Abstract
After declaring bankruptcy in March 2025, direct-to-consumer (DTC) genetic testing company 23andMe sold the data of more than 15 million people around the world to TTAM Research Institute, a nonprofit organization created by 23andMe’s founder and long-time CEO. 23andMe’s customers might breathe a sigh of relief that their data didn’t end up in the hands of different leadership. But the saga made salient the ways in which existing laws fail to fully protect genetic data against exploitation and misuse. Commercial sales of genetic data have happened before, and they will happen again. The next data sale is likely to involve a buyer unrelated to the seller, which may result in fewer privacy protections. Congress has finally expressed interest in taking action, but proposed legislation does not provide adequate or genuine consumer protection.
The Business of DTC Genetics
23andMe held one of the largest genetic databases in the world. In many ways, its DTC model was the paradigm: Consumers buy a testing kit, collect a saliva sample, and ship their biospecimen back to the company. The company extracts DNA from the sample and genotypes or sequences substantial portions of that DNA, analyzes the resulting data, and makes the results available to the consumer who registered the kit on the company’s website. Some DTC genetic testing companies (though not 23andMe) also permit users to upload raw genetic data generated elsewhere for analysis.
Information provided by DTC genetic testing companies routinely includes estimates of ancestry, health risks to the consumer or their potential children, and other traits. 23andMe promised consumer control and privacy, and indeed, its terms of service, privacy policy, and consent documents gave consumers several choices regarding their data and biospecimens (1). For example, consumers could opt in to a feature to connect with genetic relatives or allow 23andMeto use their data for research. 23andMe also provided survey questions and linked that survey data with individuals’ genetic data. Consumers had the option to allow 23andMe to store their biospecimens indefinitely and without limitation, perhaps for future, more comprehensive testing as science advances. Other provisions permitted 23andMe to retain biospecimens for other limited purposes, including to comply with legal and regulatory requirements. Thus, 23andMe’s data and biobank included more than just genetics—it also included self-reported information related to health, environment, and behavioral variables, biospecimens, and registration information, including consumers’ addresses and credit card information (1). DTC genetic testing company policies vary widely; 23andMe notably offered more consumer control than most.
A databank of this type and magnitude requires heightened protection for privacy and security. Despite being an industry leader, 23andMe still struggled to keep the data in its possession protected, suffering a data privacy breach in 2023 (2), which exposed global security risks. According to a recent lawsuit, 23andMe failed to notify consumers with Chinese and Ashkenazi Jewish heritage that their personal genetic information appeared to have been compiled into “specially curated lists” that were shared and sold on the dark web. Several other DTC genetic testing companies have also experienced data breaches and security lapses.
Genetic data are sensitive, personal, and immutable; using a DTC genetic testing service should not forfeit a consumer’s privacy (3). The information generated and held by DTC genetic testing companies can reveal an individual’s identity, genetic relatedness to others, physical traits, and health conditions and risks. Genetic data are unique to the individual, making reidentification rare but possible, even after names and other identifying information are removed (4). Yet although genetic information is highly individual, people also share predictable portions of it with genetic relatives. Asa result, a database of 15 million people makes hundreds of millions, if not billions, of people across the globe directly and indirectly identifiable. Robust privacy protection for genetic data is therefore even more essential because it is only the consumers, and not their genetic relatives, who give consent (5). Other data sources may raise similar concerns about privacy and security, also meriting enhanced protections. Even so, whereas other data evolves and changes and may be “about” people, genetic information, in a very real sense, “is” people.
Inadequate Protections
Recognizing that sensitive personal information was involved, the bankruptcy court in the 23andMe proceeding appointed a consumer privacy ombudsman (CPO) to determine whether a sale would conflict with nonbankrupt legal protections. The CPO considered a wide variety of legal protections, including genetic privacy laws, the Federal Trade Commission Act, state consumer protection legislation, state comprehensive privacy laws, and state consumer health data statutes (6). Notwithstanding the CPO’s concerns under these laws, the bankruptcy court concluded that no conflict existed, particularly with TTAM as the buyer (7, 8).
That finding, however, says little about whether the sale of these genetic data would nevertheless pose clear risks to consumers because existing laws provide limited protection. As the bankruptcy judge concluded, “These cases present challenging issues involving sensitive information. In the abstract, a company’s sale of genetic data is a scary proposition, and reasonable people might conclude that it should not be permitted in any circumstances. In our society, legislators are empowered to make decisions of that sort, and they have not taken such a firm stance” [(8), pp. 37–38]. Unlike the European Union, the US does not have a comprehensive federal privacy law to protect personal information or give rights over data (2). The Health Insurance Portability and Accountability Act (HIPAA) protects certain health information in the US. However, HIPAA is limited in its scope and applies only to health plans, health clearinghouses, health care providers, and their “business associates.” It typically does not apply to DTC genetic testing companies (2).
