Skip to main content

IISPPR

The last digital footprint: Rethinking the right to privacy and control over personal data in the digital afterlife and rights in these digital times.

Authors: Abinash Mohanty, Yashaswini Deshmukh, S. Krishna Veni, Esther Brave and Molly

Abstract

The rapid growth of digital technologies has transformed the way personal information is created, stored, and managed, resulting in digital identities that often persist beyond an individual’s death. Social media accounts, emails, cloud storage, financial records, and algorithmically generated data raise complex legal and ethical questions concerning ownership, privacy, and control after death. Although legal frameworks such as the European Union’s General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection Act, 2023 (DPDPA) have strengthened privacy protection during an individual’s lifetime, they provide limited guidance on the governance of personal data after death. This paper adopts a qualitative narrative literature review to examine contemporary scholarship on post-mortem privacy and digital legacy management. It analyses legal, technological, empirical, and philosophical perspectives to identify key challenges, including regulatory gaps, inconsistent platform governance, limited user preparedness for digital legacy planning, and emerging concerns arising from artificial intelligence and data-driven profiling. Particular emphasis is placed on the Indian legal framework and its interaction with international privacy standards. The study argues that existing laws inadequately address the persistence of digital identities and rely excessively on platform-specific contractual policies, resulting in legal uncertainty and inconsistent protection. It concludes that effective governance of the digital afterlife requires an interdisciplinary legal framework integrating privacy law, succession law, constitutional principles, and technological regulation to safeguard human dignity, autonomy, and informational self-determination in the digital age.

Keywords: Digital afterlife; post-mortem privacy; digital legacy management; informational self-determination; Digital Personal Data Protection Act, 2023; GDPR; artificial intelligence.

1. Introduction

The rapid advancement of digital technologies has fundamentally transformed the way individuals communicate, interact, and preserve information. Every online activity—from sending emails and using social media to conducting financial transactions and storing data in cloud services—creates a lasting digital footprint. Unlike physical possessions, these digital assets frequently remain accessible long after an individual’s death, raising complex legal, ethical, and technological questions concerning ownership, privacy, and control. As digital technologies become increasingly integrated into everyday life, personal identity no longer ends with biological death but continues to exist through persistent digital records and online profiles.

Traditional succession laws were developed to regulate the transfer of tangible property and financial assets. However, they were not designed to address digital assets such as emails, social media accounts, cloud storage, cryptocurrency wallets, online banking records, and AI-generated behavioural data. These assets differ significantly from conventional property because they are commonly governed by contractual agreements established by private technology companies rather than by inheritance law. Consequently, legal heirs often encounter uncertainty when seeking access to a deceased person’s digital accounts, while platform providers retain considerable discretion in determining whether such access should be granted (George & Mamedova, 2024).

This gap is not merely administrative but conceptual: privacy law has traditionally assumed a living, legally recognised subject, leaving little room for interests that persist after that subject’s death (Harbinja, 2023). Building on this premise, contemporary privacy law increasingly frames privacy as informational self-determination, enabling individuals to control how their personal information is collected, processed, and shared. This principle has significantly influenced modern data protection regimes, particularly the European Union’s General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection Act, 2023 (DPDPA), which strengthen the protection of personal data during an individual’s lifetime by emphasising consent, transparency, accountability, and individual autonomy (Paul, 2025).

Despite these developments, existing legal frameworks remain largely confined to living individuals. Buitelaar (2017) argues that this limitation has become increasingly problematic because digital identities often continue to exist long after biological death. The GDPR expressly excludes deceased persons from its scope, while the DPDPA similarly provides no comprehensive framework governing the management of personal data after death. Consequently, fundamental questions remain unresolved: whether family members should automatically inherit access to digital accounts, whether privacy interests continue after death, and whether technology companies should determine the future of digital identities through contractual terms of service. These uncertainties have become increasingly significant with the emergence of artificial intelligence capable of generating digital replicas, conversational chatbots, and virtual avatars based on historical personal data. Such technologies raise important concerns regarding consent, dignity, identity, and commercial exploitation that existing legal frameworks do not adequately address.

