Every Product You Use Is Another Company You Trust
The Procurement Lesson That Changed How I Think About Privacy
You can change your password. You can change your email. You can even change your phone number. But you can’t change your DNA.
Which is why 23andMe announcing bankruptcy felt so uncomfortable.
The Day I Gave Away my DNA?
I’m in London. It’s 2018. I buy a DNA kit, spit into a tube, send it back, and a few weeks later discover I’m 100% Polish, less likely to get bitten by a mosquito, and somehow related to Marie Antoinette.
Fun. Weird. Slightly addictive dinner conversation.
End of story?
Not quite.
Years later, 23andMe filed for bankruptcy. Suddenly, one of the company’s most valuable assets wasn’t its office furniture, website, or brand. It was the genetic information of millions of people. Not because someone hacked it. Not because someone stole it. But because when a company goes up for sale, its assets go with it. And sometimes, the asset is you.
That’s the bit we don’t think about when we click “I agree”. We’re not just trusting the company as it exists today. We’re also trusting whoever might own it tomorrow.
I Used To Think Privacy Was IT's Problem.
Then, in 2025 I moved to Switzerland, my career shifted and from Marketing Manager, I became a Procurement Manager.
Every time someone wanted to buy a new piece of software, the work didn’t end with negotiating a better price. In many ways, that was where the real work started. I supported our Data Protection Officer with supplier checks, security questionnaires, Data Processing Agreements, data storage reviews, retention periods, deletion rights, and all the other deeply unsexy things that decide whether a company should be trusted with personal data.
We weren’t trying to slow people down.
We were trying to answer one question:
Can this company be trusted with our customers’ data?
One careless purchase could expose thousands of people. A simple SaaS tool wasn’t just a SaaS tool. It was another door into the company.
It wasn't just software. Even sponsoring an industry event meant checking how attendee data would be stored and shared.
And once you see every purchase that way, it becomes hard to stop seeing it.
The Day We Thought We’d Gone Viral
I saw this earlier in my career too.
I once worked as a Head of Product Growth at a startup called Sphere where we didn’t have the right CAPTCHA protection before login. Sooner rather than later, someone took usernames and passwords leaked from another website and tested them against our app. Within a couple of hours, thousands of fake accounts had been created and our app started to crash.
At first, you have that tiny hopeful thought: “Have we gone viral?”
Nope.
We had been used as someone’s password-testing playground.
The attack wasn’t particularly sophisticated. There was no cinematic hacker in a hoodie breaking into the mainframe. It was simply the consequence of one company’s leaked data being reused somewhere else. The breach happened elsewhere. We still paid the price.
Nothing major happened, we recovered within a day, but when storing money is involved, the stakes are much higher.
The Cost of One Mistake
In 2017, Parity Technologies developed one of the most widely used Ethereum wallets. It wasn’t hacked because someone broke the cryptography behind Ethereum. The blockchain itself worked exactly as designed.
Instead, the vulnerability came from the wallet software built on top of it. An attacker exploited a flaw in the smart contract and walked away with over 150,000 ETH. A few months later, another mistake in the code permanently locked away more than 500,000 ETH, making it inaccessible forever.
Hundreds of millions of dollars became inaccessible.
Not because blockchain failed.
Because software is written by humans.
I often think about that story when people talk about data privacy. We tend to imagine privacy as something that gets stolen by sophisticated hackers. More often than not, it begins with a perfectly ordinary engineering decision.
A missed review. A deadline that couldn't move. A feature shipped a little too early.
The consequences only become obvious after thousands, or millions, of people are affected.
The Road to Your Insurance Premium
Then there are our cars.
Most of us think of them as a way to get from A to B. Increasingly, they’re also becoming data collection devices. They know how we drive, where we drive, and often much more than we realise.
In 2024, some General Motors drivers discovered that data collected through their connected vehicle services, the opt-in "Smart Driver" feature, had been shared with data brokers, who then provided driving reports to insurance companies. For some, the first sign that this had happened wasn’t a notification from their car. It was a higher insurance premium.
What I find fascinating is that nothing had gone wrong.
Nobody hacked the car. Nobody stole the data. The software behaved exactly as it had been designed to.
The surprise wasn’t the technology. It was the expectation.
Most of us assume the data our products collect exists to make the product better. We don't expect it to become part of someone else's business model.
Lessons Learned
Thankfully for those who had their DNA stored with 23andMe, a more positive ending than many expected. Following the bankruptcy, 23andMe was acquired by TTAM Research Institute, a nonprofit led by the company’s co-founder and former CEO, Anne Wojcicki, which has pledged to uphold the company’s existing privacy commitments.
Still, the episode reminds us that when we trust a company with our data, we’re also trusting its future—not just its present.
This is why privacy shouldn’t be treated as a compliance exercise. It’s a seat belt.
Engineers don’t design seat belts because they expect every driver to crash. They design them because eventually, someone will.
Software should be designed the same way.
Assume that one day, a supplier will be breached.
A startup will go bankrupt.
An engineer will make a mistake.
The question isn’t whether something will go wrong.
It’s whether you built the seat belt.
Thanks for reading, and thanks for being here, hit like or restack to let me know you’re there. And...if you feel like joining the conversation, I’m curious:
We spend hours reading product reviews before buying a new phone or coffee machine.
When was the last time you chose a product because of its privacy policy?
Or, perhaps more importantly, is there a company you trust enough that you never felt the need to read it?
I’d love to hear your thoughts in the comments.
Margo