The bills presently pending before Congress do more but remain inadequate. The proposed Genomic Data Protection Act focuses on safeguarding a consumer’s right to delete their DTC genetic testing account, associated data, and biospecimen. The proposed Don’t Sell My DNA Act focuses on chapter 11 bankruptcy and requires debtors holding genetic data to obtain affirmative written consent from consumers to sell or use their data after the bankruptcy proceeding has commenced. These efforts are laudable, but neither provides sufficiently robust protection. The Genomic Data Protection Act’s right to deletion places the onus on the consumer to affirmatively delete their data before a sale. Additionally, barriers like the death of the tested individual, testing of children by their parents, or testing under a fake name may complicate an individual’s ability to effectuate deletion. The Don’t Sell My DNA Act, meanwhile, would apply only in chapter 11 bankruptcy. This would leave consumers unprotected in other kinds of sales and perhaps disincentivize companies from declaring bankruptcy when otherwise appropriate. Yet what Congress does will reach beyond the US, too, given the popularity of DTC genetic testing across the globe, the utility of that genetic data for research and other uses, and the genetic links between individuals across borders.
State laws can offer some additional protection for some consumers. A minority of states have enacted general data privacy laws in recent years that may be relevant to the DTC genetic testing context, such as enshrining rights of access and a right to opt out of sharing data with third parties. Some states have also adopted a model Genetic Information Privacy Act (GIPA), which regulates how DTC genetic testing companies handle sensitive data (9). These laws generally apply only to a DTC genetic testing company, defined as “an entity that (a) offers consumer genetic testing products or services directly to consumers; or (b) collects, uses, or analyzes genetic data that a consumer provides to the entity” (10). Many different companies control sensitive genetic data. It is not clear whether all of them will meet this definition. Moreover, many of the GIPA laws include a provision requiring express consent for “the transfer or disclosure of the consumer’s genetic data” to third parties who aren’t vendors or service providers (10). Twenty-eight states initially sought to block 23andMe’s bankruptcy sale on this basis, arguing in part that GIPA and data privacy laws prevent the sale of genetic information without express consumer consent. Ultimately, however, the bankruptcy court and most of the states concluded that TTAM’s acquisition of 23andMe’s assets was adequate, given the congruous nature of the two entities’ leadership and business models.
Although state-level general data privacy and genetic-specific privacy laws offer some important protections, not every state has enacted such legislation. All people should enjoy these baseline protections, no matter what entity holds their genetic data or where they live, particularly as data can cross state lines. Congress should enact a federal GIPA and a general data privacy law applicable to all people and across different types of entities. (HIPAA-covered entities may be excluded, given the framework of that statute.) In addition, lawmakers should prohibit entities—and any third parties with whom they share the covered data—from attempting to reidentify any deidentified personal information. Another option, recommended by the CPO in the bankruptcy proceeding, is to adopt a trust-based privacy model and impose quasi-fiduciary duties, such as a duty of loyalty for DTC companies, requiring them to act in the best interest of their consumers (6).
Shifting Terms of Service
In the absence of comprehensive privacy laws, a company’s terms of service and/or privacy policy govern(s), even though they often fail to offer the baseline of protection that GIPAs guarantee. Most people must rely on the disclosed promises of the DTC genetic testing company (2).
Those policies also typically allow a company to unilaterally change its terms, sometimes with notice but often without express consent (11). Consider 23andMe’s terms of service. The company reserved “the right at any time to modify or discontinue, temporarily or permanently, the Services (or any part thereof) with or without notice” [terms of service in (1)]. Moreover, it clarified that “notice” may arrive “via either email or regular mail. 23andMe may also provide notices of changes to the Terms or other matters by displaying notices or links to notices to you generally on or through the Services” [terms of service in (1)]. Additionally,23andMe’s privacy policy provided, “We may make changes to this Privacy Statement from time to time. We’ll let you know about those changes here or by reaching out to you via email or some other contact method, such as through in-app notification, or on another website page or feature” [privacy policy in (1)]. Yet consumers rarely read terms of service or privacy policies in full or check back for updates (3). TTAM agreed to adopt 23andMe’sprivacy policy at the time of sale, so these provisions remained after the bankruptcy.
