A subscriber wrote in recently asking me to take a closer look at the privacy risks behind consumer DNA kits, specifically, what happens when you hand a company your genetic data. It was a good question; the answer goes well beyond the standard advice to "read the privacy policy."
A stolen credit card gets replaced. A compromised password gets reset. Your genome is different: it is permanent, and parts of it are shared with people who never agreed to put theirs in a database.
Somebody in your family has probably received one of these as a gift: a small box, a plastic tube, and instructions not to eat or drink before providing a saliva sample. You seal it, drop it in the mail, and within weeks a website tells you where your ancestors may have lived, introduces you to genetic relatives, or reports personal health traits.
It feels like a novelty purchase.
What you mailed in was one of the most persistent identifiers you possess. You can change a password, replace a credit card, move to a new address, or open a different email account. You cannot replace your genome. And that privacy decision does not affect only you, it extends to your entire family tree.
The Industry's Security Record Isn't Reassuring
In 2018, MyHeritage disclosed that a security researcher discovered a file on a private server outside the company containing email addresses and hashed passwords for 92.3 million users. MyHeritage noted that it found no evidence its segregated DNA or family-tree systems were compromised. That distinction matters, but so does the scale of the account breach.
DNA Diagnostics Center faced a different problem. A 2021 breach affected roughly 2.1 million people nationwide, involving legacy databases obtained through an earlier corporate acquisition. Ohio and Pennsylvania ultimately reached settlements totaling $400,000 in penalties over the incident.
Then there was Vitagene. In the Federal Trade Commission's first case focused on both the privacy and security of genetic information, the agency alleged that the company stored nearly 2,400 health reports and raw genetic data from at least 227 consumers in publicly accessible cloud-storage buckets without encryption or access controls. The FTC also accused the firm of misleading users about data deletion and retroactively expanding its privacy policy. The final order included a $75,000 payment alongside new security and consent requirements.
The most instructive example may be 23andMe. A credential-stuffing attack in 2023 directly compromised thousands of accounts. Because those accounts were connected to the company's "DNA Relatives" feature, the attacker accessed information associated with almost seven million customers. A joint investigation by Canadian and British privacy regulators found significant safeguards lacking at the time, including the absence of mandatory multi-factor authentication.
That is the core issue with genetic databases: an ordinary account-security failure can expose extraordinarily durable information.
Your DNA Isn't Only About You
Genetic privacy has another unusual property: it is relational.
A 2018 study in Science examined long-range familial searching in consumer genealogy databases. The researchers projected that roughly 60 percent of searches involving people of European descent could produce a third-cousin or closer match, a relationship close enough to substantially narrow an identification when combined with public records and demographic data.
The study also projected that once a genealogy database covers roughly 2 percent of a target population, nearly everyone in that population becomes findable through a third-cousin relative.
In practical terms, you do not necessarily have to submit your own DNA to become genetically identifiable. A cousin's submission may be enough.
That does not mean your relatives legally own your genome. But biologically, your DNA contains information about people other than yourself. When you upload data, enable relative matching, or authorize research, the consequences extend beyond the person who clicked "I agree."
The Company You Signed Up With May Not Hold Your Data Forever
Consent happens at a single moment in time. Corporate ownership does not stand still.
In 2020, Blackstone acquired Ancestry in a deal valuing the company at $4.7 billion. The transaction covered genealogy subscriptions, historical records, family trees, and a major consumer-genomics operation.
GEDmatch followed another path. The genealogy database was acquired by forensic-genomics firm Verogen, and QIAGEN subsequently acquired Verogen in 2023. QIAGEN now operates GEDmatch alongside GEDmatch PRO, which supports law-enforcement and forensic investigations using data made available by participating users.
Then came 23andMe. The company filed for bankruptcy protection in March 2025. Its consumer-genetics and research businesses were acquired through bankruptcy by TTAM Research Institute, a nonprofit public-benefit corporation founded by 23andMe co-founder Anne Wojcicki. The acquisition closed in July 2025, with the organization operating as the 23andMe Research Institute.
The point is not that every acquisition is sinister. The point is that when you provide genetic information, you make a decision about data whose useful life extends far beyond the corporate structure that existed when you submitted it.
Privacy policies change. Companies get bought or fail. Databases move. Your genome does not.
The Law Is Thinner Than Many Assume
Many consumers hear "health information" and assume HIPAA automatically applies. It does not.
HIPAA protects individually identifiable genetic information only when maintained by a covered entity, such as a health plan, healthcare clearinghouse, or qualifying healthcare provider. Genetic data held by a standalone direct-to-consumer company does not become HIPAA-protected simply because it concerns health.
Federal protection is also incomplete in other areas.
The Genetic Information Nondiscrimination Act (GINA) restricts the use of genetic information in health insurance and employment. However, it does not provide equivalent federal protection for life insurance, disability insurance, or long-term-care insurance. State protections vary widely depending on where you live.
Federal agencies treat genomic information as sensitive in specific contexts. For example, the Justice Department's Data Security Program established a bulk threshold of genomic data concerning more than 100 U.S. persons for rules governing transactions involving countries of concern.
In Congress, the bipartisan “Don't Sell My DNA Act” was introduced to protect genetic information during corporate bankruptcy proceedings. States are also acting independently: Connecticut enacted a genetic-privacy law to give consumers additional control over biological samples submitted to testing companies, while imposing strict disclosure rules.
The result is not a complete absence of regulation, but a patchwork.
Here is How to Protect Your Privacy
If you have taken a consumer DNA test, or are considering one, the goal is not panic. It is informed consent.
Secure the account like financial data. Use a unique password and enable multi-factor authentication. The 23andMe breach demonstrated how credential reuse becomes consequential when one account connects to thousands of relatives.
Review privacy and sharing settings. Relative matching, research participation, user connections, data sharing, and sample storage are often separate choices. Do not assume default settings reflect your preferred level of disclosure.
Know the difference between deleting data and destroying a physical sample. Procedures vary. At 23andMe, account deletion opts the customer out of research and triggers disposal of the stored sample. Ancestry provides separate controls for data deletion and sample destruction. Always check the specific policy of your provider.
Download raw data before deleting your account. Account and DNA deletion is often irreversible. Preserve reports or raw data files before initiating deletion.
Revisit settings periodically. Policies, features, ownership, and regulations change over time.
Ask before gifting a DNA kit. A genetic test is not a simple weekend project. The recipient is making a long-term privacy decision that affects non-consenting biological relatives.
The Price Is More Than $99
None of this means consumer DNA testing lacks value.
Adoptees and separated relatives have reconnected through genetic genealogy. Families have resolved historical gaps that paper records could not fix. Genetic reports can also provide meaningful information about inherited traits and potential health risks.
Those benefits are real, but so are the tradeoffs.
When you buy a DNA kit, you place persistent biological information into a commercial system whose technology, ownership, business model, and legal obligations may change over time.
You can delete an account, request sample destruction, or opt out of research. What you cannot change is the underlying code.
Passwords can be reset. Credit cards can be replaced. Your genome remains yours for life. Decide accordingly.
Sources: Federal Trade Commission; U.S. Department of Justice Data Security Program; U.S. Department of Health and Human Services; National Human Genome Research Institute; U.S. Government Publishing Office; Connecticut General Assembly; Science; Office of the Privacy Commissioner of Canada; 23andMe Research Institute; MyHeritage; Ancestry; Blackstone; and QIAGEN.
This issue exists because a subscriber wrote in. If something about cybersecurity, AI, privacy, or responsible AI has been nagging at you, send it to [email protected]. Real questions make better issues than anything on my topic list.




