How to Delete Your 23andMe Data
eff.org
eff.org
All I'm suggesting is that tapping some pixels on your backlit rectangular glass won't necessarily translate into pulses of electrons that'll eradicate the 0s and 1s representing your data.
I'm sure that corner of the codebase is one of the least visited parts, so bugs may lurk in, or misconfigurations, etc.
> Ideally the court can compel the purchaser(s) to destroy the data.
I suppose a court order holds more weight than checking a box on a web site, but I'm not sure how much I'd trust the eventual purchaser.
Worse yet, if the seller drops their guard (due to lack of funding for proper security) will someone steal the data? At that point web requests and court orders are moot.
I guess I'm seeing a black hat behind every bush. I'm not sure if this kind of data has any value on the black market.
the current US presidential administration is in the process of completely hollowing out the US judicial system. nothing in the courts can be trusted if the SCOTUS can't be trusted.
but even with sane leadership there is nothing preventing stuff from being leaked or sold.
unless you can physically verify the shred-it guys destroying the disks, it's out there.
The correct timing, appears to be that 23andMe would have had an opt-out, blocking the selling or transfer of their data. That also should have included confirmation of data deletion, if requested. Since none of that existed, the options for users are quite limited. In fact, many would have participated in 23andMe Research, so their data was likely going to wherever long before.
And what damages are you going to claim in court.
Lawyers are not cheap, no lawyer will work on a case less that even $1k. My only hope is donating to privacy fighting organizations like EFF that file class actions.
if (userRequestsToDeleteAccount || user.deactivated) { user.deactivated = true; showDeletionSuccessfulPage(); }
In this implementation, the user believes their data is deleted, but it has not.
Obviously this data infers heritage, disease risk, relations. It could be used for discrimination, surveillance, potentially poisoning .
Everyone should request their data to be deleted, but this is an engineering forum, and we know what that means in practice. Every company like this has hundreds of copies of the data, and has shared it with dozens of providers.
Like Rev Tevia said, you can't put the feathers back into an opened pillow.
Yeah, I can imagine they have a few dozen copies strewn over various backup media/blob buckets. There probably isn't much effort from what's left of their IT team to track them all down to delete.
Now the company is bankrupt this is the last thing on their task list to implement.
The cynic in me agrees, but the process was quick and easy, and I know I'm not safer by not deleting my information from 23andMe. I recommend it.
https://www.quora.com/How-much-of-the-genome-does-23andMe-se...
And they don't even have to have your DNA. Just a close enough relative will do.
Can you expand on this?
I understand the insurance thing due to genetic diseases and so on, but which jobs would I be denied for based on genetic information which wouldn’t be checked anyways?
I can only come up with stuff like colorblindness but that would probably be checked anyways if it were a strict requirement for the job so keeping the DNA secret wouldn’t help.
And what’s the scam angle when the DNA is known?
- Markers like ADHD and other neurodivergence and performance signals
- Disease likelihoods to reduce their insurance burden. Cardiovascular, cancer, neurodegeneration, etc.
- Markers for intelligence and tenacity. Personality type. Conversely, dishonesty, neuroticism, etc.
They could screen for literally any hypothetical condition that could in theory impact performance, risk, cost, etc. By excluding candidates with "low genetic scores", they might think they're saving margin.
There is a ton of literature beyond what 23andMe is legally allowed to report on with respect to the SNP data they collect. These studies report on a wide range of phenotypical states and behaviors that could impact job performance. The stack of research is deep.
> And what’s the scam angle when the DNA is known?
Look for any markers that indicate IQ, agreeableness, neurodegeneration, schizophrenia, personality type, etc. It gives scammers a hypothetically better hit rate.
And again, they don't need your DNA to do this. Just a relative's.
Here's an example (fictional preview) report from Promethease, which you can run on your SNP data you download from 23andme:
https://files.snpedia.com/reports/promethease_data/genome_Mi...
eg.
