HomeDirect-to-Consumer Genomics TestingDTC Genomics Regulatory Oversight Comparison (US/EU)

🧬 DTC Genomics Regulatory Oversight Comparison (US/EU)

This simulation compares the regulatory oversight of direct-to-consumer DNA testing in the United States and the European Union, highlighting key differences in legal frameworks, compliance requirements, and consumer protections.

Direct-to-Consumer Genomics Testing2DModerate60 FPS
dtc-genomics-regulatory-comparison ↗ Open standalone

A $1 Billion-Plus Industry Built Ahead of Its Regulators

Direct-to-consumer (DTC) genetic testing grew from a $70 saliva-kit novelty in 2007 into a global industry spanning ancestry, health-risk, and wellness testing — reaching tens of millions of consumers before either the United States or the European Union had a settled regulatory answer for what these tests actually are: medical devices, consumer products, or something in between.

  • >14M: 23andMe kits sold (cumulative) (as of company filings, 2023)
  • >23M: AncestryDNA database size (consumer DNA profiles)
  • 2006 / 2021: 23andMe founded / IPO(SPAC) (first DTC genomics unicorn)
  • Nov 22, 2013: FDA 2013 warning letter (halted health-risk marketing)

From novelty to medical-grade claims

23andMe launched in 2007 selling ancestry composition and raw genotype data for recreational use. By 2013 it was marketing "Health Reports" estimating risk for conditions including breast cancer, Parkinson's disease, and Alzheimer's — health claims that triggered FDA scrutiny because they functioned identically to a diagnostic medical device, just sold online without a physician intermediary.

On November 22, 2013, the FDA sent 23andMe a warning letter ordering it to "immediately discontinue marketing" its Personal Genome Service until it received premarket authorization, citing the risk that a false positive BRCA result could lead a healthy person to unnecessary prophylactic surgery, or a false negative could delay legitimate care. 23andMe complied, stripped health reports from the product for nearly two years, and kept selling ancestry-only kits — which fell entirely outside FDA device jurisdiction.

Two regulatory philosophies, one global product

The US and EU approached the same product category from opposite starting points. The US FDA is a premarket-gatekeeper model: a device generally cannot be sold for a health claim until cleared or approved, but an enormous carve-out (Laboratory Developed Tests, discussed in Stage 2) let most genetic tests avoid that gate entirely for decades.

The EU historically ran the opposite model for in vitro diagnostics: the IVD Directive (98/79/EC) let manufacturers self-certify low- and moderate-risk tests with no independent review at all. Genetic self-tests slipped through as self-certified "general" IVDs for years — arguably even less scrutinized than the US LDT-enforcement-discretion gap — until the 2017 IVDR replaced that directive with a strict, risk-tiered regime (Stage 3).

Neither the 2013 FDA crackdown nor the 2017 IVDR was designed around DNA-based tests specifically — both regimes are decades-old device frameworks stretched to cover a product category (mail-order genomics) that didn't exist when the underlying laws were written.

FDA De Novo, 510(k), and the Laboratory Developed Test Loophole

US oversight of DTC genetic tests runs through two parallel tracks that rarely intersect: a narrow, precedent-setting premarket pathway that a handful of tests have actually completed, and a much larger population of tests that reach consumers as "laboratory developed tests" — never independently reviewed by the FDA at all.

  • Feb 19, 2015: 23andMe Bloom syndrome clearance (first De Novo GHR authorization)
  • 2017: GHR reports pre-authorized after (FDA exempts subsequent GHR tests)
  • Mar 6, 2018: 23andMe BRCA1/2 (3 variants) (first DTC cancer-risk clearance)
  • ~12,000+: CLIA labs performing LDTs (US) (certified, not FDA device-reviewed)

The De Novo pathway and its 2015 precedent

When no "predicate" device exists for comparison, a novel low-to-moderate-risk device can use the De Novo classification pathway (created by the FDA Modernization Act of 1997) to become its own new regulatory category. On February 19, 2015, the FDA authorized 23andMe's carrier-status test for Bloom syndrome via De Novo — the first authorization of a DTC genetic health test in US history, creating a brand-new device classification: "genetic health risk assessment system."

