The promise was alluring: a simple saliva test, and suddenly, the vast tapestry of your ancestry, even predispositions to certain health conditions, would unfurl before your eyes.
23andMe, launched in 2006, rode this wave of genomic curiosity, transforming personal DNA into data points that promised not just self-discovery but also a trove for health research and drug development.
For years, it was a poster child for personalized genomics, a seemingly innocuous gateway to understanding the very blueprint of one’s being.
But the sheen has come off.
In March, the company that once seemed synonymous with unlocking personal genetic mysteries filed for Chapter 11 bankruptcy protection.
This wasn’t just a corporate restructuring; it was a seismic event that immediately rattled the foundational trust placed in the company by millions.
At the heart of the tremor? The fate of that intensely personal data – your DNA.
The alarm bells rang loud enough to prompt 27 states and the District of Columbia to file a lawsuit in bankruptcy court this week.
Their urgent plea: block the sale of 23andMe’s vast archive of genetic data without explicit customer consent.
This legal intervention comes as a biotechnology company circles, seeking court approval to acquire the struggling firm.
It’s a stark reminder that in the murky waters of digital privacy, even the most intimate personal information can become a commodity, subject to the whims of corporate insolvency and the complex dance of the market.
Anne Wojcicki, the co-founder and former CEO, has stepped down, signaling her intent to bid on the company as an independent buyer.
Her move, she stated on social media, is to be “in the best position” during the bankruptcy process.
While 23andMe assures its users that privacy and data are paramount considerations in any transaction, and that a buyer would be required to comply with applicable laws, experts are sounding a far more cautious note.
The core vulnerability lies in the patchwork quilt of U.S. privacy laws.
There is no overarching federal privacy legislation, leaving a mere 20 states with their own, often disparate, protections.
This legal vacuum creates fertile ground for uncertainty, especially when a company holding such sensitive information faces financial distress.
As Northeastern University computer science professor David Choffnes, executive director of its Cybersecurity and Privacy Institute, aptly points out, the stakes are uniquely high.
“At a fundamental biological level, this is you and only you,” Choffnes said, encapsulating the irreplaceable nature of genetic data.
Unlike a compromised email address, which can be discarded for a new one, “you just can’t do that with your genetic code.”
The risks extend beyond legal loopholes.
The very turmoil of bankruptcy – the cost-cutting, the potential job reductions – could inadvertently weaken the company’s cybersecurity defenses, leaving customer data more exposed to malicious actors.
This isn’t theoretical; 23andMe itself suffered a significant data breach in 2023, exposing the genetic information of nearly 7 million customers and leading to a $30 million class-action settlement.
It was a chilling preview of the potential consequences when the guardians of our most personal data falter.
While 23andMe has maintained that it does not share information with health insurance companies, employers, or public databases without consent, and only with law enforcement under valid legal processes like subpoenas, Choffnes highlights a broader concern.
“There’s still other things that they are allowed to do with that data, including, as they mentioned, provide cross context, behavioral or targeted advertising,” he noted.
The insidious danger here is the potential for re-identification.
Even if data is purportedly “de-identified,” research has shown how patterns in targeted advertising, for instance, could be pieced together by third parties to re-identify individuals.
The line between anonymity and exposure becomes dangerously thin.
For those who entrusted their genetic heritage to 23andMe, the immediate question is clear: what can be done?
The good news is, options exist.
California Attorney General Rob Bonta issued an urgent consumer alert even before the bankruptcy filing, reminding individuals of their right to have their data deleted.
If you are a 23andMe customer, reclaiming control over your genetic self is a deliberate but necessary process.
Log into your account, navigate to “settings,” and scroll to the “23andMe Data” section.
From there, you can “View” your data – and download a copy if you wish to retain it – before proceeding to the “Delete Data” section and clicking “Permanently Delete Data.”
A crucial final step involves confirming your deletion request via a link sent to your email.
Furthermore, if you previously allowed 23andMe to store your physical saliva sample, you can request its destruction through your account settings under “Preferences.”
And for those who consented to third-party research, that consent can be withdrawn under “Research and Product Consents.”
This unfolding drama with 23andMe is more than just a business story; it’s a profound commentary on the evolving landscape of digital privacy and the unique vulnerabilities that arise when our biological essence becomes a digital asset.
It serves as a potent reminder that in the age of personal genomics, the responsibility for safeguarding our most intimate data often falls squarely on our own shoulders, unless and until robust, comprehensive legal frameworks catch up to the accelerating pace of technological innovation.
The fight for genetic privacy is far from over.
-
Frank DiBernardo handles LNGFRM's Foodie and Miscellaneous writing tasks. He's always getting ideas from users, so don't be afraid to send an email to the editor.