Critical gap in U.S. law: GINA protects against genetic discrimination in health insurance and employment — but does not cover life insurance, long-term care insurance, or disability insurance. If you get a DNA test that reveals a risk for a degenerative condition, a life insurer could theoretically use that information. No federal law prevents this.
GINA: What the Law Protects — and What It Doesn't
The Genetic Information Nondiscrimination Act (GINA), signed into law in 2008 after over a decade of congressional debate, is the primary federal protection for genetic privacy in the United States. GINA operates in two key domains:
- Title I — Health Insurance: Prohibits group and individual health insurers from using genetic information to determine eligibility, set premiums, or impose pre-existing condition exclusions. Insurers cannot request or require genetic testing as a condition of coverage.
- Title II — Employment: Prohibits employers with 15 or more employees from using genetic information in hiring, firing, promotion, compensation, or any other terms of employment. Employers cannot request, require, or purchase genetic information about employees — including family medical history.
However, GINA has major gaps that many consumers don't realize. The law does not apply to:
- Life insurance — Life insurers can legally request and use genetic test results in underwriting
- Long-term care insurance — LTC insurers can deny coverage or raise premiums based on genetic risk
- Disability insurance — Genetic predisposition to conditions affecting future employability can be considered
- Employers with fewer than 15 employees — Small businesses are exempt from Title II
- The U.S. military — Active-duty service members are not covered by GINA for employment discrimination
- Manifest disease — GINA does not protect against discrimination based on a condition you already have; it only protects against discrimination based on genetic predisposition
Several states have passed laws that go beyond GINA. Florida (2020) became the first state to prohibit life insurers from using genetic test results; California, New York, and Massachusetts have additional protections. If you're concerned about life insurance implications, the safest approach is to secure life insurance coverage before undergoing elective genetic testing.
How Major Companies Handle Your Data
Each genetic testing company has its own privacy policy, data-sharing practices, and law enforcement access policy. Here's how the major players compare:
| Company | Data Sharing with Researchers | Law Enforcement Policy | Sample Destruction | HIPAA-Covered |
|---|---|---|---|---|
| 23andMe | Opt-in; 80%+ of users consent to research | Requires valid subpoena/court order; publishes transparency reports | Sample destroyed after processing | No |
| AncestryDNA | Opt-in; separate consent required for research | Requires valid legal process; publishes transparency reports | Sample destroyed after processing | No |
| FamilyTreeDNA | Opt-out available | Cooperates with FBI for violent crimes; opt-out available | Stored for up to 25 years | No |
| Nebula Genomics | Blockchain-based consent; opt-in | Requires valid legal process | Option to destroy sample after sequencing | No (research-grade) |
| Clinical Labs (Invitae, Color, etc.) | De-identified data may be shared; opt-out generally available | HIPAA requires valid authorization or court order | CLIA requires 2-10 year retention of test results | Yes |
23andMe's research consent: Over 80% of 23andMe's approximately 15 million customers have opted into its research program. This means their genetic data — aggregated and de-identified — has been used in hundreds of published scientific studies. De-identified data is not subject to HIPAA and can be shared broadly. If you've opted into 23andMe research and later change your mind, you can withdraw consent, but data already used in completed research cannot be retrieved from publications or partner databases.
Law Enforcement and Genetic Genealogy
The 2018 arrest of the Golden State Killer using genetic genealogy — uploading crime scene DNA to GEDmatch and identifying the suspect through distant relatives' DNA matches — marked a watershed moment for genetic privacy. Since then, genetic genealogy has been used to solve hundreds of cold cases, but the practice raises serious privacy questions.
Key facts about law enforcement access:
- Direct-to-consumer databases: 23andMe and AncestryDNA require a valid subpoena, court order, or search warrant to release individual user data. Both publish annual transparency reports documenting the number of law enforcement requests received and complied with. In 2024, 23andMe received 15 requests and complied with 10.
- GEDmatch: After policy changes in 2019, GEDmatch requires users to actively opt in for law enforcement matching. Only users who explicitly enable this feature have their data visible to law enforcement searches — and only for violent crimes (murder, sexual assault). The default setting excludes law enforcement access.
- FamilyTreeDNA: Unlike other major companies, FamilyTreeDNA openly cooperates with the FBI for violent crime investigations. Users can opt out of law enforcement matching in their privacy settings, but the company's default position is to cooperate.
Indirect exposure through relatives: Even if you never take a DNA test, your genetic privacy may be compromised by relatives who do. If a first cousin uploads their data to GEDmatch with law enforcement matching enabled, your DNA profile can be partially inferred. Genetic genealogy has demonstrated that over 60% of Americans of European descent can now be identified through a third-cousin-or-closer DNA match in a public genealogy database (Erlich et al., Science, 2018).