To strengthen genetic privacy, Congress and other lawmakers could prevent companies from making unilateral changes to substantial terms unless users affirmatively opt in (11). Under our proposal, consumers would need to opt in if a DTC genetic testing company changed its terms to allow law enforcement, for example, to access its database. Restricting the protections to substantial changes in this way serves at least two functions. First, companies will still be able to make minor updates on their own. Second, the term “substantial” offers flexibility, ensuring that the provision remains relevant, even as the market evolves. The consent required to make such changes could take the form typically required by state GIPAs, which mandate “a consumer’s affirmative response to a clear, meaningful, and prominent notice regarding the collection, use, or disclosure of genetic data for a specific purpose” (10).
Risks of Misuse
The privacy of genetic information is even more important given gaps in US discrimination law. The federal Genetic Information Non-discrimination Act prohibits discrimination in health insurance and employment but does not regulate the use of genetic information by other entities. For example, companies that offer coverage for life, long-term care, and disability insurance can underwrite based on genetic information, leaving certain individuals deemed too risky to insure. Florida is the only state that bars all three kinds of insurers from considering genetic information in underwriting. In most states, sharing genetic data with life, long-term care, and disability insurers could be legally permissible (12). Fear of genetic discrimination is a salient concern for many (12). Indeed, especially in the early days, DTC genetic testing was heralded as a way to insulate individuals from the risks of discrimination stemming from clinical genetic testing. Lawmakers should prohibit DTC genetic testing companies from sharing those data with any insurers. This baseline protection would not prevent insurers from seeking information about genetic testing completed within the bounds of clinical care but would insulate genetic data created commercially without robust informed consent or nuanced assessment of medical indication for testing.
Law enforcement may also want access to DTC genetic data. For example, in 2018, Joseph James DeAngelo was arrested as the Golden State Killer after law enforcement surreptitiously uploaded crime scene DNA to several DTC genetic testing platforms and identified him as a suspect. In the years since, law enforcement has eagerly sought suspects in hundreds of other cases via “family trees” on DTC genetic testing platforms such as GEDmatch and FamilyTreeDNA(5). Larger DTC companies such as 23andMe and Ancestry have, to date, publicized a commitment to resist law enforcement access (3).
Given those commitments, police access to consumer genetic data held by companies like 23andMe or Ancestry would be a profound betrayal of consumer trust. Yet history shows that law enforcement can find creative, if not explicitly illegitimate, ways to access these data, particularly on platforms that permit consumers to upload genetic data generated elsewhere. For instance, despite its own contrary guidance, the Federal Bureau of Investigation has uploaded casework DNA profiles to platforms that permit third-party uploads but do not authorize law enforcement use (13).
Thus, lawmakers should also implement robust procedures regulating law enforcement access (14). At a minimum, such access should be limited to DTC genetic testing companies that have made their cooperation with law enforcement an express part of consumer consent.
Neglected Biospecimens
As discussed above, 23andMe gave consumers the option to store their saliva sample after the initial genetic analysis was complete. The company also disclosed that there might be other legal obligations to retain it, such as the Clinical Laboratory Improvement Amendments. Its biobanking consent document explained that “samples are stripped of personal identifiers (i.e. name and contact information)” (1). Biospecimens can contain a wide range of biomolecules associated with health conditions such as infectious diseases (e.g., COVID-19) and other systemic diseases (e.g., Crohn’s) in addition to genetic information. Also, for 23andMe consumers who consented to research, the company stated that it might develop more extensive genetic data from the sample, including conducting whole-genome sequencing (WGS). By reading the entire genome, WGS generates much more information than traditional DTC “genotyping,” which only analyzes select areas of DNA already associated with outcomes of interest, such as disease or ancestry. Because it generates enough information to make the sequence unique to only one person, WGS also makes the data more readily identifiable (4). 23andMe’s research consent further stated that the company was entitled to analyze microbiome data that could “provide a snapshot of the trillions of microbes found in a human body, which may influence health and wellness” (1). A recent filing in the bankruptcy court disclosed that nearly 10.4 million customers had affirmatively consented to biobanking their specimen (7).
The disposition of biospecimens has made headlines in the past with the case of Henrietta Lacks, an impoverished, Black cancer patient whose tissue sample was taken for research in 1951 without her express consent. The sample was developed into the HeLa cell line that is widely used in research to this day. Backlash to this story reached such a furor that the federal government briefly considered offering more protections for biospecimens than data in federally funded research because of “autonomy interests of participants in research using their biospecimens” (15).