These challenges are particularly relevant in India, where rapid digitalisation has substantially increased internet usage, digital financial transactions, and cloud-based services. Although India’s DPDPA represents an important milestone in the protection of personal data, the absence of statutory provisions concerning post-mortem privacy leaves digital estates governed by a fragmented combination of succession law, contract law, information technology legislation, and platform-specific policies. This fragmented approach creates legal uncertainty for families while providing inconsistent protection for the privacy interests of deceased individuals.

Existing scholarship has examined digital afterlife governance from legal, technological, and philosophical perspectives (George & Mamedova, 2024; Holt et al., 2021; Buitelaar, 2017; Harbinja, 2023). George and Mamedova (2024) primarily examine deficiencies in succession and data protection laws, Holt et al. (2021) explore digital legacy management from a technological and behavioural perspective, Buitelaar (2017) evaluates the philosophical basis for recognising post-mortem privacy, and Harbinja (2023) develops a theoretical and comparative account of post-mortem privacy across property, data protection, and succession law. However, these perspectives remain largely fragmented, and comparatively little research has examined the issue within the Indian legal context or considered the implications of emerging technologies such as artificial intelligence.

Accordingly, this paper adopts a qualitative narrative literature review to examine the relationship between privacy rights and digital legacy management in the context of the digital afterlife. By analysing legal scholarship, empirical research, and contemporary privacy frameworks, the study identifies key doctrinal, technological, and policy gaps concerning post-mortem privacy. Particular emphasis is placed on the interaction between India’s Digital Personal Data Protection Act, 2023 and international privacy standards such as the GDPR. The paper argues that effective governance of digital identities after death requires an interdisciplinary legal framework grounded in human dignity, informational self-determination, and technological accountability. Such an approach would provide greater legal certainty while ensuring that digital identities continue to receive meaningful protection in an increasingly data-driven society.

2. Literature Review

2.1 Legal and Regulatory Gaps in Post-Mortem Data Governance

The rapid expansion of digital technologies has fundamentally challenged traditional legal approaches to property, privacy, and succession. Unlike tangible assets, digital assets—including social media accounts, cloud storage, emails, cryptocurrency wallets, and online financial records—are generally governed by contractual agreements between users and service providers rather than conventional inheritance law. Consequently, the death of an account holder creates uncertainty regarding ownership, access, and control of personal information.

George and Mamedova (2024) identify this phenomenon as the emergence of the digital afterlife, arguing that existing succession laws were developed to regulate physical and financial assets rather than persistent digital identities. They observe that legal heirs frequently encounter barriers when attempting to access digital accounts because platform providers retain control through contractual terms of service. Although users generate and maintain digital content throughout their lives, they rarely possess full ownership rights over the platforms on which that information is stored.

As George and Mamedova (2024) observe, technology companies have attempted to address these issues through platform-specific mechanisms such as Facebook’s Legacy Contact, Google’s Inactive Account Manager, and Apple’s Digital Legacy programme. While these initiatives provide limited post-mortem account management options, they differ considerably in scope and accessibility, resulting in inconsistent outcomes for users and their families. Consequently, posthumous access to digital information remains largely dependent on private contractual arrangements rather than uniform legal standards.

Paul (2025) argues that the limitations of contemporary privacy legislation further contribute to this regulatory gap because existing privacy frameworks primarily protect living individuals and provide little guidance regarding post-mortem data governance. Although the General Data Protection Regulation (GDPR) represents one of the world’s most comprehensive privacy frameworks, it expressly applies only to living natural persons. Similarly, India’s Digital Personal Data Protection Act, 2023 (DPDPA) strengthens privacy protections for living individuals but contains no comprehensive provisions governing personal data after death. As a result, existing legal frameworks provide limited guidance regarding whether digital identities should be inherited, deleted, preserved, or otherwise managed following death.

Taken together, the work of George and Mamedova (2024) and Paul (2025) demonstrates that traditional succession law and contemporary privacy legislation have not evolved alongside technological developments. Existing legal frameworks continue to distinguish between physical property and digital identity despite the increasing social, emotional, and economic significance of digital assets. This regulatory mismatch highlights the need for legislative reform capable of integrating data protection, succession law, and digital governance within a coherent framework.

