Genetic Privacy: What It Is and How to Protect It

Genetic privacy is the right to control who can access, store, and use information derived from your DNA, and it sits in a legal and technological gray zone that most people never think about until after they’ve spit into a tube. Unlike a stolen credit card number, your genetic code cannot be changed, replaced, or reset. It reveals information not only about you but about your parents, siblings, and children. The protections that do exist are patchwork, varying wildly by country, by the type of entity holding the data, and by what the data is being used for.

Why Genetic Data Is Different From Other Personal Information

A Social Security number can be reissued. A password can be changed. Genetic information is permanent. Your germline sequence is fixed at conception and remains the same for your entire life. That immutability means any exposure of your genetic data creates risks that do not fade with time. Decades from now, scientists will be able to extract far more meaning from the same data than anyone can today, so a breach that seems minor now could become deeply revealing later as interpretation technology advances.1Genetics in Medicine. Confidentiality, privacy, and security of genetic and genomic test information in electronic health records: points to consider

Genetic data is also uniquely identifying. Except for identical twins, each person’s genome is distinct, and even a small number of genetic variants can be matched across independently collected samples with high confidence. Consolidated databases of genetic information can be mined to identify specific individuals. As the relationship between genotype and physical traits becomes better understood, a DNA sample alone could increasingly be used to predict what someone looks like, what diseases they’re at risk for, and how they respond to medications.1Genetics in Medicine. Confidentiality, privacy, and security of genetic and genomic test information in electronic health records: points to consider

Perhaps most critically, genetic information is shared. You inherit roughly half your genome from each biological parent, and you share substantial stretches of DNA with siblings, cousins, and more distant relatives. A decision by one family member to make their genetic data available has implications for people who never consented to anything.

The Direct-to-Consumer Testing Boom

Companies offering mail-order DNA kits have turned millions of people into voluntary contributors to massive genetic databases. These direct-to-consumer genetic testing services collect saliva or cheek swab samples, extract DNA, and return results on ancestry, health predispositions, or trait predictions. But the business model doesn’t stop at the test results you receive. The genetic information collected is frequently leveraged to engage pharmaceutical companies, research institutions, and other partners.2PubMed Central. Direct-to-Consumer Genetic Testing Data Privacy: Key Concerns and Recommendations Based on Consumer Perspectives

When you agree to the terms of service for one of these kits, you’re often granting broad permissions for how your data can be stored, shared, and analyzed. Those terms can change. Companies can be acquired, go bankrupt, or pivot their business model. The 2023 bankruptcy of 23andMe brought this into sharp focus: millions of users suddenly faced questions about what would happen to their genetic data when the company’s assets went up for sale. Lawmakers have since called for stronger protections for consumer genetic data and the biological samples themselves.3PubMed Central. The precarious future of consumer genetic privacy

What U.S. Law Actually Covers

The primary federal law addressing genetic discrimination in the United States is the Genetic Information Nondiscrimination Act, commonly known as GINA. Enacted in 2008, it prohibits health insurers from using genetic information to deny coverage or set premiums, and it bars employers from requesting, requiring, or purchasing genetic information about employees or their family members, with narrow exceptions.4PubMed Central. Currents in contemporary ethics. GINA, the ADA, and genetic discrimination in employment

GINA has real teeth in the areas it covers, but its scope is limited in ways that surprise most people. It does not apply to life insurance, disability insurance, or long-term care insurance. If a life insurer asks whether you’ve had a genetic test showing elevated risk for a hereditary condition, GINA offers no protection. The law also only covers employers with 15 or more employees and does not extend to the military.

HIPAA, the health-privacy law most Americans have heard of, covers genetic information when it sits within a healthcare provider’s or health plan’s records. But direct-to-consumer testing companies are generally not “covered entities” under HIPAA, which means the genetic data you voluntarily hand to a commercial company may have far less legal protection than the same information in your medical chart. One study of workplace genomic testing programs found that while about two-thirds of companies mentioned HIPAA on their websites, not a single one mentioned GINA in the context of their wellness programs offering genetic testing.5PubMed Central. Workplace genomic testing: What do company websites say about federal privacy and anti-discrimination laws?

