⚠ Why DNA Privacy Matters More Than Other Data
Your DNA is uniquely risky: Unlike passwords or credit cards, genetic data cannot be changed if exposed. It reveals information about your biological relatives who never consented. And despite legal protections like GINA, genetic information could theoretically impact insurance (life, disability, long-term care are NOT covered by GINA) and employment. This review documents exactly what MyHeritage can and cannot do with your most sensitive data.
🌎 International Company Notice
MyHeritage is headquartered in Or Yehuda, Israel, with additional offices in Tel Aviv, Lehi (Utah), Kyiv (Ukraine), and Burbank (California). DNA testing is processed at Gene by Gene's laboratory in Houston, Texas, USA. The company was acquired by U.S. investment firm Francisco Partners in 2021. Data transfers between Israel, the US, and other jurisdictions are subject to Standard Contractual Clauses under GDPR.
⚠ 2018 Security Incident
On June 4, 2018, MyHeritage disclosed a cybersecurity breach:
92,283,889 user email addresses and hashed passwords exposed
According to MyHeritage's official statement, the breach occurred on October 26, 2017 and was discovered when a security researcher found a file on a private server outside of MyHeritage. The company stated that "Credit card information is not stored on MyHeritage" and that "family trees and DNA data are stored on segregated systems, separate from those that store the email addresses."
📊 Data Collection Scope
Genetic Information (DNA Data)
MyHeritage collects genetic data from DNA tests or uploaded results:
Biometric Data (Facial Recognition)
MyHeritage collects biometric information from photos through their Photo Tagger feature:
Health Data
MyHeritage collects self-reported family health history:
Family Tree and Genealogical Data
MyHeritage collects names, emails, family tree data, photos, and contact details:
Web Behavior and Tracking
MyHeritage collects usage data through automated means:
👥 Third-Party Sharing
No Sale or License of Personal Data (Strong Commitment)
MyHeritage makes an explicit and emphatic commitment not to sell personal data:
No Sale of Genetic or Health Data
Additional specific commitment regarding genetic data:
Service Providers
MyHeritage shares data with specific third-party service providers:
DNA Matching Feature
DNA data may be shared with genetic matches if the feature is enabled:
Research (Requires Explicit Consent)
Research use of data requires explicit user consent:
Insurance Companies (Explicitly Excluded)
MyHeritage explicitly states they will never provide data to insurance companies:
Law Enforcement Access
MyHeritage has explicit policies regarding law enforcement:
Law Enforcement - Court Orders
Information will only be provided under legal compulsion:
Business Transactions
Data transfer in case of company sale:
🔑 Data Ownership Statement
MyHeritage explicitly recognizes user ownership of DNA data:
Additionally:
🕐 Data Retention
General Retention Policy
MyHeritage retains personal information as necessary for services:
DNA Sample Retention - Up to 10 Years
Physical DNA samples may be stored for an extended period:
DNA Sample Storage Location
DNA samples are stored at the Texas laboratory:
Facial Recognition Model Retention
Biometric data has an automatic deletion policy:
Post-Deletion
Account deletion effects:
☑ User Control and Consent
Data Deletion Rights
Users can delete their data at any time:
DNA Sample Destruction
Users can request destruction of their biological sample:
DNA Matching Control
Users can control the DNA matching feature:
Research Consent Withdrawal
Users can withdraw research consent, but with limitations:
User Rights (GDPR, CCPA, etc.)
MyHeritage acknowledges various regional rights:
🔒 Security Measures
Security Implementation
MyHeritage describes their security approach:
Penetration Testing
Regular security assessments:
Access Controls
Limited personnel access:
Encryption
DNA data protection:
Laboratory Certifications
DNA testing laboratory credentials:
Security Disclaimer
MyHeritage acknowledges limitations:
🌎 GDPR/CCPA Compliance
Regional Privacy Laws
MyHeritage acknowledges jurisdiction-specific rights:
GDPR Data Protection Officer
MyHeritage has designated a DPO:
International Data Transfers
Data transfer mechanisms for international transfers:
Data Center Location
Where data is stored:
Policy Change Notification
MyHeritage commits to notifying users of material changes:
🔬 Research Program
Research Scope
Types of research MyHeritage conducts:
Scope Limitation
Research is limited to stated purposes:
No Third-Party Sale for Research
Research data will not be sold to third parties:
Anonymization of Research Data
Research data is anonymized:
No Individual Research Results
Research results are not communicated to individual participants:
Analysis