2.2 Practical and User-Centred Barriers to Digital Legacy Management

While legal scholarship primarily focuses on regulatory deficiencies, empirical research demonstrates that practical and behavioural factors present equally significant challenges. Holt et al. (2021) investigate how individuals perceive and prepare for their digital afterlife, revealing a substantial gap between recognising the importance of digital legacy planning and actually taking practical steps to organise digital assets.

Their study introduces the concept of the post-mortem privacy paradox, whereby individuals simultaneously wish to preserve personal privacy while enabling legitimate access for family members after death. Despite acknowledging these competing interests, most participants failed to document their preferences or engage in any meaningful digital estate planning. Instead, many assumed that existing platform settings or family members would adequately manage their digital assets without explicit instructions.

Holt et al. (2021) attribute this behaviour partly to psychological discomfort associated with discussions of death, together with limited awareness regarding digital estate planning. Participants frequently regarded digital legacy planning as unnecessary, emotionally distressing, or something that could be postponed indefinitely. This reluctance mirrors traditional attitudes towards preparing wills but is further intensified by limited public awareness regarding digital succession.

Holt et al. (2021) further argue that current technological systems provide insufficient support for digital legacy management by offering limited opportunities for users to express nuanced post-mortem preferences. Most online platforms offer limited mechanisms allowing users to distinguish between categories of information that should remain private and those that should be accessible after death. Consequently, existing systems often require users to choose between unrestricted disclosure and complete inaccessibility.

Accordingly, Holt et al. (2021) advocate user-centred technological design incorporating granular access controls, periodic reviews of post-mortem preferences, and automated implementation of digital legacy instructions. Their findings demonstrate that effective governance of the digital afterlife depends not only on legal reform but also on encouraging informed user participation through accessible technological solutions.

2.3 Philosophical and Jurisprudential Foundations of Post-Mortem Privacy

A central question within the literature concerns whether privacy rights can meaningfully survive death. Before determining who should control digital assets, it is necessary to establish whether deceased individuals continue to possess legally or morally protectable interests. This normative question is examined most comprehensively by Buitelaar (2017).

Buitelaar (2017) argues that modern digital technologies have fundamentally altered the relationship between personal identity and information, requiring privacy law to extend beyond traditional conceptions of bodily existence. Digital communications, behavioural data, photographs, and online interactions collectively constitute enduring representations of an individual’s personality. Since these digital traces continue to influence how deceased individuals are remembered and represented, they remain closely connected to dignity and personal identity.

Buitelaar (2017) contends that individuals retain morally significant interests after death, particularly in relation to dignity, reputation, and personal identity. Accordingly, misuse of personal information after death may constitute a genuine violation of these continuing interests, even though the deceased cannot consciously experience harm.

Buitelaar (2017) rejects the view that privacy necessarily ends with death by grounding post-mortem privacy in informational self-determination and human dignity. If individuals possess the authority during life to determine how personal information is collected, processed, and disclosed, respect for autonomy requires that clearly expressed preferences concerning digital identity continue to receive legal recognition after death. Rather than creating entirely new rights, this approach preserves autonomous decisions already made during life.

Buitelaar’s (2017) work therefore provides the principal philosophical foundation for extending privacy protections to digital identities after death. His work demonstrates that post-mortem privacy should be understood not merely as a question of inheritance but as an extension of constitutional values relating to dignity and personal autonomy.

2.4 Privacy During Life as the Foundation for Post-Mortem Privacy

The development of post-mortem privacy cannot be separated from the broader evolution of privacy law. Paul (2025) traces the development of privacy from Warren and Brandeis’ classical conception of the “right to be let alone” to the contemporary principle of informational self-determination.

According to Paul (2025), advances in digital technologies have significantly expanded the quantity of personal information generated through everyday online activities, requiring privacy law to evolve accordingly. Artificial intelligence, cloud computing, social media, and the Internet of Things generate extensive behavioural datasets that enable governments and private corporations to construct detailed digital profiles. As a result, privacy has evolved from protecting physical spaces towards regulating the collection, processing, and dissemination of personal information.

Paul (2025) observes that this transformation has influenced major privacy frameworks including the GDPR, the California Consumer Privacy Act (CCPA), and India’s Digital Personal Data Protection Act, 2023. These statutes strengthen individual control through principles of consent, transparency, accountability, and purpose limitation while recognising privacy as an important component of personal autonomy.

