[HN Gopher] How to Delete Your 23andMe Data
       ___________________________________________________________________
        
       How to Delete Your 23andMe Data
        
       Author : hn_acker
       Score  : 104 points
       Date   : 2025-03-26 19:41 UTC (3 hours ago)
        
 (HTM) web link (www.eff.org)
 (TXT) w3m dump (www.eff.org)
        
       | YooLi wrote:
       | This feels as hopeless as trying to keep your email/contacts from
       | social media sites. Even if you are vigilant about never allowing
       | an app/service to download your contacts, your friends will share
       | theirs and it is trivial to recreate your contact list. If I keep
       | my DNA from these companies, my relatives will share theirs and
       | they basically have my DNA.
        
         | CharlesW wrote:
         | > _This feels as hopeless as trying to keep your email
         | /contacts from social media sites._
         | 
         | The cynic in me agrees, but the process was quick and easy, and
         | I know I'm not safer by _not_ deleting my information from
         | 23andMe. I recommend it.
        
       | drdaeman wrote:
       | Note that despite any requests the genetic data and some personal
       | information (DOB and sex) probably _won 't_ be deleted, at least
       | because of CLIA requirements:
       | https://news.ycombinator.com/item?id=41781879 (more details in
       | https://bourniquelaw.com/2024/10/09/data-23-and-me/, linked from
       | the thread there)
        
         | CharlesW wrote:
         | Here's a great post by a lawyer, linked to further down in that
         | thread: https://bourniquelaw.com/2024/10/09/data-23-and-me/ It
         | suggests a way to challenge them on their assertions that they
         | must keep your data and samples.
        
           | bpodgursky wrote:
           | I'm sorry but this lawyer has absolutely no idea what he is
           | talking about with regards to CLIA compliance. And he even
           | admits as much, but keeps talking anyway.
        
             | CharlesW wrote:
             | CLIA is one of the excuses 23andMe uses to explain why they
             | retain your genetic information, date of birth, and sex.
             | The author cites the code sections he believes 23andMe are
             | referencing to make this claim, then explains why he
             | believes it doesn't apply. As a CLIA expert, do you mind
             | explaining what he's getting wrong for our benefit?
        
         | nelox wrote:
         | 23andMe does not operate as a laboratory itself but contracts
         | with U.S.-based labs that are certified under CLIA and
         | accredited by the College of American Pathologists (CAP).
         | According to their website, all saliva samples are processed in
         | CLIA-certified and CAP-accredited labs, ensuring compliance
         | with federal standards for accuracy and reliability. This
         | certification is crucial, as it aligns with FDA requirements
         | for certain health-related genetic tests. This distinction is
         | significant, as CLIA primarily regulates labs, not the
         | companies that contract them, potentially affecting the
         | applicability of retention requirements to 23andMe's broader
         | operations.
         | 
         | CLIA's record retention requirements, as per Section 493.1105,
         | states labs must retain test requisitions, authorizations, and
         | reports for at least 2 years, with longer periods for specific
         | tests like pathology (10 years for slides).
         | 
         | CLIA Laboratory Record Retention Requirements:
         | 
         | - Test requisitions and authorizations: 2 years minimum. - Test
         | reports: 2 years minimum, 10 years for pathology reports. -
         | Cytology slide preparations: 5 years. - Histopathology slides:
         | 10 years. - Pathology specimen blocks: 2 years. - Tissue: Until
         | diagnosis is made.
         | 
         | Notably, these requirements focus on test-related records, such
         | as requisitions (which may include patient details like date of
         | birth and sex) and reports (which for genetic tests would
         | include interpreted results). However, there is no explicit
         | mention of retaining raw genetic data, such as the full
         | genotype data, in the CLIA regulations. This raises questions
         | about whether 23andMe's assertion to retain raw genetic
         | information is strictly required by CLIA or if it extends
         | beyond the regulation for other reasons, such as research or
         | quality control.
        
       | ahmedfromtunis wrote:
       | To be honest, this is more like "requesting the data to be
       | deleted". There's nothing that guarantees that the personal
       | information will be physically wiped out of the hard drives used
       | to store them.
        
         | throwaway48476 wrote:
         | But it creates legal grounds for lawsuits if they don't.
        
