Click the Play button to listen to article

Every human being carries a unique biological identifier that reveals far more than identity - genetic data.

A genetic sequence can disclose an individual's ancestry, inherited diseases, predisposition to illness, familial relationships, and even information about generations yet unborn. Unlike a password or financial credential, genetic information cannot be changed once compromised. Therefore, a breach involving genetic data can have serious and irreversible consequences.

The rapid expansion of genome sequencing, genetic testing, reproductive technologies, and AI-driven healthcare has resulted in the unprecedented collection and processing of genetic data. While these developments promise transformative advances in healthcare, they also raise difficult questions regarding privacy concerns of such highly sensitive personal data.

Against this backdrop, the Digital Personal Data Protection Act, 2023 ('DPDPA'), together with the Digital Personal Data Protection Rules, 2025 ('DPDP Rules, 2025), establishes India's first comprehensive framework governing the processing of digital personal data.

Meaning of genetic data and the question of identifiability

The EU's General Data Protection Regulation, which provides a useful comparative standard, defines genetic data as personal data relating to inherited or acquired genetic characteristics that provide unique information about the physiology or health of a natural person and result, in particular, from the analysis of a biological sample. The GDPR treats genetic data as a special category of personal data and subjects its processing to additional safeguards.

Human tissue or a biological sample is not necessarily personal data in itself. The privacy issue becomes acute when information is extracted from the sample and can be linked, directly or indirectly, to an identifiable individual. Genetic information may identify a person by itself, through comparison with another dataset, or through its association with relatives, medical records or demographic information.

The DPDPA does not separately define genetic data, but DPDPA defines 'personal data'. Personal data includes any data through which a person can be identified. Even de-identified genetic datasets may remain vulnerable to re-identification when combined with genealogical, clinical or publicly available information. So, DPDPA compliances apply to any entity that is in practice processing (collecting, storing or performing any actions on that personal data) the genetic data.

Why Genetic Data is particularly sensitive!

Genetic data can function as a powerful identifier. Independently collected samples may often be matched with a high degree of confidence using a relatively limited number of genetic variants. Unlike a password or telephone number, genetic characteristics cannot simply be changed after a breach.

Its sensitivity also arises from the range of inferences that may be drawn from it. Genetic information can reveal ancestry, inherited disorders, disease susceptibility and physiological traits. It may influence decisions relating to healthcare, employment, insurance, family relationships or social identity. The harm may also emerge years after the original collection, when scientific techniques or additional datasets make new inferences possible.

Most importantly, genetic privacy is also familial privacy. A person may consent to the sequencing of their own genome, but the resulting information may reveal a hereditary condition affecting relatives who never participated in the research and never gave consent. The law therefore faces a difficult question: whose privacy interest is engaged when one person's genetic information reveals information about several related individuals?

Genetic data processing in large scale government projects

The Government is involved in several large-scale projects involving the processing of genetic data both at Central and State level. Some examples of such project are National Biobank and Gujarat's Tribal focused genomic database project. Even where such processing is undertaken for research, public health or other public-interest purposes, data protection cannot be overlooked. Such projects should be designed in line with the DPDPA and sound data protection practices. Given the scale and sensitivity of genetic data, safeguards should include encryption during storage and transfer, role-based access, clear internal policies, incident-response mechanisms and defined accountability. A designated person should also oversee privacy compliance and perform responsibilities similar to those of a DPO. Just as specific safeguards have been developed to protect Aadhaar data, large-scale government genomic databases also require a re-look at data privacy and protection framework.

DPDPA's 'research' exemption for genetic data

Section 17(2)(b) of the DPDPA provides a conditional exemption for research, archiving and statistical processing where the data is not used to take decisions specific to a Data Principal and prescribed standards are followed. It is therefore not a blanket exemption from data-protection obligations.