However, Paul (2025) argues that these legal developments remain largely confined to living individuals and provide only limited guidance concerning personal data after death. Although modern privacy law increasingly recognises personal data as an extension of identity, it provides little guidance regarding whether similar protection should continue after death. Consequently, the principles underpinning contemporary privacy law remain underdeveloped within the context of digital succession and post-mortem privacy.

Paul’s (2025) work therefore provides an important bridge between traditional privacy jurisprudence and contemporary debates concerning post-mortem privacy. It suggests that extending informational self-determination beyond death represents a logical continuation of existing privacy principles rather than a departure from them.

2.5 Data-Driven Profiling and Emerging Technological Challenges

The rapid development of artificial intelligence has expanded the challenges associated with post-mortem privacy beyond traditional questions of account access and digital inheritance. Contemporary AI systems are capable of analysing large volumes of personal data to generate digital avatars, conversational agents, voice replicas, and other forms of digital representation. These technologies transform digital remains from passive archives into interactive representations of deceased individuals, thereby creating new legal and ethical concerns relating to consent, identity, authenticity, and commercial exploitation. Hollanek and Nowaczyk-BasiÅ„ska (2024) describe this emerging sector as the “digital afterlife industry” and caution that interactive “deadbots” built from a person’s likeness, voice, and personal data raise distinct ethical risks that existing consent frameworks were never designed to address. Recent scholarship, particularly that of Buitelaar (2017) and George and Mamedova (2024), suggests that existing legal frameworks governing post-mortem privacy were developed before the emergence of generative artificial intelligence and therefore provide limited guidance regarding its regulation.

The significance of these developments can be understood in light of Buitelaar’s (2017) conception of informational self-determination. Buitelaar argues that digital identities remain closely connected to human dignity because they continue to represent an individual’s personality, reputation, and personal history after death. Consequently, the unauthorised use of personal data to create AI-generated representations may interfere with interests that survive biological death, particularly where such technologies reproduce an individual’s appearance, voice, or behaviour without prior consent.

Similarly, George and Mamedova (2024) demonstrate that digital assets now extend far beyond social media profiles to include emails, cloud storage, financial records, and other forms of persistent digital information. As these datasets increasingly become training material for AI systems, questions arise regarding who may authorise their continued use after death and whether platform providers should retain broad contractual discretion over such data. Their analysis highlights the absence of uniform legal standards governing digital legacy management and argues for clearer statutory regulation of digital estates.

The practical implications of AI also reinforce the concerns identified by Holt et al. (2021) regarding digital legacy planning. Their research demonstrates that individuals rarely make explicit decisions concerning their digital assets despite recognising their long-term significance. In the context of generative AI, this absence of planning becomes even more problematic because historical digital records may be repurposed to generate interactive digital identities without clearly expressed consent. This creates uncertainty not only for surviving family members but also for technology providers responsible for determining the future use of personal data.

Taken together, the literature indicates that artificial intelligence has fundamentally altered the concept of the digital afterlife. Traditional privacy frameworks primarily regulate the storage and disclosure of personal information, whereas AI increasingly enables the reconstruction and simulation of personal identity itself. Effective governance of post-mortem privacy must therefore evolve beyond conventional data protection to address the ethical and legal implications of AI-generated digital identities while safeguarding human dignity, informational self-determination, and individual autonomy (Buitelaar, 2017; George & Mamedova, 2024; Holt et al., 2021; Hollanek & Nowaczyk-Basińska, 2024).

2.6 Synthesis

Read together, this body of scholarship does not converge on a single account of the digital afterlife so much as it converges on a shared diagnosis: the law has been overtaken by the very technologies it is meant to govern, and each discipline has responded by patching the gap from its own vantage point rather than closing it. George and Mamedova (2024) expose the structural weakness of succession law, which was built for tangible property and now strains under the weight of contractually-controlled digital estates. Holt et al. (2021) complicate any purely legislative fix by showing that users themselves are often unwilling or unprepared participants in their own digital legacy planning, meaning that even a well-drafted statute could fail in practice if it is not matched by usable, granular technological design. Harbinja (2023) pushes further still, arguing that property-based and contract-based framings mischaracterise what is really at stake: not who owns the data, but whose dignity and identity the data continues to represent.

This is where the literature’s central tension surfaces. Buitelaar (2017) and Harbinja (2023) ground post-mortem privacy in the deceased’s own continuing interests — dignity, reputation, informational self-determination — treating the right as belonging, in a meaningful sense, to the person who has died. Allen and Rothman (2024) complicate this position by tracing how post-mortem privacy protections have in fact developed piecemeal across defamation, publicity, and probate law for over a century, suggesting the “no-privacy-rights-for-the-dead” doctrine was never quite true even as it was repeatedly asserted. Paul (2025), by contrast, situates the debate within the evolution of privacy law generally, implying that post-mortem privacy is less a distinct right than a logical extension of protections already accepted for the living. These are not simply differences of emphasis: they carry different practical consequences. A dignity-based approach justifies restricting what platforms and AI developers may do with a deceased person’s data regardless of family wishes, whereas an extension-based or estate-based approach more easily accommodates negotiated, family-directed outcomes. Any statutory reform will have to choose, implicitly or explicitly, between these competing justifications rather than treating them as interchangeable.

The emergence of generative AI sharpens this disagreement rather than resolving it. Hollanek and Nowaczyk-BasiÅ„ska (2024) show that deadbots and digital avatars force regulators to decide, in concrete terms, whether a deceased person’s dignity interest can override a grieving family’s wish to interact with a simulation of them — a question that abstract theories of post-mortem privacy had not previously needed to answer with this urgency. Viewed this way, the literature is less a settled consensus awaiting legislative codification than an active, unresolved argument about what post-mortem privacy is actually for. That argument is also markedly under-theorised outside Europe and North America: the near-total absence of scholarship examining India’s DPDPA against these competing justifications is not a minor omission but a genuine gap, particularly given that a jurisdiction so early in its data protection journey has an opportunity to legislate deliberately rather than retrofit a framework built for the living.

3. Research Methodology

This study uses a qualitative narrative literature review to examine post-mortem privacy and digital legacy management across legal, technological, and philosophical scholarship. A narrative approach was chosen because the subject matter is doctrinally unsettled and cuts across disciplines that do not share a common methodology or evidence base, making it unsuited to the quantitative synthesis a systematic review requires.

Sources were drawn from peer-reviewed journal articles, monographs, conference proceedings, and statutory materials on digital afterlife governance, privacy law, succession law, and artificial intelligence, identified through Google Scholar, HeinOnline, JSTOR, and Scopus using terms including post-mortem privacy, digital afterlife, digital legacy management, informational self-determination, GDPR, and Digital Personal Data Protection Act, 2023.

The literature was organised thematically around four recurring lines of inquiry: (i) regulatory gaps in governing digital assets after death; (ii) practical and behavioural barriers to digital legacy planning; (iii) the philosophical basis for post-mortem privacy; and (iv) the implications of artificial intelligence for digital identity. Rather than summarising sources individually, the analysis compares them against one another to surface points of agreement, disagreement, and unresolved tension.

The review is confined to informational privacy, autonomy, and dignity as they relate to personal data after death, with the GDPR and India’s DPDPA as its principal points of comparison; the broader law of succession and the financial valuation of digital assets fall outside its scope. As a literature-based study, it relies exclusively on secondary sources and does not draw on primary empirical data.

4. Analysis

The literature reviewed above demonstrates that the rapid expansion of digital technologies has outpaced the development of legal frameworks governing privacy and succession. Although modern data protection laws have strengthened individual control over personal information during life, they provide limited guidance regarding the governance of digital identities after death. This disconnect has created a regulatory vacuum in which technology companies frequently determine the fate of digital assets through contractual policies rather than statutory law.

One of the principal shortcomings of existing legal frameworks is their exclusive focus on living individuals. Both the GDPR and India’s DPDPA recognise privacy as an important component of individual autonomy by granting data subjects rights relating to consent, correction, erasure, and transparency. However, these protections largely cease upon death, despite the continued existence of digital identities. Harbinja (2023) traces this exclusion to a deeper conceptual gap in privacy law: because the discipline has historically required a living legal subject to hold rights, deceased persons fall outside its protective scope almost by definition, rather than through any deliberate policy choice to exclude them. As a result, information that remains capable of affecting an individual’s dignity, reputation, and family interests is left without comprehensive legal protection.

The Indian legal framework particularly illustrates this challenge. While the DPDPA establishes obligations concerning lawful processing and accountability, it does not specify how digital assets should be managed after death. Existing succession law similarly focuses on tangible property and financial assets rather than digital identities. Consequently, legal heirs often depend on platform-specific terms of service when seeking access to online accounts. This fragmented approach creates uncertainty and allows private technology companies to exercise considerable discretion over matters that directly affect personal autonomy and privacy.

Allen and Rothman (2024) offer a useful corrective at this point in the analysis. Examining the common law more broadly, they show that post-mortem privacy has never been as absent as the “no-privacy-rights-for-the-dead” doctrine suggests: fragments of protection already exist across defamation, right-of-publicity, and probate law, even though no jurisdiction treats them as a coherent whole. This matters for the Indian context because it suggests that a statutory post-mortem privacy regime would not be inventing an entirely new legal category, but rather consolidating protections that common law systems, including India’s, already recognise in scattered form.

The emergence of artificial intelligence further exposes the inadequacy of existing legislation, and does so through a different mechanism than the access disputes discussed above. AI systems are increasingly capable of generating digital avatars, voice replicas, and conversational chatbots using historical personal data. Hollanek and Nowaczyk-BasiÅ„ska (2024) describe how such “deadbots” are already being marketed commercially, often with minimal scrutiny of whether the deceased ever consented to this use of their likeness. Unlike the account-access disputes that dominate the succession-law literature, these technologies actively recreate aspects of an individual’s identity, raising distinct questions concerning consent, authenticity, and commercial exploitation that data-access frameworks are not designed to answer.

These developments suggest that post-mortem privacy should not be treated solely as an issue of inheritance. Digital identities differ fundamentally from conventional property because they incorporate personal communications, behavioural information, financial records, creative works, and representations of individual personality. Consequently, regulating digital assets exclusively through succession law overlooks their close relationship with constitutional values such as dignity, autonomy, and informational self-determination.

Building on Buitelaar’s (2017) conception of informational self-determination, and consistent with Harbinja’s (2023) account of post-mortem privacy as a distinct legal interest rather than a derivative of property law, this paper argues that dignity and autonomy provide the most defensible normative foundation for reform. If individuals possess the right during life to determine how their personal information is collected, processed, and disclosed, there is a compelling argument that these preferences should continue to receive legal recognition after death. Respecting posthumous privacy therefore represents the continuation of autonomous decisions made during life rather than the creation of entirely new legal rights.

At the same time, recognising post-mortem privacy cannot imply unrestricted confidentiality. Family members frequently possess legitimate interests in accessing financial documents, legal records, and personal communications necessary for estate administration or emotional closure, and the deadbot controversies documented by Hollanek and Nowaczyk-BasiÅ„ska (2024) show how sharply a dignity-based limit on use can cut against a grieving family’s own wishes. Effective regulation must therefore balance the privacy interests of the deceased with the legitimate interests of surviving relatives and broader public considerations, a balancing exercise already well established within constitutional and privacy jurisprudence.

Accordingly, legislative reform should move beyond fragmented platform governance towards a coherent statutory framework. India’s DPDPA could be expanded to recognise post-mortem privacy by allowing individuals to record legally binding digital legacy preferences during their lifetime, and by placing express, consent-based limits on the commercial use of a deceased person’s data to train or generate AI representations of them. Such a framework would provide greater legal certainty, strengthen respect for personal autonomy, and reduce dependence on inconsistent contractual policies. As digital technologies continue to transform human identity, legal systems must evolve to ensure that the protection of privacy extends beyond biological life in a manner consistent with constitutional principles and technological realities.

