DNA Testing Kits Collect Data That Can Never Be Taken Back — Here Is What Companies Do With Your Genetic Information

DNA Testing Kits Collect Data That Can Never Be Taken Back — Here Is What Companies Do With Your Genetic Information

It’s no secret that millions of people have mailed off a bit of saliva in a plastic tube, hoping to unlock family mysteries, discover health risks, or just satisfy their curiosity. DNA testing kits from companies like 23andMe, AncestryDNA, and MyHeritage have made this process easy—sometimes even fun. But what happens to your genetic information after the results come in? Can you ever truly take it back? And what are the real consequences when companies mishandle something as personal as your DNA?

These aren’t just abstract questions. Recent headlines—like the bankruptcy of 23andMe and lawsuits over massive data breaches—have made it painfully clear that what’s at stake isn’t just a quirky family tree or a list of distant relatives. It’s your permanent, unchangeable biological blueprint. If your credit card number leaks, you can cancel it. If your social security number is stolen, you can freeze your credit. But your DNA? That’s forever. Understanding what companies do with your genetic data, what rights you actually have, and what you can do to protect yourself is more important than ever.

What Happens to Your DNA Data After Testing?

When you send a DNA sample to a testing company, you’re not just getting a one-time analysis. You’re handing over a copy of your most private information—your genetic code. Here’s what typically happens:

  • Your sample is analyzed to produce a digital genetic profile. This profile can include ancestry information, health risk factors, and other traits.
  • Your digital genetic data is stored on company servers. This data is linked to your account, and often to other information like your name, email, and payment details.
  • Your biological sample (the saliva tube) may be stored for further testing or research, sometimes for years unless you specifically request its destruction.
  • Your data may be shared or sold—with your consent, in most cases—for research, product development, or even to third-party partners.

Some companies claim to anonymize your data before sharing it for research. But genetic data is inherently identifiable. Unlike a password or phone number, you can’t change your DNA. If it’s ever matched back to you, the consequences can be lasting.

Why Millions of Users Never Realize Their Data Was Exposed

Most people assume that once they delete their account, their data is gone. Unfortunately, that’s rarely the case. Even if you request deletion, companies may retain your genetic data for legal, regulatory, or research purposes. And if your data was already shared with research partners or sold to third parties, it’s nearly impossible to track or recall it.

This became painfully clear in 2023, when 23andMe suffered a breach that exposed the genetic information of nearly 7 million users. Many affected customers had no idea their data was at risk, and some may have assumed their information was safe because they’d changed privacy settings or deleted old accounts. The breach wasn’t just an embarrassing headline—it was a wake-up call about how little control users truly have once their DNA is in the system.

Bankruptcy and Breaches: The Risks You Didn’t Sign Up For

When 23andMe filed for bankruptcy in March 2025, it wasn’t just a business story. It raised urgent questions: Who owns all that genetic data now? What happens if the company is sold? Can your DNA be treated as just another asset?

Bankruptcy proceedings often involve selling off company assets, including databases. While privacy policies and some laws may limit how genetic data can be used or sold, there’s no guarantee your information won’t change hands. In the chaos of a bankruptcy or acquisition, your data could end up with a company you never agreed to trust.

And breaches aren’t rare. The lawsuit filed by California’s Attorney General against 23andMe in 2026 highlights that even major companies with millions of users can fail to protect sensitive data. Once your genetic information is out, there’s no putting the toothpaste back in the tube.

Common Misconceptions: What You Think You Control (But Don’t)

  • "I can delete my DNA data anytime." Deleting your account usually removes your access to the service, but it may not erase your genetic data from the company’s servers—or from research databases where it was already shared.
  • "HIPAA protects my genetic privacy." HIPAA, the U.S. health privacy law, generally doesn’t cover consumer DNA testing companies. Your data isn’t always protected the way your doctor’s records are.
  • "Genetic data is anonymous." Even if your name is removed, your DNA can be matched to you or your relatives. Researchers have repeatedly shown that so-called anonymized genetic data can be re-identified.
  • "Only I have access to my results." Depending on your privacy settings, your data may be accessible to company employees, research partners, or even law enforcement (sometimes with a warrant, sometimes not).

Who Has Access to Your Genetic Information?

It’s not just you and the testing company. Depending on your settings and the company’s policies, your genetic information may be accessed by:

  • Company employees (for analysis, troubleshooting, or research)
  • Research partners (universities, pharmaceutical companies, or other third parties)
  • Other users (if you participate in family matching or public ancestry features)
  • Law enforcement (with a court order, or in some cases, with less oversight)
  • Future owners of the company or its databases (in the event of a sale or bankruptcy)

Each step away from your direct control increases the risk that your data will be misused or exposed.

