DNA database removal is a portfolio operation across four separate systems: forensic indexes such as CODIS and state databanks, which require a legal expungement petition; direct-to-consumer companies like 23andMe and AncestryDNA, where account closure, raw data deletion, research consent withdrawal and sample destruction are separate steps; genealogy matching sites where a relative’s upload may control exposure; and law-enforcement sharing arrangements.
Key facts
- FBI expungement means removal from NDIS plus destruction of the physical sample and extracted DNA.
- Maryland requires removal from every database within 60 days of a qualifying non-conviction outcome.
- 23andMe deletion runs through Settings, Privacy and Data, Delete Account, with a grace period before it is final.
- Consumer companies may take 30 to 60 days; GDPR Article 17 and CCPA give deletion rights subject to exceptions.
Where ContentRemoval.com comes in. Forensic expungement belongs with a genetic-privacy attorney. What remains afterward is the exposure that often surrounds it: people-search listings, arrest record aggregators, leaked databases and doxxing material tied to your identity. ContentRemoval.com handles that layer through source removal, de-indexing and monitoring, keeping it separate from the legal record strategy. Individuals, family offices and their counsel usually make contact. A free 15-minute Exposure Scan maps what is removable, and the report is yours to keep. Get a Free, Confidential Exposure Scan or read how our content removal work is done.
You’ve just learned that your genetic information may exist in several places you never intended to authorize. Your 23andMe account still holds a profile, a relative uploaded shared DNA to GEDmatch, a forensic sample was collected after a 2019 arrest, and FamilyTreeDNA may sit inside a law-enforcement access pathway. The instinctive response is to send one deletion request. That instinct is wrong.
DNA database removal is a portfolio operation. Each repository has a different custodian, legal basis, evidence standard, and definition of “deleted.” A criminal profile is governed by statutes and chain-of-custody rules. A consumer genetics account is governed largely by contract, privacy policy, and applicable data-protection law. A genealogy upload may be controlled by a relative rather than by you. A law-enforcement sharing arrangement can create access relationships that aren’t visible from your consumer account.
Why DNA Database Removal Is Not One Request
The phrase “delete my DNA” hides four separate systems.
Criminal and forensic indexes include state DNA databanks, the FBI’s CODIS and NDIS structures, and crime-scene repositories. These systems exist for law-enforcement purposes. A customer-service email won’t remove a profile that statutory authority allows an agency to retain. Eligibility, certified court records, and communication through the proper state or federal channel control the outcome.
Direct-to-consumer companies such as 23andMe, AncestryDNA, and MyHeritage operate differently. You may be able to close an account, delete a raw genetic file, withdraw research consent, and request destruction of a stored saliva sample. Those actions can be separate. Account closure alone isn’t proof that the biological specimen or every derived dataset has been destroyed.

Genealogy and matching databases add another layer. A person may never have tested with GEDmatch or FamilyTreeDNA, yet a relative’s upload can expose shared genetic relationships. Your own account deletion doesn’t necessarily remove information derived from another person’s file.
Law-enforcement bulk-sharing arrangements are separate again. A company or matching platform may permit access under its terms or in response to legal process. That access can involve custodians, processors, and downstream users that aren’t represented by the account interface you can see.
The governing principle: One profile can produce several records, samples, matches, and access pathways. A successful removal strategy must identify each one separately.
The fragmentation has a legal explanation. Statutory authority governs forensic indexes, contractual consent governs many commercial services, and laboratory procedures govern physical samples. Privacy laws may provide a request right, but they don’t automatically override a criminal retention rule, a court order, or another person’s upload.
That distinction also applies to European privacy requests. A person seeking removal of consumer-held personal data may need a formal privacy-law route, such as the GDPR right to be forgotten, while a person challenging a forensic profile needs an expungement analysis. Treating both as ordinary customer support cases wastes time and can preserve the wrong evidence trail.
Forensic and Criminal DNA Expungement
Forensic removal begins with legal eligibility, not with a generalized privacy complaint. The relevant question is whether the law permits destruction of the sample and deletion of the profile based on the case outcome, the offense, and the jurisdiction that collected the DNA.
The operational standard is broader than deleting a line from a database. The FBI defines expungement as complete removal of the profile from NDIS together with destruction of associated biological materials, including liquid blood, FTA and non-FTA cards, buccal collection devices, extracted DNA, and amplified DNA. The FBI DNA expungement policy therefore sets two endpoints, not one.
Establish eligibility and assemble proof
Potential routes can arise after an arrest that didn’t lead to conviction, a dismissal, an acquittal, a reversed conviction, or another qualifying legal outcome. Juvenile matters, misdemeanors, and felony cases require jurisdiction-specific analysis. A qualifying conviction can override a request, and an unpaid obligation or outstanding warrant can create a practical barrier even where the applicant believes the underlying case ended favorably.
