Authors: Kuldeep Singh Tanwar, Akshat Janugade, Ayush Singh, Janavi Jangid, Suhani
Abstract
Every year, millions of people die without an estate plan that accounts for what they leave behind an electronic legacy. Photographs, private messages, medical records, biometric information, browsing histories, and social media accounts continue to exist long after the person who created them has died. In most jurisdictions, and particularly in India, the law has scarcely begun to address this reality.
This paper examines the post-mortem status of personal data within India’s constitutional and statutory framework. It argues that the right to privacy recognised in Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, grounded in human dignity and informational autonomy, cannot simply be treated as extinguished the instant a person dies. Where personal data retains the potential to affect the dignity or identity of the deceased, or to cause measurable harm to surviving relatives, there is a defensible constitutional basis for a limited form of posthumous privacy protection though this remains, at present, a proposed extension of doctrine rather than settled law. The Digital Personal Data Protection Act, 2023 (DPDP Act) does not supply this protection: it applies only to living data principals, leaving a governance gap that platform terms of service and succession law are structurally ill-suited to fill.
This paper offers a doctrinal and comparative legal analysis of the Indian constitutional position, examines the legislative lacuna in the DPDP Act against the member-state discretion preserved under the General Data Protection Regulation (GDPR) and the fiduciary-access model of the Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA), and considers the case for reform in light of AI-driven digital resurrection technologies. It concludes by proposing a scheme of posthumous privacy for India grounded in the dignity rationale of Puttaswamy, structured through a tiered system of consent and access, and bounded by a time limitation intended to prevent posthumous privacy from unduly constraining the legitimate interests of heirs, researchers, and the public.
1. Introduction
1.1 Background: The Persistence of Data Beyond Life
When a person passes away, the law determines how the person’s physical estate is passed on based on centuries-old concepts of succession of property, testamentary freedom, and inheritance. Today, however, there is a second estate: the collection of photographs, messages, search histories, medical records, financial records, biometric information, and social media identities that accumulate over a digital life, and which the law has yet to fully consider. This data does not transfer in any simple way, as a house or a bank account does. It remains available to the living, capable of proliferation, and is increasingly analysed, reanimated, and objectified by artificial intelligence long after the person who produced it has died.
This phenomenon is substantial in scale. There are an estimated one billion “dead” Facebook accounts, and by the end of this century, “dead” accounts are projected to outnumber “living” ones (Öhman & Watson, 2019). These profiles are not merely a record of past activity; they are an intimate history of a person’s relationships, beliefs, health, sexuality, finances, and emotional life. Were such data held by a living person, constitutional and statutory law would extend to it the highest degree of privacy protection. In most jurisdictions, that protection lapses shortly after death.
The advent of artificial intelligence has added a further and more pressing dimension to this problem. “Griefbots” systems trained on a deceased person’s digital legacy to replicate their voice, writing style, and personality are now commercially available. AI tools such as here after AI, story file, and Eternos offer bereaved families the ability to interact with AI-generated representations of deceased relatives (Hollanek & Nowaczyk-BasiÅ„ska, 2024). These technologies raise questions that existing law does not answer: whether the deceased consented to this use of their data; whether any rights survive their death; and whether technology companies bear any obligations when they commercially exploit the reconstructed likeness of a dead person.
1.2 Problem Statement
The central problem is doctrinal. Privacy is almost invariably conceived, as a matter of legal right, as an entitlement of the living. The right to privacy recognised in Puttaswamy (2017) arises under Article 21 of the Constitution, which protects the life and personal liberty of a “person,” a status ordinarily understood to require continued life. Once an individual dies, the constitutional right, on this orthodox reading, lapses with them. The DPDP Act, India’s first comprehensive data protection statute, mirrors this position: it defines its protections by reference to the living “data principal” and, in doing so, excludes the entire posthumous digital estate from statutory protection.
This legislative silence is not without practical and constitutional consequence. It effectively transfers governance of the data of the dead to technology companies, whose terms of service are commercially motivated and vary considerably across platforms. It leaves family members without any legal entitlement to access or control a deceased relative’s digital accounts, even where such access is necessary for estate administration. And as AI technologies mature, it leaves the reconstruction of deceased persons’ identities from their digital remains wholly unregulated, raising serious and unresolved questions of dignity, consent, and autonomy.
