8 Total
3 High severity
3 Medium severity
2 Low severity
Summary

This privacy statement establishes Ancestry's data collection, use, and retention practices for personal information and genetic data submitted through its genealogy platform and DNA testing services. The statement authorizes Ancestry to use genetic data for product development and, with separate user consent, for scientific research purposes, and specifies that aggregate research dataset contributions remain in use following individual account or DNA deletion requests. Users may manage DNA data preferences, research consent elections, and marketing communications through account settings or by submitting deletion requests to Ancestry's support team.

Technical / Legal Breakdown

This document is Ancestry's global Privacy Statement, governing the collection, use, sharing, and retention of personal data across Ancestry's family history, DNA testing, and related services, with its legal basis varying by jurisdiction (consent, legitimate interests, and contractual necessity under GDPR; various state law bases in the US). The policy states that Ancestry collects a broad range of data types including name, contact details, family tree information, payment data, communications, device and usage data, and — most significantly — genetic data from DNA testing kits, and the terms authorize sharing of this information with service providers, business partners, affiliated companies, and in connection with corporate transactions such as mergers or acquisitions. The treatment of genetic and health-related data is operationally distinct: the policy asserts that DNA data is used for genealogy matching, product improvement, and — with separate explicit consent — research purposes, but users who have submitted DNA samples retain a meaningful deletion right, though the policy states that deletion of raw DNA data does not affect results already incorporated into aggregate research datasets. The policy engages GDPR and UK GDPR for EU and UK residents respectively, CCPA and CPRA for California residents, and references compliance with various US state biometric and genetic privacy laws; the handling of genetic data intersects with sector-specific frameworks including the Genetic Information Nondiscrimination Act (GINA) and state-level genetic privacy statutes. Compliance teams should note that the policy's description of data sharing with research partners under a separate consent model, combined with the carve-out preserving aggregate research contributions after individual deletion, warrants careful evaluation under GDPR data minimization and purpose limitation principles and applicable US genetic privacy regimes.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial

3 important changes detected

4 versions captured · Last updated: May 2026

May 13, 2026

medium
What changed Ancestry updated its Privacy Statement on May 13, 2026, making 46 sentence additions, 52 removals, and 54 modifications across the document. Key operational changes include: clarification of permitted and prohibited uses of services; updated language about photo grouping features requiring express consent; addition of SMS messaging references for future opt-in communications; reorganization of brand coverage under a 'Related Brands' structure rather than listing specific brands; and removal of references to uploaded DNA data in the account creation section. The effective date changed from August 21, 2024 to May 12, 2026.
Why this matters The updated Privacy Statement clarifies what uses of Ancestry services are permitted and prohibited, establishes that photo face-grouping in your gallery requires your express consent, and introduces SMS messaging as a communication channel for future opt-in communications. The statement now covers Ancestry, AncestryDNA, and Related Brands under a unified framework while noting that other services operated by the company use separate privacy statements. The removal of 'uploaded DNA data' from the account creation section reflects a narrowing of that specific provision's scope, though genetic information processing remains described elsewhere in the policy. You can review the full updated statement to understand how your personal information will be processed and manage your communication preferences when SMS opt-ins become available.
View full change record →
What changed Ancestry updated the navigation menu and footer layout of its Privacy Statement on May 6, 2026. The changes reorganized how certain links are presented—moving 'About Us' into the footer, reordering some menu items, and adding a 'Do Not Sell or Share My Personal Information' link in the footer. These are structural and presentational updates to how privacy-related information and opt-out options are accessed, not changes to the actual privacy rights or data practices described in the statement itself.
Why this matters This change makes it easier to find and exercise your right to opt out of data sales or sharing under California privacy law. The 'Do Not Sell or Share My Personal Information' link is now prominently placed in the footer of Ancestry's Privacy Statement, rather than being buried elsewhere. You can click this link from the privacy page directly to manage your data sale preferences.
View full change record →

May 1, 2026 medium

Ancestry removed a reference to 'Do Not Sell or Share My Personal Information' from the footer links in their privacy statement as of May 1, 2026. This link previously connected …

View change record →
High — 3 provisions
Medium — 3 provisions
Low — 2 provisions

Monitoring

Ancestry has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Aggregate Research Data Persistence After Deletion and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

BIPA
Illinois, USA
View official text ↗
CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
HIPAA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 13, 2026 00:25 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000224
Version ID CA-V-002540
SHA-256 21f90bd97c69ddd935f68f29ca5c316329adf77e637ff77b06b75cc5de967faa
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans