Consumer Genomics and Genetic Data Toolkit: Consent, Research Use, Databases, and Access Requests

By ·

A genetic sample is the only dataset that identifies people who never consented to anything, because it identifies relatives. This toolkit assembles the working material for practitioners advising consumer testing companies, research partners, pharmaceutical licensees, and the individuals whose samples are held. It covers consent architecture and the difference between consenting to a test and consenting to a research programme, the retention and destruction of physical samples as distinct from data, the database licensing arrangements that turn a testing business into a research business, and the law enforcement request problem that reshaped the sector. It closes with the insolvency question nobody drafts for, clause language, an authorities table, and the failures that recur.

IP and Technology > Privacy Data Security | Toolkit | Published 5 November 2025 - Updated 18 April 2026 | Casey Scott McKay - marksy.us

Summary. A genetic sample identifies people who never consented, because it identifies relatives. This toolkit covers consent architecture and layered research consent, physical sample retention as distinct from data retention, database licensing to pharmaceutical and research partners, law enforcement and forensic genealogy requests, re-identification exposure, the employment and insurance prohibitions that constrain downstream use, and the insolvency question that decides what happens to a biobank when the company fails.

Keywords: consumer genomics · genetic data · informed consent · layered consent · biobank retention · research use · secondary use · database licensing · pharmaceutical partnerships · law enforcement requests · forensic genetic genealogy · relative identification · genetic non-discrimination · re-identification · sample destruction · insolvency transfer


Start Here

Genetic data is different from other personal data in four ways, and every problem in this practice descends from one of them.

It identifies people who never consented. A person's genome discloses substantial information about their parents, siblings, children, and more distant relatives. Consent obtained from one individual affects a family, and no consent framework built around individual autonomy handles that cleanly.

It cannot be de-identified in any durable sense. A genome is the identifier. Stripping a name changes very little, because the sequence can be matched against reference databases and, through relatives, against people who are in them. Anonymisation claims in this sector should be treated as claims about difficulty rather than about impossibility.

It does not change and does not expire. A password can be reset. A genome is generated once and remains accurate for the individual's life and, for inherited variants, for their descendants. A retention period is therefore not a meaningful mitigation in the way it is elsewhere.

And it exists in two forms. The physical sample and the derived data are distinct assets with distinct handling, distinct retention, and distinct destruction requirements, and consent frameworks that address only one of them are incomplete.

Four questions organise the work.

What did the individual actually consent to, and how is it recorded?

What happens to the sample, as distinct from the data?

What may be licensed to research and commercial partners?

And who else can compel or obtain access?

See The Most Personal Data There Is for the doctrinal treatment, Advising a Genetic Testing or Genomics Business for the sequence, and the Genomic Data Checklist for the working list.


Part one: consent architecture

Separate the consents. Consent to the test is not consent to research, which is not consent to commercial partnership, which is not consent to relative matching, which is not consent to retention of the physical sample. A single tick box covering all five is the sector's characteristic failure.

Layer them. A primary consent covering the testing service, and separate, independently revocable consents for each additional use. Each layered consent should be capable of being declined without losing the service.

Describe the research use honestly. "Research that may lead to new treatments" is not a description. "Your de-identified genetic data and the health information you provide may be analysed by our scientists and by pharmaceutical companies we partner with, who pay us for access, to identify targets for new medicines" is.

Say that the partners pay. The most consistent finding in consumer research on this subject is that people object to not being told, more than they object to the arrangement itself.

Address relatives explicitly. A consent form that does not mention that the results reveal information about family members, and that relative matching may expose family relationships the individual does not know about, is incomplete in the way that matters most.

Address withdrawal precisely. What can be withdrawn, what cannot, and why. Data already included in a published analysis cannot be retracted; data in an active dataset can be removed; the physical sample can be destroyed. Say which is which.

Version and record everything. Which consent version the individual saw, when, what they selected, and every subsequent change. The record is the compliance position.

Re-consent on material change. A new commercial partnership, a new category of research, or a new data-sharing arrangement is a material change, and reliance on a broad prior consent is the position that produces regulatory attention.

