Evidence: historical governance case. Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.
Case at a glance
- Case number
- 026
- Date / range
- Ongoing research program
- Sector
- Consent, ownership, and biospecimens
- Genetic asset
- Public genomic and phenotypic records
- Security principle
- Residual-Risk Transparency
Event summary
The Personal Genome Project treated re-identification as a foreseeable risk rather than promising anonymity it could not guarantee. Its open-consent model is a governance case about truthful risk disclosure, not a claim that privacy no longer matters.
Source: personalgenomes.org — Personal Genome Project Open Consent source 1.
Source: arxiv.org — Personal Genome Project Open Consent source 2.
The case in context
The Personal Genome Project takes a different approach to public-data risk: it does not depend on an absolute promise of anonymity. The governance question becomes whether participants understand what public release means and which consequences cannot be withdrawn later.
An explicit choice can still have limits. One participant cannot make every decision for relatives, and future analytical uses cannot all be predicted at enrollment. The case is useful for comparing transparent acceptance of residual risk with a reassuring but unsupported guarantee that removing a name makes a genome anonymous.
Acquisition and processing
voluntary enrollment → public genomic/phenotypic data → linkage to public records → possible identification → family and future-inference effects
The sequence of events
- voluntary enrollment
- public genomic/phenotypic data
- linkage to public records
- possible identification
- family and future-inference effects
What became inferable or exposed
Public genomic and phenotypic records
The Personal Genome Project treated re-identification as a foreseeable risk rather than promising anonymity it could not guarantee. Its open-consent model is a governance case about truthful risk disclosure, not a claim that privacy no longer matters.
Affected parties and consent
- Direct parties
- Voluntary research participants
- Indirect parties
- Relatives and connected participants may be relevant where the asset contains relationship information.
- Direct count
- Unknown / not assigned
- Indirect count
- Unknown / not assigned
- Consent status
- Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.
Security dimensions
Confidentiality
The confidentiality question concerns public genomic and phenotypic records. Exposure and further inference must be distinguished from the fact of collection or availability.
Integrity
The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Residual-Risk Transparency identifies the particular boundary examined here.
Availability
Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.
Provenance
The relevant chain follows public genomic and phenotypic records through the stages shown below. Missing public detail is not proof that internal records did not exist.
Consent, persistence, and relational exposure
Consent
Collection, custody, research purpose, transfer, withdrawal, and commercial use are separate permissions. The case concerns how those boundaries are interpreted or enforced.
Persistence
Later reuse depends on the actual asset and links to other records; no future misuse is asserted.
Relational exposure
Relatives and connected participants may be relevant where the asset contains relationship information.
Case-specific assessment
confidentiality intentionally low; integrity/provenance high; availability high; consent explicit; persistence critical; relational exposure significant.
GeneticSecurity.org analysis
Genetic Exposure Radius
No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Persistence Risk
Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Provenance Integrity
A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Proposed classification and its limits
Suggested GER: GER-2. Suggested GPR: GPR-5. Suggested GPI: GPI-4 for curated public records.
These are proposed classifications from the supplied case dossier. Conditional scores describe an assumed exposure; they are not evidence that it occurred. A single numeric value is left unassigned when the asset or outcome is not sufficiently bounded.
What this case does not prove
Open consent does not erase risk, authorize decisions for relatives, or resolve the ethics of every future use.
Mitigations and lessons
- Comprehension testing
- Staged consent
- Family-risk warnings
- Withdrawal limits stated up front
- Data-use transparency
- Ongoing participant communication
- Versioned consent text
Primary sources
Secondary sources
No additional source listed. See the evidence notes for limitations.
Policy and standards
Genetic Security Policy and StandardsReview and correction history
Source edition: September 19, 2026. Imported case account; no substantive corrections recorded.
Correction policy and logCite this case
GS-CASE-026. Open Consent: The Personal Genome Project's Honest Privacy Bargain. GeneticSecurity.org. https://geneticsecurity.org/cases/026-personal-genome-project-open-consent/