All chapters
Genomic Data Security for Research Labs
intermediateWhy Genomic Data Needs Extra Care
Genomic data is uniquely sensitive: it cannot be reset like a password, it implicates biological relatives, and re-identification risk persists even after de-identification in some cases. Any lab or team choosing where to process sequencing data should treat data handling as a first-class evaluation criterion, not an afterthought.
- Encryption: is data encrypted both at rest and in transit, not just one or the other?
- Access control: is access role-based and auditable, so you can answer "who viewed this sample" after the fact?
- Data retention: can you control how long raw reads and intermediate files are retained, and request deletion?
- Data residency: where is data physically stored, and does that satisfy your institution's or jurisdiction's requirements?
Questions Before Uploading Patient or Research Samples
- Is there a written data processing agreement, and does it clearly state who owns the uploaded data and generated results?
- What happens to data if a subscription or account is cancelled - is it deleted, exported, or retained indefinitely?
- Does the platform support de-identified or pseudonymised sample naming, so personally identifiable information never needs to be uploaded directly?
- Is encrypted storage the default for every tier, or only on specific paid plans?