WGS Test
Privacy

DNA Privacy: What Happens to Your Genetic Data After Testing?

When you spit in a tube and send it off for DNA analysis, you're trusting a company with your most intimate data. Understanding what legal protections exist — and where they fall short — is essential before you test. Here's what happens to your genetic data and how to protect it.

July 22, 2026 · 7 min read

Critical gap in U.S. law: GINA protects against genetic discrimination in health insurance and employment — but does not cover life insurance, long-term care insurance, or disability insurance. If you get a DNA test that reveals a risk for a degenerative condition, a life insurer could theoretically use that information. No federal law prevents this.

GINA: What the Law Protects — and What It Doesn't

The Genetic Information Nondiscrimination Act (GINA), signed into law in 2008 after over a decade of congressional debate, is the primary federal protection for genetic privacy in the United States. GINA operates in two key domains:

However, GINA has major gaps that many consumers don't realize. The law does not apply to:

Several states have passed laws that go beyond GINA. Florida (2020) became the first state to prohibit life insurers from using genetic test results; California, New York, and Massachusetts have additional protections. If you're concerned about life insurance implications, the safest approach is to secure life insurance coverage before undergoing elective genetic testing.

How Major Companies Handle Your Data

Each genetic testing company has its own privacy policy, data-sharing practices, and law enforcement access policy. Here's how the major players compare:

Company Data Sharing with Researchers Law Enforcement Policy Sample Destruction HIPAA-Covered
23andMeOpt-in; 80%+ of users consent to researchRequires valid subpoena/court order; publishes transparency reportsSample destroyed after processingNo
AncestryDNAOpt-in; separate consent required for researchRequires valid legal process; publishes transparency reportsSample destroyed after processingNo
FamilyTreeDNAOpt-out availableCooperates with FBI for violent crimes; opt-out availableStored for up to 25 yearsNo
Nebula GenomicsBlockchain-based consent; opt-inRequires valid legal processOption to destroy sample after sequencingNo (research-grade)
Clinical Labs (Invitae, Color, etc.)De-identified data may be shared; opt-out generally availableHIPAA requires valid authorization or court orderCLIA requires 2-10 year retention of test resultsYes

23andMe's research consent: Over 80% of 23andMe's approximately 15 million customers have opted into its research program. This means their genetic data — aggregated and de-identified — has been used in hundreds of published scientific studies. De-identified data is not subject to HIPAA and can be shared broadly. If you've opted into 23andMe research and later change your mind, you can withdraw consent, but data already used in completed research cannot be retrieved from publications or partner databases.

Law Enforcement and Genetic Genealogy

The 2018 arrest of the Golden State Killer using genetic genealogy — uploading crime scene DNA to GEDmatch and identifying the suspect through distant relatives' DNA matches — marked a watershed moment for genetic privacy. Since then, genetic genealogy has been used to solve hundreds of cold cases, but the practice raises serious privacy questions.

Key facts about law enforcement access:

Indirect exposure through relatives: Even if you never take a DNA test, your genetic privacy may be compromised by relatives who do. If a first cousin uploads their data to GEDmatch with law enforcement matching enabled, your DNA profile can be partially inferred. Genetic genealogy has demonstrated that over 60% of Americans of European descent can now be identified through a third-cousin-or-closer DNA match in a public genealogy database (Erlich et al., Science, 2018).

HIPAA vs DTC: The Regulatory Divide

The privacy protections applied to your genetic data depend entirely on who orders the test and how it's processed:

A critical point many consumers miss: even a CLIA-certified test can be non-HIPAA if it's self-ordered. If you buy a Color Health test directly without a physician's order, it may not be protected by HIPAA — despite being processed in a CLIA lab. Always verify with the provider how your data is classified before testing.

Practical Steps to Protect Your Genetic Privacy

  1. Read the privacy policy before testing — not after. Look for: data-sharing defaults (opt-in vs opt-out), research consent requirements, law enforcement cooperation policies, data retention/deletion procedures, and whether the company can sell or transfer your data in a merger or acquisition.
  2. Use a pseudonym or anonymous identifier when possible — some services allow you to register without your real name. This limits the link between your genetic data and your identity if the database is breached.
  3. Opt out of research if you're uncomfortable with your de-identified data being used in studies. Understand that "de-identified" data can sometimes be re-identified — genetic data is inherently identifying (your genome is unique).
  4. Request sample destruction — most DTC companies destroy the physical saliva/DNA sample after processing, but some retain it. Confirm destruction in writing if this matters to you.
  5. Consider paying out-of-pocket — submitting a genetic test through insurance creates a medical record that life insurers can potentially access during underwriting. Self-pay eliminates this paper trail.
  6. Secure life insurance before elective genetic testing — if you're planning to buy life, long-term care, or disability insurance, do so before undergoing genetic testing that could reveal risk factors.
  7. Use a HIPAA-covered clinical lab for medically-relevant testing — the privacy protections are legally enforced rather than dependent on a company's voluntary privacy policy.
  8. Request data deletion if you no longer want your data stored. Most companies offer account deletion that removes your data from their active systems, though some information may be retained for regulatory compliance.

The Future of Genetic Privacy

Genetic privacy law is evolving, but slowly. Several bills have been introduced in Congress — including the Genetic Information Privacy Act and updates to GINA that would extend protections to life and disability insurance — but none have passed as of 2026. In the absence of comprehensive federal legislation, your genetic privacy depends on a patchwork of state laws, company policies, and your own vigilance.

The European Union's GDPR provides stronger protections: genetic data is classified as "sensitive personal data" requiring explicit consent for processing, and the "right to be forgotten" applies. If you're in the EU or can access EU-based genetic testing services, your data enjoys stronger legal protections.

Find a DNA testing provider that respects your privacy

Compare our directory of genetic testing companies — each with privacy policies, data practices, and regulatory status reviewed.

Compare Tests Browse Directory

Frequently Asked Questions

Can my genetic data be sold if a testing company goes bankrupt?

Yes — and this is one of the most significant privacy risks. When 23andMe filed for bankruptcy in March 2025 (subsequently restructuring), the company's privacy policy stated that user data could be transferred as a business asset in a sale, merger, or bankruptcy proceeding. The FTC and several state attorneys general intervened to ensure data protection commitments transferred with the data. Read the "corporate transactions" or "business transfers" section of any genetic testing company's privacy policy — this clause determines what happens to your data if the company is acquired or fails.

What is the difference between de-identified and anonymous genetic data?

De-identified data has had direct identifiers (name, email, date of birth) stripped, but can theoretically be re-identified by combining it with other datasets. Anonymous data has been irreversibly stripped of all identifying information and cannot be re-identified. In practice, genetic data is inherently identifying — your genome is a unique identifier, and studies have shown that individuals can be re-identified from de-identified genomic datasets using public genealogy databases or demographic information. When companies say your data is "de-identified" for research, understand that re-identification is technically possible, even if prohibited by policy.

Does whole genome sequencing create more privacy risk than genotyping?

Whole genome sequencing reveals vastly more information — roughly 3 million variants versus 600,000 SNPs from genotyping — and includes data that genotyping chips miss entirely: non-coding regions, structural variants, mitochondrial DNA, and the Y chromosome. A WGS data file is fundamentally more re-identifiable and reveals more about your ancestry, health risks, and even behavioral tendencies than a genotyping file. This increased informational content inherently increases privacy risk. However, WGS providers that use blockchain-based consent (Nebula Genomics) or HIPAA-covered clinical labs (Dante Labs, certain clinical WGS providers) may offer stronger protections than DTC genotyping companies, depending on their specific policies.

Related Articles

Related reviews:

Nebula Genomics