How Europe Handles Genetic Data

The European Union’s General Data Protection Regulation classifies genetic data as a “special category” of personal data, alongside health data, biometric data, and information about racial or ethnic origin. Under the GDPR, processing genetic data is prohibited by default unless one of a limited set of exemptions applies. Those exemptions include explicit consent from the individual, substantial public interest, and certain conditions for scientific research.6International Data Privacy Law. The EU GDPR and secondary use of health and genetic data for research support purposes

The GDPR also clarified that pseudonymized data still counts as personal data if there is any realistic possibility of re-identifying the individual. This matters enormously for genetic research, where supposedly anonymized datasets have been shown to be re-identifiable. The regulation pushed EU member states to adopt specific rules for processing genetic data in research contexts, though implementation has varied by country.7PubMed Central. Rules for processing genetic data for research purposes in view of the new EU General Data Protection Regulation

The practical result is that someone in Germany or France has a meaningfully different set of rights over their genetic information than someone in the United States, particularly when it comes to commercial testing companies. European consumers can demand deletion of their data and must provide explicit consent before it is used for purposes beyond the original testing agreement.

When Police Search Your DNA

In 2018, investigators in California arrested Joseph DeAngelo, the suspected Golden State Killer, after uploading crime-scene DNA to a public genealogy database and tracing the profile to distant relatives who had voluntarily shared their genetic information. That case brought investigative forensic genetic genealogy into the public spotlight and opened a heated debate about the boundaries of genetic privacy.8PubMed. Should the police use genetic genealogy databases to assist in solving crime? Survey among university students

The technique has since been used in hundreds of cases in the United States and has expanded to Europe and Australia. Law enforcement uploads a DNA profile from a crime scene to a genealogy platform, identifies genetic relatives of the unknown suspect, and uses traditional genealogical research to narrow down the suspect’s identity. The process has led to the resolution of cold cases going back decades, but it raises a fundamental question: when one person uploads their DNA to a public database, they are also making their relatives searchable to law enforcement without those relatives’ knowledge or consent.9PubMed Central. Law enforcement use of genetic genealogy databases in criminal investigations: Nomenclature, definition and scope

From a constitutional standpoint, the legal landscape is unsettled. Police frequently conduct these searches without a warrant, relying on the argument that people who voluntarily upload their DNA to third-party platforms have no reasonable expectation of privacy in that data under the so-called third-party doctrine.10Houston Law Review. Keeping It in the Family: Direct-to-Consumer Genetic Testing and the Fourth Amendment Legal scholars have argued that the Supreme Court’s 2018 ruling in Carpenter v. United States, which limited warrantless access to cellphone location data, should logically extend to genomic databases. But courts have not yet resolved the question definitively, and police continue to use consumer genomic platforms storing hundreds of thousands or millions of profiles to infer the identity of distant relatives who may be suspects.11PubMed Central. Familial Searches, the Fourth Amendment, and Genomic Control

Your DNA Implicates Your Relatives

One of the most ethically tangled aspects of genetic privacy is that DNA is inherently familial. If you get a genetic test showing you carry a mutation linked to hereditary cancer, your siblings each have a significant chance of carrying the same mutation. Do they have a right to know? Do you have an obligation to tell them? What if you refuse?

Different countries handle this differently. In Australia, health professionals can disclose genetic information to at-risk relatives even without the patient’s consent under specific guidelines, but most practitioners are unsure of exactly when and how they’re permitted to do so. A study of Australian genetic professionals found that while many had read the relevant guidelines, awareness of their scope and clinical application was limited. Participants noted that cases of active non-disclosure by patients don’t come up frequently, and most that do arise resolve with time and discussion.12PubMed Central. Disclosure to genetic relatives without consent – Australian genetic professionals’ awareness of the health privacy law

The familial dimension extends beyond clinical settings. When you submit your DNA to a consumer testing service, you’re creating a searchable record that shares genetic material with every biological relative you have. Your second cousin’s decision to upload their DNA to a genealogy site can expose your lineage, your health predispositions, and your identity to anyone with access to that database. Consent in genetics is never truly individual.