Real-World Consequences: It’s Not Just About Privacy

When people think about DNA privacy, they often worry about hackers or identity theft. But the risks go much further:

  • Potential discrimination. The Genetic Information Nondiscrimination Act (GINA) protects against discrimination in health insurance and employment, but it does not protect you when applying for life, disability, or long-term care insurance. Some insurers may try to use genetic information to deny coverage or raise rates.
  • Family implications. Your DNA isn’t just yours—it’s shared with your relatives. If your genetic data is exposed, it can reveal information about siblings, parents, children, or even distant cousins. Some people have discovered unexpected family members or uncovered family secrets, leading to stress or conflict.
  • Loss of control. Once your genetic data is shared, it’s nearly impossible to recall or delete it everywhere. This can cause ongoing anxiety, especially if you learn your data was part of a breach or sale.
  • Emotional fallout. Learning about health risks, unknown relatives, or family history can be overwhelming. If your data is misused or exposed, it can add embarrassment, stress, or distrust to the mix.

How to Actually Limit Sharing of Your DNA Data

While you can’t un-send your DNA sample, you do have some options to reduce risk going forward. Here’s what actually works:

  1. Review your privacy settings. Log in to your DNA testing account and look for options to limit data sharing. Turn off features like family matching or research participation if you don’t want your data shared.
  2. Request data deletion. Contact customer support and ask for the deletion of your genetic data and the destruction of your biological sample. Be aware that companies may retain some data for legal or regulatory reasons, and data already shared externally may not be retrievable.
  3. Monitor company updates. Stay alert for changes to privacy policies, especially if the company is facing financial trouble or legal action. If ownership changes, review your options again.
  4. Consider opting out of research. Many companies enroll you in research by default. You can usually opt out, but you may need to do this separately from deleting your account.
  5. Limit what you share with family features. If you use family matching, be aware that your relatives may be able to see parts of your genetic information. Think carefully before enabling these features.

What Rights Do You Really Have Over Your Genetic Data?

Your rights depend on where you live and which company you use. In the U.S., laws like GINA and state privacy laws provide some protection, but there are big gaps. For example:

  • GINA protects against health insurance and employment discrimination—but not life, disability, or long-term care insurance.
  • Some states (like California) have stricter privacy laws, giving you more rights to request data deletion or limit sharing. But these laws may not apply if the company is based elsewhere.
  • Company privacy policies matter. Always read the fine print. Some companies promise not to sell your data, while others reserve the right to share or sell it under certain circumstances.

If you’re outside the U.S., your rights may be stronger (like under Europe’s GDPR), but enforcement can be inconsistent. Always check the specific rules for your region and your chosen service.

Can You Really Delete Your DNA Data?

This is one of the most common—and most misunderstood—questions. Here’s the reality:

  • Account deletion is not the same as data deletion. Deleting your account may only remove your access, not the underlying data or biological sample.
  • Some companies allow you to request deletion of your genetic data and destruction of your sample. But this process can be slow, and there’s no guarantee that backups or copies shared with partners will be deleted.
  • Data already shared for research or with third parties is usually out of your control. Even if the original company deletes your data, partners may keep copies.
  • If the company is bankrupt or sold, your options may be even more limited. Your requests could be ignored or delayed indefinitely.

It’s frustrating, but it’s better to know the limits than to assume you have more control than you really do.

Five Steps That Actually Reduce Your Risk

  1. Think before you test. If you haven’t used a DNA kit yet, weigh the benefits against the permanent risks. Once your DNA is out there, you can’t take it back.
  2. Use strong, unique passwords for your DNA testing accounts. This helps prevent unauthorized access, especially in the event of a breach.
  3. Opt out of unnecessary sharing and research programs. Don’t let your data be used in ways you’re not comfortable with.
  4. Regularly review your privacy settings and account activity. If you spot anything suspicious, contact the company immediately.
  5. Educate your family. Remember, your DNA is partly theirs. Talk to relatives before uploading family trees or sharing results online.

Bigger Picture: Why DNA Data Is Different—And Why It Deserves More Protection

Unlike passwords, credit cards, or even social security numbers, your DNA is a permanent part of who you are. It can’t be changed or replaced. That makes genetic data uniquely sensitive and uniquely valuable—not just to you, but to companies, researchers, and yes, criminals.

Companies that collect and store this data have a responsibility to protect it. When they fail—whether through negligence, poor security, or misleading promises—they deserve criticism and oversight. The laws haven’t caught up with the technology, and the burden often falls on consumers to protect themselves.

It’s not about paranoia. It’s about being realistic, informed, and cautious with information that can never be taken back. If you’re considering a DNA test, or if you’ve already taken one, take the time to review your settings, understand your rights, and think carefully about what you’re comfortable sharing. Your DNA is yours—don’t give up control lightly.

Risk Level: High. The consequences of mishandled or exposed genetic data are permanent, far-reaching, and not fully protected by current laws or company policies. Take action to protect your information, and stay informed as the landscape continues to evolve.

Suggested readings ...