uanome.

What happens to your DNA data if the testing company is sold?

Updated June 2026

Health data privacy

When you mail off a saliva tube, you're not just buying a report — you're handing a company a permanent copy of your genome. So a fair question follows: what happens to your DNA data if that company is later sold, merged, or goes bankrupt? Recent turmoil in the consumer genetics industry turned this from a hypothetical into a mainstream concern. Here's who can end up controlling uploaded genetic data, what rights you actually have, and how to lower your exposure — calmly and without the hype.

Here because of 23andMe? See the practical checklist — download, delete, and keep your DNA privately.

Why this question matters

DNA data is different from almost anything else you share online, and that difference is the whole reason this question deserves careful thought rather than panic.

First, it's permanent. A password can be reset and a compromised credit card can be cancelled. Your genome is fixed for life. If a copy ends up somewhere you didn't intend, there is no "rotate the key" fix.

Second, it's uniquely identifying and partly shared. Your genome doesn't only describe you — it overlaps meaningfully with your parents, siblings, and children, none of whom clicked "I agree." Decisions you make about your own genetic data quietly implicate relatives who were never part of the transaction.

Third — and this is easy to forget — consumer genetics companies are businesses. A business can be acquired, can merge, can change its leadership and its priorities, and can fail. When it does, the things it owns don't evaporate; they get handled according to contracts, corporate law, and sometimes a bankruptcy court. Your uploaded DNA is one of those things.

None of this means testing is unsafe or that you should regret an existing test. It simply means the reassurances you read at signup are promises made by an entity that may not look the same in five years. Understanding that upfront lets you make a deliberate choice instead of an accidental one.

What typically happens to data in an acquisition

When one company buys another, the target's assets generally transfer to the buyer — and a customer database is an asset. Most privacy policies say so explicitly, usually in a clause covering "mergers, acquisitions, or sale of assets." The practical effect is that your data can move to a new owner as part of a deal you had no direct involvement in.

The buyer typically inherits the existing privacy policy at the moment of transfer, which offers some continuity. But two caveats matter. A privacy policy is a living document: a new owner can revise it going forward, with notice, and permitted uses, research partnerships, and data-sharing terms can broaden over time. And the buyer may have a different business model, a different appetite for data monetization, or different security practices than the company you originally trusted.

So the protections you rely on are only as durable as the organization holding the data — and that organization can change without your genome ever leaving the server.

What can happen in a bankruptcy

Bankruptcy is where the "data is a business asset" principle becomes most visible. In an insolvency, a company's assets are marshalled and sold to pay creditors, and a large database of customer genetic information can be one of the most valuable things on the balance sheet. There is no automatic carve-out that makes genetic data immune from this process.

That doesn't mean a worst case is inevitable. Bankruptcy proceedings are supervised by courts, regulators and attorneys general can raise objections, and buyers often make public commitments about honoring existing privacy terms. The point is simply that the fate of uploaded genetic data in a bankruptcy can hinge on a courtroom and a list of bidders rather than on the promise you read at signup. The high-profile difficulties of major consumer DNA companies in recent years are what pushed this concern from niche to mainstream — and the general lesson holds regardless of how any single case turns out.

If you have data with a service that looks financially shaky, the timing of your action matters: a deletion request made while the company is stable is far cleaner than trying to claw data back mid-crisis or after a sale has closed. (None of this is legal advice — it's a general description of how these situations tend to unfold.)

What protections exist — and their limits

You are not powerless here. Depending on where you live and which service you used, you generally have meaningful rights and safeguards. But each one has edges worth knowing.

Taken together, these protections are real and worth using. They are not, however, a promise that a stored copy of your genome will remain under the same stewardship forever.

What you can do

You don't have to avoid learning from your DNA to keep it private. A few practical steps go a long way, and none of them require you to become a privacy expert.

  1. Understand the policy before you share. Read the transfer clause specifically — what happens in an acquisition or bankruptcy, and whether your data can be shared with research or commercial partners. Our health data privacy checklist walks through what to look for.
  2. Download your own raw data and keep it. Whatever happens to the company, you'll have your own copy under your control. See our guide on how to download your 23andMe raw data.
  3. Use your deletion rights. If you've extracted your raw file and no longer use the online reports, request account and sample deletion — ideally while the company is stable, not mid-crisis. Here's how to delete your 23andMe data step by step.
  4. Prefer providers and tools that don't retain — or that process locally. Many interpretation tools ask you to upload your raw file to their servers, which recreates the exact risk you're trying to avoid. Tools that analyze your DNA on your own device never put it on a server that can be sold or breached — our browser-based DNA explorer works this way. For the tradeoffs, see on-device vs cloud health data privacy.

