Can law enforcement access your DNA data?
Health data privacy23andMe & raw DNA
"Can police access your DNA?" is a fair and increasingly common question — and it deserves an honest, accurate answer rather than either a scare story or a brush-off. The short version: it depends heavily on where your genome lives and on laws and company policies that vary by country and change over time. Data on a company's servers can sometimes be reached through legal process, and a technique called investigative genetic genealogy has used consumer databases to identify people through their relatives. Data that never left your device is a different situation entirely. This is general information, not legal advice — here's how the pieces actually fit together.
First, an honest framing
Genetic privacy and law enforcement is a topic where it's easy to be either alarmist or dismissive, and both are wrong. The accurate picture has real nuance: the answer differs depending on which database holds your DNA, what that service's current policy is, which country's laws apply, and even what your relatives have done. Laws like the US GINA, various state genetic-privacy statutes, and the EU's GDPR shape what's possible, and they are not uniform across borders.
Two things follow from that. First, nobody — including this guide — can give you a single definitive "yes" or "no" that holds everywhere and forever, so anything you read here should be checked against the current policy of whatever service you actually use. Second, none of this is legal advice; it's a general explanation of how these situations have tended to work, so you can ask better questions and make deliberate choices. With that framing in place, the mechanics are genuinely worth understanding.
What investigative genetic genealogy is
The technique that put this whole question on the map is investigative genetic genealogy (sometimes called forensic genetic genealogy). It works roughly like this: investigators take DNA from crime-scene evidence, convert it into the kind of profile a consumer service reads, and upload that profile into a genealogy database that allows matching. The database returns not an exact hit on a named suspect but a list of relatives — people who share enough DNA to be cousins, second cousins, and so on. Investigators then build family trees from those matches, combine them with other records like age, location, and public data, and work inward until they can point to a specific person.
The crucial and counterintuitive part is that the person being sought never has to have tested. The method doesn't find them directly; it finds their genetic relatives and reasons back toward them. That's what makes it powerful for investigators — and what makes it a genuine privacy question for everyone, including people who have never spat in a tube.
The Golden State Killer example
The best-documented, most-cited case is the identification of the "Golden State Killer" in 2018. Investigators uploaded a crime-scene DNA profile to a consumer genealogy database that permitted such matching, found distant relatives of the unknown suspect, built out family trees, and used that genealogical work — alongside conventional investigation — to focus on and ultimately identify a suspect in a decades-old set of crimes. It was widely reported as the first high-profile use of the technique, and it's the case that moved investigative genetic genealogy from an obscure method into a mainstream awareness of what these databases can enable.
It's worth being precise about what that case does and doesn't show. It demonstrates that a crime-scene profile plus a matching-enabled consumer database plus patient genealogical work can identify someone through their relatives. It does not mean every consumer database works this way, that any company hands over data on request, or that this is a routine occurrence for ordinary users. It's a real, documented capability — not a description of what happens to your account day to day.
Which databases have been involved — and the companies' stated policies
This is where the "it depends" really bites, and where it's important to hedge rather than assert. Broadly, there's a meaningful difference between two kinds of services.
Some genealogy-matching databases — the sort you upload a raw file into specifically to find relatives — have historically been the ones involved in law-enforcement matching, in some cases on an opt-in basis where users could choose whether their profiles were available for such searches. GEDmatch and FamilyTreeDNA are the names most often discussed in reporting on this over the years. The important caveat: their terms, opt-in defaults, and policies around this have changed over time and continue to be revised, so what was true in one year may not describe their current settings. If you use one of these, check its current policy and your own matching settings directly.
The major testing companies — the big consumer names — have generally taken a more restrictive public stance, stating that they require valid legal process such as a warrant or subpoena before disclosing customer information, and publishing transparency reports about how they handle law-enforcement requests. Again, this should be framed carefully: these are the companies' stated positions as reported, policies and the laws behind them vary by jurisdiction and change over time, and a stated policy is a promise from a company that could later be acquired or rewrite its terms. We walk through the acquisition angle in what happens to your DNA data when a company is sold, and compare the majors' privacy postures in the most private DNA test. The honest takeaway is not "company X will never" or "company Y always will" — it's that the answer is policy- and jurisdiction-specific and worth verifying at the source.
The part people miss: a relative can expose you
Here's the point that reframes the whole question. Because you share large amounts of DNA with your family, you don't need to have tested for your genetic information to be reachable. If a sibling, parent, or cousin uploads their raw data to a matching-enabled database, that upload creates genetic links that can point back toward you — a partial genetic footprint you never chose to leave.
That's exactly the mechanism investigative genetic genealogy relies on: it identifies people through their relatives' data. It also means genetic privacy isn't fully an individual decision. Your choices affect your relatives, and theirs affect you. You can decline to upload your own genome and still be indirectly represented in a database through the people you're related to. This isn't a reason to panic — it's simply an accurate description of how shared DNA works, and it's why the topic deserves calm attention rather than either alarm or dismissal. It's the same family-implicating quality we discuss in is it safe to upload your DNA: a genome is never only about one person.
What actually reduces your exposure
Given all of that, what genuinely lowers the odds that your genetic data ends up reachable through legal process or matching? A few practical, non-alarmist steps — with the honest caveat that none of them is a guarantee, and specifics vary by service and country.
