DNA might contain health information, but unlike a doctor’s office, 23andMe is not bound by the health-privacy law HIPAA. And the company’s privacy policies make clear that in the event of a merger or an acquisition, customer information is a salable asset. 23andMe promises to ask its customers’ permission before using their data for research or targeted advertising, but that doesn’t mean the next boss will do the same. It says so right there in the fine print: The company reserves the right to update its policies at any time. A spokesperson acknowledged to me this week that the company can’t fully guarantee the sanctity of customer data, but said in a statement that “any scenario which impacts our customer's data would need to be carefully considered. We take the privacy and trust of our customers very seriously, and would strive to maintain commitments outlined in our Privacy Statement.”
HA ! Sweet vindication! I've been preaching to friends and family not to use these DNA companies for this and other reasons. They called me a loon and I should get my tin foil hat. I cant wait to see their faces
I'm so glad I never sent them my DNA. It was tempting from a genealogy perspective. But my concerns about privacy and them selling on customer information always weighed heavier than that temptation.
But I feel a lot of sympathy for those who used their services. For a while they incessantly advertised them, including via paid endorsements from many 'trusted' podcasters and YouTubers. The company's failure should bring to the fore a drive for new laws in many countries to protect consumers' DNA from being monetized and exploited. But sadly we all know it won't.