1.3 Research Objectives
This paper pursues four objectives. First, it examines whether the dignity and informational-autonomy rationale articulated in Puttaswamy (2017) provides scope for a posthumous privacy interest under the Indian Constitution, and if so, on what basis and to what extent. Second, it examines the regulatory deficit created by the DPDP Act and considers whether the Information Technology Act, 2000, succession law, and platform terms of service can adequately substitute for statutory protection. Third, it undertakes a comparative examination of the divergent approaches of the European Union and the United States to posthumous data governance specifically, the GDPR’s deliberate silence on posthumous data and RUFADAA’s fiduciary-access framework together with relevant judicial responses to digital-inheritance disputes. Fourth, building on this analysis, it proposes a purpose-oriented framework for posthumous privacy suited to the Indian constitutional context.
1.4 Research Questions
This paper investigates four questions. Does the constitutional right to privacy recognised in Indian jurisprudence survive the death of the person to whom it belongs, and if so, to what extent? To whom should the power to regulate the digital legacies of the dead be entrusted, and on what basis? Can the existing Indian legal regime constitutional, statutory, and private adequately resolve the governance problems this creates? What regulatory or judicial changes should be made to Indian law to align it with evolving international approaches to posthumous data governance?
1.5 Scope and Methodology
The paper adopts a doctrinal and qualitative research approach, analysing primary sources constitutional provisions, statutes, judicial decisions, and international instruments together with secondary legal, philosophical, and technology-policy literature. Comparative analysis is conducted across three jurisdictions, India, the European Union, and the United States, selected for their representativeness rather than for comprehensiveness; the criteria for this selection are elaborated in Part 3. The paper does not address digital assets of purely financial value, such as cryptocurrencies, non-fungible tokens, or digital bank accounts, but confines itself to personal data and the dignity and identity interests it engages.
The paper is organised as follows. Part 2 reviews the existing literature across four thematic strands foundational theories of the digital afterlife, posthumous privacy and human dignity, digital-asset succession, and AI-driven digital resurrection and identifies the gap this paper addresses. Part 3 sets out the methodology in detail. Part 4 presents the research findings. Part 5 discusses these findings against the Indian constitutional and statutory position and develops a proposed framework. Part 6 concludes by distinguishing reforms that are immediately achievable from those that require long-term legislative change.
2. Literature Review
Scholarship on digital privacy after death is comparatively recent and is firmly grounded in European and American legal systems. This review traces the literature across four themes theories of the digital afterlife, the dignity-based case for posthumous privacy, the property-based approach to digital-asset succession, and AI-driven digital resurrection before identifying, in section 2.6, the specific gap this paper addresses. The aim is not merely to summarise each contribution, but to follow the argument as it develops across the field and to identify where it has not yet gone: specifically, into a jurisdiction such as India, where privacy has been recognised as a fundamental right grounded substantively in dignity, and where the first comprehensive data protection statute has nonetheless left the dead entirely unaddressed.
2.1 The Digital Afterlife: Foundational Concepts
Edina Harbinja’s work is foundational to this field. In an influential 2017 article, she drew a principled legal distinction between privacy as a property interest and privacy as a dignity interest, arguing that only the latter offers a satisfactory account of the post-mortem dimension of privacy (Harbinja, 2017a). Her argument holds that the values privacy serves autonomy, identity, informational self-determination does not cease at the moment of death, because they remain embedded in data that continues to exist and to be capable of causing harm. Harbinja developed this argument further in her monograph, which offers the most comprehensive legal analysis of the phenomenon across European and American jurisdictions to date (Harbinja, 2023).
This foundational theoretical work does not purport to apply outside Western legal systems, nor does its author claim that it does. A 2024 qualitative study that Harbinja co-authored with Edwards and McVey adds an empirical dimension: users asked whether they want some control over their afterlife data consistently answer in the affirmative, while few are aware of any existing legal mechanism to secure that control (Harbinja et al., 2024). This preference gap is not confined to the United Kingdom, where the study was conducted; it is, if anything, more pronounced in India, where no legal mechanism for posthumous data control exists at all. In sum, the foundational scholarship has established, at considerable depth, that posthumous privacy is a coherent legal concept, but it has not tested that concept against a constitutional system in which dignity operates as a substantive component of the right to privacy a system that India’s Puttaswamy jurisprudence presents, and which this literature has not yet examined.
