In April 2023, the bankruptcy of 23andMe sent a tremor through the consumer genomics industry — not because a company had failed, but because of what its failure revealed. Millions of customers suddenly confronted a question they had never been asked to consider: when a company that holds your DNA goes under, who owns the data? The answer, under existing law, was deeply uncomfortable. Genetic information collected by direct-to-consumer (DTC) testing companies sits in a regulatory no-man's-land, largely beyond the reach of the Health Insurance Portability and Accountability Act (HIPAA) and the Genetic Information Nondiscrimination Act (GINA) — the two federal statutes most Americans assume protect their most intimate biological data.
The 23andMe episode was a catalyst, but the underlying problem is structural. The regulatory architecture governing genetic data in the United States — and, to varying degrees, across most of the world — was designed for a clinical context that no longer describes how most genetic data is actually collected, stored, and monetised. The result is a sovereignty vacuum at the intersection of biology, commerce, and law that is only now beginning to attract the legislative attention it demands.
The Architecture of the Gap
HIPAA, enacted in 1996, was designed to protect health information held by healthcare providers, insurers, and their business associates. It is a powerful instrument within its domain. But DTC genetic testing companies — 23andMe, AncestryDNA, MyHeritage, and their competitors — are not healthcare providers. They are consumer technology companies. When a customer spits into a tube and mails it to a laboratory, they are not entering a clinical relationship. They are purchasing a product. And that distinction, seemingly minor, has enormous legal consequences.
GINA, enacted in 2008, fills a different gap: it prohibits employers and health insurers from discriminating on the basis of genetic information. But it says nothing about what a DTC company can do with the data it collects, how long it can retain biological samples, or whether it can sell de-identified genomic datasets to pharmaceutical companies, insurers, or data brokers. The statute was not designed for the consumer genomics era, and it shows.
The HIPAA gap is not a technical oversight — it is a structural feature of a regulatory architecture built before the era of consumer genomics.
The consequence is a market in which tens of millions of Americans have voluntarily surrendered their most sensitive personal data — information that identifies not just them but their relatives, their descendants, and their ancestral lineage — to companies operating under privacy policies that are, in many cases, deliberately opaque. A 2025 audit by privacy researchers found that the majority of major DTC genomics companies reserved the right to share de-identified data with third parties, with limited mechanisms for consumers to exercise meaningful control over how their samples were used after collection.
The Legislative Response: Federal Ambition, State Urgency
The 119th Congress has moved to address the gap with the Genomic Data Protection Act (GDPA), introduced by Senators Bill Cassidy and Gary Peters in a rare display of bipartisan alignment. The bill would establish a federal framework specifically targeting DTC genetic testing companies, requiring them to obtain explicit consumer consent for secondary uses of data, process deletion requests within 30 days, and notify customers of company acquisitions at least 30 days before completion. Enforcement would fall to the Federal Trade Commission, which would treat non-compliance as an unfair or deceptive trade practice.
The GDPA represents a meaningful step, but its passage is far from assured. In the interim, states have moved with considerably more urgency. In early 2026, Rhode Island, South Dakota, and Vermont introduced legislation requiring DTC companies to provide clear privacy notices, obtain express consent for data collection and secondary uses, and provide mechanisms for consumers to delete data or destroy biological samples. These bills follow a pattern established by Indiana's HB 1521 (2025), which created a regulatory framework for DTC providers with penalties of up to $7,500 per violation, and Montana's expansion of its Genetic Information Privacy Act to include neurotechnology data.
A parallel legislative thread addresses national security. The Department of Justice's Bulk Data Rule, effective April 2025, restricts the transfer of large volumes of sensitive personal data — including human genomic, epigenomic, proteomic, and transcriptomic data — to countries of concern or covered persons. Crucially, the rule applies even to de-identified, pseudonymised, or encrypted data, closing a loophole that had allowed companies to argue that anonymisation rendered transfers safe. States including Utah, Virginia, and Wisconsin have introduced complementary measures prohibiting medical and research facilities from using genetic sequencers or software produced by foreign adversaries, or storing genomic data within their borders.
For every dollar invested in protecting genetic data, the commercial genomics industry generates returns that dwarf the regulatory apparatus designed to constrain it.
The De-identification Illusion
Central to the regulatory debate is the question of whether genomic data can ever be truly de-identified. The scientific consensus is increasingly clear: it cannot. Research published in leading journals has demonstrated that individuals can be re-identified from ostensibly anonymous genomic datasets using publicly available genealogy databases, demographic information, and statistical inference. A 2018 study in Science estimated that 60% of Americans of European descent could be identified from their DNA using consumer genealogy databases alone — a figure that has only grown as those databases have expanded.