> 1.42x risk of Autism
> 1.3x to 11.5x Increased risk of autoimmune thyroid disease
> 1.3x higher risk of ER+ breast cancer
> 2 - 3x higher prostate cancer risk if routinely exposed to the pesticide fonofos
> 1.5x - 2x increased risk for cervical cancer, HNSCC, and breast cancer
> 2x risk of Alzheimer's disease
> Lack of empathy? You have a SNP in the oxytocin receptor which may make you less empathetic than other people.
> Increased risk of Multiple Sclerosis.
> HLA-DRB11501 carrier; higher multiple sclerosis risk Rs3135391(C;T) is highly correlated with the HLA-DRB11501 allele. There is a 3x higher risk of multiple sclerosis associated with the (C;T) genotype.
> 1.4x higher risk of lupus increased risk of Systemic lupus erythematosus.
(And on and on...)
This is stuff that 23andme can't legally show you, and many of the studies are small and inconclusive. But many of the disease markers are noteworthy.
Just click through to the literature, eg.
You want actionable information— a 30 minute interview.
- 1.42x risk of Autism
Okay, great, the population incidence is about 1 in 36, so 1.42x risk is about 1 in 25. What possible actionable use is this? It's not even particularly useful input to "should I follow up with some kind of actual assessment".
But even that and the other not-particularly-useful numeric risk multipliers are better than:
- You have a SNP in the oxytocin receptor which may make you less empathetic than other people.
At this level of specificity, you may as well be consulting a magic 8-ball.
A person with apparent authority, telling people something about themselves, that they believed to be hidden, is a tactic for gaining psychological control. A strong-minded person should be able to withstand it under normal circumstances, but we're not all strong-minded under all circumstances. Hence the power of things like personality tests, police interrogations, and so forth.
When I was younger, I read a lot of ethics course material, and spent a lot of time thinking about how someone could get around existing laws or technology, and most of it boils down to most people believing what they're told with a bit of coaxing (building that credibility; social engineering). Luckily, I never went ahead using this information, and have actually turned down projects where my morals were put into question, but I think it prepared me to be more conscious of scams and shady advertising. I work for a digital advertising agency, and use an adblocker during my development work so I can see how a site is useful or mostly worthless when someone turns ad networks/tracking off. One of the benefits of working for a smaller company.
This scam doesn't use your actual DNA data though, just the fact that you have a profile on a DNA site.
Not just you, but your children who never had anything to do with 23andMe as well!
Second, no these data are not (yet) very informative for the subject, let alone for relatives, with the exception of monozygotic twins.
And let me flip this situation: are there any laws that prevent advertisers from looking at genetic data to target cohorts? If I were an unethical advertiser, I'd want to advertise to customers with less risk aversion, higher neuroticism, higher sense of FOMO. You could do some truly sickening stuff. Target higher mortality groups, certain personality types, cross reference with familial mortality data and have a field day...
There are untold ways this could be abused that I'm almost certain the law doesn't fully protect against.
What's to stop someone within an advertisement company from reaching out to someone in healthcare IT, and offering a large amount of money for this information? Trying to link this physical data to an online presence is probably not worth the risk and amount of money and time (at this current point in time).
All my searching currently shows that there are only laws to protect against using genetics in employment and insurance, within the US. It doesn't look like there are any other protections in the US, other than unrelated laws like HIPAA compliance. I wouldn't even try to pretend to be able to figure out other countries' laws around this (and probably don't understand US law any further than not being able to find information easily available with search tools).
HIPAA works because it comes with personal liability. Anyone who sells/leaks/loses HIPAA data gets hit with a $1000 or so fine per person. So if you sell 100 patients' data, you're personally on the hook for $100,000. Your employer pays another cool $10,000/person on top.
More of these laws should come with personal liability. HIPAA is the only one I've ever seen people take seriously.
Like other privacy regulation, it’s there to protect the industry and their business/commercial interests.
Barriers to access mean less controversy, fewer lawsuits, fewer investigative news stories, fewer insurance disputes.