People overwhelmingly report that they want clear notice of the commercial use of their biospecimens (15) and that disclosures about the commercialization of biospecimens are often confusing. For 23andMe, consumers had to read four different documents (the privacy statement, biobanking consent document, research consent document, and terms of service) in tandem to fully understand what could be done with their biospecimen (1)—an undertaking too demanding for most people to accomplish or comprehend. It is even more demanding to expect consumers to periodically review and assess what unilateral changes have been made to substantial terms without their express consent.
Moreover, none of 23andMe’s legal documents addressed the sale of biospecimens, even after the company amended those documents to account for the bankruptcy-related sale of personal data.23andMe’s privacy policy read as follows: “If we are involved in a bankruptcy, merger, acquisition, reorganization, or sale of assets, your Personal Information may be accessed, sold or transferred as part of that transaction and this Privacy Statement will apply to your Personal Information as transferred to the new entity” [privacy policy in (1)]. “Personal Information” was defined as information derived from the biospecimen (1), but these policies did not address the biospecimen itself.
Legislatures and companies ought to carefully consider how to treat these biospecimens as well, and under what conditions they may be transferred in a sale. DTC genetic testing companies should also be required to obtain affirmative and specific opt-in consent before consumer biospecimens can be sold or transferred. Alternatively, imposing a duty of loyalty would require companies to do more to bridge the disconnect between consumer understanding and company practice regarding biospecimens and associated genetic data (6).
The 23andMe bankruptcy reminds us how vulnerable people’s DTC genetic data are to sale and potential misuse, given gaps in the law and the predictable vagaries of commercial markets. Public fervor has dissipated over the sale of 23andMe to TTAM. But the next time genetic data are on the auction block will likely invite greater risks. Congress and other lawmakers must act to robustly protect DTC genetic data and biospecimens into the future.
Acknowledgements
This commentary draws from written testimony submitted to the Senate Committee on the Judiciary for its 11 June 2025 hearing “23 and You: The Privacy and National Security Implications of the 23andMe Bankruptcy.” We thank our colleagues who joined that testimony. In addition, we are grateful to anonymous reviewers for their insightful and helpful comments. K.S.B. acknowledges support by the National Center for Advancing Translational Sciences (UL1TR002240 and R01TR004244), the National Institute on Aging (U54AG084520), and the Greenwall Foundation’s Faculty Scholars Program.
References and Notes
- 1.Links to full versions of the terms of service, privacy policy, research consent, sample storage consent, and transparency report of 23andMe can be accessed at https://www.23andme.com/privacy/.
- 2.Gerke S, Jacoby MB, Cohen IG, N. Engl. J. Med 392, 937 (2025). [DOI] [PubMed] [Google Scholar]
- 3.Ram N, Va. Law Rev 105, 1357 (2019). [Google Scholar]
- 4.Spector-Bagdady K, Ann. Epidemiol 26, 515 (2016). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 5.Ram N, Consumer Genetic Technologies: Ethical and Legal Considerations, Cohen IG, Farahany N, Greely HT, Shachar C, Eds. (Cambridge Univ. Press, 2021), pp. 211–228. [Google Scholar]
- 6.Report of Consumer Privacy Ombudsman, In re: 23andMe Holding Co., no. 25-40976-357 (Bankr. E.D. Mo. 11 June 2025), Dkt. 718. [Google Scholar]
- 7.Order Approving Sale, In re: 23andMe Holding Co., no. 25-40976-357 (Bankr. E.D. Mo. 27June 2025), Dkt. 910. [Google Scholar]
- 8.Opinion M, In re: 23andMe Holding Co., no. 25-40976-357 (Bankr. E.D. Mo. 27 June 2025), Dkt. 908. [Google Scholar]
- 9.Prince AER, Spector-Bagdady K, JAMA 333, 665 (2025). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 10.Genetic Information Privacy Act, Utah Code § 13-60 pt. 1 (2025). [Google Scholar]
- 11.Roberts JL, Hawkins J, Science 367, 745 (2020). [DOI] [PubMed] [Google Scholar]
- 12.Anderson JO, Lewis AC, Prince AE, DePaul J, Health Care L 22, 1 (2021). [Google Scholar]
- 13.Baker M, “To identify suspect in Idaho killings, F.B.I. used restricted consumer DNA data,”New York Times, 25 February 2025. [Google Scholar]
- 14.Ram N, Murphy EE, Suter SM, Science 373, 1444 (2021). [DOI] [PubMed] [Google Scholar]
- 15.Spector-Bagdady K et al. , JAMA 328, 474 (2022). [DOI] [PMC free article] [PubMed] [Google Scholar]
