Skip to content
GuideToGenetics

Can DNA Test Data Be Sold?

The three main ways consumer DNA data ends up in third-party hands: research sharing, corporate asset sales, and law enforcement access, and what controls you have.

By The GuideToGenetics Editorial Team
A handshake icon over a DNA helix illustration
Photo by Towfiqu barbhuiya on Pexels

Yes, in several different ways, none of which are exactly “selling your DNA on the open market” but all of which result in your data, or data derived from it, ending up somewhere other than the company you bought the kit from. We separate the three main paths because they have different mechanics and different controls.

Path 1: De-identified research partnerships

This is the most common path and the one most consumers have actually agreed to, often without reading the consent screen carefully.

Most major consumer testing companies run a research program. If you opt in (or in some cases, simply do not opt out), your genotype data is stripped of obvious identifiers and pooled into research datasets. Those datasets are then shared with academic and pharmaceutical partners.

The canonical example is the 23andMe partnership with GlaxoSmithKline, announced in 2018. The deal granted GSK access to de-identified 23andMe data for drug-target discovery, in exchange for funding and an equity investment.

What “de-identified” means in practice. Your name and email are removed. Your genotype and any phenotype information you provided (surveys you filled out, health conditions you reported) remain. Researchers have shown that genetic data is hard to truly anonymize, because a sufficiently long stretch of unique variants can re-identify a person, especially when combined with other available data.

Your control: You can opt out of research participation in your account settings. Doing so stops future sharing. It does not retroactively recall data already shared under your prior consent. The opt-out is separate from your basic terms of service consent, and you can revoke research consent without losing access to your results.

Path 2: Corporate asset transfer

Companies get acquired, merged, or sold in bankruptcy. When they do, their data assets go with them, subject to whatever the original terms of service allowed.

The 2025 23andMe situation is the clearest recent example. The company filed Chapter 11 in March 2025. Its genetic data and core operating assets were sold to TTAM Research Institute, a nonprofit founded by 23andMe co-founder Anne Wojcicki, in mid-2025. The wind-down plan was approved by the bankruptcy court later that year. Users who had not deleted their accounts beforehand had their data transferred by default.

State attorneys general, in the bankruptcy proceedings, raised concerns about the lack of granular opt-in for the transfer itself. The court approved the sale with additional notice protections.

Your control: Almost none, after the fact. The terms of service you accepted at signup typically include a clause allowing transfer in an asset sale, and the transfer happens through corporate-law mechanisms (bankruptcy court, M&A) where individual consumers are not direct parties. The only effective control is to delete your data before the transfer is finalized, which requires you to act on the news when it breaks.

For the detailed walkthrough, see 23andMe bankruptcy: what it means for your data and 23andMe data sale to TTAM, explained.

Path 3: Law enforcement access

This path got serious attention starting with the 2018 Golden State Killer case, in which California investigators identified the suspect by uploading crime-scene DNA to GEDmatch (a public genealogy database) and matching it against the relatives of users who had uploaded their consumer-test data.

Two distinct mechanisms exist today.

Voluntary genealogy databases. GEDmatch and FamilyTreeDNA allow users to opt in (or in some configurations, opt out) of matching with law enforcement queries. Users who have opted in can be matched as relatives of crime-scene DNA. This is the route that powers forensic genetic genealogy. See DNA testing and law enforcement.

Subpoena and warrant access to consumer companies. AncestryDNA and 23andMe do not allow law enforcement to query their databases freely. They require legal process (a subpoena or warrant), they evaluate the legal sufficiency, and they publish annual transparency reports listing how many requests they received and how many they complied with. The numbers historically have been very low (in the single digits to low double digits per year).

Your control: For voluntary databases, your opt-in or opt-out at the matching service level. For the major consumer companies, you have no direct control over a properly served subpoena, but the legal threshold is meaningful.

What “selling” actually looks like

A few framings to be precise about. Companies are not selling your name and address attached to your genome on a data broker market. The standard research-partnership path involves de-identified data. The asset-transfer path involves the entire dataset moving under new corporate ownership through a court process. Law enforcement access involves specific legal mechanisms with their own thresholds.

That said, “de-identified” is not a guarantee of true anonymity, and an asset transfer is functionally a sale of the dataset to a new owner. So the practical answer to “can my DNA test data be sold” is yes, just through these specific routes rather than through a generic data-broker pipeline.

What to do with this information

The most practical hedge is to make informed choices at signup, download your raw data periodically, and use the deletion process if your situation changes. Our DNA testing privacy checklist walks through the specific settings. For the deletion mechanics, see how to delete your 23andMe data and how to delete your AncestryDNA data.

This piece is part of our Genetic Data Privacy guide.