What?
What?
I've used 23andme and it's VERY clear when you choose to share or not share your DNA.
https://time.com/5349896/23andme-glaxo-smith-kline/
While 23andMe has technically adhered to the original terms of service, they've been sharing your data without your consent with their new parent firms like pharma giant GSK (the same one described in this article) which purchased partial ownership of the company and therefore ownership of the data. You see, giving data to your parent firm is not technically giving data to a third party. This was the business model all along. The 'customers' were the product, and the real customers were pharmaco.
Getting the products (you) to pay for the cost of their own sequencing so the data is effectively free was a stroke of genius. Not only are you giving away incredibly valuable data about yourself only a tiny fraction of which is returned back to you in the form of a report, you're paying for the cost to collect it. It's brilliant.
You've been duped by the dupe that everyone saw coming.
Not only that, this is one of the benevolent aspects of 23&Me that people saw coming. It's only a matter of time before this information trickles to insurance companies.
I'm sure GP's children will love them for selling out their data to future employers and insurers.
In general trying to keep DNA secret to prevent discrimination is a losing game, a better strategy is preventing discrimination itself, which we already have to do for DNA variations that have visible manifestation. Moreover if the number of people who need protection from discrimination increases, we'll get better at preventing it, which would be useful for the people who are being discriminated now.
I really hope that would be illegal here in the EU. It being physically possible (or even easy) doesn't make it okay. Not having the dataset easily available is one safety layer to prevent discrimination. No, it sadly doesn't help in all cases. Its unlikely there will ever be something that can, unless maybe you believe in perfectly implemented government policy reeducating us or controlling our behavior.
If we knew the ways vaccination programs would be abused, should we have refrained from inoculating so much of the world against polio?
https://www.23andme.com/about/consent/
"Which of my personal information is used for research?"
"Your genetic data and any other personal information you enter into the website, except for your Registration Information (name, contact information, and credit card information), may be analyzed in the research."
It really seems people are complaining because 23andme didn't demand they sign a consent for something they had already explicitly signed a consent to. I, for one, assumed large third-party pharmaceutical companies would have access to the data when I volunteered it. Is there significant risk people misunderstood that? How?
DEF CON 25 - John Sotos
"Genetic Diseases to Guide Digital Hacks of the Human Genome"
https://en.m.wikipedia.org/wiki/Genetic_Information_Nondiscr...
The health insurer doesn't need the genome. It just needs a number from 1 to 10 from a 'de-identified' source to multiply their scores by.
ACA plan premiums can only be set based on 5 factors: age, location, tobacco use, individual vs. family enrollment, and plan.
Insurance is effective at protecting people from uncertain financial risks, but the demands of the public have gradually changed the function of health insurance to include many things outside of that.
The question was never "what functions do insurance companies do efficiently?", the question has always been "what health benefits do people deserve?". Unfortunately, these questions have different answers.
[1] https://www.npr.org/sections/health-shots/2018/08/07/6360262...
It's incredibly difficult to truly de-identify data and it's incredibly easy to re-identify it. Making data truly anonymous usually also neuters the data for any kind of predictive models.
23andMe is selling either straight up raw data (which is totally allowed under the investment terms) or tightly grouped 'summary' data which can be trivially re-identified. If they were selling actually anonymous data it would be worth nothing because it would yield no predictions.
Disclaimer: I work in ML/predictive analytics. 'anonymous data' is a marketing term for trivially reidentifiable data. If the data is truly anonymous then its predictive power tends towards 0 as does its market price. You don't think GSK dropped 300 mil on mostly useless data do you?
Trying to keep genetic identity anonymous is security through obscurity. You have shed thousands of skin cells in the time it took for you to read this. If people want your DNA it's trivial to collect -- and will only get easier and more common.
A better use of our time is to address the ramifications of public DNA and prevent it from being misused.
Now compare the cost of hacking into a database to the cost of obtaining millions of genomes by physically taking genetic material and then sequencing it. Then consider that your DNA is yours for the rest of your life.
Simply because data can be obtained by some means does not make protecting that data useless.
As the value of DNA increases, people will collect it. Restaurants, washrooms, your employer, airlines, Uber etc. all could have trivially easy access to your DNA if they choose to.
Just because there is 'trivial' access to certain attributes of people doesn't mean that it's legal to capture those attributes, and even if you do capture them, they're worthless on the legal market. E.g. see SF ban on facial recognition.
And that's only if such legal barriers are even constructed which I'm not sure they will be. Look how the privacy battle has turned out thus far.
[1] https://www.telegraph.co.uk/news/2018/04/27/golden-state-kil...
[2] https://www.latimes.com/california/story/2019-11-24/law-enfo...
[3] https://www.usatoday.com/story/tech/nation-now/2018/04/27/an...
Why, after the consistent abuses and lack of accountability across the corporate sphere, would you place any faith in a business's claim that they're just leaving what probably already amounts to billions of dollars of value on the table when there is effectively no penalty for covertly extracting said value at the cost of customer privacy?
Why, after a decade+ of security breaches and poor data handling practices, would you trust a financially motivated, publicly traded company to properly anonimize data?
https://www.nytimes.com/2019/07/23/health/data-privacy-prote...