Address minors separately, including what happens when a child reaches majority and what a parent may consent to on their behalf.

And consider the deceased, whose samples and data remain, and whose relatives may have views.


Part two: samples, retention, and destruction

The physical sample is a separate asset with its own storage, its own risk, and its own destruction requirement.

Retention should be a choice the individual makes, not a default. A person who wants their saliva sample destroyed after sequencing should be able to say so at the outset and at any time afterwards.

Destruction must be verifiable. A destruction request should produce a certificate identifying the sample, the date, and the method, and the process should be auditable.

Storage arrangements are frequently outsourced to a third-party biobank, and the contract should address custody, security, retention, destruction on instruction, and — critically — what happens on the biobank's insolvency or on termination.

Re-analysis is the reason companies retain. A stored sample can be re-sequenced as technology improves, which is genuinely valuable to the individual and is also the reason the asset persists. Explain the trade-off rather than assuming consent to it.

Data retention is separate. Raw sequence data, interpreted results, health survey responses, and derived research datasets each have different retention logic and should be addressed individually.

Backups and derived datasets are where deletion fails. A deletion that removes the account record and leaves the sequence in a research dataset and three backups is not a deletion. Design the deletion path before offering the right.

Published research cannot be unpublished, and the consent should say so.

And the destruction obligation should survive a change of control, an insolvency, and a transfer of the business, which brings us to the question the sector avoids.


Part three: insolvency, transfer, and what happens to a biobank

This is the question consumer genomics companies do not address in their terms and the one that matters most to the people whose samples they hold.

A database of genetic samples and sequences is an asset, and in an insolvency an asset is realised for creditors. A purchaser acquires it subject to whatever the terms and consents permit — and if the terms are silent, subject to arguments nobody wants to be having.

Draft for it. The terms should state what happens to samples and data on a change of control, on an asset sale, and on insolvency: whether individuals are notified, whether they may withdraw before transfer, whether the acquirer is bound by the original consents, and whether samples are destroyed if no acquirer accepts those terms.

Bind the acquirer. A provision requiring any transferee to assume the consent commitments, and prohibiting transfer to a party unwilling to do so, is enforceable as a term of the contract with the individual and is a meaningful protection.

Notify and offer withdrawal. A pre-transfer notification with a withdrawal window is the practice that regulators and legislators have gravitated toward, and adopting it voluntarily is cheaper than having it imposed.

Consider an escrow or trust structure for the samples themselves, so that custody does not simply follow the corporate entity.

Address regulator expectations, since several state genetic privacy statutes now specifically address transfer and require consent or notification.

And say it plainly in the consent. "If our business is sold or fails, here is what happens to your sample and your data" is a sentence that builds trust and that almost no consumer genomics company has written.


Part four: research use and database licensing

The business model in this sector is frequently the database rather than the test, and the licensing arrangements deserve the same care as any data transaction.

Define the dataset precisely: which fields, at what granularity, from which consented population, with which exclusions.

Consent-scope matching is the gating control. Only individuals whose consent covers the specific use may be included, and the extraction process should enforce it technically rather than relying on a filter somebody remembers to apply.

Withdrawal must propagate. An individual who withdraws should be removed from future extracts and, where feasible, from the partner's copy. Contract for it.

De-identification claims should be honest. Genetic data cannot be reliably de-identified, and a licence describing the dataset as anonymised is making a representation that may not be defensible. "Coded" or "pseudonymised", with a description of the controls, is accurate.

Prohibit re-identification expressly, prohibit linkage with other datasets that would permit it, and require notification of any inadvertent re-identification.

Structure access rather than transfer where possible: a secure analysis environment in which the partner queries the data without receiving it, with output controls, is materially safer than shipping a dataset.

Address publication: what may be published, what review the licensor may conduct, and how individual-level data is protected in supplementary material.

Address intellectual property in discoveries. A partner analysing the dataset may make patentable findings. Who owns them, what licence the database holder receives, and whether the contributing individuals share in any value are all negotiable and are frequently unaddressed. On the underlying patentability of the subject matter, note Association for Molecular Pathology v. Myriad Genetics, Inc., which held isolated naturally occurring DNA sequences unpatentable while permitting complementary DNA, and Mayo Collaborative Services v. Prometheus Laboratories, Inc. on diagnostic method claims. See Claiming Life and the Biotechnology and Synthetic Biology IP Toolkit.

