With Research consent, 23andMe may share your genetic and self-reported health data with third-party academic or commercial research partners in de-identified or aggregated form.
This analysis describes what 23andMe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The policy authorizes sharing of genetic data with external research partners, and the practical protection depends entirely on the robustness of the de-identification method used, which the summary document does not detail.
Interpretive note: The summary version of the document references research participation and data sharing generally; the specific de-identification methodology and third-party partner categories are described in the full Privacy Statement which was not fully provided.
This new provision clarifies user control over DNA sharing features, elevating genetic data sharing decisions to high severity by creating a separate named provision for this critical choice.
View full change record →Users who opt into Research authorize 23andMe to share de-identified genetic and health data with third-party partners, and the degree of re-identification risk depends on the specific de-identification methodology applied, which is not described in the summary version of this policy.
How other platforms handle this
We will also provide an individual opt-out choice, or opt-in for sensitive data, before we share your data with third parties other than our agents, or before we use it for a purpose other than which it was originally collected.
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
"You decide whether you want to participate in our sharing features, like DNA Relatives and Your Connections.Excerpt from 23andMe's Privacy Statement
REGULATORY LANDSCAPE: De-identification of genetic data for research purposes engages HIPAA Safe Harbor and Expert Determination standards in the US, GDPR anonymization requirements in Europe (which are more stringent than HIPAA Safe Harbor), and California …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The policy authorizes sharing of genetic data with external research partners, and the practical protection depends entirely on the robustness of the de-identification method used, which the summary document does not detail.
Users who opt into Research authorize 23andMe to share de-identified genetic and health data with third-party partners, and the degree of re-identification risk depends on the specific de-identification methodology applied, which is not described in the summary version of this policy.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by 23andMe.