What I worry about is having this data laundered through a couple of vendors.
"How could we know our vendor's vendor was using genetic information in their proprietary risk score?"
"How could we know our client's client was using our score for life, health, or auto insurance/employment/lending/etc decisions?"
It's a "can't unring a bell" situation and the gaps in the regulations and the incentives for bad behavior are enormous.