Address benefit sharing where the population contributing is identifiable as a community, since access and benefit-sharing expectations attach to genetic resources in ways that reach human populations too.

And address termination: what the partner returns, what it deletes, and what it may retain in published or derived form. See the Data Licensing Checklist.


Part five: law enforcement and third-party access

Forensic genetic genealogy — identifying a suspect by matching crime scene DNA against consumer databases and working outward through relatives — changed this sector permanently.

The technique works through relatives, which means a database of a million consenting individuals provides investigative reach over a far larger population who consented to nothing.

Company positions vary. Some databases permit law enforcement matching by default, some on opt-in, some prohibit it and require legal process, and some have changed position under pressure. Whatever the position, it should be stated plainly in the consent and honoured consistently.

Legal process should be required and tested. A policy of responding only to a valid subpoena, warrant, or court order, with legal review of each, is the baseline. Voluntary disclosure without process is the practice that generates the loss of trust.

The constitutional analysis is unsettled. Records voluntarily provided to a third party have historically attracted limited protection under Smith v. Maryland, while Carpenter v. United States signalled that some categories of third-party record are different. Genetic data is a strong candidate for the Carpenter treatment and the question has not been squarely resolved.

Statutory protection is developing at state level, with several genetic privacy statutes addressing law enforcement access, requiring warrants for some purposes, and imposing notification duties.

Publish a transparency report. Number of requests, categories, and outcomes. It is voluntary, it is now expected, and its absence is itself a signal.

Notify the individual where lawful. Many requests carry non-disclosure obligations; where they do not, notification should be the default.

Other third parties want access too: insurers, employers, immigration authorities, family courts, and civil litigants. Each raises a distinct question and each should have a documented process.

Employment and insurance use is constrained by statute. 42 U.S.C. § 2000ff prohibits employers from requesting, requiring, or purchasing genetic information and from discriminating on that basis, and reaches family medical history as well as test results. Health insurance discrimination on genetic information is separately prohibited; life, disability, and long-term care insurance are substantially less well covered, which is the gap consumers are least aware of and which advisers should mention.

And civil discovery can reach the data through the individual rather than the company, which is a route no company policy controls. See the Cross-Border IP Litigation Checklist for the international dimension.


Part six: re-identification, security, and breach

Assume re-identification is possible. Published research has repeatedly demonstrated it, using reference databases, relative matching, and auxiliary information. A company whose risk assessment assumes otherwise has assessed the wrong risk.

Security failures here are categorically worse than in other sectors, because the data cannot be reissued and because a breach exposes relatives.

The notification matrix is complex: state breach statutes with genetic-specific provisions in several jurisdictions, health-adjacent regimes where they apply, contractual clocks with research partners, and regulator expectations. Build it in advance. See Running a Data Breach Response.

Access controls should be segmented, with sequence data separated from identity data and from health survey responses, so that a single compromise does not yield a linked dataset.

Vendor and subprocessor risk is concentrated in sequencing providers, biobanks, and cloud infrastructure, and the diligence should reach them.

Insider risk is real in a business holding data of celebrity or public interest, and access logging with review is the control.

Re-identification by a research partner should be a contractual breach with defined consequences, and the contract should require notification.

And the response plan should include the family dimension: a breach affecting one individual affects relatives who are not customers and cannot be notified, which is a communications problem with no clean answer and which is better thought about before it happens.


Clause bank

Layered research consent. You are being asked to make three separate choices, and you may make each independently. (1) Testing: we will analyse your sample to provide the results you have purchased. This is required for the service. (2) Sample storage: we will store your physical sample so it can be re-analysed as our technology improves. You may decline, and you may ask us to destroy it at any time. (3) Research: we will include your de-identified genetic data and any health information you provide in research studies. Some of these studies are conducted with pharmaceutical and biotechnology companies who pay us for access. You may decline, and you may withdraw at any time, in which case we will remove your data from future studies. We cannot remove it from studies already published. Declining (2) or (3) does not affect the service in (1).

