Evidence: well sourced. Source-led synthesis; classifications are GeneticSecurity.org analysis, not findings by the source.
Case at a glance
- Case number
- 006
- Date / range
- 2019 onward
- Sector
- Genetic genealogy
- Genetic asset
- Uploaded genotype kits and matching relationships
- Security principle
- Governance as a Security Control
Event summary
GEDmatch states that in May 2019 it began an opt-in policy concerning comparison with law-enforcement kits used to identify perpetrators of violent crimes. Current service documentation describes several privacy settings including Private, Personal Research, Opt-in, and Opt-out.
Acquisition and processing
Genetic matching controlled by service rules and kit-level choices
What became inferable or exposed
Uploaded genotype kits and matching relationships
Genetic exposure is affected not only by encryption or account security but by platform policy, matching rules, consent defaults, and who is allowed to query a genetic database.
Affected parties and consent
- Direct parties
- People whose kits are compared under platform settings
- Indirect parties
- Relatives whose relationships become inferable
- Direct count
- Unknown / not assigned
- Indirect count
- Unknown / not assigned
- Consent status
- Settings govern comparisons; relatives may not themselves be users
Security dimensions
Confidentiality
Scope assessed from the specific asset and access described; no broader raw-genome disclosure inferred.
Integrity
No demonstrated data alteration established by the cited material.
Availability
No outage or destruction established in this case.
Provenance
Complete custody and processing evidence is unavailable; no numeric GPI rating assigned.
A setting is a rule about a particular action
Privacy settings are easiest to understand when connected to a concrete comparison. Which kit may be compared with which other kit, for what purpose, under which version of the service's rules? A broad label such as “private” can obscure those questions if the reader assumes it covers every possible action.
The case therefore treats platform documentation as a source that must be dated and read in context. A statement about an earlier policy cannot automatically establish how a current setting works. Likewise, an explanation of one kind of law-enforcement comparison should not be extended to every investigative or identification use.
Participation and family exposure are different
A user's decision can change how their uploaded information is used within a service. It cannot make that person the decision-maker for every genetic relative. The proposed exposure radius reflects this relational feature, while the consent discussion asks whose choices are actually represented.
This does not mean settings are ineffective. They can establish meaningful boundaries on permitted comparisons. The limitation is that a service-level control should be described according to what it governs, without promising that it retracts information already obtained elsewhere or resolves every question about relatives.
What to record in a review
For a hypothetical audit, preserve the policy date, the relevant setting, the described comparison purpose, and the account or kit to which the setting applies. Then distinguish the documented rule from evidence about its implementation. If the review examines deletion, state which stored items and future actions the documentation addresses.
A clear record is more useful than a general verdict that a database is either safe or unsafe. It allows readers to see which decision changes exposure and what the available evidence leaves unanswered.
GeneticSecurity.org analysis
Genetic Exposure Radius
Analysis: Relatives whose relationships become inferable. The rating describes possible scope, not harm or a count of affected people.
Confidence: moderate. Classification: GeneticSecurity.org analysis.
Genetic Persistence Risk
The described profile can remain useful for identification or comparison; retention and future linkability remain uncertain.
Confidence: low. Classification: GeneticSecurity.org analysis.
Genetic Provenance Integrity
Not assessed: the public sources do not establish enough of the complete biological and digital chain to score it. Unknown is not proof of missing controls.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
What this case does not prove
A privacy setting does not erase copies already obtained or constitute consent from every genetic relative.
Mitigations and lessons
Record the applicable policy version and selected settings; distinguish perpetrator searches from unidentified remains; reassess policies over time.
Primary sources
- PRIMARY SOURCE GEDmatch privacy and security documentation
Secondary sources
No additional source listed. See the evidence notes for limitations.
Policy and standards
Genetic Security Policy and StandardsReview and correction history
Last reviewed: September 19, 2026. Initial source synthesis; no substantive corrections recorded.
Correction policy and logCite this case
GS-CASE-006. GEDmatch: How Database Policy Changes Alter Genetic Exposure. GeneticSecurity.org. https://geneticsecurity.org/cases/006-gedmatch-law-enforcement-governance/