A Different Category, Not Automatically a Data Broker
Genealogy and DNA testing services like Ancestry, MyHeritage, FamilySearch, and 23andMe operate differently from people-search sites like Spokeo or BeenVerified. You typically sign up directly and voluntarily submit information, sometimes including a DNA sample, rather than the company scraping public records without your knowledge the way a classic data broker does. That distinction matters for how you think about the privacy tradeoffs, and for what rights you actually have.
What Makes This Data Different (and More Sensitive)
Genetic data is fundamentally different from an address or phone number: it can’t be changed if it’s exposed, and it reveals information not just about you but about your relatives, including relatives who never consented to testing at all. A DNA match can identify a biological parent, a half-sibling, or even implicate a family member in a criminal investigation, all from a sample you submitted for entirely unrelated reasons like curiosity about your ancestry.
How These Companies Actually Use and Share Data
- Law enforcement access. Some genealogy databases (notably GEDmatch and FamilyTreeDNA, historically) have cooperated with law enforcement investigative genetic genealogy requests, using DNA matches to help identify suspects in cold cases through distant relatives. Policies on this vary by company and have shifted over time in response to public pressure; check each service’s current law enforcement matching policy directly if this concerns you.
- Third-party research partnerships. Some services partner with pharmaceutical or research companies (23andMe’s relationship with GSK is a well-known example) to use aggregated, often de-identified genetic data for drug research. This is usually opt-in and disclosed, but it’s worth actually reading the consent language rather than clicking through it.
- Data breaches. 23andMe experienced a significant data breach in 2023 that exposed account and some genetic ancestry data for millions of users, underscoring that even data you deliberately shared with a trusted company isn’t immune to exposure through a security incident.
- Standard data broker exposure still applies separately. Even if you’ve never used a genealogy site, public genealogy records (historical census data, obituaries, family trees built by relatives) can still feed into standard data broker profiles the same way property or voter records do.
What You Can Do to Manage the Risk
- Read the consent form for law enforcement matching and research sharing before you submit a sample, most services let you opt out of both while still using the core ancestry features.
- Delete your data if you no longer want it stored. Ancestry, 23andMe, and MyHeritage all offer account and data deletion options, though be aware that a physical DNA sample the company still holds (if you didn’t request its destruction separately) is a distinct thing from your digital profile.
- Consider what a relative’s test means for you. Even if you’ve never taken a DNA test yourself, a close relative’s test can reveal information about you through shared DNA matches, this isn’t something you can fully control, but it’s worth being aware of.
- Handle standard data broker exposure separately. Genealogy sites are a distinct privacy category from the people-search sites that expose your current address and phone number. See our comparison of Incogni, DeleteMe, Optery, and Aura for that separate, more common exposure.
The Bottom Line
Genealogy and DNA services aren’t data brokers in the classic sense, you opt in directly rather than being scraped without knowledge, but the data involved is uniquely sensitive and uniquely permanent. The right move isn’t necessarily avoiding these services, for many people the ancestry insight is worth it, but actually reading the consent terms around law enforcement access and research sharing before you submit a sample, since those are the parts most people skip.
Where Genealogy Sites Sit in the Law, and Why It Is Not Obvious
The distinction drawn above, that you opt in rather than being scraped, is also roughly the line California’s law draws. The Delete Act’s data broker definition turns on knowingly collecting and selling personal information about a consumer with whom the business does not have a direct relationship, which is why the state’s registry is populated by the people-search and marketing-data companies rather than by services you signed up for and pay.[1]
That difference changes how you get relief, and it cuts both ways. You will not reach a DNA testing service through California’s one-request deletion platform, because that platform routes to registered data brokers.[2] What you have instead is the CCPA’s general right to delete and right to opt out of the sale and sharing of your personal information, which you exercise directly with the company.[3] More work per company, but it applies to any covered business rather than only to registered brokers.
Deletion Here Has Three Separate Objects, and Most People Request One
This is the practical gap in the deletion advice above, and it is worth being explicit, because the three are handled by different mechanisms:
- Your account and digital profile, the family tree, the uploaded documents, the match list. This is the one an account deletion covers.
- Your processed genetic data, the file the company derived from your sample. Some services treat this as a distinct step, and some will let you download it before deletion.
- The physical sample itself, the biological specimen in storage. This is usually a separate destruction request, and it is the one most commonly missed, because nothing in the account interface implies it still exists.
Requesting only the first and assuming the other two followed is the most common mistake in this category. Ask for all three explicitly, in writing, and keep the confirmation.
The Relative Problem Has No Clean Solution, But It Has a Direction
The article notes that a relative’s test exposes information about you. The consequence is worth stating plainly: this is the one privacy decision on this site you cannot make unilaterally, because a cousin’s upload can place you in a match network you never joined. Deleting your own data does not remove you from someone else’s match list, since what identifies you there is their DNA, not your record.
What that leaves is narrow but not nothing. Where a service offers a setting for relative matching or law-enforcement matching, that setting governs your appearance in those systems and is worth setting deliberately rather than accepting a default. And if you are the one considering a test, the honest framing is that you are making a disclosure decision on behalf of siblings, parents, and children who have not been asked.
The Public-Web Layer Genealogy Creates
Family trees, obituaries, and historical records are frequently published openly, and that material behaves like ordinary web content rather than like a broker database. A public tree can carry a living person’s full name, birth year, and city, and no deletion request to a testing company touches it. Where such a page exposes a home address, phone number, or email, Google accepts removal requests for those results, and its “Results about you” tool can notify you when new ones appear.[4]
The step most people skip: search your own name alongside a parent’s or grandparent’s, which is how public tree pages actually surface, rather than searching your name alone.
The Bottom Line, Sharpened
Genealogy services are not data brokers in the legal sense, and the practical consequence is that the fast fix does not apply to them. Handle them as three deliberate requests to one company, handle the public tree and obituary layer as a search-results problem, and handle the people-search sites separately with the mechanisms built for them. Treating all three as one task is why this cleanup so often ends half-finished.
References
- Data Broker Registry. California Privacy Protection Agency
- Delete Request and Opt-out Platform (DROP). CalPrivacy, State of California
- California Consumer Privacy Act (CCPA). California Office of the Attorney General
- Remove my private info from Google Search. Google Search Help