Genetic research must still be purpose-specific, proportionate and subject to appropriate safeguards, including data accuracy, justified retention and security controls. Consent also requires particular care, since participants may not foresee future research uses or familial inferences. Organisations should therefore clearly distinguish primary research, secondary use, data sharing and commercial use.

Global case studies and their legal significance

Two well-known examples illustrate why genetic-data incidents require a distinct legal and governance response.

a) deCODE Genetics, Iceland: A private company was permitted to cross-reference medical, genetic and genealogical records. The controversy was intensified by the project's initial reliance on presumed consent. The Icelandic Supreme Court later recognised that information relating to a deceased person could reveal information about living relatives.

Legal takeaway: Genetic data cannot always be treated as belonging only to the individual from whom it was obtained. Consent models and privacy assessments must account for familial and intergenerational effects. Presumed or excessively broad consent is particularly difficult to justify where the dataset can reveal information about non-participants.

b) 23andMe: The company was fined GBP 2.31 million after a breach exposed data relating to UK users, including information capable of revealing ancestry, location, family trees and health-related insights.

Legal takeaway: A genetic-data breach is not an ordinary cybersecurity incident. The information may be permanent, difficult to contain and capable of exposing relatives. Security controls, access monitoring and incident response should therefore be proportionate to the exceptional sensitivity and long-term consequences of the data.

How the DPDPA may apply in practice

The DPDPA does not classify genetic information as sensitive personal data. However, its sensitive nature may still matter during enforcement. Regulators may consider the nature and volume of the data, the number of affected individuals, and the resulting harm when assessing a breach or inadequate safeguards.

For example, a telecom-data breach and a genetic-data breach may both involve personal data, but their consequences can be very different. Genetic data may reveal inherited illnesses, ancestry, permanent biological traits and information about relatives. This raises an important question: should all personal data be subject to the same safeguards despite such differences in risk? Until specific rules or guidance address this gap, organisations should adopt risk-based safeguards for genetic data.

Some actionable compliance measures

Hospitals, biotechnology companies, research institutions and public bodies should internally classify genetic information as high-risk personal data, even though the DPDPA does not expressly use that label. At a minimum, they should adopt the following measures:

a) Some examples of technical and organizational measures:

Conduct a data-protection impact assessment ('DPIA') before beginning large-scale sequencing, biobanking, secondary research or data-linkage projects.

Maintain a clear inventory of biological samples, raw genomic files, interpreted reports, metadata and linked clinical information. If possible, even maintain a dynamic recording of processing activities ('ROPA').

Put internal privacy policies in place after consulting relevant stakeholders. An external DPDPA consultant can first identify gaps and suggest the policies required. Some examples of important policies - 'data retention and deletion' practices, 'incident management' (reporting data breaches to Data Protection Board of India) and 'consent management'.

Entities should also publish a privacy notice on their website. It should briefly explain their data protection practices, security measures and categories of third parties with whom data is shared. The notice should also provide contact details of a person who can answer privacy-related queries.

Some examples of security measures:

Implement strong encryption and key management controls, including encryption of genomic data at rest and in transit, restricted access to encryption keys, key rotation and separation of key-management responsibilities.

Apply data-loss prevention tools and controlled data-export measures to prevent unauthorized downloading, copying, emailing or transfer of genomic datasets to external devices or platforms.

Maintain secure backup and recovery arrangements

Apply physical security controls to laboratories

Apart from the above, adopting health informatics standards such as ISO 27799:2025, ISO 27789:2021, ISO/TS 22220:2026 and India's Electronic Health Records Standards, 2016 may assist organizations in designing information-security controls, audit trails and reliable subject-identification processes. These standards should play a supporting role as best practices and should not be treated as a substitute for legal compliance. The legal obligations under the DPDPA will continue to apply independently.

Genetic information is permanent, deeply personal and can reveal information about entire families. Its protection should therefore go beyond minimum compliance. For organisations handling genetic data, the greater the potential harm, the stronger the safeguards should be.

Authors are Advocates practicing at Delhi NCR. Views are personal.

Tags: