Postmortem Privacy and Digital Legacy: Who Controls Your Data After Death?
Written by Daniel Tanguay, founder of Solexi.ai.
When a person dies, their data does not. Messages, photos, cloud folders, medical records and social accounts continue to exist under the control of companies, and the question of who may open them is answered differently depending on the country, the platform and the family. Postmortem privacy is the name given to that unresolved question.
What is postmortem privacy?
Postmortem privacy refers to the interest a person has in controlling what happens to their personal information after they die. It is not a single rule but a contested area where privacy law, property law, contract law and platform policy overlap, and where the person most concerned can no longer speak.
Recent scholarship treats it as a political question as much as a legal one. Mauricio Figueroa's 2026 preprint “The politics of postmortem privacy” frames the governance of deceased persons' data as a matter of memory, dignity and power, and notes that approaches diverge considerably across jurisdictions and cultures rather than converging on one model.
- It concerns the personal data of someone who can no longer consent.
- It sits between privacy interests, family interests and commercial control.
- It is governed by a mix of statute, contract and platform policy.
- It is answered differently in different legal and cultural settings.
Does privacy end when a person dies?
In many legal systems, data protection rights are framed around living individuals, which means the strongest privacy protections may weaken or disappear at death. That does not leave the data unprotected: confidentiality obligations, contract terms, criminal law on unauthorized access and the platform's own rules all continue to apply.
The practical consequence is a gap. A family may have a moral claim to a parent's photographs and no mechanism to obtain them, while a platform may hold private messages it is contractually unwilling to disclose to anyone. The result depends far more on where you live and which service you used than on what you would have wanted.
Who may control digital information after death?
Four actors can end up deciding: the deceased person (only if they left instructions or configured a provider tool in advance), the executor or equivalent fiduciary, the surviving family, and the platform itself. When the first is silent, the other three negotiate — usually slowly, sometimes in conflict.
- The account holder, through advance instructions and provider settings.
- An executor, liquidator or fiduciary, within the authority the law grants.
- Family members, who often act without any formal authority at all.
- The service provider, applying its terms of service and its own process.
Why laws differ between jurisdictions
Figueroa's work highlights how differently the question is treated across Europe, the United States and Global South contexts, where legal traditions, data protection frameworks and cultural attitudes toward the dead do not align. Some systems extend a form of protection to the deceased or grant relatives standing; others treat the data as an ordinary asset of the estate; others leave it almost entirely to contract.
For a family, this divergence is not academic. It determines whether an executor has a statutory route to an account, whether a platform can lawfully refuse, and whether a request made from one country will be honoured by a company incorporated in another.
Family access versus personal privacy
The two interests genuinely conflict. A grieving family often wants everything: the photographs, the messages, the last conversations. The person who died may have wanted some of it preserved, some of it shared with one specific person, and some of it never seen again.
The qualitative study by Edina Harbinja, Marisa McVey and Lilian Edwards, published in SCRIPTed in December 2024, reports that awareness of these issues remains low, that existing platform mechanisms are limited, that regulatory clarity is lacking, and that legal professionals themselves face difficulty advising on digital legacy. The authors point to a need for education rather than to any settled solution.
What happens to private messages?
Private correspondence is the most contested category, because it always involves at least two people. Disclosing a message archive to a family reveals the other party's side of the conversation too, and that person never agreed to anything. Several providers therefore treat message content as the item they are least willing to release, even where they will hand over photos or account data.
Photos and digital memories
Photographs are usually the least contested and the most frequently lost. They are rarely sensitive, families almost always want them, and they are almost always stored in a cloud account nobody else can open. The obstacle is not law or policy but access: an encrypted phone, an unknown password and a second factor tied to a disconnected number.
Cloud accounts
Cloud storage concentrates everything else — scanned documents, backups, work archives, financial statements — into a single account protected by a single recovery chain. Whether a family can reach it after a death depends almost entirely on whether the account holder configured the provider's own inheritance mechanism while they were able to.
Social media
Social platforms were the first to build formal postmortem processes, and they remain the most visible: memorialization, legacy contacts, deletion requests and inactivity triggers. They are also the narrowest, because each one applies only to that platform and grants only the level of access that platform has decided to offer.
AI-generated representations after death
Voice, image and writing style can now be reconstructed from ordinary personal data, which creates a category of postmortem harm that older privacy frameworks were not designed for. A person may be entirely comfortable with their photographs being preserved and entirely opposed to a synthetic version of their voice speaking words they never said.
Because the law here is unsettled, the only reliable protection currently available is an explicit, documented statement of what the person did and did not consent to.
Consent before death
Consent given in advance is the one input that resolves most of the conflicts above. It tells the family what was wanted, gives the executor something to act on, and gives the platform a reason to apply the more generous of its options. Without it, every actor is guessing, and the guess with the most force behind it wins.
Why user intent matters
Preservation and disclosure are two different decisions that are habitually treated as one. Keeping a document safe does not require showing it to everyone, and sharing an album with a sibling does not require handing over an email archive. Recording intent separates them.
What families should discuss in advance
These conversations are uncomfortable and short. They are also the only reliable mechanism available today, since neither law nor platform policy currently supplies a general answer.
- Which accounts and archives exist, in general terms.
- Who should be contacted first, and who should not be given access.
- What should be preserved, and what should be deleted unread.
- Whether any synthetic reproduction of voice or image is acceptable.
- Where written instructions are kept and who can find them.
The Solexi perspective
Solexi.ai is being designed around the principle that preserving information does not automatically mean making all information accessible. Digital continuity should respect user intent, privacy and defined access.
That is a design principle, not a legal remedy. Solexi.ai does not provide legal advice and does not change what any platform or jurisdiction permits.
Pricing, in plain words
- 14 days free, 1 GB included during the trial
- Then CAD $199, one time only
- Lifetime access, 10 GB included
- No monthly subscription, no renewal
Frequently asked questions
Do dead people have privacy rights?
It depends on the jurisdiction. Many data protection regimes are built around living individuals, so the strongest rights may not survive death, while other legal traditions extend some protection to the deceased or give relatives standing. Research on postmortem privacy describes this variation as substantial rather than converging.
Can my family read my private messages after I die?
Not automatically. Message content is the category providers are generally most reluctant to disclose, partly because it also exposes the other participants in the conversation. Access usually depends on the provider's process and on what you configured in advance.
Is postmortem privacy a settled area of law?
No. Published research points to limited regulatory clarity, differing national approaches and difficulties even for legal professionals advising in this area.
Can I stop an AI from imitating me after my death?
There is no general, settled protection today. The practical step available now is to state your position explicitly in writing and tell the people who would be asked.
Sources & Further Reading
The organizations, researchers and professionals referenced on this page do not necessarily endorse, partner with or have any relationship with Solexi.ai. They are cited as independent sources documenting issues related to digital legacy and continuity.
- The politics of postmortem privacy
arXiv preprint — Mauricio Figueroa — Published 2026-07-10 — Last verified : 2026-08-28
https://arxiv.org/abs/2608.16905 - Post-mortem privacy and digital legacy — a qualitative enquiry
SCRIPTed: A Journal of Law, Technology & Society — Edina Harbinja, Marisa McVey, Lilian Edwards — Published 2024-12-19 — Last verified : 2026-08-28
https://journals.ed.ac.uk/script-ed/article/view/10147
Last reviewed : 2026-08-28
Solexi does not replace a legal will, a notary or a lawyer. Solexi helps you gather, organize and pass on your information.