Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement states that users who opt into research participation have their deidentified genetic data combined with data from other research participants, and that opt-out from this program is available at any time.
This analysis describes what 23andMe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the mechanism by which genetic information, once deidentified by 23andMe's processes, is aggregated into research datasets. The adequacy of the deidentification standard applied and the identity of downstream research partners are not detailed in this excerpt, which are material considerations under GDPR, HIPAA, and California GIPA transparency requirements.
Interpretive note: The document does not specify the deidentification methodology applied, the identity of research partners, or the scope of permissible downstream research use, which affects assessment of compliance with GDPR, HIPAA, and California GIPA requirements.
Under this provision, users who opt into the research program have their deidentified genetic data pooled with other participants' data for research purposes. The agreement states opt-out is available at any time through account settings.
Cross-platform context
See how other platforms handle Research Participation and Genetic Data Pooling and similar clauses.
Compare across platforms →Monitoring
23andMe has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"If you choose to participate in research, your deidentified data will be pooled with data from other participants. You can opt out at any time.Excerpt from 23andMe's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision implicates GDPR Article 9 (special category genetic data), the California Genetic Information Privacy Act, HIPAA deidentification standards under 45 CFR 164.514, and CCPA/CPRA disclosure requirements for data sharing. The FTC exercises general oversight over representations about data practices. Where the deidentification standard applied does not meet the regulatory threshold for any applicable framework, the pooled data may retain regulated status. (2) GOVERNANCE EXPOSURE: High. The provision authorizes pooling of deidentified genetic data without specifying the deidentification methodology, the identity of research partners, or the scope of permissible downstream use. GDPR requires that processing of special category data for research purposes meet specific conditions and safeguards, and CCPA requires disclosure of the categories of third parties with whom data is shared. The absence of this detail in the disclosed excerpt creates a transparency gap that compliance teams should assess. (3) JURISDICTION FLAGS: Heightened exposure exists for EU and EEA users under GDPR Article 9 and for California residents under California GIPA and CCPA/CPRA. UK users are subject to UK GDPR requirements for special category data. Illinois residents may have additional protections depending on the nature of biometric or genetic data processed. Switzerland-based users are subject to the Swiss Federal Act on Data Protection. (4) CONTRACT AND VENDOR IMPLICATIONS: If deidentified research data is shared with third-party research partners or institutions, data sharing agreements and data processing addenda may be required under GDPR Article 28 or equivalent frameworks. Procurement and legal teams should assess whether existing vendor agreements adequately govern downstream use of pooled research datasets. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should audit the deidentification methodology to confirm it meets HIPAA Safe Harbor or Expert Determination standards, GDPR pseudonymization requirements, and California GIPA definitions. The opt-out mechanism's technical implementation should be reviewed to confirm it functions as stated, including the timing of data removal from active research datasets after opt-out is exercised.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes the mechanism by which genetic information, once deidentified by 23andMe's processes, is aggregated into research datasets. The adequacy of the deidentification standard applied and the identity of downstream research partners are not detailed in this excerpt, which are material considerations under GDPR, HIPAA, and California GIPA transparency requirements.
Under this provision, users who opt into the research program have their deidentified genetic data pooled with other participants' data for research purposes. The agreement states opt-out is available at any time through account settings.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by 23andMe.