[HN Gopher] How to Delete Your 23andMe Data
___________________________________________________________________
How to Delete Your 23andMe Data
Author : hn_acker
Score : 104 points
Date : 2025-03-26 19:41 UTC (3 hours ago)
(HTM) web link (www.eff.org)
(TXT) w3m dump (www.eff.org)
| YooLi wrote:
| This feels as hopeless as trying to keep your email/contacts from
| social media sites. Even if you are vigilant about never allowing
| an app/service to download your contacts, your friends will share
| theirs and it is trivial to recreate your contact list. If I keep
| my DNA from these companies, my relatives will share theirs and
| they basically have my DNA.
| CharlesW wrote:
| > _This feels as hopeless as trying to keep your email
| /contacts from social media sites._
|
| The cynic in me agrees, but the process was quick and easy, and
| I know I'm not safer by _not_ deleting my information from
| 23andMe. I recommend it.
| drdaeman wrote:
| Note that despite any requests the genetic data and some personal
| information (DOB and sex) probably _won 't_ be deleted, at least
| because of CLIA requirements:
| https://news.ycombinator.com/item?id=41781879 (more details in
| https://bourniquelaw.com/2024/10/09/data-23-and-me/, linked from
| the thread there)
| CharlesW wrote:
| Here's a great post by a lawyer, linked to further down in that
| thread: https://bourniquelaw.com/2024/10/09/data-23-and-me/ It
| suggests a way to challenge them on their assertions that they
| must keep your data and samples.
| bpodgursky wrote:
| I'm sorry but this lawyer has absolutely no idea what he is
| talking about with regards to CLIA compliance. And he even
| admits as much, but keeps talking anyway.
| CharlesW wrote:
| CLIA is one of the excuses 23andMe uses to explain why they
| retain your genetic information, date of birth, and sex.
| The author cites the code sections he believes 23andMe are
| referencing to make this claim, then explains why he
| believes it doesn't apply. As a CLIA expert, do you mind
| explaining what he's getting wrong for our benefit?
| nelox wrote:
| 23andMe does not operate as a laboratory itself but contracts
| with U.S.-based labs that are certified under CLIA and
| accredited by the College of American Pathologists (CAP).
| According to their website, all saliva samples are processed in
| CLIA-certified and CAP-accredited labs, ensuring compliance
| with federal standards for accuracy and reliability. This
| certification is crucial, as it aligns with FDA requirements
| for certain health-related genetic tests. This distinction is
| significant, as CLIA primarily regulates labs, not the
| companies that contract them, potentially affecting the
| applicability of retention requirements to 23andMe's broader
| operations.
|
| CLIA's record retention requirements, as per Section 493.1105,
| states labs must retain test requisitions, authorizations, and
| reports for at least 2 years, with longer periods for specific
| tests like pathology (10 years for slides).
|
| CLIA Laboratory Record Retention Requirements:
|
| - Test requisitions and authorizations: 2 years minimum. - Test
| reports: 2 years minimum, 10 years for pathology reports. -
| Cytology slide preparations: 5 years. - Histopathology slides:
| 10 years. - Pathology specimen blocks: 2 years. - Tissue: Until
| diagnosis is made.
|
| Notably, these requirements focus on test-related records, such
| as requisitions (which may include patient details like date of
| birth and sex) and reports (which for genetic tests would
| include interpreted results). However, there is no explicit
| mention of retaining raw genetic data, such as the full
| genotype data, in the CLIA regulations. This raises questions
| about whether 23andMe's assertion to retain raw genetic
| information is strictly required by CLIA or if it extends
| beyond the regulation for other reasons, such as research or
| quality control.
| ahmedfromtunis wrote:
| To be honest, this is more like "requesting the data to be
| deleted". There's nothing that guarantees that the personal
| information will be physically wiped out of the hard drives used
| to store them.
| throwaway48476 wrote:
| But it creates legal grounds for lawsuits if they don't.