2.2 Posthumous Privacy, Dignity, and the Rights of the Dead
The question whether legal rights survive death is not new to legal philosophy, although it has only recently been posed in the specific form required by digital data. Smolensky’s doctrinal analysis remains the most rigorous treatment of the underlying question and concludes that recognising post-mortem interests of the dead does not require recognising the dead as continuing holders of legal personality; it requires only recognising that conduct concerning the dead has real, measurable effects on reputation, family, and community among the living (Smolensky, 2009). McCallig reaches a compatible conclusion in his study of privacy after death, arguing that intimacy does not lose its intimate character simply because its subject has died: medical records, sexual history, and private correspondence do not become less sensitive on the death of the person they concern (McCallig, 2014).
Morse and Birnhack report a related empirical finding: individuals are considerably concerned about what becomes of their digital remains, yet rarely take any legal measures to protect them, whether from an unwillingness to confront mortality or from the practical difficulty of accessing legal remedies (Morse & Birnhack, 2022). A follow-up study surveying UK users found that most believed their posthumous data was already legally protected, when in fact it is not (Morse et al., 2025). Taken together, this evidence confirms that a dignity-based case for posthumous privacy is well established in Western scholarship. What remains unexamined is how that case translates into a constitutional system in which dignity is not merely an interpretive lens on privacy but one of its constitutive elements. The Supreme Court of India in Puttaswamy (2017) treated dignity and autonomy not as illustrations of the right to privacy but as among its essential components a doctrinal starting point substantially stronger than the interpretive frameworks this literature has so far engaged with, and one it has not yet been tested against.
It should be acknowledged that this position is contestable. The orthodox view that legal personality, and with it any personal right, ends at death remains the default position in most legal systems, including India’s, and is not without justification: extending rights to those who can no longer exercise, waive, or enforce them raises genuine questions about whose interest is actually being protected. Section 5.1 returns to this objection and to the more defensible formulation this paper adopts in response to it.
2.3 Digital-Asset Succession and the Limits of the Property Approach
The earliest legal literature on digital death concerned succession rather than privacy. Kutler argued that digital assets ought to be treated as heritable property and probated like any other estate asset (Kutler, 2011). Banta extended this analysis, identifying specific difficulties executor access, inconsistent platform terms, and the legal status of accounts nominally closed on a user’s death and recommended that these be clarified by statute (Banta, 2015). Both contributions remain useful, and neither purport to be a complete solution.
The property-based approach has advanced furthest in the form of RUFADAA, now enacted in most U.S. states, under which executors and fiduciaries may obtain access to a deceased individual’s digital accounts, subject to the user’s prior instructions and platform cooperation (Uniform Law Commission, 2015). On its own terms, RUFADAA offers a workable structure for estate administration, but it shares a structural weakness identified by Harbinja and others: it says nothing about what should happen to the data once access has been granted (Harbinja, 2017b). An executor who obtains RUFADAA access to a deceased person’s private messages owes no legal duty to keep them confidential, as the deceased would have been entitled to expect during their lifetime. The privacy interest, on this model, is not transferred to anyone; it is simply extinguished. The property framework therefore resolves the question of access without resolving the question of confidentiality, and the two are not the same problem.
A proponent of the property approach might reasonably respond that this is a feature rather than a flaw: a bright-line, administrable rule of inheritance is more workable at scale than a dignity-based test requiring case-by-case evaluation of sensitivity, and estate administration has never guaranteed the confidentiality of a deceased person’s papers against inspection by an executor. This is a fair objection, and it is one reason this paper’s proposed framework, developed in Part 5, retains a property-like tiered-access structure for estate purposes while layering a dignity threshold on top of it for data whose disclosure could cause identifiable harm, rather than treating the two approaches as mutually exclusive.
This gap between access and confidentiality has not gone entirely unaddressed at the level of adjudication elsewhere. Germany’s Federal Court of Justice held, in a widely discussed decision arising from a mother’s attempt to access her deceased daughter’s Facebook account, that a user’s contractual rights in a social media account pass to her heirs under ordinary succession law in the same manner as personal letters and diaries, rejecting the platform’s argument that the confidentiality interests of the deceased’s correspondents barred such access (Bundesgerichtshof [BGH] [Federal Court of Justice], Judgment of July 12, 2018, III ZR 183/17 (Ger.)). That decision illustrates a route to resolving digital-inheritance disputes through existing succession doctrine, in a jurisdiction that, like India, has no dedicated posthumous-privacy statute. It resolves the question of access, however, and consistently with the critique above does not itself address the ongoing confidentiality of the data once an heir has obtained it.