I’d say it’s also designed to reduce contamination or adulteration of data: if every facility needs to do new testing and new evaluation then they can be sure they got the results they need, instead of taking some rando’s word for it.
HIPAA isn’t the most onerous barrier to personal access to records, but it’s a huge hassle for someone who wants it opened up for family, friends, and other entities because those forms are onerous. With good transparency in patient portals, authorized users can manage a lot on their own.
Also, good luck reading anything but textual notes, because imaging and other medical data is often always distributed in proprietary file formats that don’t simply import into Gimp!
HIPAA as a whole is not.
The HIPAA Privacy and Security Rules, which are enforced by a different entity than the rest of HIPAA, are (the bulk of HIPAA is insurance administration rules enforced by the Centers for Medicare and Medicaid Services; the Privacy and Security Rules are personal privacy and information security rules enforced by the DHHS Office of Civil Rights.)
I once joined a health sharing ministry where reviews said "it requires an Olympic-class athlete in paperwork and bureaucracy". Being "not insurance" it was completely DIY and "self-pay" and begging for reimbursements after the fact.
I've also attempted to visit independent PCPs. An independent PCP who isn't part of a major health system, when they refer you out, refers you to some other independent specialist with their own process, their own IT tooling and portal, and their own claims/billing services. Now multiply those specialists by the number of your conditions, or simply the multiplicity of organs in your body, and all the fiefdoms commanded by different medical boards.
I sincerely pity any sane family of 4 or 5, because speaing for myself as an insane family of 1, the process is mind-blowing, byzantine, and frustrating by design, and the gatekeeping is exhausting but, obviously, necessary. Dealing with doctors arguably did not drive me insane, but it certainly helps keep me that way.
Gatekeeping doesn't end with single-payer and socialization, but all this back-and-forth and multiple independent systems should ideally be coalesced into one monolithic Brazil/12 Monkeys sized system.
I pity parents with sick children the most, I suppose. I mean it's bad enough for elderly parents and adult children to handle when they don't love their parents enough. But for parents to care for a sick child enough to funnel them into endless medical appointments, drugs, invasive therapies and even experimental Herr Mengele shit because it's cheap or free, feels like cruelty and exploitation being visited on that family, rather than mercy or healing. I found the Karen Ann Quinlan case (I suppose I was too young to remember when it hit the news before Terri Schiavo) and I found Karen's parents' attitude and comments to be quite poignant. It's called a "right-to-die" milestone, but I consider that the parents advocated for her right to be free from pain and distress associated with unnecessary medical treatment.
HIPAA is a fuckin' bugaboo when you're trying to coordinate care among payors, providers, billers, HIMS admins, family and friends, because all of these parties I mention are compartmentalized and the compartmentalization is nearly as fierce as military/espionage systems, except there's usually not a guy sitting next to the curtain wielding a semiautomatic rifle.
1. Ancestry, but that is about as reliable as a photo and puts a company at far greater legal risk.
2. Actionable SNPs associated with a metabolic oddities. Hmm, that might work for a small number of cases but would probably produce huge backlash.
3. We know who your daddy is. Oh great, thanks so much. I hate you.
Any advertiser going these routes will be running right into a brick wall.
Can you think of plausible scenarios that make someone a buck without legal repercussions and hate mail?
I can think of a few things you could try, maybe. But judging from 23andMe's present state, it's clear that whatever things they tried to monetize customers' DNA info, didn't work out well for them.
(I study actuarial genetics in the UM-HET3 mice and do quite a bit of human genetics related to aging. See this PMID: https://pubmed.ncbi.nlm.nih.gov/36173858/ )
Some will be easier than others, sure. I'm trying to decide how "safe" my data is, since I created a single-use gmail account, with fictitious name, and paid for it with a gift card. I was afraid that some information in there might lead to being uninsurable, so I decided to row away from the rocks. Thankfully, my genetics didn't pop up any red flags, knock on wood.