| ahmedfromtunis wrote:
| Of course. And I'm not saying that they might do it in
| malice.
|
| All I'm suggesting is that tapping some pixels on your
| backlit rectangular glass won't _necessarily_ translate into
| pulses of electrons that 'll eradicate the 0s and 1s
| representing your data.
|
| I'm sure that corner of the codebase is one of the least
| visited parts, so bugs may lurk in, or misconfigurations,
| etc.
| Cheer2171 wrote:
| Sure, you can sue the hollowed out shell of a bankrupt
| limited liability corporation that will soon have no assets
| for a court to sieze for whatever paltry damages a court
| finds.
| ks2048 wrote:
| Has anyone tried to export their ancestry data? I've notice the
| PDF summary lists broad regions, but the data in the App shows
| more details (e.g. specific counties of countries). Anyone know
| how to export that data? I'll just take some screenshots, but
| maybe this info is somewhere else in the export.
| dahinds wrote:
| Click on the "Scientific Details" instead of the Summary.
| pmarreck wrote:
| Why? If it's already out there, it's kind of too late, is it not?
| rglover wrote:
| The data has already been sold off to the real customers (i.e.,
| not you and me) [1]. You can (and should) request a deletion, but
| the damage has already been done.
|
| [1] https://gizmodo.com/23andme-is-selling-your-data-but-not-
| how...
| dahinds wrote:
| This is false, we've sold data with PII to no one. Or it is
| misleading: the page you linked to even says, "It is selling
| de-identified, aggregate data for research, if you give them
| consent."
| EA-3167 wrote:
| To what extent and using what method is it "de-identified"?
| Plenty of such schemes are very easy to circumvent,
| especially with a large enough pool of data. Given the nature
| of genetics in particular positively identifying a single
| case can be used to unmask whole families. In particular
| depending on the anonymization this would be a task suited to
| 'AI' very well.
| dekhn wrote:
| https://www.23andme.com/about/individual-data-consent
|
| Basically, if you imagine this as a table of "user's name,
| date of birth, and address" keys mapping to genomic and
| other data, the key was replaced with a random identifier
| that could not be trivially joined to recover the user
| name, date of birth, and address.
|
| These systems are not robust against motivated and
| capitalized adversaries.
| dahinds wrote:
| I can go to a data broker and purchase access to de-
| identified EMR data for most of the U.S. population.
| There are much more useful de-identified datasets around
| than ours, if someone is motivated to try to re-identify
| those datasets. That data is all bought and sold without
| anyone's consent and this is all fine under HIPAA.
| dahinds wrote:
| Here "de-identified" means stripped of PII (name, address,
| phone number, email, etc). You are correct that genetic
| information is intrinsically identifiABLE (in the sense
| that it is stable and uniquely distinguishing for
| individuals). When we've shared individual-level data with
| a partner, it was with consent of the participants
| involved, and under a contract that prohibits re-
| identification.
| ziddoap wrote:
| > _It is selling de-identified, aggregate data_
|
| Just a note that re-identifying aggregate data is a whole
| field of study that is decently successful.
| dahinds wrote:
| Indeed, but here "re-identification" generally means the
| sort of attack where you have an aggregated genomic
| dataset, and you already have access to full genomic data
| for a target individual, and you use the genomic dataset to
| infer something about that target that you didn't know,
| like whether or not they participated in that study. Not to
| entirely minimize this sort of attack, but the NIH decided
| it was a sufficiently low risk that most of the sorts of
| datasets it applies to (like GWAS) are routinely shared
| with no access controls.
| dekhn wrote:
| Providing another company access to deidentified data _is_
| "selling your data", to argue otherwise is just semantics.
|
| Note that selling deidentified data (genomic, health, etc) is
| common in the industry already and 23&Me is hardly unique in
| this respect.