           | ahmedfromtunis wrote:
           | Of course. And I'm not saying that they might do it in
           | malice.
           | 
           | All I'm suggesting is that tapping some pixels on your
           | backlit rectangular glass won't _necessarily_ translate into
           | pulses of electrons that 'll eradicate the 0s and 1s
           | representing your data.
           | 
           | I'm sure that corner of the codebase is one of the least
           | visited parts, so bugs may lurk in, or misconfigurations,
           | etc.
        
           | Cheer2171 wrote:
           | Sure, you can sue the hollowed out shell of a bankrupt
           | limited liability corporation that will soon have no assets
           | for a court to sieze for whatever paltry damages a court
           | finds.
        
       | ks2048 wrote:
       | Has anyone tried to export their ancestry data? I've notice the
       | PDF summary lists broad regions, but the data in the App shows
       | more details (e.g. specific counties of countries). Anyone know
       | how to export that data? I'll just take some screenshots, but
       | maybe this info is somewhere else in the export.
        
         | dahinds wrote:
         | Click on the "Scientific Details" instead of the Summary.
        
       | pmarreck wrote:
       | Why? If it's already out there, it's kind of too late, is it not?
        
       | rglover wrote:
       | The data has already been sold off to the real customers (i.e.,
       | not you and me) [1]. You can (and should) request a deletion, but
       | the damage has already been done.
       | 
       | [1] https://gizmodo.com/23andme-is-selling-your-data-but-not-
       | how...
        
         | dahinds wrote:
         | This is false, we've sold data with PII to no one. Or it is
         | misleading: the page you linked to even says, "It is selling
         | de-identified, aggregate data for research, if you give them
         | consent."
        
           | EA-3167 wrote:
           | To what extent and using what method is it "de-identified"?
           | Plenty of such schemes are very easy to circumvent,
           | especially with a large enough pool of data. Given the nature
           | of genetics in particular positively identifying a single
           | case can be used to unmask whole families. In particular
           | depending on the anonymization this would be a task suited to
           | 'AI' very well.
        
             | dekhn wrote:
             | https://www.23andme.com/about/individual-data-consent
             | 
             | Basically, if you imagine this as a table of "user's name,
             | date of birth, and address" keys mapping to genomic and
             | other data, the key was replaced with a random identifier
             | that could not be trivially joined to recover the user
             | name, date of birth, and address.
             | 
             | These systems are not robust against motivated and
             | capitalized adversaries.
        
               | dahinds wrote:
               | I can go to a data broker and purchase access to de-
               | identified EMR data for most of the U.S. population.
               | There are much more useful de-identified datasets around
               | than ours, if someone is motivated to try to re-identify
               | those datasets. That data is all bought and sold without
               | anyone's consent and this is all fine under HIPAA.
        
             | dahinds wrote:
             | Here "de-identified" means stripped of PII (name, address,
             | phone number, email, etc). You are correct that genetic
             | information is intrinsically identifiABLE (in the sense
             | that it is stable and uniquely distinguishing for
             | individuals). When we've shared individual-level data with
             | a partner, it was with consent of the participants
             | involved, and under a contract that prohibits re-
             | identification.
        
           | ziddoap wrote:
           | > _It is selling de-identified, aggregate data_
           | 
           | Just a note that re-identifying aggregate data is a whole
           | field of study that is decently successful.
        
             | dahinds wrote:
             | Indeed, but here "re-identification" generally means the
             | sort of attack where you have an aggregated genomic
             | dataset, and you already have access to full genomic data
             | for a target individual, and you use the genomic dataset to
             | infer something about that target that you didn't know,
             | like whether or not they participated in that study. Not to
             | entirely minimize this sort of attack, but the NIH decided
             | it was a sufficiently low risk that most of the sorts of
             | datasets it applies to (like GWAS) are routinely shared
             | with no access controls.
        
           | dekhn wrote:
           | Providing another company access to deidentified data _is_
           | "selling your data", to argue otherwise is just semantics.
           | 
           | Note that selling deidentified data (genomic, health, etc) is
           | common in the industry already and 23&Me is hardly unique in
           | this respect.
        
