Call & Times

Genetic testing firms set guidelines of privacy, work with police

- By TONY ROMM and DREW HARWELL

Ancestry, 23andMe and other popular companies that offer genetic testing pledged on Tuesday to be upfront when they share users’ DNA data with researcher­s, hand it over to police or transfer it to other companies, a move aimed at addressing consumers’ mounting privacy concerns.

Under the new guidelines, the companies said they would obtain consumers’ “separate express consent” before turning over their individual genetic informatio­n to businesses and other third parties, including insurers. They also said they would disclose the number of law-enforcemen­t requests they receive each year.

The new commitment­s come roughly three months after local investigat­ors used a DNA-comparison service to track down a man police believed to be the Golden State Killer, who allegedly raped and killed dozens of women in California in the 1970s and 1980s. Investigat­ors identified the suspect using a decades-old DNA sample obtained from the crime scene, which they uploaded to GEDmatch, a crowdsourc­ed database of roughly a million distinct DNA sets shared by volunteers.

Investigat­ors said they did not need a court order before using GEDmatch, sparking fresh fears that users’ biological data might be too easy to access – and could end up in the wrong hands – without additional regulation on the fast-growing, already popular industry.

Yet adherence to the rules is voluntary. While the policy offers users of participat­ing sites added new protection­s at a time of great “uncertaint­y,” it doesn’t have the force of law, said Justin Brookman, the director of consumer privacy and technology policy at Consumers Union.

“In general, I think there should be stronger transparen­cy requiremen­ts and legally binding rules for everyone around the transfer and use of super sensitive data like this,” he said.

Jules Polonetsky, the leader of the Future of Privacy Forum, a Washington D.C.-based nonprofit that helped companies draft the new privacy guidelines, said that his organizati­on’s work began months before the Golden State Killer incident. But he said hopes the blueprint can serve as a “first effort at showing the sector what the right way to handle some of these challenges is.”

“I don’t think the average consumer has wrapped their head around the range of issues they should think about when they make a decision to share [DNA] data,” Polonetsky added.

Consumer DNA testing services have surged in popularity in recent years: One report from research firm Kalorama Informatio­n estimates that the market could triple in value from $99 million to $310 million by 2022.

The growth has been spurred on by the federal government, which recently opened the door for 23andMe to sell consumers genetic tests that could be used to inform them of their likely risk for contractin­g certain diseases. And the industry has been supercharg­ed with fresh investment amid heightened interest from academics and drugmakers who hope to tap DNA databases in search of new health insights and cures.

Last week, 23andMe announced it had struck a research deal with GlaxoSmith­Kline, which would see the pharmaceut­ical giant invest $300 million in the genomics company. As part of that pact, GlaxoSmith­Kline can access “de-identified” genetic data about 23andMe users – provided they’ve previously given their consent – so that the firm can “gather insights and discover novel drug targets driving disease progressio­n,” the company said.

Under the “best practices” adopted by 23andMe and its peers, such sharing is permitted. GlaxoSmith­Kline is “not getting any direct access or receiving any sort of individual customer informatio­n,” said Kate Black, the global privacy officer for 23andMe, just insights about broad chunks of users and their medical traits. The DNA test- ing company also said it previously had asked users’ permission to participat­e in research, and it estimates 80 percent of its users agree to take part in such studies.

Other companies – Helix, MyHeritage, Habit, African Ancestry and FamilyTree­DNA – pledged Tuesday to adopt a similar approach, the Future of Privacy Forum said. When it comes to health research, they said they would explain the “risks, benefits and purpose of the research” to consumers, while providing easy-to-read privacy policies, according to the new guidelines.

Customers of these DNA testing services would gain some limited rights to have their biological data deleted, but they may not be able to withdraw data that was already in use by researcher­s. Companies, meanwhile, would have to ensure the person submitting DNA data is the actual owner of that data.

“Because privacy is such a hot topic, and consumers are concerned about privacy, this is the equivalent of peer pressure,” said Elissa Levin, who leads policy and clinical services at Helix, a company that connects consumers with apps that analyze genome data. “I think it’ll really be an opportunit­y to start to have true clarity and transparen­cy between the good players and the not-so-good players.”

Yet users still may not know everything. Under the industry-made rules, DNA testing services don’t have to tell their consumers every time their data has been stripped of their identity, combined with others’ genetic informatio­n, combed for insights, then turned into statistics, and perhaps shared with a third party for further analysis.

And while companies have said they’ll report each year on the law-enforcemen­t requests they receive, users might not learn about the legal demands if investigat­ors obtain gag orders. Companies like Ancestry and 23andMe have committed to “attempt to notify” their customers about such requests whenever they can. Moreover, the tool tapped by investigat­ors in the Golden State Killer case, GEDmatch, is an open-source database that isn’t covered by the industry’s new best practices.

Those that promise to protect consumers’ sensitive personal data – then fail to adhere to those promises – could invite penalties from the Federal Trade Commission.

“The FTC remains vigilant in protecting consumers’ privacy and security. If companies fail to keep their promises to consumers – whether they made those promises in website privacy policies or by signing onto industry best practices – they could be subject to FTC law enforcemen­t action,” said spokeswoma­n Juliana Gruenwald Henderson.

A few companies already adhere to some of the new industry-made rules. Ancestry and 23andMe, for example, currently report to users the law enforcemen­t requests they receive. In 2017, Ancestry received 34 valid law enforcemen­t requests – all related to credit card or identity theft – and provided data in 31 cases. At 23andMe, the company received five requests this year but turned over user data on none of them.

 ?? Anthony Kwan/Bloomberg ?? An automatic nucleic acids extraction machine used in examining DNA.
Anthony Kwan/Bloomberg An automatic nucleic acids extraction machine used in examining DNA.

Newspapers in English

Newspapers from United States