Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
EU and UK users have legal rights to access, correct, delete, and port their data, and to object to certain processing. They can also complain to their local data protection authority.
This analysis describes what Ancestry's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
GDPR provides the strongest set of consumer data rights of any applicable framework in this policy. EU and UK users have enforceable rights including the right to erasure and data portability, backed by regulatory authority.
The updated Privacy Statement no longer displays a dedicated 'Do Not Sell or Share My Personal Information' link in the footer, which was previously accessible to California residents under CCPA requirements. This link allowed users to exercise data-sharing opt-out rights. The footer now lists 'Consumer Health Privacy' as a separate item but does not explicitly direct users to their CCPA controls. California residents may need to locate their opt-out rights through alternative navigation paths on the Ancestry site.
View change record →The updated privacy policy removes the 'Do Not Sell or Share My Personal Information' link from the footer navigation. This link previously provided direct access to Ancestry's data-sharing opt-out mechanism, which is a required disclosure under California's CCPA. While the removal does not eliminate the opt-out right itself, it may make the opt-out control less easily discoverable from the privacy policy page. Affected users may need to locate the opt-out mechanism through alternate navigation or search methods.
View change record →The updated Privacy Statement clarifies what uses of Ancestry services are permitted and prohibited, establishes that photo face-grouping in your gallery requires your express consent, and introduces SMS messaging as a communication channel for future opt-in communications. The statement now covers Ancestry, AncestryDNA, and Related Brands under a unified framework while noting that other services operated by the company use separate privacy statements. The removal of 'uploaded DNA data' from the account creation section reflects a narrowing of that specific provision's scope, though genetic information processing remains described elsewhere in the policy. You can review the full updated statement to understand how your personal information will be processed and manage your communication preferences when SMS opt-ins become available.
View change record →Removal of explicit GDPR/UK GDPR rights provisions eliminates detailed disclosure of European privacy protections and data controller identification.
View full change record →EU and UK users can exercise data subject rights directly with Ancestry and have the additional protection of being able to escalate complaints to their national data protection authority. The designated controllers for each region are identified, which is important for knowing who to contact with rights requests.
How other platforms handle this
When you exercise any of your applicable legal rights to access, amend, or delete your personal information, we may request additional information from you for the purpose of confirming your identity.
When we rely on consent as the legal basis, you have the right to withdraw your consent for data processing at any time.
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
Monitoring
Ancestry has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"If you are located in the European Economic Area or the United Kingdom, you have the right to access your personal data, rectify inaccurate data, request erasure, object to processing, request restriction of processing, and request data portability. You also have the right to lodge a complaint with your local supervisory authority. Ancestry Ireland UC is the data controller for personal data processed in connection with the provision of our services to users in the EEA, and Ancestry.com Operations Inc. is the data controller for users in the UK.Excerpt from Ancestry's Privacy Statement
(1) REGULATORY LANDSCAPE: This provision directly engages GDPR Articles 15-22 (data subject rights) and Articles 13-14 (transparency requirements). The designated supervisory authorities are the Irish Data Protection Commission (for EEA users, given Ancestry Ireland UC as controller) and the UK Information Commissioner's Office (for UK users). These authorities have enforcement powers including fines up to 4% of global annual turnover under GDPR. (2) GOVERNANCE EXPOSURE: Medium. The policy correctly identifies the applicable controllers for EEA and UK users. The practical adequacy of Ancestry's rights response procedures, including identity verification, response timelines, and handling of genetic data erasure requests, should be audited against GDPR operational requirements. (3) JURISDICTION FLAGS: EEA users fall under Irish DPC jurisdiction. UK users fall under ICO jurisdiction. The post-Brexit UK GDPR framework creates parallel obligations that must be managed separately from EU GDPR compliance. Transfers of EEA user data to Ancestry's US entities must be covered by appropriate Chapter V transfer mechanisms (Standard Contractual Clauses or equivalent). (4) VENDOR AND CONTRACT IMPLICATIONS: Cross-border data flows between Ancestry Ireland UC and US entities must be governed by GDPR-compliant transfer mechanisms. Any processing by US-based service providers of EEA user data must be covered by Standard Contractual Clauses or equivalent instruments. (5) COMPLIANCE CONSIDERATIONS: Legal teams should confirm that Ancestry Ireland UC's role as EEA controller is operationally implemented (not just nominally designated), including that the Irish DPC has been appropriately notified and that records of processing activities under GDPR Article 30 are maintained. Transfer impact assessments for US data flows should be current.
Regulatory citations, enforcement risk, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
GDPR provides the strongest set of consumer data rights of any applicable framework in this policy. EU and UK users have enforceable rights including the right to erasure and data portability, backed by regulatory authority.
EU and UK users can exercise data subject rights directly with Ancestry and have the additional protection of being able to escalate complaints to their national data protection authority. The designated controllers for each region are identified, which is important for knowing who to contact with rights requests.
ConductAtlas has identified this type of provision across 295 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Ancestry.