This has profound implications for the regulatory frameworks that rely on de-identification as a safe harbour. If de-identified genomic data is not truly anonymous, then the entire architecture of consent and data sharing built on that assumption is compromised. The DOJ's decision to apply its Bulk Data Rule to de-identified data reflects an emerging regulatory recognition of this reality, but it remains an exception rather than the rule in domestic privacy law.
Genomic data is the only category of personal information that simultaneously identifies you, your relatives, your descendants, and your ancestral lineage — a permanence no other data type can claim.
CRISPR and the Governance of Heritable Change
The genomic sovereignty debate extends beyond data privacy to encompass the governance of genetic modification itself. The CRISPR-Cas9 revolution has transformed gene editing from a laboratory curiosity into a clinical reality, with the FDA approving the first CRISPR-based therapy — Casgevy, for sickle cell disease and beta-thalassaemia — in late 2023. By 2026, the pipeline of somatic cell therapies in clinical trials has expanded dramatically, with applications ranging from cancer immunotherapy to rare metabolic disorders.
Somatic cell editing — modifying non-reproductive cells to treat individual patients — is now a regulated, if expensive, clinical modality. The governance challenge lies elsewhere: in germline editing, which involves heritable changes to embryos, eggs, or sperm, and in the increasingly blurred boundary between therapy and enhancement.
The 2018 case of He Jiankui, the Chinese scientist who created the world's first gene-edited babies in defiance of scientific consensus and regulatory norms, remains the defining cautionary tale of the field. His experiment — editing the CCR5 gene in embryos to confer resistance to HIV — was conducted without adequate oversight, with falsified consent documents, and with consequences for the edited children that remain incompletely understood. He was sentenced to three years in prison by Chinese authorities, but the episode exposed the fragility of international governance mechanisms that rely on voluntary compliance and professional self-regulation.
The Equity Dimension
The governance of CRISPR therapies is inseparable from questions of access and equity. The first approved CRISPR therapy, Casgevy, carries a list price of approximately $2.2 million per patient — a figure that places it beyond the reach of the vast majority of patients globally, including many in the high-income countries where it is approved. The diseases it treats, sickle cell disease and beta-thalassaemia, disproportionately affect populations in sub-Saharan Africa, the Middle East, and South Asia — precisely the regions least able to afford the therapy.
This creates a troubling dynamic in which the most transformative genetic technologies are developed using research that draws on diverse global populations — including the genetic diversity of communities in the Global South — but the resulting therapies are priced for wealthy markets. The governance frameworks being developed in 2026 are beginning to grapple with this tension, with proposals for tiered pricing, compulsory licensing, and international technology transfer mechanisms. But the structural incentives of the pharmaceutical industry, which requires high prices to recoup the enormous costs of clinical development, work against equitable access.
The HIPAA gap is not a technical oversight — it is a structural feature of a regulatory architecture built before the era of consumer genomics.
The World Health Organization's Human Genome Editing Registry, established in the wake of the He Jiankui affair, represents an attempt to create international transparency around germline editing research. But it is a voluntary mechanism, and its coverage is incomplete. The more fundamental challenge is that the governance of genetic technologies is inherently transnational — a researcher in one jurisdiction can conduct experiments that would be prohibited in another — while the regulatory frameworks that govern it remain stubbornly national.
The Sovereignty Imperative: What Meaningful Genetic Rights Look Like
The emerging consensus among legal scholars, bioethicists, and privacy advocates is that meaningful genetic rights require a framework that goes beyond the consent-and-notice model that dominates current data protection law. Several principles are gaining traction in academic and policy circles.
Inalienability and Limits on Consent
The first principle is that some aspects of genetic sovereignty should be inalienable — not subject to waiver through consent, however informed. The argument is that the permanence and familial implications of genetic data make it categorically different from other personal information. When an individual consents to the collection and use of their genomic data, they are not only making a decision about themselves; they are making a decision that affects their relatives, their children, and their descendants. A consent framework that treats this as an individual transaction fails to capture the collective dimension of genetic information.
This argument has found expression in proposals for a "genetic commons" — a framework in which genomic data is treated as a shared resource, with governance structures that give communities, not just individuals, a voice in how it is used. The analogy is to indigenous data sovereignty frameworks, which have developed sophisticated mechanisms for collective governance of data that belongs to communities rather than individuals.
