What Counts as “Genetic Data”? Comparing Definitional Frameworks Across the U.S., E.U., and China

When 23andMe filed for Chapter 11 bankruptcy in March 2025, regulators and consumers alike scrambled to ask the same question: who, exactly, owns the genetic data of fifteen million customers, and what legal regime governs its sale to a third party? But before that question can be answered, a prior one must be: what is genetic data, legally? The world’s major legal systems give surprisingly different answers, and the gap between them turns out to determine far more than terminology. Definition sets the ceiling on what any subsequent governance regime can do. This blog maps the definitional frameworks of the United States, the European Union, and China.

I. The United States: Genetic Data as Holder-Defined Information

The U.S. has no general-purpose genetic privacy statute, and no single substantive definition of genetic data either. What exists instead is a stack of partly overlapping definitions, each tied to a different statutory regime.

The Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule defines genetic information indirectly: it became “protected health information” (PHI) only after the 2013 Omnibus Rule, implementing § 105 of the Genetic Information Nondiscrimination Act of 2008 (GINA), directed the Department of Health and Human Services to treat it as such.[1] But HIPAA’s reach is holder-defined: data is “PHI” only when held by a covered entity—health plans, health-care clearinghouses, and most providers—or their business associates. The same DNA sequence is PHI in a hospital’s electronic health record and ordinary consumer information in a direct-to-consumer (DTC) testing company’s database, because DTC firms are not covered entities.

GINA itself uses a substantively broader definition, though it strictly operates only within the statute’s specific anti-discrimination contexts (namely employment and group health insurance). Within those narrow bounds, it defines “genetic information” to include not only an individual’s genetic test results, but also the genetic test results of family members, family medical history, and participation in clinical research involving genetic services.[2] This broader definition reaches information that is not in any laboratory database at all—a family Christmas-card mention of an aunt’s breast cancer can fall within it.

State law adds further definitional layers. California’s Privacy Rights Act (CPRA) classifies genetic data as one species of “sensitive personal information,” subject to use-limitation rights, regardless of who holds it.[3] Illinois’s Genetic Information Privacy Act (GIPA) defines a narrower category subject to a strict written-consent regime.[4] Most distinctively, five states—Alaska, Colorado, Florida, Georgia, and Louisiana—include provisions treating genetic data as the property of the individual from whom it is derived. However, this move creates a more property-like framing rather than a strictly functional one,[5] as courts have generally not enforced these statutes as robust property entitlements.

The cumulative result is an unusually fragmented definitional landscape: the same molecular reality may be PHI under HIPAA, “genetic information” under GINA, “sensitive personal information” under California law, and individual property under Florida law—each with its own scope, exclusions, and enforcement consequences.

II. The European Union: Genetic Data as a Substantively Defined Special Category

The General Data Protection Regulation takes the opposite path. Article 4(13) defines genetic data substantively, as “personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question.”[6] The definition is holder-independent: the data is special because of what it is, not who has it.

Article 9(1) then places genetic data in the GDPR’s “special categories” shelf, alongside racial or ethnic origin, religious beliefs, biometric data, health data, and data about sexual orientation.[7] Special-category status is not a label but a substantive consequence: such data may not be processed at all unless one of ten enumerated grounds applies (Article 9(2)), including explicit consent, public-health necessity, and scientific research subject to appropriate safeguards.

Member States may refine the definition further. Germany’s Gendiagnostikgesetz (GenDG) draws additional definitional lines between diagnostic genetic testing (used to establish an existing condition) and predictive testing (used to assess future risk), with stricter rules attaching to the latter.[8] France’s Code de la santé publique defines permissible purposesof genetic analysis—medical, judicial, or research only—and treats analysis for any other purpose as a definitional violation.[9]

The E.U. model’s strength is conceptual coherence: genetic data is recognizable as such regardless of where it sits. Its weakness is that the breadth of Article 4(13) and the openness of the “scientific research” ground have generated significant interpretive variation across Member States.

III. China: Dual Classification — Sensitive Personal Information and National Genetic Resource

While the E.U. focuses on the inherent nature of the data, China takes a fundamentally different path. Its framework is distinctive because it operates on two definitional tracks at once. Under the Personal Information Protection Law (PIPL), Article 28 lists categories of “sensitive personal information”—biometric, religious belief, specific identity, medical and health, financial accounts, location, and the personal information of minors under fourteen.[10] “Genetic data” is not separately named, but China’s national personal-information-security standard and leading commentators read it into the biometric and medical-health categories.[11]

In parallel, the 2019 Regulation on the Administration of Human Genetic Resources (HGR Regulation), supplemented by Implementing Detailed Rules effective in 2023, defines “human genetic resources” (HGR) to include both biological materials (organs, tissues, cells, blood specimens, gametes, embryos, and so on) and information derived from those materials—at the population level.[12] HGR is administered as a national strategic resource, with collection, preservation, and overseas provision subject to Ministry of Science and Technology approval, and foreign entities prohibited from independently collecting Chinese HGR at all.

