23andMe · 23andMe Terms of Service · View original document ↗

Prohibition on Insurance Company and Employer Use

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity 23andMe recorded 4 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for 23andMe Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Insurance companies and employers are prohibited from using 23andMe's services, and the service cannot be used for forensic genealogy investigations.

This analysis describes what 23andMe's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This restriction is intended to prevent genetic data derived from 23andMe's services from being used to make insurance or employment decisions, which aligns with the Genetic Information Nondiscrimination Act's protections, though enforcement of this contractual restriction depends on user representation at account creation.

Recent Activity

This document changed recently

Medium May 5, 2026

The updated Terms now apply only to users who live outside the United States, Canada, EEA, UK, and Switzerland, or who access the Services from outside those regions. US, Canadian, EEA, UK, and Swiss…

High Apr 19, 2026

The updated Terms of Service now apply exclusively to users in the United States, narrowing the geographic scope from the prior version that addressed users in multiple regions. The terms now contain…

Medium Mar 23, 2026

The updated terms now apply only to users who live outside or access services outside the United States, Canada, EEA, UK, and Switzerland. Previously, the terms applied to US-based users. The terms a…

Consumer impact (what this means for users)

By prohibiting insurance companies and employers from accessing the service, the Terms assert a contractual barrier against the use of 23andMe genetic data for underwriting or employment screening purposes, though the practical enforceability of this restriction depends on how the company verifies user identity at registration.

How other platforms handle this

Mistral AI Medium

Customer will not, and will not permit any other person (including any End User) to: ... (d) attempt to reverse engineer, decompile, or otherwise attempt to discover the source code or underlying components (e.g., algorithms, weights, or systems) of the Mistral AI Products, including using the Outpu...

Delta Airlines Medium

All content on this Internet site ("the delta.com website") is owned or controlled by Delta Air Lines and is protected by worldwide copyright laws.

Runway Medium

You shall not (and shall not permit any third party to) either (a) take any action or (b) Make Available any Content on or through the Services that: [...] (viii) directly or indirectly uses the Services (including, but not limited to, Outputs) to create, train, develop, or improve similar or compet...

See all platforms with this clause type →

Monitoring

23andMe has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
You are not an insurance company or an employer; and You will not use the Services for any investigative forensic genealogy uses.

— Excerpt from 23andMe's 23andMe Terms of Service

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: The Genetic Information Nondiscrimination Act prohibits health insurers and employers from using genetic information for underwriting or employment decisions. The contractual prohibition in the Terms mirrors these statutory protections but operates as a contract-based restriction rather than a regulatory compliance mechanism. The FTC and relevant state attorneys general may be relevant enforcement actors if the prohibition is found to be inadequately implemented or circumvented. GOVERNANCE EXPOSURE: Medium. The prohibition is stated as a user representation at account creation, meaning enforcement depends on the accuracy of user-provided information. There is no described verification mechanism in the visible document text, which means the restriction may be difficult to operationalize. For corporate compliance teams, this provision signals that 23andMe has not authorized enterprise use by insurers or employers, and any such use would constitute a breach of the Terms. JURISDICTION FLAGS: Several states, including California, New York, and Florida, have state-level genetic privacy statutes that extend protections beyond GINA. Organizations in these states should evaluate whether their interactions with genetic testing services require specific compliance measures. The prohibition on forensic genealogy use is also relevant in jurisdictions where law enforcement genealogy databases are an active legal and policy issue. CONTRACT AND VENDOR IMPLICATIONS: HR and benefits vendors who might contemplate integrating genetic data into wellness programs should note that 23andMe's Terms explicitly prohibit employer use. Any procurement arrangement that involves 23andMe data in an employment context would conflict with the Terms as stated. COMPLIANCE CONSIDERATIONS: Compliance teams at insurance companies or employers who encounter 23andMe data in any context should confirm that their use does not violate GINA, applicable state genetic privacy laws, or these Terms. Organizations conducting genealogy research for any investigative purpose should review the forensic use prohibition before engaging 23andMe services.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has authority over deceptive practices and may be relevant if the prohibition on insurer and employer use is circumvented in ways that harm consumers
    File a complaint →
  • Hhs Ocr
    HHS OCR enforces HIPAA and oversees genetic information privacy in health contexts, relevant to the prohibition on insurance company use of genetic data
    File a complaint →

Applicable regulations

CFAA
United States Federal

Provision details

Document information
Document
23andMe Terms of Service
Entity
23andMe
Document last updated
May 5, 2026
Tracking information
First tracked
May 11, 2026
Last verified
May 12, 2026
Record ID
CA-P-010919
Document ID
CA-D-00147
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
16a44b36aa17e55ddf47ae29310c84ef467de0a10b43cf99d04895259b10a9f1
Analysis generated
May 11, 2026 23:34 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: 23andMe
Document: 23andMe Terms of Service
Record ID: CA-P-010919
Captured: 2026-05-11 23:34:45 UTC
SHA-256: 16a44b36aa17e55d…
URL: https://conductatlas.com/platform/23andme/23andme-terms-of-service/prohibition-on-insurance-company-and-employer-use/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does 23andMe's Prohibition on Insurance Company and Employer Use clause do?

This restriction is intended to prevent genetic data derived from 23andMe's services from being used to make insurance or employment decisions, which aligns with the Genetic Information Nondiscrimination Act's protections, though enforcement of this contractual restriction depends on user representation at account creation.

How does this clause affect you?

By prohibiting insurance companies and employers from accessing the service, the Terms assert a contractual barrier against the use of 23andMe genetic data for underwriting or employment screening purposes, though the practical enforceability of this restriction depends on how the company verifies user identity at registration.

Is ConductAtlas affiliated with 23andMe?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by 23andMe.