Proportionality and Purpose Limitation
The second principle is proportionality: the use of genetic data should be strictly limited to the purposes for which it was collected, with robust mechanisms to prevent secondary uses. This is a familiar principle in data protection law — the GDPR's purpose limitation principle is a well-established example — but its application to genomic data requires particular rigour given the sensitivity of the information and the difficulty of reversing disclosure.
The DOJ's Bulk Data Rule represents a form of proportionality reasoning applied to national security: the sensitivity of genomic data justifies restrictions on its transfer that would not apply to less sensitive categories of personal information. The challenge is extending this reasoning to the domestic commercial context, where the incentives for secondary use are powerful and the regulatory mechanisms are weak.
Temporal Rights and the Right to Deletion
The third principle is temporal: individuals should have meaningful rights to control their genetic data over time, including the right to deletion of both digital data and biological samples. The GDPA's requirement that DTC companies process deletion requests within 30 days is a step in this direction, but it raises difficult questions about what deletion means in the context of genomic data that has already been incorporated into research datasets, shared with third parties, or used to train machine learning models.
Genomic data is the only category of personal information that simultaneously identifies you, your relatives, your descendants, and your ancestral lineage — a permanence no other data type can claim.
For every dollar invested in protecting genetic data, the commercial genomics industry generates returns that dwarf the regulatory apparatus designed to constrain it.
The International Dimension: Regulatory Arbitrage and the Race to the Bottom
The governance of genetic data and genetic modification is complicated by the same dynamic that affects all transnational regulatory challenges: the risk of regulatory arbitrage, in which research and commercial activity migrates to jurisdictions with the weakest oversight. The He Jiankui case is the most dramatic example, but it is not the only one. The global market for DTC genetic testing is characterised by significant variation in regulatory requirements, creating incentives for companies to locate data processing in jurisdictions with permissive privacy regimes.
The European Union's General Data Protection Regulation (GDPR) classifies genetic data as a special category of personal data, subject to heightened protections and a prohibition on processing without explicit consent. This represents a significantly more protective framework than exists in most of the United States, and it has driven some DTC companies to maintain separate data processing arrangements for European customers. But the GDPR's extraterritorial reach is limited, and its enforcement has been uneven.
The emerging international consensus, reflected in the WHO's governance frameworks and the work of the OECD, is that effective governance of genetic technologies requires international coordination — not just harmonisation of standards, but mechanisms for mutual recognition, information sharing, and joint enforcement. The challenge is that the political will for such coordination is limited, particularly in an era of geopolitical fragmentation and strategic competition over biotechnology.
Looking Forward: The Decade Ahead
The genomic sovereignty debate will intensify over the coming decade as the technology continues to advance. Several developments are likely to shape the trajectory of the field.
The cost of whole-genome sequencing has fallen from approximately $100 million in 2001 to under $200 today, and is projected to fall further. As sequencing becomes cheaper, the volume of genomic data being collected will grow exponentially — not just by DTC companies, but by healthcare systems, research institutions, employers, and insurers. The regulatory frameworks being developed today will need to be robust enough to govern a world in which genomic data is as ubiquitous as financial data.
The convergence of genomics with artificial intelligence is creating new capabilities for genomic analysis that were not anticipated when existing regulatory frameworks were designed. Machine learning models trained on large genomic datasets can identify disease risk factors, predict drug responses, and infer ancestry and physical characteristics with increasing accuracy. These capabilities create new risks of discrimination and surveillance that existing frameworks are not equipped to address.
The development of polygenic risk scores — statistical models that aggregate the effects of thousands of genetic variants to predict complex traits like intelligence, height, or disease susceptibility — is creating new pressure on the boundary between therapy and enhancement. As these scores become more accurate and more widely available, the governance questions they raise will become more urgent: who has access to this information, who can act on it, and what constraints should apply to its use in contexts ranging from reproductive medicine to employment?
The answers to these questions will not be found in the existing regulatory frameworks, which were designed for a different era. They will require new thinking about the nature of genetic sovereignty, the limits of individual consent, and the collective dimensions of genomic data. The legislative activity of 2025 and 2026 — the GDPA, the state-level privacy bills, the DOJ's Bulk Data Rule — represents the beginning of that reckoning, not its conclusion.
What is clear is that the stakes are high. Genomic data is the most intimate category of personal information that exists — information that is permanent, heritable, and shared with every biological relative. The governance frameworks that emerge from the current legislative moment will shape not just the privacy rights of individuals today, but the biological sovereignty of generations yet to come.