2.4 AI and Digital Resurrection
AI technology capable of reconstructing a deceased person from their digital footprint has made a significant contribution to this debate. Hollanek and Nowaczyk-BasiÅ„ska offer the most comprehensive ethical and legal examination to date of “Griefbots,” voice clones, and video avatars generated from a deceased person’s data, and argue for a dedicated regulatory framework grounded in three requirements: the deceased’s prior informed consent, clear disclosure to users that they are interacting with a simulation, and limits on commercial exploitation (Hollanek & Nowaczyk-BasiÅ„ska, 2024). No jurisdiction examined in this paper currently mandates any of these three requirements.
Ciani and Pagallo examine the same problem through the lens of data-protection principles specifically, asking how GDPR concepts such as purpose limitation, data minimisation, and consent would apply to AI-based memorial chatbots if the Regulation were extended to cover the deceased, and conclude that its present silence on this question is itself a live regulatory failure (Ciani & Pagallo, 2025). A further contribution argues that the problem may be better addressed through design than through law alone, proposing that consent and transparency mechanisms be built into the architecture of AI afterlife platforms rather than imposed solely through external regulation (Springer Nature, 2026). The underlying commercial dynamics are set out in earlier work by Floridi and Öhman, who characterise the digital afterlife as an industry whose commercial incentives do not align with the dignity interests of the people whose data it exploits (Floridi & Öhman, 2017). This body of scholarship has identified a genuine legal problem and proposed workable responses to it, almost entirely within European and American law. The DPDP Act does not address AI-driven processing of a deceased person’s data at all, which means that, in India, there is currently no legal basis on which to challenge the use of a dead person’s data to construct an AI simulation of them, notwithstanding that the companies offering such services operate globally and are not beyond the reach of Indian courts.
2.5 Where the Literature Leaves Us
Taken as a whole, the literature accomplishes three things. It establishes, on a principled basis, that posthumous privacy has a coherent legal foundation rather than resting on sentiment alone. It demonstrates that the property-based response, most fully developed in RUFADAA, lacks the structural capacity to protect privacy once access has been granted. And, through the AI-afterlife scholarship, it shows that the practical stakes of this problem are considerably higher than they were even a decade ago. What the literature has not done is examine how posthumous data protection ought to be constructed in a jurisdiction governed by a constitutional dignity paradigm of the kind India’s Puttaswamy jurisprudence supplies. This is a distinctive feature of the Indian case: a large and young internet-using population generating a correspondingly large digital footprint, combined with a new data protection statute that addresses posthumous data through deliberate silence rather than considered rejection, and whose consequences remain unexamined.
2.6 Research Gap and the Contribution of this Paper
The scholarship reviewed above has established three things with reasonable confidence: that a dignity-based case for posthumous privacy is analytically coherent and increasingly accepted in Western legal literature (Harbinja, 2017a, 2023); that the leading property-based response, RUFADAA, resolves questions of access to a deceased person’s data without addressing the privacy of what is accessed (Harbinja, 2017b); and that AI-driven resurrection technologies compound both problems by creating a new legal object a simulation of the dead presented to the living for which no jurisdiction examined here has developed specific rules (Hollanek & Nowaczyk-BasiÅ„ska, 2024; Ciani & Pagallo, 2025). What this literature has not done, largely because its authors have worked within European and American legal systems, is test the dignity-based argument against a constitutional order in which dignity functions as a substantive component of a fundamental right rather than an interpretive gloss upon it. India’s Puttaswamy jurisprudence presents precisely such an order, paired with a data protection statute that has chosen not to engage with posthumous data at all. This combination of constitutional dignity doctrine and statutory silence has not, to this paper’s knowledge, been examined in the existing literature on post-mortem privacy, digital-asset succession, or AI afterlife technologies. This paper’s contribution is to supply that examination: it treats the comparative positions of the GDPR and RUFADAA not as models for direct transplantation but as reference points against which to construct a dignity-based, India-specific framework for posthumous data governance, addressing both ordinary posthumous privacy and its more acute AI-driven variant.
3. Methodology
Having identified this gap, the paper now sets out the method used to address it. The paper adopts a doctrinal and comparative legal methodology. It does not generate primary empirical data through surveys, interviews, or statistical analysis; its claims are legal in character concerning what existing law provides, where it falls short, and what a reformed framework should contain and its method is accordingly one of legal analysis and reasoned argument from authoritative sources.