- Prefer not uploading in the first place. The cleanest way to keep your genome out of a searchable database is to never place it in one. Reading your raw file with an on-device tool means there's no server-side copy to match or subpoena. Our free DNA explorer parses your 23andMe or AncestryDNA file right in your browser with nothing uploaded, and you can confirm it yourself in the browser's Network tab.
- If you've uploaded, check the matching settings. On services that permit law-enforcement matching, look for whether you can opt out or make your profile non-matchable. These settings and their defaults change periodically, so review the current options rather than relying on what they were when you signed up.
- Use your deletion rights. If you no longer use a service, deleting your uploaded profile reduces future exposure. Our guide to deleting your 23andMe data shows what a real deletion looks like — while noting its limits below.
- Choose tools built around not retaining your genome. For ongoing use, prefer options that analyze on your device rather than storing your DNA on a server. Our roundup of the best privacy-first 23andMe alternatives weighs these choices through the same lens.
The honest limits
It would be dishonest to imply any of this makes you untouchable, so here are the edges. Deletion reduces exposure going forward but can't recall copies that were already matched, exported, or stored in a backup while your data was live — and it depends on the company actually honoring the request. Opting out of matching depends on the service offering that option and on you keeping up with policy changes. And the relative-exposure problem means that even doing everything right on your own account doesn't fully control what a family member's upload might reveal.
None of that is a counsel of despair. It's the realistic picture: on-device analysis meaningfully shrinks your own attack surface — there's no stored genome to search when your file never left your phone — while being honest that genetic privacy is partly shared and partly outside any one person's control. A smaller, closer footprint is a real improvement, not a magic shield.
The bottom line
Can law enforcement access your DNA? The accurate answer is: it depends on where your genome lives, on policies and laws that vary by service and country and change over time, and even on what your relatives have done — which is why this is general information, not legal advice, and why checking current policies at the source matters. Investigative genetic genealogy has shown that a crime-scene profile plus a matching-enabled consumer database can identify people through their relatives, as the Golden State Killer case demonstrated. The major testing companies describe stricter, legal-process requirements, though those are stated policies worth verifying rather than permanent guarantees. Through all of it, one structural fact holds: a genome that was never uploaded isn't sitting in any database to be searched. Keeping your DNA on your own device doesn't answer every question about genetic privacy — but it takes this particular one off the table.
The genome that stays on your phone
Quanome reads your raw DNA file on your own device and never uploads it. There's no server-side copy of your genome to subpoena, match against a crime-scene profile, or hand over — because the interpretation happens locally, on hardware you hold. Import your 23andMe, AncestryDNA, or MyHeritage file, read your traits and health-relevant variants, and keep them on a private timeline. Learn more about Quanome →
Frequently asked questions
Can police access your DNA?
It depends on where your DNA lives and the laws where you are, so this is general information rather than legal advice. Data sitting on a company's servers can be reached through legal process — subpoenas, warrants, or court orders — and some consumer databases have been searched by investigators. Data that only ever lived on your own device is not something a third party can hand over, because they never had a copy of it.
Can police use 23andMe or Ancestry?
The major testing companies have publicly stated that they require valid legal process — such as a warrant or subpoena — before disclosing customer data, and have published transparency reports describing how they respond. Policies and laws vary by company and country and change over time, so treat any specific claim as something to verify against their current policy. What a company says today is a promise from an entity that can be acquired or change its terms later.
What is investigative genetic genealogy?
It's a technique where investigators upload a DNA profile built from crime-scene evidence into a consumer genealogy database to look for relatives of an unknown person, then use family trees to narrow down a suspect. It doesn't require the suspect to have ever tested — a match to a cousin can be enough of a lead. The Golden State Killer case in 2018 is the famous, well-documented example that brought the method into public view.
Can my relative's DNA expose me?
Yes, at least partially. Because you share large stretches of DNA with your relatives, a profile uploaded by a cousin, sibling, or parent can create a genetic link back toward you even if you never tested or uploaded anything yourself. This is the uncomfortable part of genetic privacy: it isn't fully an individual choice, because your relatives' decisions affect you and yours affect them.
How do I keep my DNA away from law enforcement matching?
The most reliable step is to not place your genome in a database that permits matching in the first place — read your file with an on-device tool instead of uploading it. If you've already uploaded, check the current settings on that service: some let you opt out of law-enforcement matching or make your profile non-matchable, and most let you delete your data. None of this is legal advice, and the specifics differ by service and jurisdiction.
Does deleting my DNA help?
Deleting your uploaded profile reduces your future exposure and is worth doing if you no longer use a service. But deletion depends on the company honoring it, may not reach every backup, and cannot recall copies that were already exported or matched while the data was live. That gap is why not uploading in the first place is structurally cleaner than deleting later.
Do all DNA databases allow police searching?
No — they differ, and the details change over time. Some genealogy-matching databases have historically permitted or been involved in law-enforcement searches, sometimes on an opt-in basis; the major testing companies describe stricter policies requiring legal process. Because these settings and policies are revised periodically, the only reliable answer is to check the current terms of the specific service you use.
Does Quanome's data get searched by police?
Quanome reads your raw DNA file locally on your device, so there is no genome stored on a Quanome server to search, match, or hand over in response to legal process. That removes this particular question from the table — there's simply no server-side copy involved. As always, this is general information about how the tool works, not legal advice about your situation.
Quanome is live — free on iPhone and Android
Make sense of your DNA and health data privately. Download Quanome free on the App Store or Google Play.
Quanome is free on the App Store and Google Play. Want product news too? Leave your email below.
