Does Privacy Die With Humans? The Contested Status of Post-Mortem Data Rights

A recurring question in data protection practice is whether the dead retain any enforceable privacy interest, or whether privacy as a personal, dignity-rooted right necessarily expires at death. The answer varies sharply across jurisdictions, and the gap matters enormously in practice, especially for estates handling a deceased person’s digital accounts, for families seeking to stop republication of a deceased relative’s medical or genetic data, and for organisations deciding how long to retain records after a data subject dies.

The Default Position: Privacy Is Personal, and Personal Rights Die With the Person

Most data protection statutes define their scope by reference to a “living individual,” deliberately excluding the deceased. The GDPR is explicitly states that the Regulation does not apply to the personal data of deceased persons, leaving Member States free to legislate separately if they choose. Nigeria’s Data Protection Act 2023 follows the same architecture, defining a “data subject” in terms consistent with a living natural person, so the NDPC’s enforcement machinery is not generally available to a deceased person’s estate. Kenya’s Data Protection Act 2019 mirrors this approach. The doctrinal logic is that privacy protects dignity, autonomy, and informational self-determination capacities that, strictly speaking, require a living rights-holder to exercise them.

Where Member States and Common-Law Systems Diverge

The GDPR’s silence is not the end of the story — it is an invitation. Several EU states have legislated bespoke post-mortem regimes. France’s *Loi pour une République numérique* gives individuals the ability to leave binding instructions for how their data should be handled after death, enforceable by designated heirs. Under German jurisprudence, courts have recognised a limited posthumous personality right, allowing next of kin to challenge grossly disrespectful uses of a deceased person’s image or personal data, particularly in the period shortly after death.

South Africa’s POPIA takes a notably different, more protective stance. it explicitly extends certain obligations to the personal information of deceased data subjects, and next of kin or an estate representative can lodge complaints with the Information Regulator on the deceased’s behalf. This makes South Africa something of an outlier on the continent, granting statutory standing that Nigeria and Kenya withhold.

In the United States, there is no federal answer state law governs, and it varies widely. A handful of states have enacted Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA) provisions, giving executors defined rights to access a deceased person’s digital accounts for estate-administration purposes but this is an access-and-administration right, not a privacy right properly speaking. Separately, the common-law right of publicity in some states (notably California and a handful of others) survives death for a fixed term, protecting a deceased person’s name, image, and likeness from unauthorised commercial exploitation — closer to an intellectual-property interest than to informational privacy.

The Practical Gap This Creates

The consequence of excluding the deceased from data protection statutes is that families are frequently pushed toward alternative, less-fitting causes of action for defamation (which dies with the deceased in most common-law jurisdictions, since reputation is personal), breach of confidence (viable in some jurisdictions where information was disclosed in confidence during the person’s lifetime), or general tort principles around dignity and grief. None of these were designed for the specific harm of, say, a deceased person’s medical records being leaked, or their social media account being impersonated after death.

For privacy practitioners, the following three considerations should guide advice in this area

Check for jurisdiction-specific extensions.

Do not assume the GDPR’s exclusion of the deceased is universal. France, Germany, and South Africa each carve out meaningful post-mortem protections, and more EU states are legislating in this space.

Distinguish access rights from privacy rights.

RUFADAA-style statutes and executor powers solve an administrative access problem; they do not create a substantive privacy claim against a third party who has misused the deceased’s data.

Advise proactive planning: Where the law allows binding post-mortem data instructions (as in France), encourage clients to leave them. Where it does not, contractual and estate-planning tools including data provisions in wills, designated legacy contacts on major platforms remain the most reliable safeguard.

The global trend is not toward a uniform answer but toward a widening patchwork.Most data protection statutes still exclude the deceased by default, but a growing number of jurisdictions are carving out targeted protections in recognition that data-driven harms to the dead and to their grieving families are real, even if the doctrinal home for redressing them remains unsettled.

Add a Comment

Your email address will not be published.