Withdrawal effect. If you withdraw your research consent we will, within [30] days: exclude your data from all future extracts and studies; instruct each current research partner to cease using your data and to delete it from their active datasets, and obtain their confirmation; and remove your data from our research database. We cannot recall data from analyses already completed or from research already published, and we cannot recall aggregate results that include your data. If you also ask us to destroy your sample we will do so within [30] days and will provide a certificate of destruction.

Change of control and insolvency. Your sample and your data may be transferred as part of a sale, merger, or transfer of our business only if the transferee agrees in writing to be bound by the consents you have given and by this clause. We will notify you at least [30] days before any such transfer and you may withdraw your consents and require destruction of your sample before it takes effect. If our business enters insolvency proceedings and no transferee will accept those obligations, your sample will be destroyed and your data deleted, and we have instructed our insolvency practitioner accordingly.

Research partner access. Recipient shall access the Dataset solely within the Secure Environment and shall not export record-level data. Recipient shall not attempt to re-identify any individual, shall not link the Dataset with any other dataset without Provider's written approval, and shall notify Provider within [24] hours of any actual or suspected re-identification, whether or not intentional. Recipient shall implement Provider's Withdrawal Instructions within [10] business days and shall certify compliance. Recipient shall submit any proposed publication to Provider [30] days in advance for review limited to the protection of individual privacy.

Law enforcement policy. Provider will disclose genetic data or samples to law enforcement only on receipt of a valid subpoena, search warrant, or court order, and only after legal review of its validity and scope. Provider will resist requests that exceed the process presented. Provider will notify the affected individual unless prohibited by law, and will seek to lift any non-disclosure obligation at the earliest opportunity. Provider will publish, at least annually, the number of requests received, the categories, and the outcomes.

Discovery ownership. Where Recipient makes an invention arising from analysis of the Dataset, Recipient shall own it, and shall grant Provider a non-exclusive, worldwide, royalty-free licence to practise it for internal research purposes. Recipient shall notify Provider of any patent application within [30] days of filing. Recipient shall not seek any patent claim covering a naturally occurring sequence as such, and acknowledges the limits established in Association for Molecular Pathology v. Myriad Genetics, Inc..


Worked scenarios

A partnership announced before the consent covered it. A testing company announces a pharmaceutical collaboration. Customers discover that their data is included on the basis of a research consent given years earlier describing "scientific research". The consent is arguably broad enough. The reaction is not about the legal analysis; it is about not having been told. The company offers an opt-out, loses a proportion of its research population, and spends a year rebuilding trust. Re-consent before the announcement would have cost a fraction and would have produced a research population that had actually agreed.

A withdrawal that did not propagate. An individual withdraws research consent. The company removes the record from its active database. Three research partners hold extracts that include it, two of which have no contractual withdrawal obligation. The data remains in use. When this is discovered, the company's position is that it complied with its own policy — which is true and is not what the individual was told.

A law enforcement request without process. A company receives an urgent request from investigators and provides a match voluntarily, believing it is assisting in a serious case. It probably was. The disclosure was inconsistent with its published policy, becomes public, and produces a class action, a legislative hearing, and a permanent change in customer behaviour across the sector. The policy existed; the process for applying it under pressure did not.

An insolvency with no provision. A testing company fails. Its principal asset is a biobank and a sequence database. The terms say nothing about insolvency. The insolvency practitioner's duty is to creditors, the customers' consents were given to a company that no longer functions, and the samples sit in a freezer while the position is argued. The clause that resolves it in advance is four sentences and is in the bank above.


Failures that recur

A single consent covering testing, storage, research, commercial partnership, and relative matching.

Research consent described as "to advance science" without disclosing that partners pay for access.

No mention of relatives in a consent for a test that reveals information about them.

Withdrawal offered without a propagation mechanism to research partners.

Deletion that leaves the sequence in a research dataset and in backups.

"Anonymised" used to describe genetic data.

No provision for change of control or insolvency.

A law enforcement policy with no process for applying it under pressure.

No transparency reporting, which is now conspicuous by its absence.

