 6.9 million people, which is the cousin problem in miniature: the security of your record depended on the password hygiene of everyone who shared a segment of DNA with you. The company agreed a $30 million class settlement in September 2024. The UK's Information Commissioner fined it £2.31 million on 17 June 2025 for failing to require multi-factor authentication and for weak controls on raw genetic data, after a joint investigation with Canada's privacy commissioner.
The people harmed by the breach did not have a claim against the buyer. They became unsecured creditors of a shell with a new name and a filing deadline. The asset sale moved the record. It did not move the promise, or the liability for breaking it.
Every attorney general said the same thing: delete. It is good advice and it reaches less than it sounds.
The first ceiling is written into the same policy. "You can change your mind any time about your participation, however any Research involving your data that has already been performed or published prior to your withdrawal from 23andMe Research will not be reversed, undone, or withdrawn." The company has said for years that about 80 percent of its customers consented to research, and that consent was the basis of a business: in July 2018 GSK paid $300 million for a stake and a drug-discovery collaboration built on the consented data. The genome had been sold once before the bankruptcy sold it again. Deletion cannot reach a study that has already run, and the policy says so.
The second ceiling is the relative. On 24 April 2018 police in Sacramento arrested Joseph James DeAngelo, the man later convicted as the Golden State Killer. He had never given anyone his DNA. Investigators had uploaded a crime-scene profile to GEDmatch, a free genealogy database, and found more than a hundred distant relatives, some as close as third cousins. They built family trees from those matches until one branch held a man of the right age in the right places, then picked a tissue out of his trash to confirm it. A first cousin shares about an eighth of your DNA and a sibling about half, and neither of them needs your permission to spit in a tube. Your genome is not a personal record. It is a shared one, and you hold one copy.
The third ceiling is the one the bankruptcy exposed. The consent that mattered was never the checkbox. It was structural: who may own the database, under what change-of-control terms, and what the research consent already licensed. Each customer could tick or untick a box; none of them could edit the sentence under "change of ownership," and that sentence was the one the court read.
There is a technology for making a record carry its own history. Content Credentials, the C2PA standard, attach a signed manifest to a photo or video that records where it came from and what was done to it, and the manifest is bound to the file cryptographically. Strip it and the file arrives with no credentials at all, which a checking platform can see; alter the file and the signature no longer validates. The promise about the asset travels with the asset.
Nothing like that exists for consent. What travelled with the 23andMe database was the second half of the sentence from 3 March: "this Privacy Statement will apply to your Personal Information as transferred to the new entity." A privacy statement is a unilateral document that the new owner may amend. What crossed the table was not a promise. It was a document, and the next owner holds the pen.
In fairness, the pen has been used well so far. The current policy, hosted at the nonprofit's domain, adds a clause the old one lacked: "We will not sell or transfer your genetic data in connection with any merger, acquisition, bankruptcy, reorganization, or asset sale unless the buyer is also a U.S. nonprofit research institution or for-profit entity that satisfies all requirements of the Committee on Foreign Investment in the United States." That is a real narrowing, and it did not arrive alone. When TTAM won the bidding on 13 June it made binding commitments: to honor the existing rights to delete an account and to opt out of research, in perpetuity; to email every customer at least two business days before closing with instructions for doing either; to seat a consumer privacy advisory board within ninety days; not to transfer genetic data in any later bankruptcy or change of control unless the recipient adopts the same policies; and to pay for two years of identity monitoring. The judge's approval leaned on those commitments, and they are more than most buyers offer.
Read the new clause against the statute, though, and notice that it still describes the transfers it permits. A sale to a qualifying buyer would be consistent with the policy, which is the branch of section 363 that requires no ombudsman at all. The clause is better. It is still a clause, in a document the owner can edit, and the next owner will inherit the pen along with the freezer.
