
Judge Simmons: GEDmatch Genetic Data Privacy Class Action Claims Advance
Summary
- A federal judge allowed key portions of a class action lawsuit against GEDmatch.com operators Verogen Inc. and Qiagen NV to proceed.
- Plaintiffs can pursue claims alleging law enforcement bypassed opt-out settings to access DNA profiles and that a Meta tracking pixel transmitted user data.
- U.S. District Judge James Simmons Jr. deemed unauthorized law enforcement access to genetic profiles a "substantial privacy invasion."
- Claims related to the 2023 acquisition of Verogen by Qiagen were dismissed for lacking specific detail, but plaintiffs have the option to amend their complaint.
- The ruling highlights increasing legal scrutiny over genetic data privacy, particularly concerning explicit user consent and third-party data sharing.
Judicial Ruling Advances Genetic Data Privacy Lawsuit
The court's decision to advance claims related to unauthorized law enforcement genetic data access and the use of tracking technologies like the Meta tracking pixel lawsuit underscores the increasing scrutiny faced by companies handling sensitive biological information.
A federal judge has allowed significant portions of a GEDmatch genetic data privacy class action to proceed, focusing on allegations that a genealogical research site operator improperly shared users' DNA profiles. U.S. District Judge James Simmons Jr. partially denied a motion to dismiss claims brought against Verogen Inc., the San Diego-based operator of GEDmatch.com, and Qiagen NV, a European multinational that acquired the platform in 2023. The lawsuit, initiated by ten named plaintiffs from Alaska, Illinois, New Hampshire, New Mexico, and Oregon, centers on the alleged unauthorized disclosure of sensitive genetic information to third parties, including law enforcement agencies and Meta.
Judge Simmons's ruling on Wednesday marks a pivotal moment for the plaintiffs, who contend that their privacy was substantially invaded when their DNA profiles were accessed against their explicit wishes. The court's decision permits the plaintiffs to advance claims concerning a purported technical vulnerability within GEDmatch’s PRO platform, which allegedly enabled law enforcement users to bypass privacy settings and conduct comparisons against profiles of individuals who had specifically opted out of such access. This aspect of the Verogen Qiagen DNA privacy lawsuit highlights critical questions surrounding user consent and the security of highly personal data.
Unauthorized Law Enforcement Access and Data Sharing Concerns
Central to the ongoing litigation are allegations of unauthorized law enforcement genetic data access. The plaintiffs assert that a "technical loophole" in GEDmatch’s PRO platform allowed police to circumvent user-defined privacy preferences, thereby gaining access to genetic profiles that users had explicitly restricted from such comparisons. Judge Simmons underscored the gravity of this issue, stating that "unauthorized access to genetic profiles by law enforcement actors, against users’ expressed preferences, presents at the very least, a substantial privacy invasion." This finding by the Joe Biden appointee, Judge Simmons Jr., paves the way for further examination of the platform's security protocols and its adherence to user privacy choices.
Beyond law enforcement, the class action also addresses concerns related to the sharing of user activity data with Meta. Plaintiffs allege that Verogen installed a Meta tracking pixel on GEDmatch.com in 2020. This pixel was reportedly configured to capture user actions, including page views and, at certain times, DNA kit upload events, transmitting this activity data, along with users' Facebook ID numbers, to Meta. The judge, however, limited these specific claims to only those users who uploaded their DNA after the Meta pixel had been integrated into the website, narrowing the scope of potential liability for this particular alleged genetic information disclosure liability.
Acquisition-Related Claims Dismissed, Opportunity to Amend
While allowing several key allegations to proceed, Judge Simmons Jr. was not persuaded by the plaintiffs' claims that their privacy was violated specifically by the 2023 sale of Verogen to Qiagen or subsequent commercial activities. The court found that the plaintiffs had not adequately demonstrated a legally sufficient connection between Qiagen’s acquisition and any prohibited disclosure, retention, or use of their specific genetic information. The ruling indicated that the allegations, as currently pleaded, lacked the necessary particularity to establish that the acquisition agreement mandated a prohibited disclosure of each named plaintiff’s protected genetic information, or that Qiagen’s post-acquisition commercial endeavors specifically involved access to or use of their individual DNA profiles.
Despite this partial dismissal, the court has granted the plaintiffs an opportunity to amend their complaint to address the identified shortcomings. During a November hearing, attorneys for Verogen and Qiagen, including Kristine Argentine of Seyfarth Shaw, argued for the dismissal of the entire case on procedural grounds, asserting that users had not demonstrated how they were harmed by any potential disclosures. The defense maintained that the management of Verogen’s genetic database remained unchanged after the sale, with client data staying under the original company’s control. They also contended that users had agreed to Verogen’s terms and conditions, which included provisions for a potential sale to another entity, implying consent for such transfers.
Broader Implications for Genetic Data Privacy
This ruling carries significant weight for the burgeoning field of genetic data privacy. The plaintiffs' claims are anchored in the developing legal frameworks governing genetic data in their respective home states, including Alaska, Illinois, New Hampshire, New Mexico, and Oregon. The court's decision to advance claims related to unauthorized law enforcement genetic data access and the use of tracking technologies like the Meta tracking pixel lawsuit underscores the increasing scrutiny faced by companies handling sensitive biological information. It signals a judicial recognition of the "substantial privacy invasion" that can occur when genetic data is accessed or shared without explicit user consent, particularly when it bypasses established privacy controls.
The partial denial of the motion to dismiss in this GEDmatch genetic data privacy class action highlights the complex challenges associated with managing and protecting highly personal genetic information in the digital age. Companies operating in this space, especially those involved in genealogical research or DNA analysis, are now on notice regarding their potential genetic information disclosure liability. The ability for plaintiffs to amend their complaint regarding the acquisition-related claims further emphasizes the evolving legal landscape and the need for robust data privacy protocols that anticipate and address potential vulnerabilities, whether through technical loopholes, third-party integrations, or corporate transactions.
Practical Implications
This ruling signals increased litigation risk for companies handling genetic data, particularly concerning explicit user consent for law enforcement access and third-party data sharing via tracking technologies like Meta pixels. Compliance officers should review data privacy policies, M&A data transfer protocols, and technical implementations to ensure robust protection against unauthorized disclosures and potential class action liability.
Source
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Get the latest legal & regulatory intelligence in United States
Wansom is AI and can make mistakes.