Forensic DNA Phenotyping

Beyond matching DNA profiles to databases, a growing field called forensic DNA phenotyping allows investigators to predict what a person looks like directly from biological material left at a crime scene. This means predicting eye color, hair color, skin color, and potentially facial features or age from a DNA sample alone, producing a kind of “biological witness” to help identify unknown individuals.13PubMed. Forensic DNA Phenotyping: Predicting human appearance from crime scene material for investigative purposes

Validated tests already exist for categorizing eye, hair, and skin color from DNA, with accuracy levels that vary by trait and color category. For eye color prediction, accuracy ranges from good to excellent depending on the model used, while hair and skin color prediction is somewhat less precise but still informative for investigative purposes.14PubMed Central. The Use of Forensic DNA Phenotyping in Predicting Appearance and Biogeographic Ancestry The technology is useful when traditional DNA profiling hits a dead end because the suspect’s profile isn’t in any criminal database. Instead of searching for a match, investigators generate a physical description from the DNA itself.15Journal of Interdisciplinary Research in Allied Health and Pharmacy. Forensic DNA phenotyping; Current updates and future prospects

The privacy implications are significant. As this technology improves, any biological trace you leave behind, a stray hair, a drinking cup in a restaurant, could theoretically be used to reconstruct a rough portrait of your appearance. And because the same DNA variants that predict appearance can also reveal ancestry and health information, the line between “what you look like” and “what diseases you might develop” is thinner than it seems.

Newborn Screening and Residual Bloodspots

Nearly every baby born in the United States has a small blood sample taken within the first day or two of life for newborn screening, a set of tests designed to detect serious treatable conditions early. What many parents don’t realize is that in most states, leftover blood spots from these tests are stored, sometimes indefinitely, and may be used for purposes beyond the original screening, including research. The storage and use of these residual specimens has generated significant controversy, primarily because of public concerns over the lack of parental knowledge and consent for these activities.16PubMed Central. Retention and research use of residual newborn screening bloodspots

Lawsuits in Texas and Minnesota forced changes to state policies after parents learned their children’s blood spots had been stored and used without their awareness. The stored spots contain enough DNA for genotyping, and as extraction and sequencing technology improves, the amount of information recoverable from a decades-old dried blood spot continues to grow. Some states have responded by requiring parental consent for research use and by destroying older stored specimens. Others continue to retain them with minimal oversight.

Indigenous Data Sovereignty

Genetic research has a particularly troubled history with Indigenous communities around the world. DNA samples have been collected from Indigenous groups, sometimes under vague consent processes, and then used or reused in research those communities never agreed to. Benefits from discoveries made using their genetic data have rarely flowed back to the communities that provided it.17PubMed. Indigenous Data Sovereignty in Genomics and Human Genetics: Genomic Equity and Justice for Indigenous Peoples

Indigenous data sovereignty is a framework asserting the right of Indigenous peoples to control data about their communities and lands. In genomics, this means Indigenous communities should have authority over how their genetic data is collected, stored, shared, and interpreted. Some tribal nations in the United States have established their own institutional review boards and data governance agreements, requiring researchers to partner with community leaders and return both data and findings to the community. This approach recognizes that genetic information from a population can reveal migration patterns, kinship networks, and health predispositions that have collective significance beyond any individual’s medical record.

How Vulnerable Are Genetic Databases to Attack

The question of how secure genetic databases actually are has been studied systematically. A scoping review analyzing research published between 2017 and 2023 identified 42 original studies that demonstrated a successful privacy attack on genetic data.18JMIR Bioinformatics and Biotechnology. Assessing Privacy Vulnerabilities in Genetic Data Sets: Scoping Review These attacks range from re-identification of supposedly anonymized individuals in research datasets to inference attacks that extract private genetic information from aggregate statistics.

The threat extends beyond raw genetic data. Functional genomics data, like gene expression levels generated from RNA sequencing, can leak identifying information during processing. Even summarized or aggregated data derived from raw sequences can contain enough signal to identify individuals or infer their genetic variants.19Nature. Functional genomics data: privacy risk assessment and technological mitigation The upshot is that simply stripping names from genetic datasets is not enough to protect privacy. De-identification is far harder for genetic data than for most other types of personal information, precisely because a genome is itself an identifier.

