Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement states that Ancestry retains DNA Data and Genetic Information indefinitely until a user actively deletes their DNA test results or closes their account, with no automatic expiration.
This analysis describes what Ancestry's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes an indefinite retention period for one of the most sensitive categories of personal data Ancestry processes, conditioned solely on user-initiated deletion action, which may require evaluation under GDPR Article 5(1)(e) storage limitation and data minimization principles and under applicable U.S. state genetic privacy statutes.
The updated Privacy Statement no longer displays a dedicated 'Do Not Sell or Share My Personal Information' link in the footer, which was previously accessible to California residents under CCPA requirements. This link allowed users to exercise data-sharing opt-out rights. The footer now lists 'Consumer Health Privacy' as a separate item but does not explicitly direct users to their CCPA controls. California residents may need to locate their opt-out rights through alternative navigation paths on the Ancestry site.
View change record →The updated privacy policy removes the 'Do Not Sell or Share My Personal Information' link from the footer navigation. This link previously provided direct access to Ancestry's data-sharing opt-out mechanism, which is a required disclosure under California's CCPA. While the removal does not eliminate the opt-out right itself, it may make the opt-out control less easily discoverable from the privacy policy page. Affected users may need to locate the opt-out mechanism through alternate navigation or search methods.
View change record →The updated Privacy Statement clarifies what uses of Ancestry services are permitted and prohibited, establishes that photo face-grouping in your gallery requires your express consent, and introduces SMS messaging as a communication channel for future opt-in communications. The statement now covers Ancestry, AncestryDNA, and Related Brands under a unified framework while noting that other services operated by the company use separate privacy statements. The removal of 'uploaded DNA data' from the account creation section reflects a narrowing of that specific provision's scope, though genetic information processing remains described elsewhere in the policy. You can review the full updated statement to understand how your personal information will be processed and manage your communication preferences when SMS opt-ins become available.
View change record →Under this clause, Ancestry retains DNA Data and all derived Genetic Information, including ethnicity estimates, DNA matches, and trait insights, for as long as the account remains active or until the user specifically requests deletion of DNA test results or closes the account.
Cross-platform context
See how other platforms handle DNA Data and Genetic Information Retention and similar clauses.
Compare across platforms →Monitoring
Ancestry has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Ancestry retains your DNA Data to provide you with the features and functionality you purchase (or are gifted), including continuously updated features, increasingly granular ethnicity estimates and improved ancestral regions and ancestral journeys, as well as other new features based on your DNA Data. Your DNA Data is kept until you delete your DNA test results or your account.Excerpt from Ancestry's Privacy Statement
REGULATORY LANDSCAPE: This provision implicates GDPR Article 5(1)(e) (storage limitation) and Article 5(1)(c) (data minimization), enforced by the Irish Data Protection Commission as lead supervisory authority. It also engages Washington's My Health MY Data Act, Illinois GIPA, and analogous state genetic privacy statutes, as well as CCPA and CPRA provisions relating to retention period disclosure. The FTC may also have jurisdiction over unfair or deceptive practices related to data retention representations. GOVERNANCE EXPOSURE: High. Indefinite retention of genetic data contingent solely on user action creates ongoing exposure under GDPR's storage limitation principle. Regulators in the EU have issued guidance requiring that retention periods be defined by purpose, not by user inaction, and the absence of a defined maximum retention period may be scrutinized. JURISDICTION FLAGS: EU and UK users face the highest exposure given GDPR and UK GDPR storage limitation requirements. California users have CCPA rights to request deletion. Washington state users may have additional protections under the My Health MY Data Act. Illinois and Texas genetic privacy statutes may impose independent requirements. CONTRACT AND VENDOR IMPLICATIONS: Organizations that are Ancestry corporate customers or research partners should note that the retention framework governs data that may be shared with them under the Informed Consent to Research arrangement. The laboratory partner retention carve-out under CLIA creates a parallel retention obligation that is not within Ancestry's direct control. COMPLIANCE CONSIDERATIONS: Legal teams should assess whether the retention policy as stated satisfies GDPR Article 13/14 transparency requirements regarding retention periods, and whether a defined maximum retention period tied to specific purposes should be established. Consent mechanism audits should confirm that users are clearly informed of retention duration at point of collection.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes an indefinite retention period for one of the most sensitive categories of personal data Ancestry processes, conditioned solely on user-initiated deletion action, which may require evaluation under GDPR Article 5(1)(e) storage limitation and data minimization principles and under applicable U.S. state genetic privacy statutes.
Under this clause, Ancestry retains DNA Data and all derived Genetic Information, including ethnicity estimates, DNA matches, and trait insights, for as long as the account remains active or until the user specifically requests deletion of DNA test results or closes the account.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Ancestry.