Protect Personal Genetic Information

Risks and practical recommendations to prevent misuse of genetic data.

Why this matters

Recommendations

Companies (research, testing)

  1. Adopt privacy-by-design: minimize collection and retention of raw genetic data.
  2. Require explicit, granular consent for each use and third‑party sharing.
  3. Use strong encryption (at-rest and in-transit) and strict key management.
  4. Implement differential access controls and audit logging for all access.
  5. Offer robust opt-out and deletion processes that remove derived insights too.

Organizations (hospitals)

  1. Governance: institutional review boards must assess privacy harms and benefits.
  2. Data minimization, secure compute enclaves, and purpose limitation for secondary uses.
  3. Transparent data-sharing agreements and accountability for downstream users.
  4. Community engagement and clear communication of risks to participants.
  5. Routine privacy impact assessments and public reporting of breaches.

Lawmakers & regulators

  1. Enact strong nondiscrimination protections for genetic information.
  2. Define narrow permitted uses and require data minimization standards.
  3. Mandate breach notification with specifics on genetic data risks.
  4. Require transparency reports, audits, and enforceable penalties.
  5. Support public funding for secure infrastructures and independent oversight.

Take action