Crucially, this also created a *predicate*: because Bloom syndrome carrier testing now had an approved regulatory class with defined special controls (accuracy studies, comprehension studies, labeling requirements), the FDA in 2017 announced it would allow subsequent 23andMe Genetic Health Risk (GHR) reports — Parkinson's, late-onset Alzheimer's (APOE), Celiac disease and others — to launch without additional premarket review, so long as they met the same special controls. This is why 23andMe could add BRCA1/2 (3 founder variants common in Ashkenazi Jewish populations) as a De Novo authorization in March 2018, and later products could reference it as a predicate under the faster 510(k) "substantial equivalence" pathway.

The Laboratory Developed Test enforcement-discretion gap

The overwhelming majority of DTC and clinical genetic tests never go through De Novo, 510(k), or PMA (Premarket Approval) at all. They are sold as Laboratory Developed Tests (LDTs) — tests designed, manufactured, and run entirely within a single CLIA-certified laboratory (regulated under the Clinical Laboratory Improvement Amendments of 1988, which governs analytical quality, not clinical validity). Since the 1976 Medical Device Amendments technically gave FDA authority over LDTs as devices, the agency chose not to enforce that authority for nearly 50 years — a policy called "enforcement discretion."

That changed on May 6, 2024, when the FDA issued a final rule to phase out enforcement discretion for LDTs over four stages through 2028, explicitly citing the growth of high-risk, direct-to-consumer genetic and companion-diagnostic tests as a driver. The rule was immediately challenged in federal court by the American Clinical Laboratory Association (ACLA) and the Association for Molecular Pathology, arguing FDA lacks statutory authority over lab-developed services under the Clinical Laboratory Improvement Act framework — leaving the ultimate scope of US premarket review for most genetic LDTs unresolved even as the rule's phase-in clock runs.

Because De Novo/510(k) clearance is device-specific and company-specific, a single accurate BRCA test from one company tells you nothing about whether a competitor's BRCA test — sold as an unreviewed LDT — meets the same analytical or clinical validity bar. Two DTC products can claim to test "the same gene" under completely different levels of FDA scrutiny.

GINA: a narrow federal non-discrimination shield

The one federal law consumers most associate with "genetic privacy," the Genetic Information Nondiscrimination Act of 2008 (GINA), does not regulate testing companies or their data practices at all — it prohibits health insurers and employers from using genetic information in coverage or hiring decisions. GINA explicitly does not cover life insurance, disability insurance, or long-term-care insurance, and it imposes no data-security, retention, or deletion obligations on a DTC company like 23andMe or AncestryDNA. HIPAA, similarly, typically does not apply to DTC genomics firms because they are not "covered entities" (providers, insurers, clearinghouses) — a DTC company's privacy practices are governed mainly by its own terms of service and, since 2021, by state laws (Stage 4).

IVDR Class C: Mandatory Notified Body Review for Genetic Self-Tests

Regulation (EU) 2017/746 on in vitro diagnostic medical devices (IVDR) fully replaced the old self-certification directive on May 26, 2022, and it treats genetic self-testing devices far more strictly than the pre-2022 regime — or, in most cases, than the US LDT track. Under IVDR Annex VIII, Rule 3, devices intended for genetic testing and devices for self-testing are both automatically pushed into Class C, the second-highest risk tier, short of only Class D (transmissible-agent and public-health-critical tests).

  • May 26, 2022: IVDR full application date (replaced IVD Directive 98/79/EC)
  • A–D: IVD device risk classes (Class C = high risk, Notified Body req.)
  • ~10–12: IVDR-designated Notified Bodies (EU) (as of 2024, bottleneck for reviews)
  • ~85%: Devices needing new IVDR review (vs. ~8% under old IVDD self-cert)

From near-total self-certification to independent conformity assessment

Under the 1998 IVD Directive, manufacturers could self-declare conformity for roughly 80–90% of IVDs, including most genetic self-tests, by simply affixing a CE mark after an internal technical file review — no external body ever examined the evidence. IVDR flipped this ratio: because Annex VIII, Rule 3(a)/(l) classifies both "genetic testing" devices and any device "intended by the manufacturer for self-testing" as Class C by default, essentially all DTC genetic tests now require a Notified Body (an independent, EU-designated conformity-assessment organization, e.g. BSI, TÜV SÜD, DEKRA) to review clinical evidence, analytical performance, and a post-market surveillance plan before a CE mark can be issued.

Class C review typically requires: analytical validity studies (sensitivity, specificity, reproducibility across sample types), clinical evidence linking genotype to the claimed phenotype/health outcome, usability/comprehension testing specific to a lay self-testing population, and a Unique Device Identification (UDI) registration in the EUDAMED database for post-market traceability.

Compliance costs reshaped market access

The jump from self-certification to mandatory third-party Class C review raised compliance costs and timelines sharply — reports from EU diagnostics trade bodies put IVDR technical documentation and Notified Body review costs at hundreds of thousands of euros per device family, with review backlogs stretching 12–18+ months given only a handful of Notified Bodies were IVDR-designated in the rule's early years. Several DTC genomics companies responded by restricting EU sales, routing EU customers through licensed local laboratories instead of direct mail-order kits, or narrowing EU product lines to ancestry-only (non-medical) reports that fall outside IVDR's device definition entirely.

National carve-outs add another layer: Germany's Genetic Diagnostics Act (Gendiagnostikgesetz, GenDG, 2010) independently requires that genetic testing for health purposes be ordered and explained by a physician — effectively banning unmediated DTC health-risk genetic testing regardless of IVDR status. France's bioethics law (most recently reaffirmed in the 2021 bioethics revision) similarly prohibits genetic testing outside a medical/research/judicial context, making it a criminal offense to solicit DTC genetic testing for personal use — among the strictest DTC bans among wealthy democracies.

Post-Brexit, the UK is no longer bound by IVDR at all: the MHRA runs its own UKCA marking scheme, currently on an extended transition allowing CE-marked devices to continue circulating — meaning a DTC test's legal status can now differ across the UK, EU, and US even though the underlying assay is chemically identical.

Regulatory dimension comparison, selected jurisdictions

ProductIndicationTrial DesignKey Result
United States (FDA)De Novo/510(k) for cleared tests; enforcement-discretion gap for most LDTsGINA (employment/insurance only); no comprehensive federal genetic-privacy law23andMe De Novo (2015); FTC Sec.5 actions vs. Flo, BetterHelp
European Union (IVDR)Class C, mandatory Notified Body conformity assessmentGDPR Art.9 — genetic data is "special category," explicit consent required~85% of IVDs newly require 3rd-party review vs. old IVDD
United Kingdom (post-Brexit)UKCA marking; CE-marked devices accepted through extended transitionUK GDPR — mirrors EU Art.9 special-category protectionsMHRA operates independently of EU Notified Bodies
US States (CA, IL, WA, FL, UT)No premarket device review — consumer-privacy statutes onlyCCPA/CPRA, Illinois GIPA (2008), WA My Health My Data Act (2023)Patchwork enforcement; GIPA carries private right of action

GDPR Article 9 Special-Category Data vs the US State Patchwork

Genetic data is not treated as ordinary personal data anywhere serious data-protection law exists — but how strongly it is protected diverges sharply between the EU's single binding standard and a fragmented US landscape built from one narrow federal law plus a growing, inconsistent set of state statutes.

  • May 25, 2018: GDPR effective date (Regulation (EU) 2016/679)
  • €20M or 4%: Max GDPR fine (of global annual turnover, whichever higher)
  • 2008: Illinois GIPA private right of action (statutory damages per violation)
  • ~12+: US states with genetic privacy law (as of 2025, still expanding)

GDPR Article 9: consent as the default legal basis

GDPR Article 9(1) prohibits processing "genetic data" (and biometric, health, and several other categories) by default. Processing is lawful only under specific exceptions listed in Article 9(2) — overwhelmingly, DTC genomics companies rely on 9(2)(a): the data subject has given "explicit consent" to processing for one or more specified purposes. This is a materially higher bar than the general "legitimate interest" or "contract necessity" bases available for ordinary personal data under Article 6: explicit consent must be freely given, specific, informed, unambiguous, and separately revocable at any time, with processing for a new purpose (e.g., selling aggregated data to a pharmaceutical partner) requiring fresh consent.

GDPR additionally grants data subjects a right to erasure ("right to be forgotten," Article 17) and data portability (Article 20) that most US consumers simply do not have as a matter of federal law — an EU resident can generally compel a DTC company to delete their raw genotype file and derived reports; a US consumer's ability to do the same depends entirely on which state they live in and that company's own retention policy.

The US patchwork: GINA's narrow scope plus emerging state statutes

At the federal level, GINA (2008) remains the primary genetic-specific US law, and it regulates only two relationships: health insurance underwriting and employment decisions. It does not restrict how a DTC company collects, stores, shares, monetizes, or retains genetic data — that gap has been filled unevenly by states:

• Illinois Genetic Information Privacy Act (GIPA, 1998, amended 2008/2021) — the strictest, requiring written informed consent before genetic testing/disclosure and, unusually, granting a private right of action with statutory damages, similar in enforcement structure to Illinois' well-known Biometric Information Privacy Act (BIPA). • California CCPA/CPRA (2020/2023) — classifies genetic data as "sensitive personal information," giving consumers rights to opt out of sale/sharing and request deletion, enforced by the California Privacy Protection Agency. • Washington My Health My Data Act (2023) — passed partly in response to fears about reproductive and genetic health data following Dobbs v. Jackson, broadly covering "consumer health data" with a private right of action. • Florida and Utah genetic-privacy statutes (2021) — require consumer consent for genetic data collection, storage, and third-party sharing/destruction, with sector-specific carve-outs.

No two of these state laws define "genetic data," "consent," or "deletion" identically, so a single DTC company's compliance obligations literally change at state lines — the opposite of GDPR's single EU-wide standard.

A US consumer and an EU consumer can submit saliva to the same company for the same test and receive fundamentally different legal guarantees about who can subsequently buy, subpoena, or inherit access to their raw genetic data — not because the science differs, but because the applicable law does.

Law-enforcement access: a use case neither regime anticipated

Both regimes were largely silent on a use that became publicly prominent after DTC data began aggregating in third-party genealogy databases: law-enforcement genetic genealogy. GEDmatch, a free genealogy-matching site (not a testing company) whose database was built from uploads of 23andMe/AncestryDNA raw data files, was used by investigators in April 2018 to identify the Golden State Killer by matching crime-scene DNA against distant relatives' uploaded profiles — without a warrant, and without those relatives having consented to law-enforcement search when they uploaded their data years earlier.

GEDmatch subsequently changed its default to opt-out for law-enforcement matching (2019), and the US Department of Justice issued interim policy in 2019 requiring investigators to first attempt matches only in databases that explicitly allow law-enforcement use. No comparable practice has emerged at meaningful scale in the EU, partly because GDPR's consent-specificity requirements make repurposing genealogy data for criminal investigations without a new legal basis considerably harder to justify — though EU member-state criminal procedure codes, not GDPR itself, ultimately govern law-enforcement DNA database access.

When the Gap Becomes Real: Breach, Bankruptcy, and Enforcement

By the mid-2020s, the theoretical gap between light-touch US oversight and stricter EU rules produced concrete, high-profile consequences — a mass data breach, a bankruptcy that put millions of genetic profiles up for sale as a corporate asset, and a string of FTC actions establishing that "unfair or deceptive practices" enforcement, not dedicated genetic-privacy law, is still the primary US backstop.

  • Oct 2023: 23andMe breach disclosed (credential-stuffing attack)
  • 6.9M: Profiles affected (via "DNA Relatives" feature scraping)
  • Mar 23, 2025: 23andMe Chapter 11 filing (genetic database sold as asset)
  • $7.8M: BetterHelp FTC settlement (2023, shared health data despite promises)

The 23andMe breach: credential stuffing, not a hack of DNA itself

In October 2023, 23andMe disclosed that attackers had used "credential stuffing" — reusing passwords leaked from unrelated prior breaches — to log into roughly 14,000 individual accounts. Because 23andMe's "DNA Relatives" feature let logged-in users see profile and ancestry-match data for their genetic relatives by default, the attackers scraped and later sold on hacking forums data connected to an estimated 6.9 million profiles, including names, birth years, relationship labels, and in some subsets self-reported ancestry and health-related information. Notably, raw genotype files were reportedly not exfiltrated in bulk — the exposure was primarily of the social/relational graph the DNA Relatives feature had constructed, not the sequence data itself, which nonetheless still let outside parties infer sensitive family and ancestry information about people who had never used the service.

23andMe's response drew criticism for initially appearing to shift responsibility to affected users' password hygiene rather than the platform's default-on relative-matching and lack of mandatory multi-factor authentication; the company subsequently required MFA and faced dozens of consolidated class-action lawsuits and state attorney-general investigations across the US.

Bankruptcy turns genetic data into a contested corporate asset

On March 23, 2025, 23andMe filed for Chapter 11 bankruptcy protection, listing its genetic database — data from more than 15 million customers — among its sellable assets. This triggered an immediate response absent from most bankruptcy filings: multiple US state attorneys general (including California and others) publicly urged customers to log in and delete their genetic data before any sale closed, and California's attorney general specifically invoked the CCPA/CPRA right to delete. The company's bankruptcy court–approved sale process ultimately drew scrutiny over whether existing consent terms could legally transfer with the data to a new owner, and a court-appointed consumer privacy ombudsman was required to review the sale's privacy implications — a direct consequence of the US relying on bankruptcy-court and state-AG intervention rather than a dedicated genetic-data transfer restriction of the kind GDPR's purpose-limitation principle would more directly impose on an EU-based company.

The 23andMe bankruptcy was arguably the first case where a company's genetic database — arguably its most sensitive corporate asset — became a headline financial-restructuring issue, forcing regulators to improvise data-protection remedies through bankruptcy and consumer-protection law that neither FDA device rules nor GINA were ever designed to provide.

FTC Section 5: the de facto US privacy regulator for health/genetic data

In the absence of a dedicated US genetic-privacy regulator, the Federal Trade Commission has stepped into the gap using its general authority under Section 5 of the FTC Act to police "unfair or deceptive acts or practices" — essentially, holding companies to their own stated privacy promises. Precedent-setting actions include: Flo Health (2021 settlement) — a period- and fertility-tracking app that told users it would not share health data externally while sending ovulation and pregnancy-intention data to Facebook and Google via analytics SDKs; BetterHelp ($7.8M settlement, 2023) — an online therapy platform that shared consumers' health information, including intake-questionnaire responses, with advertising platforms after promising confidentiality; and GoodRx ($1.5M settlement, 2023, first enforcement of the FTC's Health Breach Notification Rule) — for sharing prescription and health data with advertisers without notifying consumers.

None of these actions used a genetic-data-specific statute; all relied on the same "your privacy policy is a promise, and breaking it is deceptive" theory the FTC has applied since the early 2000s. For DTC genomics specifically, this means the practical strength of US privacy protection for genetic data currently depends heavily on how carefully a company worded its own terms of service — not on a uniform statutory floor, the way GDPR Article 9 provides across all 27 EU member states regardless of any individual company's policy language.

⚙ Under the hood

This simulation compares the regulatory oversight of direct-to-consumer DNA testing in the United States and the European Union, highlighting key differences in legal frameworks, compliance requirements, and consumer protections.

CanvasBiomedicine

2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install

What did you find?

Add reproduction steps (optional)