| yoaviram wrote:
| Better yet, send them a legally binding data deletion request (if
| you live in a jurisdiction that has strong data protection laws):
|
| https://yourdigitalrights.org/d/23andme.com
| brian-armstrong wrote:
| The distinction isn't super important, but 23andMe doesn't have
| your whole genome, just some specific locations from it. Roughly
| 750k base pairs or so.
|
| https://www.quora.com/How-much-of-the-genome-does-23andMe-se...
| echelon wrote:
| Enough to be denied insurance, have job offers rescinded, or be
| targeted by scams.
|
| And they don't even have to have _your_ DNA. Just a close
| enough relative will do.
| echoangle wrote:
| > have job offers rescinded, or be targeted by scams
|
| Can you expand on this?
|
| I understand the insurance thing due to genetic diseases and
| so on, but which jobs would I be denied for based on genetic
| information which wouldn't be checked anyways?
|
| I can only come up with stuff like colorblindness but that
| would probably be checked anyways if it were a strict
| requirement for the job so keeping the DNA secret wouldn't
| help.
|
| And what's the scam angle when the DNA is known?
| echelon wrote:
| This would be wholly illegal, but companies could screen
| candidates prior to extending offers to them. After they
| get your primary details and history, they can look you up
| in the gene database. They could look for a whole host of
| genetic markers, including but not limited to:
|
| - Markers like ADHD and other neurodivergence and
| performance signals
|
| - Disease likelihoods to reduce their insurance burden.
| Cardiovascular, cancer, neurodegeneration, etc.
|
| - Markers for intelligence and tenacity. Personality type.
| Conversely, dishonesty, neuroticism, etc.
|
| They could screen for literally any hypothetical condition
| that could in theory impact performance, risk, cost, etc.
| By excluding candidates with "low genetic scores", they
| might think they're saving margin.
|
| There is a ton of literature beyond what 23andMe is legally
| allowed to report on with respect to the SNP data they
| collect. These studies report on a wide range of
| phenotypical states and behaviors that could impact job
| performance. The stack of research is deep.
|
| > And what's the scam angle when the DNA is known?
|
| Look for any markers that indicate IQ, agreeableness,
| neurodegeneration, schizophrenia, personality type, etc. It
| gives scammers a hypothetically better hit rate.
|
| And again, they don't need _your_ DNA to do this. Just a
| relative 's.
| analog31 wrote:
| >>> And what's the scam angle when the DNA is known?
|
| A person with apparent authority, telling people something
| about themselves, that they believed to be hidden, is a
| tactic for gaining psychological control. A strong-minded
| person should be able to withstand it under normal
| circumstances, but we're not all strong-minded under all
| circumstances. Hence the power of things like personality
| tests, police interrogations, and so forth.
| consumer451 wrote:
| > Enough to be denied insurance...
|
| Not just you, but your children who never had anything to do
| with 23andMe as well!
| a2dam wrote:
| The Genetic Information Nondiscrimination Act makes it
| illegal to adjust health (but not life) insurance premiums or
| discriminate for employment based on genetic information.
| Couples who do genetic testing before having kids have the
| same protections and they're very effective.
| echelon wrote:
| Companies do illegal things _all the time_.
|
| And let me flip this situation: are there any laws that
| prevent advertisers from looking at genetic data to target
| cohorts? If I were an unethical advertiser, I'd want to
| advertise to customers with less risk aversion, higher
| neuroticism, higher sense of FOMO. You could do some truly
| sickening stuff. Target higher mortality groups, certain
| personality types, cross reference with familial mortality
| data and have a field day...
|
| There are untold ways this could be abused that I'm almost
| certain the law doesn't fully protect against.
| hammock wrote:
| How do we know it hasn't already been sold at least once? The OMG
| expose makes me think
| randomNumber7 wrote:
| Hello, I was sent back from the future to tell you there is
| already a backup.
| Boogie_Man wrote:
| Me trying to sequence ppls genomes in my basement doesn't seem so
| bad now.
___________________________________________________________________
(page generated 2025-03-26 23:00 UTC)