Standards & data protection
How these standards protect laboratory and participant data
MyDNABank’s architecture and processes are informed by internationally recognised frameworks for information security, privacy and genomic data. Below is what each standard means in practice for laboratories storing data with us.
These frameworks guide our design and operations. References below describe how they inform our approach — they are not claims of formal certification unless separately stated in a written agreement.
Frameworks we design against
What each standard means in practice
A plain-language view of how recognised security, privacy and genomic frameworks shape protection on MyDNABank.
Security & privacy frameworks
ISO 27701
ISO 27799
GDPR
HIPAA
Genomic & biobanking frameworks
GA4GH
ISO 20387
ISO/TC 215
What this means for you
- Genomic data is encrypted before it reaches MyDNABank, with protection at rest and in transit
- Access is role-based, least-privilege and continuously monitored
- Every research request is checked against recorded consent scope before analysis proceeds
- Raw participant data remains on governed pathways and is not handed over in an unmanaged way
- Storage events, access requests and analysis runs are logged in a tamper-evident manner