The file should normally include:
- Certified disposition: Provide the final court record establishing dismissal, acquittal, reversal, or another qualifying result.
- Identity evidence: Include government identification and any information needed to match the request to the laboratory record.
- Jurisdictional form: Use the applicable state form, such as a California DOJ or BSCC process, a Florida FDLE request, or a New York DCJS form where required.
- Sworn declaration: State the relevant non-conviction facts accurately and identify every known collection event.
- Custodian inventory: Ask which agency, laboratory, state databank, and federal channel received the profile or sample.
The sequence matters. Submit the petition to the originating agency or designated state authority, obtain laboratory verification, request removal from the state databank, and require the state CODIS administrator to address NDIS notification. If a private laboratory holds a retained specimen under contract, send a parallel destruction request. Don’t assume the public agency’s action reaches a contractor automatically.
Compare the state-level mechanics
The legal mechanics differ sharply. Maryland requires destruction or expungement when a qualifying case doesn’t end in conviction, when a conviction is finally reversed or vacated without a new trial, or after an unconditional pardon. Its statute also requires removal from every database the record entered, including local, state, and federal systems, within 60 days of the triggering event. See the Maryland DNA expungement statute.
| State | Eligible Offenses | Petition Channel | Typical Timeline |
|---|---|---|---|
| Maryland | Qualifying matters ending without conviction, final reversal or vacation without a new trial, or unconditional pardon | Statutory expungement through the responsible state process | Statutory action within 60 days of the trigger |
| California | No past or present qualifying offense and no other legal basis to retain the specimen, sample, or searchable profile | California DOJ and applicable court or prosecutorial process | Depends on eligibility, documentation, and agency handling |
| Wyoming | Records subject to an expungement order | CODIS Manager, with NDIS deletion request and written confirmation | Removal and confirmation within five working days after the order under the state rule |
Wyoming’s rule requires the CODIS Manager to remove identifying information and DNA records from the state database within five working days after an expungement order, request deletion from NDIS, and provide written confirmation to the laboratory supervisor within five working days. California law separately requires destruction of the specimen and sample and expungement of the searchable profile where the statutory eligibility threshold is met. The Wyoming CODIS rule illustrates why written confirmation should be treated as a deliverable, not a courtesy.
If you’re still determining whether your underlying criminal matter qualifies, a focused resource on crimes eligible for record erasure can help frame the broader record-removal analysis. It doesn’t replace a DNA-specific petition, but it can clarify why a favorable disposition may support more than one remedy.
Track three confirmations: profile deletion, physical-sample destruction, and written completion evidence. If any one is missing, the file is incomplete. For related arrest-record exposure outside the DNA system, the arrest record removal service addresses a separate but often connected privacy problem.
Direct-to-Consumer Genetic Companies
Commercial deletion is more accessible than forensic expungement, but it still fails when a customer confuses account closure with full data destruction. Your instruction should address the account, raw genetic data, research participation, matching functions, and stored biological sample as distinct items.

For 23andMe, use the account settings path, Settings, Privacy & Data, Delete Account. Submit a separate written request for destruction of the biological sample, identify the biobanking consent, and expressly revoke research participation if you previously opted in. The service’s stated deletion process includes a grace period before irreversible deletion, so preserve the request date and ask for written confirmation after the period ends.
For AncestryDNA, use DNA, Settings, Delete Test. Follow up with support in writing, requesting destruction of the stored saliva sample and revocation of informed consent for research. Don’t rely on the deletion screen to prove that a sample has been destroyed.
For MyHeritage, use Settings, My Profile, Delete Account, then send a separate DNA kit destruction request. Treat the DNA account, family-tree content, matching status, raw data, and physical kit as separate records in your request.
FamilyTreeDNA requires the same discipline. Address account closure, matching visibility, research participation, and any law-enforcement-related access setting independently. With 23andMe research opt-in, revoke consent separately from account deletion, then ask the company to identify what data remains in any legally permitted retention category.
A practical request should identify the account email, kit or sample identifier, desired deletion actions, consent revocation, sample destruction, downstream sharing restrictions, and the person authorized to receive confirmation. Companies may process these requests over 30 to 60 days, depending on the platform and request type. Preserve every ticket number and insist on a written response that distinguishes deletion from suppression, account closure, and sample destruction.
The central trap is simple: closing an account may not delete a raw DNA file held on research servers, and withdrawing research consent may not automatically erase information already processed under a separate legal basis. The platform’s privacy policy controls the mechanics, but your written request should remove ambiguity.
This short walkthrough provides a visual reference for the account-level process:
Ask for confirmation of each endpoint. If the response only says “your account has been closed,” send a follow-up demanding a direct answer about the raw profile, biological sample, research consent, matching participation, and third-party disclosures.
Privacy Law Routes That Actually Move Records
Privacy law can force a commercial custodian to respond, but it doesn’t create a universal right to erase a forensic profile. The strongest route depends on residence, the company’s role, the data category, and whether another legal obligation requires retention.
Under GDPR Article 17, a qualifying data subject can request erasure from a controller, subject to exceptions such as legal obligations, public interest, and legal claims. The request should identify the data, state that erasure is sought under Article 17, ask the controller to notify relevant recipients where required, and request a reasoned explanation for any refusal. Escalation generally goes to the relevant European supervisory authority.
The CCPA and CPRA provide a deletion right for covered personal information, subject to exceptions. A California request should identify the consumer, specify the genetic data or account at issue, request deletion from the company’s systems and service providers where applicable, and ask the business to identify the statutory basis for any denial. The California Privacy Protection Agency or the California attorney general may become relevant depending on the dispute.
State genetic privacy statutes create a patchwork rather than a single American standard. Illinois GIPA emphasizes written consent before genetic information is collected, disclosed, or analyzed in covered circumstances. California treats genetic information as a sensitive category under its privacy framework. Utah, Florida, and Washington provide different protections and exclusions, so the request must be specific to the custodian and the transaction.
| Jurisdiction | Statute | Deletion Right | Response Window | Enforcement Body |
|---|---|---|---|---|
| European Union and EEA contexts | GDPR Article 17 | Erasure subject to statutory exceptions | Use the controller’s applicable GDPR response period | Relevant national supervisory authority |
| California | CCPA and CPRA | Deletion subject to statutory exceptions | Use the business’s applicable California privacy response process | California Privacy Protection Agency or attorney general |
| Illinois | GIPA | Consent and disclosure protections, with remedies depending on the facts | Depends on the request and dispute route | Illinois courts and applicable enforcement authorities |
| Other U.S. states | State-specific genetic and consumer privacy laws | Varies by statute, custodian, and exemption | Varies by jurisdiction and business process | State regulator or court, depending on the law |
Don’t send a generic “delete everything” message to a pathology provider, testing company, or broker. A medical or forensic custodian may disclose a different retention rule than a consumer platform. A provider’s notice, such as the Texas Autopsy Services privacy notice, shows why the identity of the custodian matters before you choose a legal route.
Demand precision: Ask what was deleted, what was retained, why it was retained, who received it, and whether the biological sample was destroyed.
A regulator complaint works best when supported by the original request, delivery record, account identifiers, the company’s substantive response, and a concise explanation of the unresolved endpoint. Privacy law is a tool, not a substitute for identifying the correct database.
Where Deletion Is Legally Impossible
Some records won’t disappear because the custodian has a continuing legal basis to hold them. A consumer request can’t override a qualifying criminal retention rule, a live investigation, a court order, or another person’s independently controlled upload.
CODIS, NDIS, and state forensic indexes require an eligibility analysis. If the legal basis for retention remains, an agency can refuse deletion. Even when an expungement order exists, the practical problem may be incomplete propagation between local, state, and federal repositories. The remedy is not repeated customer-service emails. It is a properly supported petition, agency escalation, and documented confirmation from each relevant custodian.
GEDmatch and FamilyTreeDNA matching environments present a different obstacle. Your relative may control the upload, and your opt-out can’t necessarily erase the relative’s file or every match derived from it. If a platform’s terms permit law-enforcement matching, account-level privacy changes may limit future access without undoing a prior disclosure.
Third-party reuploaders and raw-data brokers sit outside the original laboratory’s control. A person can download a file from one service and upload it elsewhere, creating a fresh record with a new custodian. The original deletion confirmation doesn’t reach that new copy.
The durable responses are narrower than many privacy vendors admit:
- Litigate or enforce expungement: Use the court order and statutory mechanism where a forensic profile remains unlawfully retained.
- Pursue sealed-court relief: Ask counsel whether a sealed motion or protective order can address ongoing access or disclosure.
- Consider defensive data strategies only with counsel: Deliberately altering or poisoning raw genetic data can create legal, scientific, and family consequences. It isn’t a default recommendation.
- Control family uploads: Tell relatives, in writing, that uploading shared genetic material can expose your relationships and that you object to further disclosure.
The right objective isn’t an unrealistic promise that every trace can vanish. It is to remove lawful-to-remove records, stop new sharing, identify access that should end, and preserve evidence when a custodian refuses.
Monitoring and Reupload Prevention
A deletion request is the opening move, not the durable defense. Genetic information is unusually difficult to contain because relatives share portions of it, raw files can be copied, and a new upload can recreate exposure after the original account has vanished.
Build a monitoring regime around the four ecosystems. Start with quarterly genealogy audits. Review public genealogy forums and matching services for references connected to your known family identifiers, and use controlled synthetic kits only where the method is lawful, platform-compliant, and reviewed by counsel. The objective is detection, not covert access to another person’s account.
