Evidence: well sourced. Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.
Case at a glance
- Case number
- 030
- Date / range
- 2019 onward
- Sector
- Consumer genetics and commercial data
- Genetic asset
- Consumer genealogy profiles and matching access
- Security principle
- Material Policy Change
Event summary
FamilyTreeDNA's 2019 disclosure that it was cooperating with FBI investigations showed how a consumer genealogy service's matching policy can materially change the exposure of existing customers and their relatives.
Source: familytreedna.com — FamilyTreeDNA And FBI Matching source 1.
The case in context
FamilyTreeDNA's law-enforcement cooperation raised questions about how an established consumer relationship changes when a new kind of matching becomes possible. The historical disclosure, later policy changes, and current service rules are different time periods and should not be collapsed into one account.
Matching access is also different from receiving raw files or exporting an entire database. The relevant permission needs to be named. The governance lesson is that meaningful notice should explain the new action, who can perform it, and how a user's choices affect future comparisons.
Acquisition and processing
consumer uploads → policy/terms change → law-enforcement kits → relative matches → genealogical narrowing
The sequence of events
- consumer uploads
- policy/terms change
- law-enforcement kits
- relative matches
- genealogical narrowing
What became inferable or exposed
Consumer genealogy profiles and matching access
FamilyTreeDNA's 2019 disclosure that it was cooperating with FBI investigations showed how a consumer genealogy service's matching policy can materially change the exposure of existing customers and their relatives.
Affected parties and consent
- Direct parties
- FamilyTreeDNA customers and matching participants
- Indirect parties
- Relatives and connected participants may be relevant where the asset contains relationship information.
- Direct count
- Unknown / not assigned
- Indirect count
- Unknown / not assigned
- Consent status
- The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.
Security dimensions
Confidentiality
The confidentiality question concerns consumer genealogy profiles and matching access. Exposure and further inference must be distinguished from the fact of collection or availability.
Integrity
The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Material Policy Change identifies the particular boundary examined here.
Availability
Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.
Provenance
The relevant chain follows consumer genealogy profiles and matching access through the stages shown below. Missing public detail is not proof that internal records did not exist.
Consent, persistence, and relational exposure
Consent
The relevant boundary is the consumer permission or representation attached to storage, sharing, and later use. Unauthorized access is not authorized by ordinary participation in a service.
Persistence
Later reuse depends on the actual asset and links to other records; no future misuse is asserted.
Relational exposure
Relatives and connected participants may be relevant where the asset contains relationship information.
Case-specific assessment
confidentiality high; integrity low; consent critical; persistence high; relational exposure high.
GeneticSecurity.org analysis
Genetic Exposure Radius
No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Persistence Risk
Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Provenance Integrity
A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Proposed classification and its limits
Suggested GER: GER-3. Suggested GPR: GPR-4/5. Suggested GPI: GPI-3 for documented matching operations.
These are proposed classifications from the supplied case dossier. Conditional scores describe an assumed exposure; they are not evidence that it occurred. A single numeric value is left unassigned when the asset or outcome is not sufficiently bounded.
What this case does not prove
Matching access does not establish that investigators received unrestricted raw-genome access or a bulk database export.
Mitigations and lessons
- Prospective opt-in
- Conspicuous notice
- Narrow crime criteria
- Legal-process verification
- Public transparency reports
- User-visible audit history
- Deletion/withdrawal mechanisms
Primary sources
- PRIMARY SOURCE familytreedna.com — FamilyTreeDNA And FBI Matching source 1
Secondary sources
- SECONDARY SOURCE fpf.org — FamilyTreeDNA And FBI Matching source 2
Policy and standards
Genetic Security Policy and StandardsReview and correction history
Source edition: September 19, 2026. Imported case account; no substantive corrections recorded.
Correction policy and logCite this case
GS-CASE-030. FamilyTreeDNA: When a Consumer Database Opened a Law-Enforcement Door. GeneticSecurity.org. https://geneticsecurity.org/cases/030-familytreedna-fbi-matching-policy/