Description

Entry into force with grace period of California Genetic Information Privacy Act

The Genetic Information Privacy Act (SB 41) was signed into law on 6 October 2021 by the Californian Governor. The act requires companies that provide direct-to-consumer genetic testing to inform consumers about the company’s policies and procedures regarding the collection, use, maintenance, and disclosure of genetic data and to obtain the consumer’s express consent for the use of their genetic data. The law gives consumers the right to revoke their consent in which case companies have to destroy the consumer’s biological sample within 30 days. Furthermore, the companies will have to comply with the laws for genetic data disclosure to law enforcement without the consumer’s consent and to implement and maintain security procedures to protect consumers’ genetic data. The law will take effect from 1th of January 2022.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
other service provider
Implementation Level
subnational
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2021-09-09
adopted

On 9 September 2021 the California Senate passed the Genetic Information Privacy Act (Senate Bill 4…

2021-10-06
in grace period

The Genetic Information Privacy Act (SB 41) was signed into law on 6 October 2021 by the California…

2022-01-01
in force

The Genetic Information Privacy Act (SB 41) is implemented on 1 January 2022. The act requires comp…

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Private organisation
Economic activity other service provider
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data: genetic: data collection
Regulatory tool
Obligation to make customer data available to government agencies
User consent: Opt-in requirement
User right to deletion of personal data
Sanctions
Fine
Regulated subjects
1
personal data: genetic: storage (any form)
Regulatory tool
Obligation to make customer data available to government agencies
User consent: Opt-in requirement
User right to deletion of personal data
Sanctions
Fine
Regulated subjects
1
personal data: genetic: data processing
Regulatory tool
Obligation to make customer data available to government agencies
User consent: Opt-in requirement
User right to deletion of personal data
Sanctions
Fine
Regulated subjects
1

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data: genetic: data collection

personal data: genetic: storage (any form)

personal data: genetic: data processing