All chapters

Genomic Data Security for Research Labs

intermediate

Why Genomic Data Needs Extra Care

Genomic data is uniquely sensitive: it cannot be reset like a password, it implicates biological relatives, and re-identification risk persists even after de-identification in some cases. Any lab or team choosing where to process sequencing data should treat data handling as a first-class evaluation criterion, not an afterthought.

  • Encryption: is data encrypted both at rest and in transit, not just one or the other?
  • Access control: is access role-based and auditable, so you can answer "who viewed this sample" after the fact?
  • Data retention: can you control how long raw reads and intermediate files are retained, and request deletion?
  • Data residency: where is data physically stored, and does that satisfy your institution's or jurisdiction's requirements?

Questions Before Uploading Patient or Research Samples

  • Is there a written data processing agreement, and does it clearly state who owns the uploaded data and generated results?
  • What happens to data if a subscription or account is cancelled - is it deleted, exported, or retained indefinitely?
  • Does the platform support de-identified or pseudonymised sample naming, so personally identifiable information never needs to be uploaded directly?
  • Is encrypted storage the default for every tier, or only on specific paid plans?