The dual classification is the analytically distinctive feature. The same DNA sequence is, simultaneously, individual sensitive personal information under PIPL and a fragment of a national strategic resource under the HGR Regulation. Neither framework displaces the other; they operate in parallel, and a researcher may comply with one and still violate the other. No comparable dual-track logic exists in U.S. or E.U. law.

IV. Three Definitional Strategies, Four Substantive Features

Stepping back, the three jurisdictions are organizing the same underlying reality—identifiable DNA-based information about an individual—through three different framing moves.

The U.S. defines genetic data by who holds it: contextual, sectoral, transaction-bound. The E.U. defines it by what it is: substantive, identity-based, holder-independent. China defines it by what it represents: simultaneously individual data and collective national asset.

Beyond basic definitions, any effective regime must grapple with what makes genetic data legally unique: it remains identifiable even when stripped of names, it implicates non-consenting blood relatives, it predicts future health risks, and it is entirely immutable. How each jurisdiction captures these features varies significantly. The E.U.’s substantive Article 4(13) most directly captures identifiability and predictive value. China’s HGR-level classification operationalizes the collective and kinship dimensions through population-level controls. The U.S. patchwork captures fragments of all four but harmonizes none. Immutability—the fact that genetic data cannot be revoked or replaced once exposed—is not operationalized by any of the three.

The practical fallout of these divergent philosophies becomes obvious when returning to the 23andMe bankruptcy. How the sale of fifteen million customers’ data is handled depends entirely on which legal reality applies. Under the U.S. framework, because a DTC database is not held by a covered entity, it is generally not considered PHI. The consequence is exactly what this definitional patchwork creates—the sale is governed largely by consumer protection and bankruptcy law rather than health privacy. In contrast, under the E.U.’s substantive approach, this information remains a heavily protected special category of data regardless of who holds it or buys it. Meanwhile, in China, such a transfer would simultaneously trigger strict individual sensitive personal information protections and face stringent national security controls as a transfer of a national genetic resource.

References

[1] 45 C.F.R. § 160.103 (2024); HIPAA Omnibus Rule, 78 Fed. Reg. 5566 (Jan. 25, 2013); Genetic Information Nondiscrimination Act of 2008, § 105 (directing HHS to treat genetic information as “health information” under HIPAA).

[2] Genetic Information Nondiscrimination Act of 2008, Pub. L. No. 110-233, § 201, 122 Stat. 881 (defining “genetic information” to include genetic tests of the individual or family members, and the manifestation of a disease or disorder in family members).

[3] Cal. Civ. Code § 1798.140(ae)(1)(F) (West 2024) (classifying “genetic data” as a category of “sensitive personal information”).

[4] 410 Ill. Comp. Stat. 513 (2024); see also Bridges v. Blackstone, Inc., 66 F.4th 687 (7th Cir. 2023).

[5] See Jessica L. Roberts, Progressive Genetic Ownership, 93 Notre Dame L. Rev. 1105, 1128 (2018) (identifying Alaska, Colorado, Florida, Georgia, and Louisiana); Cole v. Gene by Gene, Ltd., No. 1:14-cv-00004, 2017 U.S. Dist. LEXIS 101761 (D. Alaska June 30, 2017).

[6] Regulation (EU) 2016/679, of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with Regard to the Processing of Personal Data, art. 4(13), 2016 O.J. (L 119) 1 [hereinafter GDPR].

[7] GDPR, supra note 6, art. 9(1).

[8] Gendiagnostikgesetz [GenDG] [Genetic Diagnosis Act], July 31, 2009, BGBl. I at 2529 (Ger.), §§ 3, 8–10.

[9] Code de la santé publique [C.S.P.] [Public Health Code] arts. L1131-1 to L1131-7 (Fr.).

[10] Personal Information Protection Law of the People’s Republic of China (promulgated by the Standing Comm. Nat’l People’s Cong., Aug. 20, 2021, effective Nov. 1, 2021), arts. 28–29.

[11] See GB/T 35273-2020, Information Security Technology — Personal Information Security Specification § 3.2 & Annex B (P.R.C. Standardization Admin., effective Oct. 1, 2020) (enumerating “personal genetic data” as “personal biometric information” and as “personal sensitive information”); Bird & Bird, China Health and Medical Data Protection (I): Human Genetic Resources Information (Mar. 2022), https://www.twobirds.com/en/insights/2022/china/china-health-and-medical-data-protection-i-human-genetic-resources-information (concluding that HGR information “is likely to also constitute sensitive personal information” under PIPL “unless it has been anonymized”).

[12] Regulation on the Administration of Human Genetic Resources (promulgated by the State Council, May 28, 2019, effective July 1, 2019), arts. 2, 7, 11, 21–28; Detailed Implementing Rules of the Regulation on the Administration of Human Genetic Resources (Ministry of Sci. & Tech., effective July 1, 2023); Biosecurity Law of the People’s Republic of China, arts. 53–56 (effective Apr. 15, 2021).