3.1 Doctrinal Analysis
The primary method employed is doctrinal. The paper identifies and analyses the relevant legal rules constitutional provisions, statutory text, judicial decisions, and international instruments and evaluates whether they adequately address the governance problem identified in Part 1. This exercise is not purely descriptive. Doctrinal analysis, as understood in legal scholarship, requires evaluating the internal coherence of legal rules, identifying gaps and contradictions within them, and constructing principled arguments for how the law ought to develop (Hutchinson & Duncan, 2012). The framework proposed in Part 5 is the product of this analytical process rather than an independent policy recommendation divorced from legal reasoning.
3.2 Primary Sources
The paper draws on four categories of primary source. Constitutional materials comprise Article 21 of the Constitution of India and the Supreme Court’s decision in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), with particular attention to the concurring opinions of Chandrachud J. and Kaul J. on informational privacy and dignity. Statutory materials comprise the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, read alongside their respective statements of objects and reasons and relevant subordinate legislation. International instruments comprise the General Data Protection Regulation (Regulation (EU) 2016/679), with particular attention to Recital 27 and the member-state discretion it preserves over posthumous data, and the Revised Uniform Fiduciary Access to Digital Assets Act as enacted in the United States. Platform governance materials comprise the terms of service and legacy policies of major platform Facebook, Google, Apple, and WhatsApp examined as instances of private ordering in the absence of public law.
3.3 Comparative Method
The comparative analysis covers three jurisdictions India, the European Union, and the United States selected not for comprehensiveness but for representativeness. The European Union represents the most developed statutory approach to data protection globally, and its deliberate silence on posthumous data under the GDPR, a silence that has generated substantial scholarly and regulatory commentary, is instructive precisely because it reflects a considered legislative choice rather than an oversight. The United States represents a property-based approach to digital succession, most fully developed in RUFADAA, which prioritises estate administration over privacy protection, and which has additionally been supplemented by judicial recognition of digital-inheritance claims in other jurisdictions applying similar succession principles. India represents a jurisdiction with a constitutionally grounded right to privacy and a new comprehensive data protection statute, but unlike either the European Union or the United States no legislative engagement whatsoever with the posthumous dimension of personal data. The comparison is not undertaken to argue that India should simply import either model; it is undertaken to identify what each model gets right, what each gets wrong, and what a framework designed for India’s specific constitutional and social context would need to contain.
3.4 Scope and Limitations
This paper does not address digital assets of purely financial value cryptocurrency holdings, non-fungible tokens, or digital bank accounts except where they intersect with privacy interests. Its focus is personal data: the communications, records, and identity materials that attract privacy protection during a person’s lifetime. It does not address the law of defamation of the dead as a freestanding subject, though the analogy it offers is drawn on briefly in Part 5. Its geographic focus on three jurisdictions necessarily excludes other relevant approaches Canada, Australia, South Korea, and several South Asian jurisdictions have each developed relevant law or policy but the three jurisdictions selected are sufficient to map the principal legal strategies available and to test this paper’s central argument against them.
4. Results
Applying the doctrinal and comparative method set out in Part 3, this research identifies five principal findings, presented descriptively below; their analytical implications are addressed in Part 5.
4.1 Most Jurisdictions Lack Dedicated Posthumous Privacy Legislation
The comparative survey confirms the position long suggested in the literature: comprehensive posthumous privacy legislation does not exist in any of the major jurisdictions examined. The GDPR, widely regarded as the most advanced data protection framework in force, expressly excludes deceased persons from its scope under Recital 27, while permitting member states to legislate for the posthumous processing of personal data should they choose to do so (European Parliament & Council of the European Union, 2016). As of the time of writing, fewer than half of EU member states have exercised this discretion in any substantial way, and those that have France being the most developed example have enacted limited mechanisms rather than comprehensive frameworks. The United States has addressed the related but distinct question of executor access to digital accounts through RUFADAA, but has not enacted federal or state legislation specifically governing the privacy of posthumous personal data. The United Kingdom, post-Brexit, retains a domestic version of the GDPR but has likewise not addressed posthumous privacy by statute. The pattern across jurisdictions is consistent: legislatures have either avoided the question entirely or treated it as a matter of succession law rather than privacy law.
