CASE FILE #61

A Digital Estate Is Governed by Both Law and Platform Rules

Photographs, cloud storage, email, subscriptions and cryptographic keys are subject to different legal and technical arrangements after death. A list of accounts alone is not enough without instructions, authority and secure access.

A Digital Estate Is Governed by Both Law and Platform Rules
Editorial illustration created with AI assistance.Photographs, cloud storage, email, subscriptions and cryptographic keys are subject to different legal and technical arrangements after death. A list of accounts alone is not enough without instructions, authority and secure access.
Listen
00:00/00:00
1.00 ×
Ready
Article contents
  1. 1. What the evidence shows
  2. 2. How to read the claim in context
  3. 3. Five questions to ask
  4. 4. Conclusion

Technology, privacy & family

The bereaved may know someone’s wishes and still be unable to access their data. A provider may offer a tool for heirs, an account may be tied to a device, and some secrets should not be known by anyone else. A digital estate is therefore not one password in an envelope, but a plan for different kinds of assets.

1. What the evidence shows

Recital 27 of the GDPR states that the Regulation does not apply to the personal data of deceased persons and leaves Member States free to provide their own rules. This does not mean that all data automatically become public or legally unprotected after death.[1]

Google offers Inactive Account Manager, in which users can set a waiting period, contacts and selected data to share in advance, or arrange for the account to be deleted. The feature helps only if it has been configured beforehand and the contact details remain current.[2]

Apple lets users designate a Legacy Contact. A request for access requires an access key and a death certificate, and the data made available are subject to limitations; this is not a transfer of the password or a complete unlocking of the account.[3][4]

2. How to read the claim in context

The inventory must first be divided into memories, financial or business assets, licenses and subscriptions, work data, health information and authentication secrets. Each category needs a different custodian and a different transfer method.

A password in a will may be out of date years later, and a will may not remain confidential at every stage of the proceedings. It is safer to use the platform’s official tools, a password manager with emergency access, and a separate instruction document that does not contain the secrets themselves.

The plan must also specify what should be deleted. Automatically preserving everything can harm the privacy of both the deceased and the people in their messages and photographs. An estate is not only about access, but also about legitimate limits to access.

What we know
  • The GDPR itself does not govern the data of deceased people in the same way as the data of living people.
  • Major platforms have their own legacy tools that can be configured in advance.
  • Access to an account and ownership of individual assets are not the same question.
What we do not yet know
  • The outcome of a particular inheritance dispute without knowing the applicable law and contracts.
  • Whether all important data are included in a platform’s export.
  • Whether a family inventory is current without regular review.

3. Five questions to ask

  1. Which data should be preserved, transferred or deleted?
  2. Is there an official Legacy Contact or inactive-account contact?
  3. Who has legal authority, and who has technical access?
  4. Where are the instructions kept without storing passwords in plain text?
  5. Was the plan tested and updated during the past year?

4. Conclusion

A digital inheritance cannot be created with a single universal password. A workable plan combines an inventory, wishes, legal authority and the services’ official tools, while protecting secrets and other people’s privacy.

— Jiný Kontext
Sources and literature

Sources and further reading 4 sources

  1. Other sourceGDPR, recital 27 — the European framework for the data of deceased persons. Source checked: 31 August 2026.
    GDPR, recital 27 — the European framework for the data of deceased persons. Source checked: 31 August · 2026
  2. Other sourceGoogle: Inactive Account Manager — a configurable process for an inactive account. Source checked: 31 August 2026.
    Google: Inactive Account Manager — a configurable process for an inactive account. Source checked: 31 August · 2026
  3. Other sourceApple: How to add a Legacy Contact — setting up a contact and access key. Source checked: 31 August 2026.
    Apple: How to add a Legacy Contact — setting up a contact and access key. Source checked: 31 August · 2026
  4. Other sourceApple: How to request access to a deceased family member’s account — documents, procedure and access limitations. Source checked: 31 August 2026.
    Apple: How to request access to a deceased family member’s account — documents, procedure and access limitations. Source checked: 31 August · 2026