GDPR and digital legacy: what happens to EU data after death
TimeWill · Updated 2026-08-07
GDPR itself does not directly govern deceased persons — member states set their own rules. But platforms use GDPR as a reason to deny access, citing third-party privacy. The practical solution is the same as in the US: leave explicit consent, use platform legacy tools, and store credentials in an encrypted vault.
In the EU, the GDPR (Article 27) leaves the protection of deceased persons to each member state. This means there is no single EU-wide rule for what happens to your email, photos, or social media when you die — but the practical obstacles are the same everywhere.
Why platforms refuse access
Even when a family provides a death certificate, platforms may refuse because releasing the account could expose the private data of other people — the deceased's contacts, for example. GDPR's protection of third-party personal data gives them a legal reason to say no.
How member states handle it
- Germany — Digital inheritance is treated like physical inheritance — accounts pass to heirs, but enforcement against platforms is difficult
- France — Digital death provisions allow heirs to request access or closure of accounts
- Other EU states — Rules vary; some extend data protection rights to heirs, others leave it to platform policies and general inheritance law
What actually works
- Platform legacy settings — Memorialization and inactivity tools work regardless of local law
- Explicit instructions — State in your will or a digital legacy letter who should access what
- An encrypted vault — Passwords and recovery codes stored with a release mechanism remove the need to negotiate with platforms
- Separate private content — Use end-to-end encryption for content you never want released, even to family
Privacy vs. inheritance
The tension is real: you may want some messages to remain private even after death, while your heirs need account access to settle your affairs. A layered approach solves this — share what is needed (passwords, financial accounts) and keep the rest encrypted or set to auto-delete.
FAQ
Q: Does GDPR apply after death?
The GDPR explicitly does not apply to deceased persons (member states decide). But many platforms cite GDPR privacy obligations to refuse family access to a deceased person's account.
Q: Can I request a deceased relative's data under GDPR?
It depends on the platform and the country. Some platforms offer memorialization or limited data release with a death certificate; others refuse entirely.
Q: Does leaving passwords help?
Yes. If a trusted person can log in legitimately, they avoid the platform access dispute entirely — but only with your clear permission.
Related Guides
Plan your digital legacy for the EU
Grant access on your terms without waiting for platforms or courts.
Start free