Standards & data protection

How these standards protect laboratory and participant data

MyDNABank’s architecture and processes are informed by internationally recognised frameworks for information security, privacy and genomic data. Below is what each standard means in practice for laboratories storing data with us.

These frameworks guide our design and operations. References below describe how they inform our approach — they are not claims of formal certification unless separately stated in a written agreement.

What each standard means in practice

A plain-language view of how recognised security, privacy and genomic frameworks shape protection on MyDNABank.

Security & privacy frameworks

ISO 27001

What it is
The international standard for information security management systems.
How MyDNABank aligns
We apply its principles to access control, encryption, risk management and continuous monitoring of storage and access events.

ISO 27701

What it is
An extension of ISO 27001 focused on privacy information management.
How MyDNABank aligns
We use it to strengthen protection of personal data and participant privacy across the full data lifecycle.

ISO 27799

What it is
Guidelines for information security management in health, based on ISO 27001.
How MyDNABank aligns
We adapt security controls to the sensitive nature of health and genomic data.

GDPR

What it is
The European Union’s General Data Protection Regulation.
How MyDNABank aligns
It underpins our approach to lawful basis, consent handling, data-subject rights and processing within the EU.

HIPAA

What it is
The United States framework for protecting health information.
How MyDNABank aligns
Where US-related data or partners are involved, we follow its principles for handling protected health information.

Genomic & biobanking frameworks

GA4GH

What it is
The Global Alliance for Genomics and Health — frameworks and tools for responsible genomic data sharing.
How MyDNABank aligns
We draw on its guidance for interoperability, consent frameworks and controlled-access models in governed research access.

ISO 20387

What it is
A standard for biobanking competence and quality.
How MyDNABank aligns
It informs our practices for secure storage, handling and governance of genomic and associated data resources.

ISO/TC 215

What it is
The ISO technical committee for health informatics.
How MyDNABank aligns
We align our approach with broader health-informatics and data-exchange expectations.

What this means for you

  • Genomic data is encrypted before it reaches MyDNABank, with protection at rest and in transit
  • Access is role-based, least-privilege and continuously monitored
  • Every research request is checked against recorded consent scope before analysis proceeds
  • Raw participant data remains on governed pathways and is not handed over in an unmanaged way
  • Storage events, access requests and analysis runs are logged in a tamper-evident manner

Ready to discuss storage for your laboratory?