HIPAA vs DTC: The Regulatory Divide
The privacy protections applied to your genetic data depend entirely on who orders the test and how it's processed:
- HIPAA-covered testing: When a genetic test is ordered by a healthcare provider and processed through a CLIA-certified clinical lab (e.g., Invitae, Color Health, GeneDx, clinical WGS), the results are Protected Health Information (PHI) under HIPAA. This means strict rules govern who can access the data, for what purposes, and with what safeguards. Data breaches must be reported. Unauthorized disclosure can result in significant fines and criminal penalties.
- Non-HIPAA testing: Direct-to-consumer tests (23andMe, AncestryDNA, MyHeritage, consumer WGS from Nebula) are not covered entities under HIPAA. Your privacy protections come from the company's privacy policy — a contract that the company can change — and from the FTC Act, which prohibits unfair or deceptive trade practices but provides far weaker protections than HIPAA.
A critical point many consumers miss: even a CLIA-certified test can be non-HIPAA if it's self-ordered. If you buy a Color Health test directly without a physician's order, it may not be protected by HIPAA — despite being processed in a CLIA lab. Always verify with the provider how your data is classified before testing.
Practical Steps to Protect Your Genetic Privacy
- Read the privacy policy before testing — not after. Look for: data-sharing defaults (opt-in vs opt-out), research consent requirements, law enforcement cooperation policies, data retention/deletion procedures, and whether the company can sell or transfer your data in a merger or acquisition.
- Use a pseudonym or anonymous identifier when possible — some services allow you to register without your real name. This limits the link between your genetic data and your identity if the database is breached.
- Opt out of research if you're uncomfortable with your de-identified data being used in studies. Understand that "de-identified" data can sometimes be re-identified — genetic data is inherently identifying (your genome is unique).
- Request sample destruction — most DTC companies destroy the physical saliva/DNA sample after processing, but some retain it. Confirm destruction in writing if this matters to you.
- Consider paying out-of-pocket — submitting a genetic test through insurance creates a medical record that life insurers can potentially access during underwriting. Self-pay eliminates this paper trail.
- Secure life insurance before elective genetic testing — if you're planning to buy life, long-term care, or disability insurance, do so before undergoing genetic testing that could reveal risk factors.
- Use a HIPAA-covered clinical lab for medically-relevant testing — the privacy protections are legally enforced rather than dependent on a company's voluntary privacy policy.
- Request data deletion if you no longer want your data stored. Most companies offer account deletion that removes your data from their active systems, though some information may be retained for regulatory compliance.
The Future of Genetic Privacy
Genetic privacy law is evolving, but slowly. Several bills have been introduced in Congress — including the Genetic Information Privacy Act and updates to GINA that would extend protections to life and disability insurance — but none have passed as of 2026. In the absence of comprehensive federal legislation, your genetic privacy depends on a patchwork of state laws, company policies, and your own vigilance.
The European Union's GDPR provides stronger protections: genetic data is classified as "sensitive personal data" requiring explicit consent for processing, and the "right to be forgotten" applies. If you're in the EU or can access EU-based genetic testing services, your data enjoys stronger legal protections.
Find a DNA testing provider that respects your privacy
Compare our directory of genetic testing companies — each with privacy policies, data practices, and regulatory status reviewed.
Compare Tests Browse DirectoryFrequently Asked Questions
Can my genetic data be sold if a testing company goes bankrupt?
Yes — and this is one of the most significant privacy risks. When 23andMe filed for bankruptcy in March 2025 (subsequently restructuring), the company's privacy policy stated that user data could be transferred as a business asset in a sale, merger, or bankruptcy proceeding. The FTC and several state attorneys general intervened to ensure data protection commitments transferred with the data. Read the "corporate transactions" or "business transfers" section of any genetic testing company's privacy policy — this clause determines what happens to your data if the company is acquired or fails.
What is the difference between de-identified and anonymous genetic data?
De-identified data has had direct identifiers (name, email, date of birth) stripped, but can theoretically be re-identified by combining it with other datasets. Anonymous data has been irreversibly stripped of all identifying information and cannot be re-identified. In practice, genetic data is inherently identifying — your genome is a unique identifier, and studies have shown that individuals can be re-identified from de-identified genomic datasets using public genealogy databases or demographic information. When companies say your data is "de-identified" for research, understand that re-identification is technically possible, even if prohibited by policy.
Does whole genome sequencing create more privacy risk than genotyping?
Whole genome sequencing reveals vastly more information — roughly 3 million variants versus 600,000 SNPs from genotyping — and includes data that genotyping chips miss entirely: non-coding regions, structural variants, mitochondrial DNA, and the Y chromosome. A WGS data file is fundamentally more re-identifiable and reveals more about your ancestry, health risks, and even behavioral tendencies than a genotyping file. This increased informational content inherently increases privacy risk. However, WGS providers that use blockchain-based consent (Nebula Genomics) or HIPAA-covered clinical labs (Dante Labs, certain clinical WGS providers) may offer stronger protections than DTC genotyping companies, depending on their specific policies.
Related Articles
How to Read Your Raw DNA Data: A Practical Guide
WGS vs Genotyping: Which Test Is Right for You?
What Is Whole Genome Sequencing? A Complete Beginner's Guide
Related reviews: