US FDA de novo/510(k) vs EU IVDR + GDPR — how direct-to-consumer genetic testing is (and isn't) regulated on two continents
Direct-to-consumer (DTC) genetic testing grew from a $70 saliva-kit novelty in 2007 into a global industry spanning ancestry, health-risk, and wellness testing — reaching tens of millions of consumers before either the United States or the European Union had a settled regulatory answer for what these tests actually are: medical devices, consumer products, or something in between.
23andMe launched in 2007 selling ancestry composition and raw genotype data for recreational use. By 2013 it was marketing "Health Reports" estimating risk for conditions including breast cancer, Parkinson's disease, and Alzheimer's — health claims that triggered FDA scrutiny because they functioned identically to a diagnostic medical device, just sold online without a physician intermediary.
On November 22, 2013, the FDA sent 23andMe a warning letter ordering it to "immediately discontinue marketing" its Personal Genome Service until it received premarket authorization, citing the risk that a false positive BRCA result could lead a healthy person to unnecessary prophylactic surgery, or a false negative could delay legitimate care. 23andMe complied, stripped health reports from the product for nearly two years, and kept selling ancestry-only kits — which fell entirely outside FDA device jurisdiction.
The US and EU approached the same product category from opposite starting points. The US FDA is a premarket-gatekeeper model: a device generally cannot be sold for a health claim until cleared or approved, but an enormous carve-out (Laboratory Developed Tests, discussed in Stage 2) let most genetic tests avoid that gate entirely for decades.
The EU historically ran the opposite model for in vitro diagnostics: the IVD Directive (98/79/EC) let manufacturers self-certify low- and moderate-risk tests with no independent review at all. Genetic self-tests slipped through as self-certified "general" IVDs for years — arguably even less scrutinized than the US LDT-enforcement-discretion gap — until the 2017 IVDR replaced that directive with a strict, risk-tiered regime (Stage 3).
Neither the 2013 FDA crackdown nor the 2017 IVDR was designed around DNA-based tests specifically — both regimes are decades-old device frameworks stretched to cover a product category (mail-order genomics) that didn't exist when the underlying laws were written.
US oversight of DTC genetic tests runs through two parallel tracks that rarely intersect: a narrow, precedent-setting premarket pathway that a handful of tests have actually completed, and a much larger population of tests that reach consumers as "laboratory developed tests" — never independently reviewed by the FDA at all.
When no "predicate" device exists for comparison, a novel low-to-moderate-risk device can use the De Novo classification pathway (created by the FDA Modernization Act of 1997) to become its own new regulatory category. On February 19, 2015, the FDA authorized 23andMe's carrier-status test for Bloom syndrome via De Novo — the first authorization of a DTC genetic health test in US history, creating a brand-new device classification: "genetic health risk assessment system."
Crucially, this also created a *predicate*: because Bloom syndrome carrier testing now had an approved regulatory class with defined special controls (accuracy studies, comprehension studies, labeling requirements), the FDA in 2017 announced it would allow subsequent 23andMe Genetic Health Risk (GHR) reports — Parkinson's, late-onset Alzheimer's (APOE), Celiac disease and others — to launch without additional premarket review, so long as they met the same special controls. This is why 23andMe could add BRCA1/2 (3 founder variants common in Ashkenazi Jewish populations) as a De Novo authorization in March 2018, and later products could reference it as a predicate under the faster 510(k) "substantial equivalence" pathway.
The overwhelming majority of DTC and clinical genetic tests never go through De Novo, 510(k), or PMA (Premarket Approval) at all. They are sold as Laboratory Developed Tests (LDTs) — tests designed, manufactured, and run entirely within a single CLIA-certified laboratory (regulated under the Clinical Laboratory Improvement Amendments of 1988, which governs analytical quality, not clinical validity). Since the 1976 Medical Device Amendments technically gave FDA authority over LDTs as devices, the agency chose not to enforce that authority for nearly 50 years — a policy called "enforcement discretion."
That changed on May 6, 2024, when the FDA issued a final rule to phase out enforcement discretion for LDTs over four stages through 2028, explicitly citing the growth of high-risk, direct-to-consumer genetic and companion-diagnostic tests as a driver. The rule was immediately challenged in federal court by the American Clinical Laboratory Association (ACLA) and the Association for Molecular Pathology, arguing FDA lacks statutory authority over lab-developed services under the Clinical Laboratory Improvement Act framework — leaving the ultimate scope of US premarket review for most genetic LDTs unresolved even as the rule's phase-in clock runs.
Because De Novo/510(k) clearance is device-specific and company-specific, a single accurate BRCA test from one company tells you nothing about whether a competitor's BRCA test — sold as an unreviewed LDT — meets the same analytical or clinical validity bar. Two DTC products can claim to test "the same gene" under completely different levels of FDA scrutiny.
The one federal law consumers most associate with "genetic privacy," the Genetic Information Nondiscrimination Act of 2008 (GINA), does not regulate testing companies or their data practices at all — it prohibits health insurers and employers from using genetic information in coverage or hiring decisions. GINA explicitly does not cover life insurance, disability insurance, or long-term-care insurance, and it imposes no data-security, retention, or deletion obligations on a DTC company like 23andMe or AncestryDNA. HIPAA, similarly, typically does not apply to DTC genomics firms because they are not "covered entities" (providers, insurers, clearinghouses) — a DTC company's privacy practices are governed mainly by its own terms of service and, since 2021, by state laws (Stage 4).
Regulation (EU) 2017/746 on in vitro diagnostic medical devices (IVDR) fully replaced the old self-certification directive on May 26, 2022, and it treats genetic self-testing devices far more strictly than the pre-2022 regime — or, in most cases, than the US LDT track. Under IVDR Annex VIII, Rule 3, devices intended for genetic testing and devices for self-testing are both automatically pushed into Class C, the second-highest risk tier, short of only Class D (transmissible-agent and public-health-critical tests).
Under the 1998 IVD Directive, manufacturers could self-declare conformity for roughly 80–90% of IVDs, including most genetic self-tests, by simply affixing a CE mark after an internal technical file review — no external body ever examined the evidence. IVDR flipped this ratio: because Annex VIII, Rule 3(a)/(l) classifies both "genetic testing" devices and any device "intended by the manufacturer for self-testing" as Class C by default, essentially all DTC genetic tests now require a Notified Body (an independent, EU-designated conformity-assessment organization, e.g. BSI, TÜV SÜD, DEKRA) to review clinical evidence, analytical performance, and a post-market surveillance plan before a CE mark can be issued.
Class C review typically requires: analytical validity studies (sensitivity, specificity, reproducibility across sample types), clinical evidence linking genotype to the claimed phenotype/health outcome, usability/comprehension testing specific to a lay self-testing population, and a Unique Device Identification (UDI) registration in the EUDAMED database for post-market traceability.
The jump from self-certification to mandatory third-party Class C review raised compliance costs and timelines sharply — reports from EU diagnostics trade bodies put IVDR technical documentation and Notified Body review costs at hundreds of thousands of euros per device family, with review backlogs stretching 12–18+ months given only a handful of Notified Bodies were IVDR-designated in the rule's early years. Several DTC genomics companies responded by restricting EU sales, routing EU customers through licensed local laboratories instead of direct mail-order kits, or narrowing EU product lines to ancestry-only (non-medical) reports that fall outside IVDR's device definition entirely.
National carve-outs add another layer: Germany's Genetic Diagnostics Act (Gendiagnostikgesetz, GenDG, 2010) independently requires that genetic testing for health purposes be ordered and explained by a physician — effectively banning unmediated DTC health-risk genetic testing regardless of IVDR status. France's bioethics law (most recently reaffirmed in the 2021 bioethics revision) similarly prohibits genetic testing outside a medical/research/judicial context, making it a criminal offense to solicit DTC genetic testing for personal use — among the strictest DTC bans among wealthy democracies.
Post-Brexit, the UK is no longer bound by IVDR at all: the MHRA runs its own UKCA marking scheme, currently on an extended transition allowing CE-marked devices to continue circulating — meaning a DTC test's legal status can now differ across the UK, EU, and US even though the underlying assay is chemically identical.
| Product | Indication | Trial Design | Key Result |
|---|---|---|---|
| United States (FDA) | De Novo/510(k) for cleared tests; enforcement-discretion gap for most LDTs | GINA (employment/insurance only); no comprehensive federal genetic-privacy law | 23andMe De Novo (2015); FTC Sec.5 actions vs. Flo, BetterHelp |
| European Union (IVDR) | Class C, mandatory Notified Body conformity assessment | GDPR Art.9 — genetic data is "special category," explicit consent required | ~85% of IVDs newly require 3rd-party review vs. old IVDD |
| United Kingdom (post-Brexit) | UKCA marking; CE-marked devices accepted through extended transition | UK GDPR — mirrors EU Art.9 special-category protections | MHRA operates independently of EU Notified Bodies |
| US States (CA, IL, WA, FL, UT) | No premarket device review — consumer-privacy statutes only | CCPA/CPRA, Illinois GIPA (2008), WA My Health My Data Act (2023) | Patchwork enforcement; GIPA carries private right of action |
Genetic data is not treated as ordinary personal data anywhere serious data-protection law exists — but how strongly it is protected diverges sharply between the EU's single binding standard and a fragmented US landscape built from one narrow federal law plus a growing, inconsistent set of state statutes.
GDPR Article 9(1) prohibits processing "genetic data" (and biometric, health, and several other categories) by default. Processing is lawful only under specific exceptions listed in Article 9(2) — overwhelmingly, DTC genomics companies rely on 9(2)(a): the data subject has given "explicit consent" to processing for one or more specified purposes. This is a materially higher bar than the general "legitimate interest" or "contract necessity" bases available for ordinary personal data under Article 6: explicit consent must be freely given, specific, informed, unambiguous, and separately revocable at any time, with processing for a new purpose (e.g., selling aggregated data to a pharmaceutical partner) requiring fresh consent.
GDPR additionally grants data subjects a right to erasure ("right to be forgotten," Article 17) and data portability (Article 20) that most US consumers simply do not have as a matter of federal law — an EU resident can generally compel a DTC company to delete their raw genotype file and derived reports; a US consumer's ability to do the same depends entirely on which state they live in and that company's own retention policy.
At the federal level, GINA (2008) remains the primary genetic-specific US law, and it regulates only two relationships: health insurance underwriting and employment decisions. It does not restrict how a DTC company collects, stores, shares, monetizes, or retains genetic data — that gap has been filled unevenly by states:
• Illinois Genetic Information Privacy Act (GIPA, 1998, amended 2008/2021) — the strictest, requiring written informed consent before genetic testing/disclosure and, unusually, granting a private right of action with statutory damages, similar in enforcement structure to Illinois' well-known Biometric Information Privacy Act (BIPA). • California CCPA/CPRA (2020/2023) — classifies genetic data as "sensitive personal information," giving consumers rights to opt out of sale/sharing and request deletion, enforced by the California Privacy Protection Agency. • Washington My Health My Data Act (2023) — passed partly in response to fears about reproductive and genetic health data following Dobbs v. Jackson, broadly covering "consumer health data" with a private right of action. • Florida and Utah genetic-privacy statutes (2021) — require consumer consent for genetic data collection, storage, and third-party sharing/destruction, with sector-specific carve-outs.
No two of these state laws define "genetic data," "consent," or "deletion" identically, so a single DTC company's compliance obligations literally change at state lines — the opposite of GDPR's single EU-wide standard.
A US consumer and an EU consumer can submit saliva to the same company for the same test and receive fundamentally different legal guarantees about who can subsequently buy, subpoena, or inherit access to their raw genetic data — not because the science differs, but because the applicable law does.
Both regimes were largely silent on a use that became publicly prominent after DTC data began aggregating in third-party genealogy databases: law-enforcement genetic genealogy. GEDmatch, a free genealogy-matching site (not a testing company) whose database was built from uploads of 23andMe/AncestryDNA raw data files, was used by investigators in April 2018 to identify the Golden State Killer by matching crime-scene DNA against distant relatives' uploaded profiles — without a warrant, and without those relatives having consented to law-enforcement search when they uploaded their data years earlier.
GEDmatch subsequently changed its default to opt-out for law-enforcement matching (2019), and the US Department of Justice issued interim policy in 2019 requiring investigators to first attempt matches only in databases that explicitly allow law-enforcement use. No comparable practice has emerged at meaningful scale in the EU, partly because GDPR's consent-specificity requirements make repurposing genealogy data for criminal investigations without a new legal basis considerably harder to justify — though EU member-state criminal procedure codes, not GDPR itself, ultimately govern law-enforcement DNA database access.
By the mid-2020s, the theoretical gap between light-touch US oversight and stricter EU rules produced concrete, high-profile consequences — a mass data breach, a bankruptcy that put millions of genetic profiles up for sale as a corporate asset, and a string of FTC actions establishing that "unfair or deceptive practices" enforcement, not dedicated genetic-privacy law, is still the primary US backstop.
In October 2023, 23andMe disclosed that attackers had used "credential stuffing" — reusing passwords leaked from unrelated prior breaches — to log into roughly 14,000 individual accounts. Because 23andMe's "DNA Relatives" feature let logged-in users see profile and ancestry-match data for their genetic relatives by default, the attackers scraped and later sold on hacking forums data connected to an estimated 6.9 million profiles, including names, birth years, relationship labels, and in some subsets self-reported ancestry and health-related information. Notably, raw genotype files were reportedly not exfiltrated in bulk — the exposure was primarily of the social/relational graph the DNA Relatives feature had constructed, not the sequence data itself, which nonetheless still let outside parties infer sensitive family and ancestry information about people who had never used the service.
23andMe's response drew criticism for initially appearing to shift responsibility to affected users' password hygiene rather than the platform's default-on relative-matching and lack of mandatory multi-factor authentication; the company subsequently required MFA and faced dozens of consolidated class-action lawsuits and state attorney-general investigations across the US.
On March 23, 2025, 23andMe filed for Chapter 11 bankruptcy protection, listing its genetic database — data from more than 15 million customers — among its sellable assets. This triggered an immediate response absent from most bankruptcy filings: multiple US state attorneys general (including California and others) publicly urged customers to log in and delete their genetic data before any sale closed, and California's attorney general specifically invoked the CCPA/CPRA right to delete. The company's bankruptcy court–approved sale process ultimately drew scrutiny over whether existing consent terms could legally transfer with the data to a new owner, and a court-appointed consumer privacy ombudsman was required to review the sale's privacy implications — a direct consequence of the US relying on bankruptcy-court and state-AG intervention rather than a dedicated genetic-data transfer restriction of the kind GDPR's purpose-limitation principle would more directly impose on an EU-based company.
The 23andMe bankruptcy was arguably the first case where a company's genetic database — arguably its most sensitive corporate asset — became a headline financial-restructuring issue, forcing regulators to improvise data-protection remedies through bankruptcy and consumer-protection law that neither FDA device rules nor GINA were ever designed to provide.
In the absence of a dedicated US genetic-privacy regulator, the Federal Trade Commission has stepped into the gap using its general authority under Section 5 of the FTC Act to police "unfair or deceptive acts or practices" — essentially, holding companies to their own stated privacy promises. Precedent-setting actions include: Flo Health (2021 settlement) — a period- and fertility-tracking app that told users it would not share health data externally while sending ovulation and pregnancy-intention data to Facebook and Google via analytics SDKs; BetterHelp ($7.8M settlement, 2023) — an online therapy platform that shared consumers' health information, including intake-questionnaire responses, with advertising platforms after promising confidentiality; and GoodRx ($1.5M settlement, 2023, first enforcement of the FTC's Health Breach Notification Rule) — for sharing prescription and health data with advertisers without notifying consumers.
None of these actions used a genetic-data-specific statute; all relied on the same "your privacy policy is a promise, and breaking it is deceptive" theory the FTC has applied since the early 2000s. For DTC genomics specifically, this means the practical strength of US privacy protection for genetic data currently depends heavily on how carefully a company worded its own terms of service — not on a uniform statutory floor, the way GDPR Article 9 provides across all 27 EU member states regardless of any individual company's policy language.