Can Police Access Your 23andMe Data? The Legal Mechanism Behind Genetic Privacy

Your spit goes into a tube. The tube goes to a lab. The lab sequences your DNA, builds your ancestry profile, and stores the data on 23andMe's servers. Then what? Can police walk in and demand access? Do they need a warrant? What about your relatives, can their DNA expose you?
The answer depends on which database holds your data, what legal process police use, and whether you or your family uploaded genetic information to public platforms. The mechanism isn't simple, and the privacy protections aren't uniform across services.
The Legal Framework: Warrants, Subpoenas, and Terms of Service
Police can't browse 23andMe's database on a whim. The company's terms of service outline a specific legal process for law enforcement requests. 23andMe requires a valid court order, search warrant, or subpoena before disclosing user data. Administrative subpoenas, the kind issued by agencies without judicial oversight, don't suffice for genetic information.
When police seek genetic data, they typically follow one of three paths. First, they can obtain a warrant based on probable cause that specific genetic data is evidence of a crime. Second, they can request data through a subpoena if the information is relevant to an ongoing investigation and a judge approves. Third, they can ask the user for consent, bypassing legal process entirely. Most people don't consent, so police rely on warrants.
The Fourth Amendment protects against unreasonable searches, but courts have ruled that data held by third parties, like 23andMe, receives less constitutional protection than data you keep in your home. The third-party doctrine, established in cases like Smith v. Maryland, holds that you lose some privacy expectations when you voluntarily share information with companies. Genetic data falls into this category once you mail that tube.
23andMe publishes a transparency report showing how many law enforcement requests they receive and how often they comply. In recent years, the company reports receiving fewer than 10 requests annually for genetic data, and they've rejected most for insufficient legal basis. That doesn't mean police aren't interested, it means they're using other methods.
The GEDmatch Loophole: Public Databases Change Everything
23andMe requires warrants. GEDmatch doesn't. GEDmatch is a public genealogy database where users upload DNA data from testing services like 23andMe, AncestryDNA, or MyHeritage to search for relatives. Anyone can create an account, upload a genetic profile, and search for matches. That includes police.
Law enforcement discovered GEDmatch's investigative potential in 2018 when investigators used the platform to identify the Golden State Killer. They uploaded crime scene DNA to GEDmatch, found distant relatives, and used genealogical research to narrow suspects. The technique, called genetic genealogy or familial searching, has since solved hundreds of cold cases.
GEDmatch initially operated as an open platform where all uploaded profiles were searchable by anyone. After the Golden State Killer case drew attention, the company changed its terms of service to make profiles private by default, requiring users to opt in to law enforcement searches. But many users uploaded data before the change, and thousands have opted in since. Police continue using the platform.
The legal mechanism here is straightforward: GEDmatch is a public database. Users voluntarily upload their DNA. Police don't need warrants to search public records. Courts have consistently held that people have no reasonable expectation of privacy in information they share publicly, even if they didn't anticipate law enforcement use.
Other public databases exist. FamilyTreeDNA allows law enforcement searches with user consent. DNA.land, a research-focused platform, has cooperated with investigators. If your genetic data lives on any public platform, police can access it without asking you.
Familial Searching: How Your Relatives Expose You
You never took a DNA test. Your cousin did. Police can still identify you.
Familial searching works by comparing crime scene DNA to genetic databases, looking for partial matches that indicate a family relationship. If your cousin uploaded DNA to GEDmatch and police have DNA from a crime scene, algorithms can flag your cousin as a potential relative of the suspect. Investigators then build family trees, identify possible matches, and narrow the suspect pool through traditional detective work.
The genetic connection doesn't prove guilt, it creates a lead. Police still need evidence linking you to the crime. But the initial identification happens because your relative shared genetic material you both inherited from common ancestors.
This technique has limitations. It works best with close relatives, siblings, parents, children, first cousins. More distant relationships produce weaker matches that require more genealogical research to trace. The method also depends on database size. Larger databases increase the odds of finding a familial match. GEDmatch holds around 1.5 million profiles. Combined with other public databases, researchers estimate that police can identify roughly 60% of Americans of European descent through familial searching, even if those individuals never took a DNA test themselves.
The legal framework varies by jurisdiction. Some states restrict familial searching in government-run DNA databases, requiring specific legislative authorization. But those restrictions don't apply to private databases like GEDmatch. Police use whatever tools are available, and public genetic databases remain largely unregulated.
What 23andMe Actually Hands Over When Police Come Knocking
When police present a valid warrant to 23andMe, what do they get? The company's law enforcement guide specifies the types of data they can disclose: genetic information, ancestry composition, DNA relatives (if the user opted in to that feature), account registration details, and communication records.
Genetic information includes raw DNA data, the specific genetic markers sequenced from your sample. This data can be compared to crime scene DNA or used to identify familial relationships. Ancestry composition shows your ethnic background and geographic origins, which might help narrow suspect pools in some investigations. DNA relatives reveals other 23andMe users you're genetically related to, if you enabled that feature.
Account details include your name, email address, billing information, and IP addresses used to access the account. Communication records might include messages exchanged through 23andMe's platform or customer service interactions. Police can use this metadata to trace account activity, identify associates, or establish timelines.
23andMe claims to notify users when they receive law enforcement requests, unless a court order specifically prohibits disclosure. Gag orders are common in national security investigations and some criminal cases, so you might never know your data was accessed. The transparency report shows notification rates, but it's not comprehensive.
The data 23andMe hands over is limited to what police request in the warrant. A narrow warrant seeking only genetic data won't include billing information unless investigators specifically ask for it. But warrants can be broad, and judges often approve expansive requests if prosecutors argue investigative necessity.
The Ancestry.com and MyHeritage Comparison: Different Companies, Different Policies
23andMe isn't the only genetic testing company, and policies vary. AncestryDNA, owned by Ancestry.com, follows a similar legal process, requiring warrants or court orders for genetic data disclosure. Their transparency report shows they receive more law enforcement requests than 23andMe, around 30 annually in recent years, and comply with roughly half after legal review.
MyHeritage, an Israel-based company, operates under different legal jurisdictions. They comply with valid legal requests from law enforcement in countries where they operate, but the specifics depend on local laws. International requests require cooperation between governments, adding procedural complexity that sometimes delays or prevents disclosure.
The key difference across companies is their relationship with public databases. 23andMe and AncestryDNA keep user data in proprietary databases that require legal process for police access. But if users export their raw DNA data and upload it to GEDmatch or FamilyTreeDNA, that data becomes accessible to law enforcement without warrants. The companies themselves don't control what happens to exported data.
This creates a privacy paradox. You can take a DNA test with a company that has strong legal protections, then voluntarily upload your data to a public platform that has none. Many users do this to access more genealogical tools or find additional relatives. Each upload expands police access.
The Fourth Amendment Question: Do You Have a Privacy Right in Your DNA?
Courts are still working this out. The Supreme Court hasn't directly ruled on whether genetic data held by private companies receives Fourth Amendment protection. Lower courts have issued conflicting opinions, and the legal landscape remains unsettled.
Some courts have held that voluntarily sharing DNA with a testing company constitutes a waiver of privacy expectations under the third-party doctrine. You chose to send your spit to 23andMe, knowing they would analyze and store it. That voluntary disclosure, these courts argue, eliminates Fourth Amendment protections.
Other courts have recognized genetic data as uniquely sensitive, deserving stronger protections than credit card records or phone metadata. Genetic information reveals health conditions, ancestry, familial relationships, and traits you might not want disclosed. Some judges have required warrants even when the third-party doctrine might otherwise apply, citing the sensitive nature of genetic data.
The Supreme Court's decision in Carpenter v. United States (2018) provides some guidance. That case held that police need warrants to access cell phone location data, even though phone companies collect and store the information. The Court recognized that modern technology creates new privacy concerns that the third-party doctrine doesn't adequately address. Some legal scholars argue Carpenter should extend to genetic data, but no appellate court has definitively applied it yet.
State laws add another layer. California's Genetic Information Privacy Act requires consumer consent before sharing genetic data with third parties, including law enforcement, except when police have a warrant. Montana, Alaska, and Maryland have similar statutes. But most states lack specific genetic privacy laws, leaving the issue to federal constitutional interpretation.
The Practical Reality: What You Can Actually Control
You can't stop police from obtaining a warrant if they have probable cause. You can't prevent your relatives from uploading DNA to public databases. But you can make informed decisions about whether to take a DNA test at all, and what to do with the data if you do.
If genetic privacy matters to you, don't upload DNA to public databases. Use 23andMe's privacy settings to opt out of DNA relatives features, which limits familial matching within the platform. Don't share raw DNA data files with third parties. Don't post genetic information on social media or genealogy forums.
If you've already taken a test and uploaded data to GEDmatch or similar platforms, you can delete your profile. GEDmatch allows users to remove their data, though the company's privacy policy notes that data shared with law enforcement before deletion remains in investigative files. Deletion prevents future searches, but it doesn't erase past disclosures.
Consider whether the benefits of genetic testing outweigh the privacy tradeoffs. Ancestry information, health risk reports, and relative matching provide value to millions of users. But those benefits come with permanent privacy costs. Once your DNA is sequenced and stored, you can't fully un-share it. Companies can be breached, acquired, or subpoenaed. Data exported to public databases becomes permanently accessible.
Some people use pseudonyms when registering for DNA tests, hoping to obscure their identity. This provides minimal protection. Your genetic data itself is identifying, police can match it to crime scene DNA or use familial searching regardless of the name on the account. Billing information, shipping addresses, and IP addresses also link accounts to real identities.
The Breach Risk: What Happens When Genetic Databases Get Hacked
23andMe disclosed a breach in 2023 affecting roughly 7 million users. Attackers used credential stuffing, automated login attempts using passwords stolen from other breaches, to access accounts. Once inside, they scraped DNA relatives data and ancestry information, then posted it for sale on hacking forums.