Sample destruction offered with no certificate and no audit.

Discovery ownership in a research partnership left to good faith.

And no separate treatment of minors, or of what happens when they reach majority.



Part seven: the relative problem, treated seriously

Every other issue in this practice is a variation on one fact, and it deserves direct treatment rather than a mention.

A genome is shared property in a biological sense and individual property in a legal one. An individual can consent to the analysis, storage, research use, and law enforcement matching of a dataset that describes their siblings, parents, children, and cousins in substantial detail. Those people have no vote.

Relative matching services make it concrete. A person who tests learns of half-siblings, undisclosed parentage, and family relationships that other living people had chosen not to disclose. The service performs exactly as designed and the consequence falls on somebody who never used it.

Forensic genealogy extends the reach further, converting a database of a million volunteers into investigative coverage of a much larger population.

The honest framing for a client is that consent in this sector is structurally incomplete, and that the practices which survive scrutiny are the ones that acknowledge it: disclosure that relatives are affected; default settings that do not expose relationships without a deliberate choice; a mechanism for a person to indicate that they do not wish to be matched; and restraint about what is inferred and surfaced without being asked.

Design choices matter more than consent language here. A service that surfaces an unexpected close relative in a notification, without warning and without a preparatory step, has made a design decision with consequences no consent form mitigates.

Provide a genuine opt-out from matching, distinct from research consent and from the test itself.

Provide a support pathway. The sector's most difficult moments are personal rather than legal, and a company that offers nothing when a customer discovers something life-altering has misunderstood the product it sells.

And record the design rationale. When a regulator or a legislature examines the sector, the companies that can show they considered the family dimension and made deliberate choices will be treated differently from those that shipped the default.


Part eight: governance and operating model

Name an owner for the consent architecture. In most companies the consent language is owned by marketing, the research programme by science, the partnerships by business development, and the compliance position by nobody.

Establish a review body — internal, with external input — that assesses new research uses, new partnerships, and new features against the consents actually given. Institutional review board involvement is required for some research and is good practice well beyond the requirement.

Gate every new use. No new research category, partnership, feature, or data-sharing arrangement launches without a documented consent-coverage assessment and, where needed, a re-consent programme.

Maintain a consent version register and the ability to determine, for any individual, exactly what they saw and selected.

Maintain a sample register with location, custody, retention election, and destruction status.

Maintain a partner register with the dataset provided, the consent basis, the withdrawal propagation mechanism, and the last confirmation received.

Log every access to identity-linked sequence data, and review the logs.

Publish a transparency report covering law enforcement requests and, increasingly, research partnerships.

Train the customer support team, who receive the withdrawal requests, the family discoveries, and the law enforcement enquiries first, and whose ad hoc responses become the company's practice.

And report to the board, because this is a business whose principal asset is other people's biological information and whose principal risk is the loss of their trust.


Part nine: diligence in a genomics transaction

Consent coverage is the whole exercise. Obtain every historical consent version with its effective dates, map the customer population to versions, and test whether the current and planned uses are covered by what each cohort actually agreed. Expect the largest and oldest cohort to be covered by the weakest consent, and expect that cohort to be the commercially valuable one.

Withdrawal integrity. Test a withdrawal end to end: does the individual disappear from the research database, from future extracts, and from partner copies, with confirmations?

Sample custody. Where are the physical samples, who holds them, under what contract, with what destruction obligation, and what happens on the biobank's insolvency?

Partner agreements. Every research and commercial licence, with the consent basis it relies on, the re-identification prohibition, the withdrawal propagation obligation, the publication review, and the discovery ownership terms.

Re-identification exposure. Any incident, any research demonstrating it against the company's datasets, and the controls in place.

Law enforcement history. Requests received, responses given, and whether any response departed from the published policy.

Regulatory contacts. Inquiries, consent decrees, and state genetic privacy statute compliance in each state of operation.

Insolvency and transfer provisions in the customer terms — and if there are none, the cost of introducing them, which requires notifying and in practice re-consenting the customer base.