5. Discussion

The analysis demonstrates that existing legal frameworks are insufficient to address the complexities of post-mortem privacy in an increasingly digital society. Although contemporary data protection laws recognise informational privacy as a fundamental right during an individual’s lifetime, they provide limited protection once biological life ends. Consequently, digital identities continue to exist without a coherent legal framework governing their management, leaving decisions concerning access, preservation, and deletion largely to private technology companies (Paul, 2025). This is not a marginal drafting oversight in either the GDPR or the DPDPA; it reflects a structural feature of privacy law identified by Harbinja (2023) — that the field was conceived around a living rights-holder and has never been systematically redesigned to accommodate one who has died. Framing the gap this way matters, because it suggests that no amount of incremental amendment to consent or erasure provisions will close it; what is required is a deliberate extension of the law’s conceptual boundaries, not a patch.

The findings also indicate that digital assets cannot be adequately regulated through succession law alone. Unlike conventional property, digital identities combine financial value with deeply personal information reflecting an individual’s relationships, communications, beliefs, and behaviour. Their unique nature requires a legal approach that integrates privacy law, succession law, and constitutional principles rather than treating digital assets solely as inheritable property or contractual rights. Allen and Rothman’s (2024) account is instructive here: they show that common law systems have never in fact treated the dead as entirely without protection, but have instead extended fragments of privacy-like interests through defamation, the right of publicity, and probate administration. Read against the Indian position, this suggests that a statutory post-mortem privacy regime would not be a conceptual novelty imported wholesale from continental data protection thinking, but a consolidation of protections Indian law arguably already gestures toward in scattered form — through, for instance, posthumous reputation in defamation and the administration of a deceased person’s estate under succession law. The absence of a unifying statute is therefore less an absence of underlying values than a failure to coordinate them.

A second point of disagreement in the literature, and one the discussion should not paper over, concerns whose interests should prevail when they conflict. Buitelaar (2017) and Harbinja (2023) locate the core interest in the deceased’s own dignity and autonomy, which implies that a family’s wish to access, publish, or repurpose a deceased relative’s data should yield to preferences the deceased expressed, or would plausibly have expressed, while alive. Holt et al. (2021), however, show empirically that most people never articulate such preferences at all, which leaves a dignity-centred framework with little to work from in the overwhelming majority of cases. In practice, then, family-directed access is likely to remain the operative default even under a dignity-based statute, simply because explicit instructions will be rare. This is a genuine limitation of the dignity-based justification that the literature has not fully confronted: a right grounded in autonomy is only as strong as people’s willingness to exercise it in advance, and the evidence suggests they largely do not.

The increasing use of artificial intelligence further reinforces the need for legislative reform, and does so in a way that exposes the limits of a purely access-oriented framework. Technologies capable of generating digital avatars, voice replicas, and AI-driven memorial applications blur the distinction between preserving digital records and recreating aspects of personal identity. Hollanek and Nowaczyk-BasiÅ„ska’s (2024) account of the commercial “digital afterlife industry” is a useful corrective to the assumption, implicit in much of the succession-law literature, that the central post-mortem privacy question is who may open a deceased person’s accounts. Deadbots and griefbots raise a different question entirely: whether anyone — family included — should be able to authorise an ongoing, interactive simulation of a deceased person’s voice and personality for commercial or even purely private use. Without clear legal standards governing consent and commercial use, such technologies risk undermining human dignity and informational autonomy in ways that access-control mechanisms like Facebook’s Legacy Contact or Google’s Inactive Account Manager were never designed to address (Buitelaar, 2017; Hollanek & Nowaczyk-BasiÅ„ska, 2024).

Within the Indian context, these challenges are particularly significant because the Digital Personal Data Protection Act, 2023 does not specifically regulate post-mortem privacy despite the country’s rapid digitalisation, its large base of first-generation internet users, and the correspondingly low levels of digital estate planning that Holt et al.’s (2021) findings would predict in any population unfamiliar with the practice. India’s relatively late entry into comprehensive data protection legislation is, in this respect, an underused opportunity rather than a pure disadvantage: unlike the GDPR, which excluded the deceased at a moment when AI-generated digital replicas were not yet a live policy concern, the DPDPA could be amended with both the succession-law gap and the deadbot problem already visible. Future reform should therefore proceed on at least three fronts — recognising legally binding digital legacy preferences made during life, establishing clear default procedures for family access to financial and administrative digital records where no preference has been expressed, and imposing express, consent-based limits on the commercial and AI-driven use of a deceased person’s likeness, voice, and behavioural data. Such measures would strengthen legal certainty while ensuring that privacy remains a meaningful constitutional value throughout the digital lifecycle, rather than one that is assumed, by omission, to end at death.