Configure breach monitoring for raw genetic files and database dumps where the service supports that function. A raw-data file hash can help identify a known copy, but it won’t detect every transformed or re-encoded file. Treat an alert as an evidence lead, not proof that a particular platform still holds the original.

Put family controls in writing
Family members can unintentionally defeat a carefully executed removal plan. Conduct a family-tree audit to identify relatives who have tested, then send a clear written directive explaining that uploading shared genetic material may expose other family members. For an estate or family office, address genetic-data handling in succession documents and privacy protocols so heirs don’t treat a testing kit as an ordinary consumer asset.
Save every deletion confirmation, sample-destruction response, research-consent revocation, and support ticket in an evidence ledger. Record the date, custodian, account or kit identifier, requested action, response, and unresolved issue. That record supports a regulator complaint, a court filing, or a renewed request after a platform changes ownership or policy.
Set annual reviews across all four ecosystems and shorter reviews after a known breach, family upload, legal proceeding, or platform-policy change. If raw credentials, database dumps, or related identity material appear online, dark web monitoring can form part of a broader exposure-monitoring program, although it can’t delete a forensic record held under statutory authority.
Durable protection comes from repetition: Remove what can be removed, restrict new uploads, monitor for reappearance, and preserve evidence every time.
The person coordinating this program should have authority to contact relatives, vendors, counsel, and family-office administrators. Fragmented ownership produces fragmented results.
Building Your Removal Strategy and Knowing When to Escalate
Start with the threat model, not the wishlist. If a past arrest creates the greatest legal or professional risk, address the forensic index first. If commercial exposure is the concern, prioritize the testing companies and sample destruction. If a relative uploaded shared DNA, the family and matching problem takes priority. If a data broker or breach market has copied identity material, pursue source removal and monitoring separately.
The sequence should be deliberate:
- Forensic eligibility first: Obtain certified dispositions and pursue state expungement, including the federal NDIS channel where applicable.
- Commercial closure second: Delete DTC accounts, revoke research consent, request raw-data deletion, and obtain sample-destruction confirmation.
- Relative-upload audit third: Identify matching databases and contact the uploader or platform about privacy settings and deletion.
- Processor demands fourth: Use GDPR, CCPA, or another applicable privacy law against residual commercial processors and brokers.
- Monitoring last, and continuously: Watch for reuploads, new family uploads, breach exposure, and unexplained access.
Escalate when a custodian sends a refusal without a substantive legal explanation, fails to respond meaningfully within 30 days, continues to permit law-enforcement access after a valid expungement, or when unknown relative matches indicate an unauthorized upload. A genetic-privacy attorney should handle contested statutory eligibility, court orders, subpoenas, and any dispute involving forensic retention. A removal-service vendor can help with consumer-facing exposure, data brokers, leaked databases, search results, and ongoing monitoring. A straightforward DTC deletion request can be handled personally if the account owner can document every step and follow up firmly.
ContentRemoval.com offers personal-data removal support for people-search listings, exposed addresses and phone numbers, leaked credentials, database dumps, doxxing material, and court or public-record aggregators. Its role is distinct from forensic expungement counsel, but it can help manage the online and broker exposure that remains after the legal record strategy is complete.

DNA database removal isn’t a one-time event. It is an ongoing privacy posture built from legal eligibility, precise requests, verified destruction, family controls, and documented monitoring.
If your genetic data is tied to leaked databases, people-search records, doxxing, or exposed personal information, ContentRemoval.com can assess the exposure and build a discreet removal and monitoring plan. Contact the firm for a confidential review that separates forensic legal remedies from commercial and online data-removal actions.
Frequently asked questions
How do I get my DNA removed from a criminal database?
Start with legal eligibility: a dismissal, acquittal, reversal or other qualifying outcome. Assemble the certified disposition, identity evidence, the state’s expungement form and a sworn declaration, then petition the originating agency or state authority, obtain laboratory verification, and require the state CODIS administrator to notify NDIS. Track three confirmations: profile deletion, sample destruction and written completion.
Does deleting my 23andMe or Ancestry account destroy my DNA sample?
Not automatically. Account closure, raw genetic file deletion, research consent withdrawal and destruction of the stored saliva sample are separate actions. Send a written request that names each one, including the kit identifier, and insist on a response that distinguishes deletion from suppression and account closure. Companies may take 30 to 60 days.
Can I remove my DNA from GEDmatch if a relative uploaded it?
Usually not on your own. The relative controls the upload, and your opt-out cannot erase their file or every match derived from it. Adjusting privacy settings may limit future law-enforcement matching without undoing prior access. The practical steps are a written objection to the relative, a request to the platform, and ongoing monitoring.