Question… If the NHS had a breach like this, would the ICO fine them in a similar fashion?
OmegaPoint6 on
One thing to remember with these sorts of companies, it isn’t just their users data. By sharing your DNA with one of these companies you’re also sharing your relatives genetic information as well.
OkYogurt2157 on
yeah, I’m Jewish enough to feel pretty shit about this
lesson learned
WebDevWarrior on
This isn’t even the most dangerous aspect of the story.
Yes the fact they got hacked was insane and the way the organisation covered it up was stupid, but the fact that the organisation folded into bankrupsy as a result of people abandoning the platform and now the data has changed hands, the new owners are free to sell all of that personal genetic data to whomever they like, because as a new owner they are not bound by the old Ts&Cs and the US does not have the same tight laws we have in the UK or EU regarding sensitive data.
Some people think that requests for data deletion have not been acknowledged from the point at which they announced they were going under because at that point they were no longer an active organisation so when people started freaking out and trying to deal with their regret it was beyond too late as the dataset was „frozen“ in place for the new owners.
Simply put: Never hand out your raw biometric (DNA) data to anyone you don’t trust because once its out there, you can’t get it back. It’s there for anyone to take advantage of for good or for bad. It will be attached to you, your family, your distant relatives, to people you don’t know, and it could damage anyone in your vacinity.
And if that private company goes under, it could go to the highest bidder or if they get hacked it could go on the deep web. Even if it doesn’t it could be sold off to be used to discriminate against you for the purposes of things like insurance (US insurance companies are itching to get this data so they can screen people to deny them coverage if they spot potential DNA issues).
Leave A Reply
Du musst angemeldet sein, um einen Kommentar abzugeben.
4 Kommentare
Question… If the NHS had a breach like this, would the ICO fine them in a similar fashion?
One thing to remember with these sorts of companies, it isn’t just their users data. By sharing your DNA with one of these companies you’re also sharing your relatives genetic information as well.
yeah, I’m Jewish enough to feel pretty shit about this
lesson learned
This isn’t even the most dangerous aspect of the story.
Yes the fact they got hacked was insane and the way the organisation covered it up was stupid, but the fact that the organisation folded into bankrupsy as a result of people abandoning the platform and now the data has changed hands, the new owners are free to sell all of that personal genetic data to whomever they like, because as a new owner they are not bound by the old Ts&Cs and the US does not have the same tight laws we have in the UK or EU regarding sensitive data.
Some people think that requests for data deletion have not been acknowledged from the point at which they announced they were going under because at that point they were no longer an active organisation so when people started freaking out and trying to deal with their regret it was beyond too late as the dataset was „frozen“ in place for the new owners.
Simply put: Never hand out your raw biometric (DNA) data to anyone you don’t trust because once its out there, you can’t get it back. It’s there for anyone to take advantage of for good or for bad. It will be attached to you, your family, your distant relatives, to people you don’t know, and it could damage anyone in your vacinity.
And if that private company goes under, it could go to the highest bidder or if they get hacked it could go on the deep web. Even if it doesn’t it could be sold off to be used to discriminate against you for the purposes of things like insurance (US insurance companies are itching to get this data so they can screen people to deny them coverage if they spot potential DNA issues).