By: Mary Kate O’Connell
When the Golden State Killer was apprehended in 2018 after decades of killing, raping, and burglarizing Californians, genetic genealogy was heralded as the best new forensic method for solving cold cases. The identification of the Golden State Killer was in part due to the work of genealogist Barbara Rae-Venter, who uploaded crime scene evidence to GEDmatch, which allowed her to meticulously fill out branches of the Golden State Killer’s family tree using DNA that had been voluntary submitted to genetic testing companies such as Ancestry.com and 23andMe. Once Venter had traced the Golden State Killer back to common ancestors in GEDmatch, she scoured through social media and public records to narrow down the results. Since Venter’s identification of the Golden State Killer, more than fifty other “cold cases” have been solved using genetic genealogy.
Although the “pro” of public safety may outweigh the “con” of privacy infringement when it comes to forensic genealogy methods, increased regulation of genetic genealogy is needed to protect individual’s right to privacy under the Fourth Amendment of the U.S. Constitution. Currently, the main bodies of law protecting individuals from the exploitation of their genetic DNA include the U.S. Common Rule and the 21st Century Cures Act. The U.S. Common Rule requires participants in clinical research trials to be informed of how their data might be shared before they give consent. The 21st Century Cures Act restricts researchers from releasing any genetic data to law enforcement and makes such data inadmissible in court if it is unlawfully obtained or hacked. Both of these regulations, however, fail to address the lack of privacy protections for genetic data voluntarily submitted to companies such as Ancestry.com, 23andMe, and GEDMatch.
European Union’s General Data Protection Regulation (“GDPR”) may serve as a
good example of the privacy regulation needed in the United States to protect
individuals’ genetic data. Under the GDPR, genetic data is considered
personally identifying information (“PII”), and therefore the sharing or
transmission of such data requires strict adherence to informed consent and
those who exploit such data can be held liable for privacy violations. To move towards a privacy regulation such as
GDPR, the United States must first reclassify DNA as PII. Although it sounds
simple, such a reclassification is likely to be challenging to achieve as doing
so would create obstacles for law enforcement to perform routine detective work
involving DNA testing, which has proved to be the fastest and most effective
forensic method for investigating and solving a crime. Until DNA is reclassified as PII, individuals
should remain cognizant of the potential long-term ramifications of voluntarily
submitting their saliva to genetic testing companies and avoid submitting it if
they have a secret to hide.
 See Megan Molteni, What the Golden State Killer Tells Us About Forensic Genetics, Wired (Apr. 24, 2019, 4:00 am) https://www.wired.com/story/the-meteoric-rise-of-family-tree-forensics-to-fight-crimes/.
 See Heather Murphy, She Helped Crack the Golden State Killer Case. Here’s What She’s Going to Do Next, The New York Times (Aug. 29, 2018) https://www.nytimes.com/2018/08/29/science/barbara-rae-venter-gsk.html.
 See Molteni, supra note 1.
 See Megan Molteni, The Future of Crime-Fighting is Family Tree Forensics, Wired (Dec. 26, 2018, 8:00 am) https://www.wired.com/story/the-future-of-crime-fighting-is-family-tree-forensics/.
 See Megan Molteni, The US Urgently Needs New Genetic Privacy Laws, Wired (May 1, 2019, 8:00 am) https://www.wired.com/story/the-us-urgently-needs-new-genetic-privacy-laws/.
 See Ancestry, Your Privacy, https://www.ancestry.com/cs/legal/privacystatement (last updated Dec. 23, 2019); See also 23andMe, Privacy Highlights, https://www.23andme.com/about/privacy/ (last updated Jan. 1, 2020).
 See Cassie Martin, Why a warrant to search GEDmatch’s genetic data has sparked privacy concerns, ScienceNews (Nov. 12, 2019, 4:07 pm) https://www.wired.com/story/genome-hackers-show-no-ones-dna-is-anonymous-anymore/.
 See Id.
 See U.S. Const. amend. IV.
 See Protection of Human Subjects, 49 C.F.R. § 11.101 2018; See also 21st Century Cures Act, Pub.L. No. 114 – 255, § 2036 (2016).
 See Protection of Human Subjects, 49 C.F.R. § 11.101 2018.
 See 21st Century Cures Act, Pub.L. No. 114 – 255, § 2036 (2016).
 See Regulation 2016/679 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data, and Repealing Directive 95/46/EC, 2016 O.J. L 119.
 See Id.
 See Molteni, supra note 6.
 See Id.