I guess if you signed up using your normal e-mail address and your real name and used your credit card, you can still take the Shaggy defense ("It wasn't me"), but I suppose at that point they could ask you to prove it. I mean, most businesses aren't obligated to do business with you, for any or no reason at all.
See Latanya Sweeney's work for more information: https://latanyasweeney.org/work/genomic.html
It’s not true—not yet—but once you say it, it will be.
Just… don’t mention that part. Not until after the first.
CLIA’s record retention requirements, as per Section 493.1105, states labs must retain test requisitions, authorizations, and reports for at least 2 years, with longer periods for specific tests like pathology (10 years for slides).
CLIA Laboratory Record Retention Requirements:
- Test requisitions and authorizations: 2 years minimum. - Test reports: 2 years minimum, 10 years for pathology reports. - Cytology slide preparations: 5 years. - Histopathology slides: 10 years. - Pathology specimen blocks: 2 years. - Tissue: Until diagnosis is made.
Notably, these requirements focus on test-related records, such as requisitions (which may include patient details like date of birth and sex) and reports (which for genetic tests would include interpreted results). However, there is no explicit mention of retaining raw genetic data, such as the full genotype data, in the CLIA regulations. This raises questions about whether 23andMe’s assertion to retain raw genetic information is strictly required by CLIA or if it extends beyond the regulation for other reasons, such as research or quality control.
[1] https://gizmodo.com/23andme-is-selling-your-data-but-not-how...
Basically, if you imagine this as a table of "user's name, date of birth, and address" keys mapping to genomic and other data, the key was replaced with a random identifier that could not be trivially joined to recover the user name, date of birth, and address.
These systems are not robust against motivated and capitalized adversaries.
Just a note that re-identifying aggregate data is a whole field of study that is decently successful.
Homomorphic encryption enables standard GWAS workflows (not just summary stats) while “sharing” all genotypes and phenotypes. Richard Mott and colleagues have a paper and colleagues on this method;
Note that selling deidentified data (genomic, health, etc) is common in the industry already and 23&Me is hardly unique in this respect.
There is considerable confusion about the distinction between aggregated data and de-identified individual-level data. I would say that I don't consider sufficiently aggregated data to be "your data" in a particularly meaningful personal sense of "your", even though there are still some re-identification risks from these types of datasets.
I was contesting the statement that "The data has already been sold... [and] the damage is already done" which I still think is highly misleading.
I don't think 23andme has been casual or callous with people's data; they are probably a step above the average firm that handles this sort of data. The consent process is well-documented.
My complaint has always been about 23&Me has always been Anne Wojciki's naivete about the utility of genomic data for health treatment, as well as whether her company needed to work with the government (she wrote a useful retrospective that helped shed light: https://hbr.org/2020/09/23andmes-ceo-on-the-struggle-to-get-...).
Most of us who worked in genomics at the time were sort of dumbfounded by her approach and wanted to know what magic she had that let her get as far as she did with the company and its product.
I don't have any problem with the family history side of the product; that's how my dad found out that he had a number of unexpected children (IVF through donated sperm) who were able to connect with him years after their conception. And I really wish disease genetics had turned out to be far more straightforward as I've long been fascinated with how complex phenotypes arise from genomes.
I think we've generally been pretty careful to present only scientifically well supported results, which has not helped the perceived utility of our health product. There are certainly valid arguments to be had about the business model.
(as for your question, I have no idea)
"Dear Sir,Madam
while reading a recently acquired db, i came across your brother in law who has disease xy. Now, me being a decent person, i kept things qiet for now. No need to rattle potential love interests , your children or the community with news about this genetic curse. If you want this silence to last, just subscribe by donating 0.01 bitcoin per year to the Mammal & Animal Foundation for Integrity Agency."
This right here is the chernobyll of privacy.
Would like to download everything first before requesting deletion.
Still, I figure I have a few trillion backup copies… albeit in very raw format
I am sorry to all of you that gave your family DNA to a SV startup.
It must suck to feel like you have no say in what happens to your private information.
No one has been able to explain this to me.
I definitely feel now that was the correct instinct.