Finally, the scope of this review is itself worth acknowledging as part of the discussion rather than only as a limitation. Because the analysis relies exclusively on secondary literature drawn predominantly from European, North American, and comparative theoretical scholarship, it cannot speak to how Indian courts, platforms, or families are actually navigating digital estates in practice; the near-total absence of Indian empirical work on this question, noted throughout this review, means the paper’s proposals for DPDPA reform are necessarily grounded in principle rather than in evidence of how such reform would be received or used. This is precisely the gap that future empirical research in the Indian context should address.

6. Conclusion

The rapid expansion of digital technologies has fundamentally transformed the nature of privacy, identity, and personal information. While contemporary data protection laws have significantly strengthened the protection of personal data during an individual’s lifetime, they remain largely inadequate in addressing the persistence of digital identities after death. As individuals increasingly leave behind extensive digital footprints, existing legal frameworks continue to rely on fragmented combinations of privacy law, succession law, and platform-specific contractual policies that fail to provide consistent protection for post-mortem privacy.

This study demonstrates that the challenges of the digital afterlife extend beyond traditional questions of inheritance. Digital assets are not merely economic resources but also repositories of personal identity, relationships, memories, and behavioural information. Consequently, regulating them solely through succession law or private contractual arrangements overlooks their broader constitutional and ethical significance. The analysis further highlights that emerging technologies, particularly artificial intelligence, have intensified these concerns by enabling the creation of digital replicas and AI-generated representations of deceased individuals, raising novel questions concerning consent, dignity, and commercial exploitation.

By synthesising legal, technological, and philosophical scholarship, this paper argues that effective governance of post-mortem privacy requires an interdisciplinary approach grounded in the principles of informational self-determination, human dignity, and technological accountability. In the Indian context, the absence of explicit provisions governing digital identities after death represents an important legislative gap that warrants future reform. Strengthening the interaction between privacy law, succession law, and digital governance would provide greater legal certainty while protecting both individual autonomy and legitimate family interests.

Ultimately, as human lives become increasingly intertwined with digital technologies, the law must evolve to recognise that meaningful protection of personal identity cannot end with biological death. Developing a coherent legal framework for the digital afterlife is therefore essential not only for safeguarding individual privacy but also for ensuring that constitutional values of dignity, autonomy, and justice remain effective in an increasingly digital society.

References

Allen, A. L., & Rothman, J. E. (2024). Postmortem privacy. Michigan Law Review, 123(2), 285.

Buitelaar, J. C. (2017). Post-mortem privacy and informational self-determination. Ethics and Information Technology, 19(2), 129–142. https://doi.org/10.1007/s10676-017-9421-9

George, A. S., & Mamedova, S. (2024). Digital afterlife: Preserving online legacies beyond death. Partners Universal International Innovation Journal, 2(1), 1–14. https://doi.org/10.5281/zenodo.10581860

Harbinja, E. (2023). Digital death, digital assets and post-mortem privacy: Theory, technology and the law. Edinburgh University Press.

Hollanek, T., & Nowaczyk-Basińska, K. (2024). Griefbots, deadbots, postmortem avatars: On responsible applications of generative AI in the digital afterlife industry. Philosophy & Technology, 37(2), 63.

Holt, J., Nicholson, J., & Smeddinck, J. D. (2021). From personal data to digital legacy: Exploring conflicts in the sharing, security and privacy of post-mortem data. In Proceedings of the Web Conference 2021 (WWW ’21, pp. 2745–2756). Association for Computing Machinery. https://doi.org/10.1145/3442381.3450030

Paul, P. P. (2025). The right to privacy in the digital age: Navigating evolving vulnerabilities and legal frameworks. Canonsphere Law Review, 1(3).

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). (2016). Official Journal of the European Union, L 119, 1–88.

Warren, S. D., & Brandeis, L. D. (1890). The right to privacy. Harvard Law Review, 4(5), 193–220.

Leave a Reply

Your email address will not be published. Required fields are marked *