Intellectual property. The interpretation algorithms, reference panels, and analytical methods held as trade secret; any patents and their position after Myriad and Mayo; and chain of title on all of it. See the Employee Invention Checklist.

And quantify the cost of re-consenting the base, the revenue at risk if a partnership relies on an inadequate consent, and the exposure from any breach affecting relatives who are not customers.


Part ten: the three-day test

The quickest diagnostic on a consumer genomics business takes three days. Pick one customer at random and ask for five things.

The exact consent screens they saw, in the version current when they registered, with the selections they made. The list of every research study and every commercial partner that has received their data, matched against those selections. The location and custody record of their physical sample, with the retention election they made. The record of what would happen, technically, if they withdrew tomorrow — which systems, which partners, which backups, within what period. And the provision in the terms telling them what happens to their sample and data if the company is sold or fails.

A company that produces all five is running the business the way it should be run. A company that produces two is the ordinary case. A company that produces none is holding a million people's genomes on the strength of a form nobody has read since it was written — which is, at present, the sector's normal condition.


One paragraph to remember

Genetic data identifies people who never consented, cannot be de-identified, does not expire, and exists in two forms. Layer the consents and let each be declined; say plainly that partners pay; disclose the relative dimension and default to not exposing relationships; treat the physical sample as a separate asset with its own destruction path; require legal process for law enforcement and publish what you receive; make withdrawal propagate to partners by contract; and write down, in the terms, what happens to the biobank if the company fails — because somebody will need to know, and by then it will be too late to ask.


The consent form, item by item

Where a consent has to be drafted from scratch, this is what a regulator, a review body, and a customer will each look for.

A heading that says what it is, not "Terms of Service".

A statement of what the sample is used for, in the order it happens: collection, sequencing, interpretation, result delivery, and then whatever else.

Each additional use as a separate, independently declinable choice, with a default of not selected.

Plain language on research: who analyses the data, whether they are external, whether they pay, and what kinds of study.

Plain language on relatives: that results reveal information about family members, that matching may surface relationships the customer does not expect, and how to switch matching off.

Plain language on law enforcement: the company's policy, stated as a policy rather than as a possibility.

Retention, separately for sample and data, with the customer's election recorded.

Withdrawal, with an honest account of what can and cannot be undone.

Change of control and insolvency, in the terms and referenced in the consent.

Contact route for questions, withdrawal, and destruction requests, with a named function and a response time.

A version number and date, and a copy provided to the customer.

And a readability standard. If the consent cannot be understood by somebody reading it once, on a phone, before they have received any results, it has not obtained consent to anything — whatever it says.


Adjacent contexts worth distinguishing

The consumer testing model is one of several, and applying its framework to the others produces the wrong advice.

Clinical genetic testing ordered by a physician sits inside the medical relationship, with the medical privacy rule at 45 C.F.R. § 164 applying, professional duties running to the patient, and results entering the medical record. The consent architecture is clinical rather than commercial, and the research use question runs through institutional review rather than through terms of service.

Research biobanks operate under research consent frameworks with oversight, and their governance is generally stronger than the consumer sector's — which is why consumer companies entering research partnerships are frequently held to standards their own consents were not built for.

Newborn screening programmes hold samples from an entire population, collected under public health authority, with retention and secondary use questions that have produced litigation and legislation in several states.

Ancestry-only services feel less sensitive to customers and are not, since the underlying data is the same and relative matching is the core feature.

Direct-to-consumer health interpretation brings regulatory classification questions about whether the product is a medical device, and the analysis differs sharply by the claim made.

Employer and insurer wellness programmes collecting genetic information run directly into 42 U.S.C. § 2000ff and its narrow voluntary-wellness exception, and should be assumed prohibited until an adviser has confirmed otherwise.

Law enforcement databases are governed by their own statutory regimes and are not the subject of this toolkit, but they are the destination of the forensic genealogy pipeline and their rules shape what the consumer sector is asked for.

And international transfers add a further layer, since several jurisdictions treat genetic data as a special category with transfer restrictions that a global testing operation must address before, rather than after, building a single global database.


A closing observation

The sector's regulatory trajectory is unusually easy to predict, because every difficult question in it has the same shape: an individual consented to something narrow, a business built something broad on that consent, and the people most affected were never asked.

