Recent months have proven tumultuous for 23andMe, the popular genetic-testing and ancestry-tracking company, which has found itself at the center of controversy following significant data privacy breaches.
With over 15 million users entrusting their most private information to the company, many individuals are now left questioning how to safeguard their sensitive genetic data amid troubling revelations. The stakes have escalated as the company reported approximately 6.9 million users were impacted by a data breach where hackers deliberately targeted accounts belonging to individuals of Chinese or Ashkenazi Jewish heritage, with the stolen information eventually appearing on the dark web.
Adding to the concern, 23andMe announced last month it would lay off about 40 percent of its workforce due to persistent financial and management hurdles—issues exacerbated by the data leak. Within this backdrop, many past customers are urgently asking, “Can I delete the genetic data the company has from me?”
The reality, as it turns out, is layered. Users do have the option to delete their data from the 23andMe platform at any time. A representative for the company shared with CNET, "Once your request is submitted, the process of deleting data begins immediately and automatically and can take about 30 days to complete." Yet, not all data must vanish within this timeframe.
When initiating the deletion of their account, users are informed there are variations concerning what personal information is deleted and retained. The spokesperson elaborated, stating, “If a customer opted in to 23andMe Research, their Personal Information will no longer be used in any future research projects. Please note, data cannot be removed from research that's already been conducted.”
This situation becomes more perplexing as reports surfaced indicating genotyping laboratories tasked with processing customer samples retain certain information, including sex, date of birth, and genetic information, for up to two to three years depending on legal mandates. While the retained data is stripped of identifiable information like names and contact details, this linguistic barrier does little to assuage user anxiety over how their genetic information could presume the risk of exposure.
Potential users pondering the termination of their relationship with 23andMe are also advised to think carefully about preserving their data prior to deletion. If one chooses to delete their account, it is recommended to download one's genetic data. The process is relatively straightforward and entails logging back onto their account and retrieving the desired files via settings.
“Can you delete your 23andMe account? Yes. But the steps taken to permanently wipe your data from the platform can often be perplexing,” said one associated expert.
Upon downloading all relevant data—including raw genotyping data, family connections, and ancestry reports—users must navigate back to their account settings and select the option to permanently delete their data. Once the request is confirmed via email, the deletion process is triggered.
Most will acknowledge this dilemma resonates more broadly within the tech and healthcare industries, where data privacy concerns have emerged as pivotal issues. With the rise of AI and big data technologies, the protection of personal data remains top-of-mind for regulatory bodies and corporations alike. Recent legal frameworks and policies have sought to create more stringent protections around sensitive data.
The European Union (EU), for example, introduced the latest Digital Operational Resilience Act (DORA) with the objective of fostering stability and security among digital infrastructures used by financial entities. The regulation emphasizes the importance of safeguarding digital assets, underscoring how even potentially innocuous data can morph overnight to become the linchpin of someone's identity.
These initiatives serve as reminders of the responsibilities tech companies retain concerning user data. The call for transparency and accountability has never been louder, especially as many young adults and parents are reaching out to companies seeking clarity on how algorithms engineered for everyday usage may infringe upon their rights to privacy.
For those still concerned about the fate of their personal genetic data at companies such as 23andMe, it raises glaring questions about what it means to share one's DNA with third parties. Is the allure of discovering ancestral roots worth the potential risks to personal privacy?
Indeed, as more consumers demand accountability from institutions managing this kind of sensitive data, companies are pressed to adapt and address data privacy concerns head-on. This trend signals the dawning of greater consumer awareness about data rights as part of the broader societal pursuit of ethical data use.