By: Paul Zajde

In 2018, California detectives famously used forensic evidence from a commercial DNA database to catch the Golden State Killer thirty-five years after his last murder, but privacy experts were not impressed with this scientific feat.[1] The database, GEDmatch, which hosts over a million users, was searched by law enforcement without a warrant or subpoena.[2] This was—and generally remains—entirely legal thanks to the third-party doctrine, which exempts the government from needing a warrant to search information held by a third party.[3] 23andMe and Ancestry, DNA databases with over fifteen million users combined, consider the third-party doctrine bad for business as customer concerns over privacy grow.[4] The industry therefore stands to gain from Montana and Maryland’s new restrictions on law enforcement searches of commercial DNA databases.

Montana passed into law H.B. 602 on May 7, 2021.[5] The statute provides that “a government entity may not obtain DNA search results from a consumer DNA database . . . without a search warrant . . . unless the consumer whose information is sought previously waived the consumer’s right to privacy in the information.”[6] The privacy waiver exception was not in the original bill, and privacy advocates argued that the enacted law will have little effect since most consumer DNA databases require a privacy waiver of some kind.[7] Notably, the privacy waiver exception does not apply to familial DNA search results, which was the method used to identify the Golden State Killer.[8] Search results from partial matching will also require a warrant irrespective of a privacy waiver.[9]

Maryland enacted a similar law on May 30, 2021.[10] However, instead of a warrant supported by probable cause, the Maryland statute only requires “judicial authorization.”[11] Authorization may only be granted in cases of murder, rape, felony sexual assault, “or a criminal act involving circumstances presenting a substantial and ongoing threat to public safety or national security.”[12] Further, before seeking authorization to search a commercial database, law enforcement must first search the Maryland DNA database and the National DNA database to no avail.[13]

Importantly, the Maryland statute prevents law enforcement from searching commercial databases unless the database “[p]rovides explicit notice to its service users . . . that law enforcement may use its service to investigate crimes or to identify human remains.”[14] Law enforcement may also seek authorization to access forensic material in a commercial database if the individual’s informed consent is obtained in writing.[15] This forensic material must be destroyed upon completion of the investigation.[16] The law also provides criminal penalties and a civil cause of action for violations of the statute.[17]

Ancestry claims that it received “no valid requests for access to customers’ DNA data between January 1 and June 30, 2021.”[18] Likewise, 23andMe claims that there have been no instances “where data was produced without prior, explicit consent by the individual specified in the request.”[19] Both companies have publicly stated that they do not voluntarily collaborate with law enforcement, and these laws will likely legitimize those claims and help the companies acquire new, privacy-conscious consumers.[20]

For example, pursuant to Maryland’s new statute, 23andMe and Ancestry could render their databases inaccessible to police by not providing “explicit notice to [their] service users .  .  . that law enforcement” could access their databases.[21] If new user agreements reflect this change, 23andMe and Ancestry should be able to concretely shield their customers from police searches in Maryland.[22] These new Fourth Amendment protections are likely to be featured in marketing campaigns to obtain customers who currently do not trust the relationship between these companies and law enforcement.[23]

