safeguard the integrity, privacy, and security of genetic data and provide a civil penalty therefor.
What changed between versions
Added seven new definitions including 'biological sample,' 'consumer,' 'de-identified data,' 'direct-to-consumer genetic testing company,' 'express consent,' 'genetic data,' and 'service provider' to clarify who and what the law protects.
Requires direct-to-consumer genetic testing companies to provide clear privacy notices, obtain separate express consent for each use of genetic data beyond primary testing purposes, and implement security programs to protect genetic data.
Mandates that companies provide consumers with mechanisms to access, delete, or destroy their genetic data and biological samples, including revocation of consent within thirty days.
Requires companies to obtain informed consent for sharing genetic data with third parties for research purposes, following federal standards for human research subjects.
Authorizes the attorney general to seek civil penalties of up to $5,000 per violation for companies that fail to comply with the new genetic data protection requirements.