The deeper principle: the safest data is data that was never uploaded

Every protection above — policies, consent, deletion, regional law — is a way of managing a copy of your genome that already lives on someone else's server. They're useful, but they all share the same underlying vulnerability: they depend on the ongoing good behavior and continued existence of the company holding the data, plus every future owner, contractor, and backup, and its security against breaches.

There is one category of risk that none of those safeguards can fully close, and one that sidesteps it entirely. Once a copy is uploaded, deletion reduces exposure going forward but can't guarantee that no copy ever propagated somewhere during the time it was stored. By contrast, data that was never uploaded in the first place simply isn't part of any acquisition, bankruptcy, or breach. There's nothing on a server to transfer, because there's no server copy at all.

That's the quiet advantage of on-device analysis. It isn't a stronger promise — it's a smaller attack surface.

How Quanome's on-device model sidesteps this

Quanome is built around exactly that principle. Your raw DNA file is parsed locally on your phone, and the interpretation happens on the device. Your genome is never uploaded to a Quanome server, which means there is no server-side copy to be sold in an acquisition, put in play in a bankruptcy, transferred to a new owner, or exposed in a data breach.

This doesn't make Quanome the only reasonable choice, and it doesn't erase every privacy consideration — no single tool does. But for this specific, permanent, and uniquely sensitive class of data, keeping the genome on your own device removes the whole "what happens when the company changes hands" question from the table. There's simply no uploaded genome to change hands.

The bottom line

A genetic database is a business asset, and business assets change hands — through acquisitions, restructurings, and bankruptcies. That's not a reason to fear DNA testing; it's a reason to be deliberate about where your genome ends up living. Knowing what typically happens to data when a company is sold — and that you can download your own copy, delete the uploaded one, use your legal rights, and choose tools that keep analysis on your device — puts the decision back where it belongs: with you.

Want to start by taking control of your file? Browse more guides on the Quanome blog.

Keep your DNA data on your own device, not someone else's server

Quanome reads your raw DNA file locally on your phone — it's never uploaded, so it can't be sold, breached, or transferred with a company. Learn more about Quanome →

Try the iOS beta →

Frequently asked questions

Can a genetic testing company sell my DNA data if it's acquired?

Customer genetic data is typically treated as a business asset, so it can transfer to a buyer in an acquisition or bankruptcy. The buyer generally inherits the existing privacy policy, but policies can be changed over time with notice.

What happens to my DNA data if the company goes bankrupt?

In an insolvency, a customer database can become an asset sold to satisfy creditors, and there is no special carve-out that automatically exempts genetic data. Deletion requests are strongest when made before any sale closes, so acting early matters.

Do I still own my DNA if I upload it to a service?

You don't lose ownership of your genome in the abstract, but the company holds a stored copy governed by its terms. Who effectively controls that copy can change if the company is acquired, restructured, or shut down.

Can I delete my DNA data before or after a company is sold?

Most major services let you request account and data deletion, and many also let you ask the lab to discard your saliva sample. Deletion is strongest before a sale, and some data may persist in backups or anonymized research sets.

What laws protect my genetic data?

Protections vary by region. In the US, GINA limits genetic discrimination in health insurance and employment, and several states have specific genetic-privacy laws. The EU's GDPR treats genetic data as a special category needing stronger safeguards. None of these guarantees your data can never change hands.

How do I reduce the risk of my DNA data being transferred?

Download and keep your own raw data file, then delete your uploaded copy if you no longer need it. For ongoing analysis, prefer tools that read your DNA on your own device instead of uploading it to a server.

Is on-device DNA analysis safer than uploading?

For this specific class of risk, yes. If your DNA is parsed on your phone and never uploaded, there's no server-side genome that could be sold, breached, or transferred when a company changes hands.

Does Quanome upload my DNA?

No. Quanome reads your raw DNA file locally on your device, so the interpretation happens without your genome leaving your phone. There's no copy on Quanome's servers to transfer in an acquisition.

The Quanome iOS beta is live

Make sense of your DNA and health data privately — try Quanome free on TestFlight now (Android coming later).

Try the iOS beta →

Free TestFlight beta for iPhone. Not on iOS? Leave your email and we'll keep you posted (and ping you when Android lands).