Privatty All articles
Data Privacy

Swabbed and Sold: The Hidden Market Trading on Your Genetic Identity

Privatty
Swabbed and Sold: The Hidden Market Trading on Your Genetic Identity

The appeal of consumer DNA testing is straightforward: spend roughly one hundred dollars, mail a small tube of saliva, and receive a detailed portrait of your ethnic heritage and potential health predispositions within a matter of weeks. Since the mid-2010s, tens of millions of Americans have done exactly that. What the marketing rarely emphasizes is the secondary life that sample leads once the ancestry report lands in your inbox.

Your DNA is not merely a curiosity about your great-grandparents' origins. It is a permanent biological identifier—one that cannot be changed if it is compromised, unlike a password or even a Social Security number. The companies holding that information have, in many documented cases, treated it as a commercial asset rather than a private record held in trust.

How the Sharing Actually Works

Most major direct-to-consumer genetic testing companies generate revenue from two distinct streams. The first is the testing kit itself. The second—and, for some companies, the more lucrative—involves licensing aggregated or de-identified genetic data to pharmaceutical companies, academic researchers, and, in certain circumstances, law enforcement agencies.

The critical phrase here is de-identified. Companies routinely argue that data stripped of a name and address no longer constitutes personal information. Geneticists and privacy researchers have challenged this position for years. A 2013 study published in Science demonstrated that researchers could re-identify individuals from supposedly anonymous genetic datasets using only publicly available information. When your DNA is involved, true anonymization is exceptionally difficult to guarantee.

GlaxoSmithKline's 2018 partnership with 23andMe—a $300 million agreement granting the pharmaceutical company access to genetic data for drug development—drew significant public attention to this practice. The arrangement was technically disclosed in 23andMe's terms of service, but the disclosure was buried within documents that the company's own research has shown most users do not read in full. Users who had already submitted their samples and consented under earlier, less explicit terms found themselves in an ambiguous position.

Law Enforcement and the Genealogy Loophole

The commercial marketplace is only one dimension of the problem. Law enforcement agencies have developed a parallel interest in consumer genetic databases, and the legal framework governing their access remains inconsistent across states.

The identification of the Golden State Killer in 2018 brought forensic genealogy into public conversation. Investigators uploaded crime scene DNA to GEDmatch, a free genealogy platform, and cross-referenced it against user profiles to identify distant relatives of the suspect. The technique was effective—and it raised immediate questions about consent. Users who submitted their DNA to GEDmatch to find living relatives had not anticipated becoming part of a criminal investigation database.

Following public pressure, GEDmatch updated its policies to require users to actively opt in before their profiles could be searched by law enforcement. However, the platform was subsequently acquired by Verogen, a forensic genomics company, introducing new concerns about the long-term direction of that data. Other genealogy platforms maintain varying standards, and several smaller services have no explicit policy restricting law enforcement access whatsoever.

Federal law offers limited protection. The Genetic Information Nondiscrimination Act (GINA) prohibits discrimination by employers and health insurers on the basis of genetic information, but it does not regulate how testing companies share data with third parties. No comprehensive federal privacy law currently addresses the consumer genetic data market with the specificity the situation demands.

The Companies With the Loosest Guardrails

Not all testing companies approach data governance with equal rigor. Ancestry DNA and 23andMe have published relatively detailed privacy policies and offer users some degree of opt-out control over research participation, though the defaults frequently favor sharing. MyHeritage, based in Israel, stores data subject to Israeli privacy law rather than US frameworks, which introduces a separate jurisdictional complexity for American users.

Smaller, budget-oriented testing services present a more pronounced risk. Several operate with privacy policies that are vague about third-party sharing, contain broad consent language that effectively permits almost any form of data use, and provide no accessible mechanism for users to request deletion of their biological samples or associated records. When these companies are acquired—an increasingly common occurrence as the genetic data industry consolidates—user data transfers to the acquiring entity under terms that may differ substantially from those in place at the time of original consent.

Real Consequences for Real People

The abstract concern becomes concrete when examined through documented cases. In 2020, a Florida court ordered GEDmatch to allow law enforcement access to its full database—not merely the profiles of users who had opted in—as part of a specific investigation. A judge later reversed that order, but the episode illustrated how quickly judicial processes can override platform-level privacy commitments.

Insurance industry observers have noted growing interest among life and long-term care insurers in genetic risk data, despite GINA's employment and health insurance protections not extending to those product categories. While no insurer has publicly acknowledged using consumer genetic data in underwriting decisions, the gap in legal protection remains open.

Perhaps most concerning is the permanence of the exposure. A data breach at a genetic testing company is categorically different from a breach at a retail platform. You can replace a credit card number. You cannot replace your genome.

Steps You Can Take Right Now

If you have already submitted a DNA sample to a testing company, several concrete actions are available to you.

Request deletion of your biological sample. Most major services are legally required to destroy the physical sample upon request. Submit this request in writing and retain a copy. Note that deletion of the sample does not automatically remove your genetic profile from the company's database.

Opt out of research participation. Log into your account settings and locate the research consent section. The default for most platforms is opt-in, meaning your data is being shared unless you explicitly decline. Change this setting immediately.

Submit a data deletion request. Under the California Consumer Privacy Act (CCPA), California residents have the right to request deletion of their personal data, including genetic profiles. Residents of other states with similar legislation—Virginia, Colorado, and Connecticut among them—hold comparable rights. Even if your state has not enacted equivalent protections, many companies will honor deletion requests as a matter of policy.

Review the privacy policies of any genealogy platform you use. Pay specific attention to sections addressing law enforcement access, third-party data sharing, and what happens to your data in the event of an acquisition or bankruptcy.

Consider whether testing is necessary in the first place. If you have not yet submitted a sample, weigh the benefits against the long-term privacy implications. The information a DNA test provides is valuable—but so is the data itself, to parties whose interests may not align with your own.

The Regulatory Gap and What It Means for You

Until Congress passes comprehensive genetic privacy legislation—a prospect that has stalled repeatedly—the consumer genetic data market will continue to operate in a regulatory environment that lags well behind the technology it governs. State-level protections are expanding but remain uneven. The burden of protecting this data, for now, falls disproportionately on individual users.

Your genetic information is the most permanent record of who you are. The companies that hold it have demonstrated, through their business models and their policy choices, that they do not always treat it with the gravity that permanence demands. Knowing the mechanisms of this market—and acting on that knowledge—is among the most consequential privacy decisions you can make.

All Articles

Related Articles

Granted Without Thinking: How Apps Quietly Collect Far More Than They Need

Granted Without Thinking: How Apps Quietly Collect Far More Than They Need

Every Word You Send: How Email Providers Read Your Messages and Build a Portrait of Your Private Life

Every Word You Send: How Email Providers Read Your Messages and Build a Portrait of Your Private Life

Files in the Cloud, Data on the Market: What Your Storage Provider Knows About How You Live

Files in the Cloud, Data on the Market: What Your Storage Provider Knows About How You Live