Written by: Stevie Gluckman
Edited by: Rafaela Paquet
Feb 2025

Featured image: Large, J. (2024, June 21). https://www.ipvanish.com/blog/dna-testing-privacy/
23andMe, one of the most prominent consumer genetic testing companies, announced layoffs of about 40% of its workforce this past November. Without new funds, the company has warned the public that it has“substantial doubt” that it will survive. The firm’s financial instability has raised concerns about data privacy, in the realms of both personal rights and international security. 23andMe’s limited privacy policy, the shortcomings of U.S. legislation, and the potential for foreign acquisition prove that new laws are becoming more necessary as the genetic testing industry grows.
A Privacy Policy That Allows Data Transfers
23andMe’s privacy policy explicitly states that consumer data can be transferred in the event of an acquisition, merger, or sale of assets. While the company claims that shared data is de-identified, meaning that all names are removed from personal information and replaced with numerical IDs; genetic information is inherently sensitive and unique, with the proven potential to be re-identified through advanced techniques. This provision means that the genetic profiles of millions of customers could fall into the hands of another entity; possibly one with fewer commitments to data protection. The company’s recent 2023 data breach, where a hacker gained access to millions of pieces of data, makes this fear feel like a realistic possibility.
The potential of a financial sale introduces significant uncertainty. Customers entrust 23andMe with intimate details about their genetic makeup, expecting this information to remain secure and confidential. However, the policy shows that such data could easily be treated as an asset in a financial transaction, exposing individuals to risks that include misuse of their genetic information.
Broader Implications: Insurance and Discrimination
The potential misuse of genetic data raises questions about how this information could be taken advantage of in industries like insurance. Under the Genetic Information Nondiscrimination Act (GINA) of 2008, U.S. health insurers and employers are prohibited from using genetic data to discriminate against individuals. However, GINA does not extend to life, disability, or long-term care insurance. This means insurers in these sectors could deny coverage or set higher premiums based on genetic predispositions to certain diseases. Experts caution that, especially in this time of instability, the company may be tempted to sell user data for short-term recovery profit. If 23andMe’s data were acquired by an insurer, whether directly or indirectly, it could lead to discriminatory practices and a breach of consumer trust.
Foreign Acquisition: Lessons from the Grindr Case
Another looming concern is the possibility of foreign acquisition. A comparable case occurred when Beijing Kunlun Tech, a Chinese firm, acquired the dating app Grindr in 2016. U.S. authorities eventually forced the company to divest its ownership after citing national security concerns related to sensitive personal data, such as the geolocation of important personnel. With 23andMe’s genetic database holding even more sensitive information than Grindr, a foreign acquisition could pose severe risks, including genetic surveillance, profiling, or even bioweapon development.
The Committee on Foreign Investment in the United States (CFIUS) could step in to block such a transaction, as it did with Grindr, although this does not fully mitigate the risk. If CFIUS intervenes after data has already been exposed or shared, the damage could be irreversible. The case highlights the need for proactive legislation to address these scenarios before they become crises.
A Call for Stronger Genetic Privacy Laws
The situation with 23andMe underscores a critical gap in U.S. privacy protections. Existing laws like GINA, while a step forward, are insufficient to address the complexities of genetic data in an era of globalization and advanced technology. New regulations must expand GINA to include protections for all types of insurance and impose stricter controls over how genetic data is transferred or sold. Additionally, legislation should ensure consumer consent is required for any transfer of genetic data, even in cases of bankruptcy or acquisition.
Genetic data is a double-edged sword: while it holds immense potential for advancing medicine and health, it also poses unprecedented risks when mishandled. By strengthening privacy laws and creating international frameworks for genetic data protection, we can safeguard individual rights and national security, ensuring this powerful resource is used responsibly.