If you build a product that collects data people cannot change, and genetic data is the clearest case but biometrics, health records and children's data are close behind, the protective branch of section 363(b)(1) is a sentence you control. Write "we will not transfer personal information to persons not affiliated with us," keep it in force, and the statute's brake engages the day you file. The boilerplate that says "may be sold or transferred" is not a neutral default. It is a choice to disable a protection your users would probably have wanted, made on their behalf, by you.
If you want consent to survive a sale, put it where sales are negotiated. A covenant in the asset purchase agreement that binds the buyer to the research-consent terms, with a right for the ombudsman or a state to enforce it, is a promise that moves with the record. A privacy statement is not. The ombudsman's report is a usable checklist for what such a covenant should contain: separate and affirmative consent for any new use, direct notice of the transaction to each person rather than a policy update, safeguards for the data of people who have died, and the right to withdraw from research going forward. Every one of those was recommended in June 2025 and none of them was required by the statute.
If you are a customer, delete, by all means. It reaches your account, your sample if you ask, and your participation in research from today forward. It does not reach the research already done, and it does not reach your cousin. The decision that mattered was made before the tube went in the mail, and it was made by reading, or not reading, one paragraph under "change of ownership." If you want to see the rest, the docket is free on the claims agent's site: Chrome Holding Co., formerly 23andMe Holding Co., case 25-40976, Eastern District of Missouri. Large bankruptcies keep their filings on a claims agent's page at no charge, which is where the sale order, the ombudsman's report and the renaming order all sit; the federal PACER system charges by the page for the same documents, and the RECAP archive mirrors what other readers have already paid for. Read the sale order before the press release. The order says what the buyer is bound to; the release says what the buyer intends.
The record was sold twice. The promise stayed behind, under a new name, on a docket with a deadline.
Sources: 23andMe Privacy Statement, full version, as captured by the Internet Archive on 3 March 2025 (the pre-petition "change of ownership" and research-withdrawal clauses). https://web.archive.org/web/20250303073415/https://www.23andme.com/legal/privacy/full-version/ · 23andMe Privacy Statement, current version at the nonprofit's domain (the added genetic-data transfer restriction). https://www.23andme.org/legal/privacy/full-version/ · 11 U.S.C. § 363(b)(1) (sale of personally identifiable information in bankruptcy). https://www.law.cornell.edu/uscode/text/11/363 · 11 U.S.C. § 332 (consumer privacy ombudsman). https://www.law.cornell.edu/uscode/text/11/332 · Kroll Restructuring Administration, official claims agent, case page for Chrome Holding Co., formerly 23andMe Holding Co., No. 25-40976, U.S. Bankruptcy Court for the Eastern District of Missouri (petition date, successful and backup bidders, sale order of 27 June 2025, name-change order of 11 September 2025, case closures of 21 January 2026, cyber-incident claims bar date). https://restructuring.ra.kroll.com/23andMe/ · California Department of Justice, "Attorney General Bonta Urgently Issues Consumer Alert for 23andMe Customers," 21 March 2025. https://oag.ca.gov/news/press-releases/attorney-general-bonta-urgently-issues-consumer-alert-23andme-customers · Regeneron Pharmaceuticals, "Regeneron Enters into Asset Purchase Agreement to Acquire 23andMe for $256 Million," 19 May 2025. https://investor.regeneron.com/news-releases/news-release-details/regeneron-enters-asset-purchase-agreement-acquire-23andmer-256/ · The Washington Post, "23andMe gets bid from former CEO, upending sale to drugmaker Regeneron," 5 June 2025. https://www.washingtonpost.com/business/2025/06/05/23andme-bankruptcy-auction-bidding/ · 23andMe Media Center, "23andMe Reaches Agreement for Sale of Business to TTAM Research Institute Following Final Round of Bidding in Court-Approved Sale Process," 13 June 2025 (the $305 million price and TTAM's binding privacy commitments). https://mediacenter.23andme.com/press-releases/23andme-reaches-agreement-sale-business-ttam-research-institute/ · NPR, "What happens to all of 23andMe's genetic DNA data?", 3 October 2024 (the roughly 80 percent research-consent rate and the research program's publication count). https://www.npr.org/2024/10/03/g-s1-25795/23andme-data-genetic-dna-privacy · NPR, "Dozens of states sue to block the sale of 23andMe personal genetic data," 10 June 2025. https://www.npr.org/2025/06/10/nx-s1-5429041/23andme-states-lawsuit-genetic-data · New York Attorney General, "Attorney General James Sues 23andMe to Protect New Yorkers' Genetic Data," June 2025. https://ag.ny.gov/press-release/2025/attorney-general-james-sues-23andme-protect-new-yorkers-genetic-data · Richards, N. M., Report of the Consumer Privacy Ombudsman, In re 23andMe Holding Co., et al., No. 25-40976 (Bankr. E.D. Mo., June 2025). https://business.cch.com/CybersecurityPrivacy/23andmeombudsmanreport.pdf; also posted as "Report of Prof. Neil Richards, the Consumer Privacy Ombudsman in the 23andMe Bankruptcy Case," SSRN. https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5476672 · The Record, "23andMe privacy ombudsman recommends company obtains consent for sale of customer data," June 2025. https://therecord.media/23andme-privacy-ombudsman-recommends-consent-sale · NPR, "Judge OKs sale of 23andMe, and its trove of DNA data, to a nonprofit led by its founder," 30 June 2025 (Judge Walsh's "only in a technical sense" and "scary proposition" language). https://www.npr.org/2025/06/30/nx-s1-5451398/23andme-sale-approved-dna-data · Bloomberg Law, "23andMe's Genetic Data Sale Shifts Privacy Scrutiny to Buyer," July 2025. https://news.bloomberglaw.com/privacy-and-data-security/23andmes-genetic-data-sale-shifts-privacy-scrutiny-to-buyer · TTAM Research Institute completion of the acquisition of 23andMe, 14 July 2025, as reported in the HIPAA Journal, "Bankruptcy Court Approves Sale of 23andMe." https://www.hipaajournal.com/genetic-testing-company-23andme-files-for-bankruptcy/ · CNBC, "There's just one week left to claim part of 23andMe's $30 million data breach settlement" (the September 2024 class settlement). https://www.cnbc.com/select/23andme-30-million-dollar-settlement/ · Information Commissioner's Office, "23andMe fined £2.31 million for failing to protect UK users' genetic data," 17 June 2025. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/06/23andme-fined-for-failing-to-protect-uk-users-genetic-data/ · Security.org, "23andMe Data Breach: What Was Exposed, Who Was Affected" (the April to September 2023 credential-stuffing timeline and the 6.9 million figure, which the company disclosed in December 2023). https://www.security.org/identity-theft/breach/23andme/ · GSK, "GSK and 23andMe sign agreement to leverage genetic insights for the development of novel medicines," 25 July 2018 (the $300 million investment and collaboration). · CNN, "Police used free genealogy database to track Golden State Killer suspect, investigator says," 26 April 2018. https://www.cnn.com/2018/04/26/us/golden-state-killer-dna-report · NPR, "In Hunt For Golden State Killer, Investigators Uploaded His DNA To Genealogy Site," 27 April 2018. https://www.npr.org/sections/thetwo-way/2018/04/27/606624218/in-hunt-for-golden-state-killer-investigators-uploaded-his-dna-to-genealogy-site · Coalition for Content Provenance and Authenticity, C2PA Technical Specification (Content Credentials manifests and their cryptographic binding to assets). https://c2pa.org/specifications/specifications/
The promise should travel with the asset
The essay's own comparison is C2PA: a signed manifest bound to a file, so stripping it is visible and altering it breaks the signature. Agent systems have the identical gap in a different place. An output is handed on, and the record of what produced it, on what inputs, under what constraints, stays behind with whoever ran it. Chain of Consciousness is a tamper-evident record written as the work happens and bound to the thing it describes, so the account of how a decision was made moves with the decision instead of being reconstructed by its next owner.
Hosted Chain of Consciousness · Verify a record
pip install chain-of-consciousness · npm install chain-of-consciousness