Privacy-Preserving Technologies

Researchers have been developing technical solutions to the problem of analyzing genetic data without exposing it. One promising approach is homomorphic encryption, which allows computations to be performed on encrypted data without ever decrypting it. In practical terms, this means a researcher or a cloud server could run an analysis on your genomic data and return results without ever seeing the underlying DNA sequence. Early implementations have shown this is feasible: one system demonstrated privacy-preserving cancer-type prediction for roughly 500 individuals in under a minute, with a single prediction taking about one second.20Scientific Reports. Privacy-preserving cancer type prediction with homomorphic encryption Another system proved that genome analysis could be carried out entirely in an untrusted cloud environment without requiring the decryption key or any interaction with the data owner.21PubMed Central. Private genome analysis through homomorphic encryption

Blockchain technology has also entered the picture. Several research groups have built prototype systems that give individuals control over their own genomic data. One blockchain-based system lets data owners sell access to their genomic data while using homomorphic computation and a secure two-party protocol so that the buyer can run queries without seeing the raw data.22Future Generation Computer Systems. A blockchain-based application for genomic access and variant discovery using smart contracts and homomorphic encryption Another system, called ConsentChain, provides a web portal where patients can grant or withdraw access to their clinical genomic data at any time, with all consent transactions recorded on the blockchain.23PubMed Central. A Blockchain-Based Dynamic Consent Architecture to Support Clinical Genomic Data Sharing (ConsentChain): Proof-of-Concept Study A third framework combines blockchain-based access control with federated learning, so that genetic association studies can be run across multiple institutions without centralizing the raw data in one place.24Computer Standards & Interfaces. An intelligent blockchain-based access control framework with federated learning for genome-wide association studies

These technologies are still largely in the research and pilot stage. None has been deployed at the scale of a major consumer testing company. But they represent a genuine path toward a future where genetic data can be useful to medicine and research without requiring individuals to hand over their raw sequences to entities they must simply trust.

Practical Steps You Can Take

While the legal and technological landscape is still evolving, there are concrete things you can do right now to reduce the exposure of your genetic information:

  • Read the terms: Before using any consumer genetic testing service, read the privacy policy and data-sharing agreements. Look specifically for whether the company shares data with third parties, whether you can opt out of research use, and what happens to your data if the company is sold or goes bankrupt.
  • Request deletion: Most major testing companies allow you to request that your genetic data and your physical sample be destroyed. If you’ve already taken a test and are uncomfortable with ongoing storage, submit a deletion request. Whether the company truly purges all copies is harder to verify, but making the request at least removes your data from active use.
  • Be selective about public databases: Uploading your raw genetic data to open genealogy platforms like GEDmatch means law enforcement and potentially other parties can search it. If you want to participate in genetic genealogy, understand that you are making a choice that affects not just you but your biological relatives.
  • Ask about newborn screening: If you’re a new parent, ask your state’s newborn screening program what happens to leftover blood spots after testing. Some states allow you to opt out of long-term storage or research use.
  • Know GINA’s limits: If you’re considering genetic testing and worried about insurance discrimination, understand that GINA protects you in health insurance and employment but not in life, disability, or long-term care insurance. This may affect timing and disclosure decisions.
  • Limit raw data sharing: Avoid posting raw genetic data files on forums, cloud drives, or social media. Once raw data is shared publicly, it cannot be recalled.

Workplace Genetic Testing Programs

An emerging area of concern is workplace wellness programs that include genetic testing. Some employers now offer or encourage employees to take genetic tests as part of corporate wellness initiatives, often marketed as a health benefit. These programs may promise insights into nutrition, fitness, or disease risk. The genetic data collected through these programs, however, occupies a legal gray zone.

A study examining the websites of 50 companies offering workplace genomic testing found that none of them mentioned GINA in the context of their wellness programs, despite the law being the primary federal protection against genetic discrimination in employment. About two-thirds mentioned HIPAA, but HIPAA’s protections may not apply if the testing company is not a covered entity under that law.5PubMed Central. Workplace genomic testing: What do company websites say about federal privacy and anti-discrimination laws? The omission of GINA is troubling because employees may reasonably assume their genetic information is protected by the same rules that apply in healthcare settings, when in reality the protections may be thinner.

If your employer offers a genetic testing program through a wellness initiative, it’s worth asking who holds the data, how long it’s retained, whether you can opt out without losing other wellness incentives, and whether the testing company is bound by GINA or HIPAA. The answers may not be reassuring, and the fact that companies aren’t volunteering this information to employees suggests the industry hasn’t fully grappled with the privacy implications of what it’s selling.