Legislatures have responded to each instance separately — law enforcement access, insolvency transfer, employment use — and will continue to. A company that anticipates the pattern rather than the specific rule will spend less and be trusted more.

The anticipation is not complicated. Ask, of any proposed use: would the person whose sample this is have expected it when they spat in the tube? And would their sister?

If the answer to either is no, the use needs a fresh consent, a different design, or a decision not to proceed. That test predicts the regulatory outcome in this sector more reliably than any statute currently on the books, and it is available to any adviser willing to ask it out loud in a product meeting.


One practical addition

Keep a single page, updated quarterly, listing every category of person who can currently obtain access to a customer's genetic data: the customer, the company's own staff by role, each named research partner, each commercial partner, each subprocessor, law enforcement on legal process, and anybody else. Circulate it internally.

Most companies cannot produce that page without a week's work, and the exercise of producing it reliably identifies at least one access route nobody had thought about — which is the point.

Key Authorities at a Glance

Genetic non-discrimination and employment. 42 U.S.C. § 2000ff prohibits employers from requesting, requiring, or purchasing genetic information, including family medical history, and from discriminating on that basis. 42 U.S.C. § 12112 constrains medical examinations and inquiries and requires separate confidential medical records. Health insurance discrimination on genetic information is separately prohibited; see Genetic Information Nondiscrimination.

Health information. 45 C.F.R. § 164 applies where a covered relationship exists; most consumer testing falls outside it, into the framework described in The App That Knows Your Diagnosis. 15 U.S.C. § 45 supplies deception and unfairness authority, which has been used against genetic testing practices inconsistent with published statements.

Third-party records and law enforcement. Smith v. Maryland; Carpenter v. United States; Maryland v. King on arrestee DNA collection; Riley v. California on the digital-content distinction. State genetic privacy statutes increasingly require warrants and notification.

Patentability of genetic subject matter. Association for Molecular Pathology v. Myriad Genetics, Inc.; Mayo Collaborative Services v. Prometheus Laboratories, Inc.; Diamond v. Chakrabarty; 35 U.S.C. § 101; 35 U.S.C. § 112.

Property in tissue. Moore v. Regents of the University of California held that a patient retained no property interest in cells removed during treatment, while recognising informed consent and fiduciary duty claims — the case remains the reference point for what an individual does and does not own in their own biological material.

Data rights and trade secret. Feist Publications, Inc. v. Rural Telephone Service Co.; 17 U.S.C. § 103; 18 U.S.C. § 1836 with Rockwell Graphic Systems, Inc. v. DEV Industries, Inc..

| Authority | Governs | Practical consequence | | --- | --- | --- | | 42 U.S.C. § 2000ff | Employment | Genetic screening prohibited | | 42 U.S.C. § 12112 | Medical inquiries | Separate confidential records | | Moore v. Regents | Property in tissue | No property claim; consent claims survive | | Myriad | Sequence patents | Isolated natural DNA unpatentable | | Mayo | Diagnostic claims | Correlations are not eligible | | Carpenter | Third-party records | The argument for warrant protection | | Smith v. Maryland | Third-party doctrine | The position being displaced | | Maryland v. King | Arrestee DNA | Collection upheld on identification grounds | | 15 U.S.C. § 45 | Deception | Practice must match published statements | | Feist | Facts | The database is contractual, not owned | | 18 U.S.C. § 1836 | Trade secrets | Methods and interpretation algorithms | | 45 C.F.R. § 164 | Health privacy | Applies only where covered |


Related Documents

The triad

Health data and privacy

Biotechnology and research

Data rights and incidents


Marksy is not a law firm. This toolkit is provided for general informational purposes and does not constitute legal advice. Genetic privacy statutes, law enforcement access rules, and research consent expectations vary substantially by jurisdiction and are changing quickly. Clause language is illustrative and must be adapted to the arrangement, and consent language in particular should be reviewed by counsel and tested with the population it addresses. Nothing here creates an attorney-client relationship. Consult qualified privacy and life sciences counsel before relying on any position described here.

Read this article on Marksy