       | yoaviram wrote:
       | Better yet, send them a legally binding data deletion request (if
       | you live in a jurisdiction that has strong data protection laws):
       | 
       | https://yourdigitalrights.org/d/23andme.com
        
       | brian-armstrong wrote:
       | The distinction isn't super important, but 23andMe doesn't have
       | your whole genome, just some specific locations from it. Roughly
       | 750k base pairs or so.
       | 
       | https://www.quora.com/How-much-of-the-genome-does-23andMe-se...
        
         | echelon wrote:
         | Enough to be denied insurance, have job offers rescinded, or be
         | targeted by scams.
         | 
         | And they don't even have to have _your_ DNA. Just a close
         | enough relative will do.
        
           | echoangle wrote:
           | > have job offers rescinded, or be targeted by scams
           | 
           | Can you expand on this?
           | 
           | I understand the insurance thing due to genetic diseases and
           | so on, but which jobs would I be denied for based on genetic
           | information which wouldn't be checked anyways?
           | 
           | I can only come up with stuff like colorblindness but that
           | would probably be checked anyways if it were a strict
           | requirement for the job so keeping the DNA secret wouldn't
           | help.
           | 
           | And what's the scam angle when the DNA is known?
        
             | echelon wrote:
             | This would be wholly illegal, but companies could screen
             | candidates prior to extending offers to them. After they
             | get your primary details and history, they can look you up
             | in the gene database. They could look for a whole host of
             | genetic markers, including but not limited to:
             | 
             | - Markers like ADHD and other neurodivergence and
             | performance signals
             | 
             | - Disease likelihoods to reduce their insurance burden.
             | Cardiovascular, cancer, neurodegeneration, etc.
             | 
             | - Markers for intelligence and tenacity. Personality type.
             | Conversely, dishonesty, neuroticism, etc.
             | 
             | They could screen for literally any hypothetical condition
             | that could in theory impact performance, risk, cost, etc.
             | By excluding candidates with "low genetic scores", they
             | might think they're saving margin.
             | 
             | There is a ton of literature beyond what 23andMe is legally
             | allowed to report on with respect to the SNP data they
             | collect. These studies report on a wide range of
             | phenotypical states and behaviors that could impact job
             | performance. The stack of research is deep.
             | 
             | > And what's the scam angle when the DNA is known?
             | 
             | Look for any markers that indicate IQ, agreeableness,
             | neurodegeneration, schizophrenia, personality type, etc. It
             | gives scammers a hypothetically better hit rate.
             | 
             | And again, they don't need _your_ DNA to do this. Just a
             | relative 's.
        
             | analog31 wrote:
             | >>> And what's the scam angle when the DNA is known?
             | 
             | A person with apparent authority, telling people something
             | about themselves, that they believed to be hidden, is a
             | tactic for gaining psychological control. A strong-minded
             | person should be able to withstand it under normal
             | circumstances, but we're not all strong-minded under all
             | circumstances. Hence the power of things like personality
             | tests, police interrogations, and so forth.
        
           | consumer451 wrote:
           | > Enough to be denied insurance...
           | 
           | Not just you, but your children who never had anything to do
           | with 23andMe as well!
        
           | a2dam wrote:
           | The Genetic Information Nondiscrimination Act makes it
           | illegal to adjust health (but not life) insurance premiums or
           | discriminate for employment based on genetic information.
           | Couples who do genetic testing before having kids have the
           | same protections and they're very effective.
        
             | echelon wrote:
             | Companies do illegal things _all the time_.
             | 
             | And let me flip this situation: are there any laws that
             | prevent advertisers from looking at genetic data to target
             | cohorts? If I were an unethical advertiser, I'd want to
             | advertise to customers with less risk aversion, higher
             | neuroticism, higher sense of FOMO. You could do some truly
             | sickening stuff. Target higher mortality groups, certain
             | personality types, cross reference with familial mortality
             | data and have a field day...
             | 
             | There are untold ways this could be abused that I'm almost
             | certain the law doesn't fully protect against.
        
       | hammock wrote:
       | How do we know it hasn't already been sold at least once? The OMG
       | expose makes me think
        
       | randomNumber7 wrote:
       | Hello, I was sent back from the future to tell you there is
       | already a backup.
        
       | Boogie_Man wrote:
       | Me trying to sequence ppls genomes in my basement doesn't seem so
       | bad now.
        
       ___________________________________________________________________
       (page generated 2025-03-26 23:00 UTC)