Provision record
Ancestry · Ancestry Privacy Statement · View original document ↗

GDPR Rights for EU and UK Users

Low severity High confidence Explicitdocumentlanguage Common · 295 of 352 platforms
Get alerted the next time Ancestry changes these terms. Follow Ancestry →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Ancestry recorded 2 documented changes in the last 30 days.
Follow Ancestry →
Monitor governance changes for Ancestry Monitor emails you the same day this changes. The archive stays free.
Follow Ancestry →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

EU and UK users have legal rights to access, correct, delete, and port their data, and to object to certain processing. They can also complain to their local data protection authority.

This analysis describes what Ancestry's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

GDPR provides the strongest set of consumer data rights of any applicable framework in this policy. EU and UK users have enforceable rights including the right to erasure and data portability, backed by regulatory authority.

Recent Activity

This document changed recently

Medium Jun 21, 2026

The updated Privacy Statement no longer displays a dedicated 'Do Not Sell or Share My Personal Information' link in the footer, which was previously accessible to California residents under CCPA requirements. This link allowed users to exercise data-sharing opt-out rights. The footer now lists 'Consumer Health Privacy' as a separate item but does not explicitly direct users to their CCPA controls. California residents may need to locate their opt-out rights through alternative navigation paths on the Ancestry site.

View change record →
Medium Jun 2, 2026

The updated privacy policy removes the 'Do Not Sell or Share My Personal Information' link from the footer navigation. This link previously provided direct access to Ancestry's data-sharing opt-out mechanism, which is a required disclosure under California's CCPA. While the removal does not eliminate the opt-out right itself, it may make the opt-out control less easily discoverable from the privacy policy page. Affected users may need to locate the opt-out mechanism through alternate navigation or search methods.

View change record →
Medium May 13, 2026

The updated Privacy Statement clarifies what uses of Ancestry services are permitted and prohibited, establishes that photo face-grouping in your gallery requires your express consent, and introduces SMS messaging as a communication channel for future opt-in communications. The statement now covers Ancestry, AncestryDNA, and Related Brands under a unified framework while noting that other services operated by the company use separate privacy statements. The removal of 'uploaded DNA data' from the account creation section reflects a narrowing of that specific provision's scope, though genetic information processing remains described elsewhere in the policy. You can review the full updated statement to understand how your personal information will be processed and manage your communication preferences when SMS opt-ins become available.

View change record →

Clause Stability Mostly Stable

1
Change
3
Months Monitored
May 10, 2026
First Seen
May 20, 2026
Last Seen
This clause type exists across 5261 other provisions on other platforms.
This clause has changed once in 3 months of monitoring.

Change history

removed Jun 2, 2026

Removal of explicit GDPR/UK GDPR rights provisions eliminates detailed disclosure of European privacy protections and data controller identification.

View full change record →

Consumer impact (what this means for users)

EU and UK users can exercise data subject rights directly with Ancestry and have the additional protection of being able to escalate complaints to their national data protection authority. The designated controllers for each region are identified, which is important for knowing who to contact with rights requests.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Export Your Data
    EU and UK users can submit data subject rights requests (access, erasure, portability, objection) by emailing privacy@ancestry.com or through the Ancestry Privacy Center. Ancestry is required to respond within one month under GDPR.

How other platforms handle this

Discord Medium

When you exercise any of your applicable legal rights to access, amend, or delete your personal information, we may request additional information from you for the purpose of confirming your identity.

GitHub Medium

When we rely on consent as the legal basis, you have the right to withdraw your consent for data processing at any time.

Tinder Medium

If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.

See all platforms with this clause type →

Monitoring

Ancestry has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Ancestry → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
If you are located in the European Economic Area or the United Kingdom, you have the right to access your personal data, rectify inaccurate data, request erasure, object to processing, request restriction of processing, and request data portability. You also have the right to lodge a complaint with your local supervisory authority. Ancestry Ireland UC is the data controller for personal data processed in connection with the provision of our services to users in the EEA, and Ancestry.com Operations Inc. is the data controller for users in the UK.

Excerpt from Ancestry's Privacy Statement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly engages GDPR Articles 15-22 (data subject rights) and Articles 13-14 (transparency requirements). The designated supervisory authorities are the Irish Data Protection Commission (for EEA users, given Ancestry Ireland UC as controller) and the UK Information Commissioner's Office (for UK users). These authorities have enforcement powers including fines up to 4% of global annual turnover under GDPR. (2) GOVERNANCE EXPOSURE: Medium. The policy correctly identifies the applicable controllers for EEA and UK users. The practical adequacy of Ancestry's rights response procedures, including identity verification, response timelines, and handling of genetic data erasure requests, should be audited against GDPR operational requirements. (3) JURISDICTION FLAGS: EEA users fall under Irish DPC jurisdiction. UK users fall under ICO jurisdiction. The post-Brexit UK GDPR framework creates parallel obligations that must be managed separately from EU GDPR compliance. Transfers of EEA user data to Ancestry's US entities must be covered by appropriate Chapter V transfer mechanisms (Standard Contractual Clauses or equivalent). (4) VENDOR AND CONTRACT IMPLICATIONS: Cross-border data flows between Ancestry Ireland UC and US entities must be governed by GDPR-compliant transfer mechanisms. Any processing by US-based service providers of EEA user data must be covered by Standard Contractual Clauses or equivalent instruments. (5) COMPLIANCE CONSIDERATIONS: Legal teams should confirm that Ancestry Ireland UC's role as EEA controller is operationally implemented (not just nominally designated), including that the Irish DPC has been appropriately notified and that records of processing activities under GDPR Article 30 are maintained. Transfer impact assessments for US data flows should be current.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable regulations

BIPA
Illinois, USA
CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
HIPAA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Ancestry Privacy Statement
Entity
Ancestry
Document last updated
May 5, 2026
Tracking information
First tracked
May 10, 2026
Last verified
May 10, 2026
Record ID
CA-P-009748
Document ID
CA-D-00224
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
6404a1de46dca19f4191a94a541520c718b42d6494fed8f445da90855dfa3641
Analysis generated
May 10, 2026 22:05 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Ancestry
Document: Ancestry Privacy Statement
Record ID: CA-P-009748
Captured: 2026-05-10 22:05:48 UTC
SHA-256: 6404a1de46dca19f…
URL: https://conductatlas.com/platform/ancestry/ancestry-privacy-statement/provision/CA-P-009748/gdpr-rights-for-eu-and-uk-users/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Low
Categories

Other risks in this policy

Related Analysis

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Ancestry's GDPR Rights for EU and UK Users clause do?

GDPR provides the strongest set of consumer data rights of any applicable framework in this policy. EU and UK users have enforceable rights including the right to erasure and data portability, backed by regulatory authority.

How does this clause affect you?

EU and UK users can exercise data subject rights directly with Ancestry and have the additional protection of being able to escalate complaints to their national data protection authority. The designated controllers for each region are identified, which is important for knowing who to contact with rights requests.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 295 platforms. See the full comparison.

Is ConductAtlas affiliated with Ancestry?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Ancestry.