> A 23andMe spokesperson told TIME that data privacy is a “top priority” for the company, emphasizing that customer data isn’t used in research without consent, and that GlaxoSmithKline will only receive “summary statistics from analyses 23andMe conducts so that no single individual can be identified.”
Also, if I buy some shares in Amazon I don't get have all their client data.
There are obvious loopholes to the statement “no single individual can be identified”.
https://www.gsk.com/media/5349/annual-report-2018.pdf
> 23andMe in which the Group holds 14.5%.
You can also find a list of subsidiaries of GSK in there and you will note that 23andMe is not listed among them.
If a publicly traded-company has more than 5% of outstanding shares owned by a single entity, they have to file an SEC Form 13D. This is a typical cut-off to indicate an activist investor [2]. Far less than the 14.5% GSK owns. Without knowing who owns the other 85.5% of 23andMe (or visibility into their board and voting structure), we have no idea who controls the company.
You would need to spend about $44 billion to own 5%, or 24.8 million shares, of Amazon. I'm still not clear on how GSK's purchase of 14.5% of 23andMe along with the exclusive agreement that came with it is the same as buying a single share of Amazon stock.
[1] https://www.cnbc.com/2018/07/24/glaxosmithkline-23andme-team...
Buying 14.5% of a company does not come with an automatic collaboration agreement nor would a collaboration agreement come with 14.5% of a company's stock unless there is specific terms for that in some contract which establishes both. And there very well may have been - but both a collaboration agreement and 14.5% ownership can exists without such a contract.
> I'm still not clear on how GSK's purchase of 14.5% of 23andMe along with the exclusive agreement that came with it is the same as buying a single share of Amazon stock.
The argument that was made and that I was responding to was that GSK is 23andMe's parent firm and therefore not legally a 3rd party ... and I'm not sure how I much clearer I can say a shareholder is a shareholder.
If you want to argue that the exclusive collaboration agreement (which is not the same thing as 14.5% ownership) somehow defeats 23andMe's privacy policy then please, argue for it. Maybe it does - but you have not done anything more than allude to it doing so.
> You would need to spend about $44 billion to own 5%, or 24.8 million shares, of Amazon.
And spending that much will not entitle me to an exclusive collaboration agreement with Amazon nor will it make me somehow not a 3rd party of Amazon and therefore allow Amazon to give me all their client data without violating any privacy policies as the person I was responding to claimed.
> Without knowing who owns the other 85.5% of 23andMe (or visibility into their board and voting structure), we have no idea who controls the company.
We don't - but board members and owners are not the same as parent companies and I don't see how that somehow defeats their privacy policy either but if you think it can please clarify.
The point is that GSK wouldn't have invested $300 million without the exclusive collaboration agreement. That is why it's different than buying a publicly traded stock. GSK is not just a random shareholder, they are a significant owner (may even have board seats) with an exclusive collaboration agreement. You are splitting those things up to make your argument, but they are linked together.
I'm going to have to investigate this more thoroughly. If it's true, then I'll delete my data at 23&me (and hope that data deletion actually does what it says).
I'm certainly not doing anything to cure that disease. Strict privacy advocates aren't doing something to cure that disease (I guess they might be, but how would I know, they don't talk about themselves much ;) ).
I value a cure for Parkinson's more than I value my privacy. If selling the DNA I provided as part of a research dataset (that I provided without knowing who would be doing the research, but knowing it'd be someone because that's how research works) cures Parkinson's, I'm on board.
(b) To address that issue, I vote for politicians who advocate for radically restructuring how healthcare is paid for in the US to minimize incentives to gouge unlucky individuals
Novartis recently won approval for a cure to a rare genetic disorder, priced at two million dollars: https://www.reuters.com/article/us-novartis-genetherapy/nova...
And that's the best case scenario, the worst case scenario is that your data is used to increase your insurance and healthcare rates.
Moreover, it normalises crappy corporate behaviour.
There's something so purely dystopian about paying a company to collect our genomic data, which then helps to create medical breakthroughs that none of us will be able to afford.
This is why it's so important that companies refrain from selling our genomes to biotech companies.
If the treatment ends up costing $100k, the genetic info you provided resulted in a discount from infinite dollars to an actual finite amount.
That's a pretty big discount.
I'm shocked that it needs to be spelled out on HN, but companies like 23andMe are the epitome of 'you are the product'.
I don't believe myself to have been duped. I've made concessions based on priorities. Would I prefer this work be done, publicly funded, by the NIH and other non-profit researchers? Absolutely. Am I willing to wait for perfection? Absolutely not. Federal law currently protects your DNA data from employers and insurance companies. If you find that to be insufficient, run for office.
Disclaimer: Interviewed and was offered a role at 23andme a lifetime ago (2011), no other affiliation besides being a satisfied customer.
Yeah GSK is definitely where the resources are. To circumvent regulations and laws.
Fuck actual research right?
If you don’t like the law, fix the law. If you have evidence a drug company or data provider violated the law, report them to your attorney general.
If you are covered under 42 CFR Part 2, then it would not be allowed because the patient has to give consent to ALL parties.
Not without express consent. The default is 0 hops. Same rules applies for banking info.
You want to share with someone else? You have to ask for consent again. A lot of people did unknowingly sign up to have their data shared like you say though, which I think is a regulatory failure more than anything else.
JohnFen's comment is correct. This is why 42 CFR Part 2 was created; HIPAA was too loose with patient data.