The breach exposed the risk of storing genetic data online. Unlike passwords, you can't change your DNA if it leaks. Once genetic information is public, it stays public. Attackers can use it for identity theft, insurance discrimination, or blackmail. Law enforcement can use it for investigations, whether or not you're a suspect.
23andMe responded by requiring two-factor authentication for all accounts and resetting passwords for affected users. But the stolen data remains in circulation. Other genetic testing companies face similar risks. Any database holding millions of genetic profiles becomes a target.
Breaches don't just expose individual users. They expose relatives who never took DNA tests. If your genetic data leaks and someone uses familial searching to identify your siblings, parents, or cousins, their privacy is compromised too. The interconnected nature of genetic information means one person's breach can cascade across families.
The Ethical Debate: Should Police Use Genetic Genealogy?
Law enforcement argues that genetic genealogy solves violent crimes that would otherwise remain unsolved. The Golden State Killer case is the most prominent example, a serial rapist and murderer who evaded capture for decades until genetic genealogy identified him. Hundreds of other cold cases, including murders and sexual assaults, have been solved using similar techniques.
Privacy advocates counter that genetic genealogy creates a de facto universal DNA database without consent or oversight. When police can identify anyone through their relatives' DNA, everyone becomes subject to genetic surveillance, whether or not they've committed crimes. This shifts the burden of privacy loss onto innocent people who never agreed to participate in law enforcement investigations.
The debate touches on consent, proportionality, and the balance between public safety and individual rights. Some argue that solving violent crimes justifies the privacy intrusion, especially when victims and their families have waited years for justice. Others argue that the ends don't justify the means, that genetic surveillance represents a fundamental shift in the relationship between citizens and the state, one that should require explicit democratic authorization rather than emerging through ad hoc police practices.
Several states have begun regulating genetic genealogy. Maryland requires judicial authorization before police can use familial searching in state DNA databases. California restricts law enforcement use of consumer genetic data except with warrants. But these laws apply only to state-run databases and in-state companies. They don't govern GEDmatch, which operates as a private entity accessible to police nationwide.
The International Dimension: Cross-Border Genetic Data Requests
Genetic testing companies operate globally, but legal protections vary by country. If you're a U.S. citizen and your DNA is stored on servers in Ireland (where 23andMe maintains European data), can U.S. police access it? What if you're European and your data is stored in the U.S.?
The answer depends on mutual legal assistance treaties (MLATs) and data protection laws like the EU's General Data Protection Regulation (GDPR). GDPR restricts data transfers to countries without adequate privacy protections, but law enforcement requests often create exceptions. Companies must comply with valid legal process in the jurisdictions where they operate, even if that conflicts with user expectations.
23andMe stores European user data separately and applies GDPR protections, which generally require higher legal standards for data disclosure than U.S. law. But if U.S. police obtain a warrant and the data is relevant to a U.S. investigation, the company may still comply, depending on the specifics of the request and applicable treaties.
International genetic databases complicate this further. If you upload DNA to a platform based in one country, accessible to users in another, and police from a third country request access, which legal framework applies? The question remains largely unresolved, and companies make case-by-case decisions based on legal advice and risk assessments.
The Expungement Question: Can You Delete Genetic Data After Police Access It?
If police obtain your genetic data through a warrant, can you force them to delete it after the investigation concludes? Generally, no. Once law enforcement lawfully acquires evidence, they can retain it indefinitely, subject to agency retention policies and applicable statutes of limitations.
Some jurisdictions require destruction of DNA samples after analysis, but they don't require deletion of the genetic profile data derived from those samples. The data itself, the sequence of genetic markers, remains in investigative files and databases. If you're arrested and later exonerated, you can petition for expungement of DNA records in some states, but the process varies and isn't guaranteed.
This creates a permanent record problem. Your genetic data, once accessed by police, becomes part of the investigative record. It can be compared against future crime scene DNA. It can be used in unrelated investigations if police believe it's relevant. Deletion rights are limited, and enforcement is difficult.
The Bottom Line: Genetic Privacy Is a Permanent Tradeoff
Here's the reality: genetic testing companies require warrants for police access, but public databases don't. Your relatives' DNA can identify you even if you never took a test. Once your genetic data exists in a database, private or public, you can't fully control who accesses it or how it's used. Breaches, acquisitions, legal changes, and familial searching all create pathways for disclosure you didn't anticipate when you spit in that tube.
If genetic privacy matters to you, the safest choice is not to take a DNA test. If you've already tested, don't upload data to public platforms, use privacy settings to limit sharing, and understand that the data exists permanently. If your relatives have tested or uploaded DNA publicly, you're exposed through familial searching whether you participate or not.
The legal framework is evolving. Courts are grappling with Fourth Amendment questions. States are passing genetic privacy laws. But the technology has outpaced regulation, and police are using tools that exist now, under rules that were written for a different era. The mechanism behind genetic data access isn't simple, and the privacy protections aren't strong enough to guarantee control. That's the tradeoff you accept when you mail your spit to a lab.



