TL;DR: Your provider's privacy information should explain who handles your blood test data, why and for how long, including relevant sharing and transfer arrangements: ICO privacy-information guidance.
Key takeaways
- Personal test results that reveal health information fall within the ICO's description of health data, which receives extra protection: special category data guidance.
- Privacy information should explain purposes, the lawful basis, retention and applicable sharing arrangements: ICO's information checklist.
- Consent is not the only possible legal condition for using health data, so ask which rules apply to the proposed use: ICO processing guidance.
- You can request deletion, but the right does not apply in every circumstance: ICO guidance on erasure.
- mescreen™'s current process page describes international sample shipment and digital reporting; it is not a complete explanation of every data-handling arrangement: How mescreen™ Works.
Why does blood test data need particular care?
Blood test data linked to an identifiable person can reveal health information, placing it within a specially protected category of personal data. The Information Commissioner's Office, or ICO, includes personal test results in its explanation of health data.
The ICO explains that health data covers more than a named diagnosis. Information revealing someone's health status can fall within the definition even when it does not identify a particular condition. That is a data-protection point, not a claim that a test can diagnose anything.
When comparing home blood tests, put health data privacy alongside the sample instructions and intended use. Our recommendation is to ask how the information will be handled before you provide it, rather than trying to reconstruct the arrangement afterwards.
“Your privacy matters” is a pleasant sentence. On its own, it is not much of an explanation.

Who should the privacy information identify?
It should identify the organisation collecting the data and explain relevant recipients or categories of recipients. ICO guidance says this can include organisations processing information on the provider's behalf, not just organisations receiving it for their own purposes.
You do not need to master the entire supply chain to ask a useful question. Start with: which organisation is responsible for my information, which other organisations handle it, and what does each need it for?
Ask the provider to explain the service you are actually considering. Do not assume the brand taking payment, the laboratory doing the analysis and the system providing the report are necessarily the same organisation. Equally, do not assume that different organisations imply a problem. The point is to obtain the actual arrangement, not guess it.
The ICO allows recipients to be described by category where appropriate. If a description is too broad to help you understand the service, ask for clarification rather than treating unfamiliar wording as evidence of misconduct.
Does buying a test mean consenting to every use of the data?
Do not treat a purchase as an explanation of every data use; ask what the provider proposes to do and what legal basis supports it. The ICO says organisations must explain their purposes and lawful basis for processing personal data.
For special category data, the ICO's processing guidance describes two layers: a lawful basis under Article 6 of the UK General Data Protection Regulation, or UK GDPR, and an applicable condition under Article 9. Explicit consent is one possible condition, not the only one.
Our suggested questions are deliberately concrete: is the information used only to provide the service, or also for research, marketing, product development or another purpose? Which uses are optional, and how would a choice be changed later? These are questions for the provider, not claims about mescreen™'s current practices.
The answer should separate the purposes. “Improving your experience” should not have to explain quite so much by itself.

What should you ask about international handling?
Ask where the sample goes and where the associated personal data is handled as separate questions. A statement about sample shipping is not a complete description of report storage, access or data transfers.
The current mescreen™ UK process page says a guided finger-prick dried blood spot sample is shipped internationally to a partner laboratory. It also describes digital reporting and an optional educational walkthrough. These are first-party process statements, not an independent audit of data protection.
If you are considering that service, request the current privacy information covering laboratory handling and the reporting system. Ask which locations and organisations are involved and what safeguards apply to any relevant international data transfers. The ICO's privacy-information guidance includes information about international transfers and applicable safeguards.
This article does not establish a partner country, server location, transfer mechanism or security standard for MeScreen. Those details should come from current, service-specific documentation, not a reassuring guess.
How long can a provider keep your results?
The provider should explain the retention period or the criteria used to decide it; there is no single period established by this article. That distinction appears in the ICO's privacy-information checklist.
Ask which records the answer covers. Your practical checklist might distinguish account details, reports, support correspondence and any other information used in the service. Ask about physical sample storage separately rather than assuming a data-retention answer covers the sample too.
Request the explanation before treating account closure as the end of every record. This is a question about the provider's actual policy and obligations, not a suggestion that information is being kept improperly.
There is no need for a dissertation. A clear account of what is kept, why and for how long is a perfectly respectable ambition.

Can you ask for blood test data to be deleted?
Yes, you can request deletion, but that does not mean every record must always be erased. The ICO's public guidance explains the right to erasure and circumstances in which an organisation can retain information, including legal obligations or the establishment, exercise or defence of legal claims.
If an organisation refuses a request, the same guidance says it should explain why and tell you about the right to complain. This article does not decide whether an exception applies to a particular provider or record.
Our recommendation is to identify the information you want deleted and ask what, if anything, would remain and why. If you are unhappy with the response, the ICO advises raising the complaint with the organisation first, then complaining to the ICO if the issue remains unresolved.
Where does mescreen™ fit into this decision?
mescreen™'s current UK page describes a wellness and functional laboratory assessment, not a medical diagnostic test. It says the result should not be used to rule a medical condition in or out and does not replace appropriate medical care: How mescreen™ Works.
That intended-use boundary is separate from the privacy questions. A clear explanation of data handling does not establish clinical usefulness, and a product description does not by itself demonstrate a provider's data-protection compliance.
For a broader purchasing discussion, see questions to ask before buying an at-home health test. Keep intended use, clinical evidence and privacy information as separate parts of the decision.
Limitations
This is a consumer checklist, not legal advice, a security assessment or an audit of mescreen™ or another provider. It does not verify retention periods, sharing practices, laboratory location, encryption or compliance. It does not imply that any provider has acted improperly.
The cited ICO pages currently display notices that guidance is under review following changes made by the Data (Use and Access) Act. Use the latest ICO guidance and service-specific documentation for a current decision, and seek qualified advice where necessary.

No clinical application, individual result interpretation or health benefit is established here. Generated images are editorial illustrations, not patient records, security certificates, mescreen™ facilities or testimonials.
What should you ask before ordering?
Ask for the latest privacy information covering the service you are considering. Contact mescreen™ for the relevant notice and clarification of any unanswered data-handling questions. You do not need to include a test report merely to request general privacy information.
Sources
- What is special category data?, Information Commissioner's Office. Health-data definition and examples; displayed update 9 April 2024.
- What are the rules on special category data?, Information Commissioner's Office. Lawful basis and additional processing conditions.
- What privacy information should we provide?, Information Commissioner's Office. Purposes, recipients, transfers, retention and rights.
- Your right to get your data deleted, Information Commissioner's Office. Erasure, exceptions and complaints.
- How mescreen™ Works, mescreen™ UK.
- At-Home Health Tests UK: Questions Before You Buy, mescreen™ UK.
- Contact mescreen™, mescreen™ UK.

