⚠ Data Sensitivity Tier 1: Genetic Data
Genetic data requires the highest privacy protections - it cannot be changed, reveals information about biological relatives who never consented, and may have implications for employment and insurance. This review focuses on documented policy language with exact citations.
📊 Data Collection Scope
Genetic Information
23andMe collects detailed genetic data from your DNA sample:
Self-Reported Health Data
Beyond DNA, 23andMe collects extensive health and personal history information:
Biological Sample Information
Your physical saliva sample and laboratory analysis data:
Registration and Account Data
Standard personal identifiers linked to your genetic data:
Web Behavior and Tracking
Online activity tracking through various technologies:
👥 Third-Party Sharing
Research Partners (Including Pharmaceutical Companies)
23andMe explicitly states that research may involve pharmaceutical companies:
Research Data Sharing (De-identified)
Research results may be shared with collaborators and published:
Service Providers
Various contractors have access to personal information:
Law Enforcement Access
23andMe's policy on law enforcement cooperation:
Insurance and Employers (Excluded)
23andMe explicitly states they will not share with certain parties:
Mergers and Acquisitions
Restrictions on genetic data transfer in corporate transactions:
🔍 Law Enforcement Transparency (as of June 2, 2025)
According to 23andMe's Transparency Report:
11 total law enforcement requests received
15 users/accounts specified in requests
0 instances where data was produced
🕐 Data Retention
General Retention Policy
23andMe retains data for service delivery and legal compliance:
Genetic Data - Extended Legal Retention
Genetic information is subject to extended retention requirements under federal law:
Post-Deletion Record Keeping
Even after account deletion, certain records are maintained:
☑ User Control and Consent
Research Participation (Opt-In)
Research involvement requires explicit consent:
Sample Storage Choice
Users can choose whether to retain or destroy their biological sample:
Account Deletion
Users can delete their account, but the process is irreversible:
Irreversibility Warning
23andMe emphasizes the permanent nature of deletion:
Research Withdrawal Limitations
Important limitation on withdrawing from research:
Data Access and Download
Users can access their personal information:
🔒 Security Measures
Security Implementation
23andMe describes their security approach:
Ongoing Security Review
Security practices are regularly updated:
Two-Factor Authentication
Account protection mechanisms:
🌎 GDPR/CCPA Compliance
Regional Privacy Rights
23andMe acknowledges jurisdiction-specific rights:
US State Privacy Laws
California and other state residents have additional rights:
GINA Protection
Federal genetic non-discrimination protections:
Research De-identification
How research data is processed:
Analysis