It might be argued that this legislative restraint is itself defensible: legislating prematurely on a technologically fast-moving and ethically contested question risks freezing in place rules that quickly become obsolete, and the GDPR’s choice to leave the matter to member-state discretion can be read as a considered acknowledgment of that difficulty rather than an oversight. The position developed in Part 5 is that the cost of continued silence a governance vacuum filled by private platforms outweighs the benefit of legislative caution, but the caution itself is not unreasonable.
4.2 Platform Policies Function as De Facto Law
In the absence of statutory regulation, the governance of deceased persons’ digital data is effectively determined by platform terms of service. This research examined the legacy policies of four major platforms. Facebook’s Memorialisation Policy permits an account to be converted to a memorial state, managed by a designated Legacy Contact, though the Legacy Contact’s powers are limited: they cannot read private messages, access stored payment methods, or remove the account without a separate removal request (Meta, n.d.). Google’s Inactive Account Manager permits users to designate trusted contacts who may download specified data after a defined period of inactivity (Google, n.d.). Apple does not currently permit inheritance of an iCloud account absent a court order, a position that has generated litigation in at least one jurisdiction. WhatsApp’s terms of service terminate the account on death and provide no mechanism for family access.
These policies share two characteristics relevant to this paper’s argument. First, they vary considerably: the same deceased person’s data may be accessible on one platform and entirely inaccessible on another, depending solely on corporate policy. Second, they are commercially motivated platform legacy policies are designed principally to manage reputational risk rather than to give effect to the privacy interests of deceased users. A market-based defence of this arrangement would note that platform policies can adapt more quickly than legislation and can be tailored to the technical realities of each service. That flexibility, however, is precisely what produces the inconsistency identified above: the same data may be treated differently depending on which platform holds it, for reasons unrelated to the sensitivity of the data itself. The resulting system of governance is inconsistent, non-transparent, and unaccountable to any democratic process.
4.3 India’s DPDP Act 2023 Creates a Near-Total Legislative Vacuum
The DPDP Act defines “data principal” as the individual to whom personal data relates, and its core protections, the right to access, correction, erasure, and grievance redress, attach to that individual (Government of India, 2023). The Act does not specify what happens to these rights upon the data principal’s death. It makes no provision for the transmission of data rights to nominees or legal heirs. It neither permits nor prohibits posthumous data processing by data fiduciaries, and it does not address the use of a deceased person’s data for secondary purposes, including AI training. On the question of posthumous data, the legislative silence is, in substance, total.
This silence is not accidental. The Joint Parliamentary Committee that examined the Personal Data Protection Bill, the DPDP Act’s predecessor, noted the question of posthumous data in its 2021 report but declined to recommend specific provisions, citing the need for further consultation (Joint Committee on the Personal Data Protection Bill, 2021). That consultation has not produced any legislative output. The result is that India, with more than 900 million internet users and a constitutional right to privacy the Supreme Court has described as an inalienable natural right, currently has no statutory framework governing what happens to personal data when those users die.
4.4 The IT Act 2000 and Succession Law Do Not Fill the Gap
Two existing legal instruments might, in principle, provide some regulatory coverage for posthumous personal data: the Information Technology Act, 2000, and the general law of succession. Neither does so adequately. The IT Act’s principal data protection provision is Section 43A, which imposes liability on corporate bodies for the negligent handling of sensitive personal data, supplemented by the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (Government of India, 2000, 2011). Both instruments are directed at protecting the rights of living individuals whose data is being processed; neither addresses posthumous data in any respect. The Indian Succession Act, 1925, governs the transmission of property on death, but personal data does not fit comfortably within the category of transmissible property, particularly where, as is typical, it is held by a third-party platform under a licensing arrangement rather than owned outright by the user (Government of India, 1925).
4.5 AI Technologies Have Materially Raised the Stakes
This research confirms that AI-driven digital resurrection technologies systems that reconstruct a deceased individual’s voice, personality, or written style from their digital remains are now commercially available and in active use. Companies including HereAfter AI, StoryFile, and Eternos offer services of this kind to bereaved families. The data on which these systems are trained is typically sourced from social media profiles, messaging applications, voice recordings, and other personal data generated during the deceased’s lifetime, in most cases without consent to this specific use (Hollanek & Nowaczyk-BasiÅ„ska, 2024). None of this use is currently regulated by Indian law. The posthumous privacy problem is accordingly no longer hypothetical or remote: it is a live commercial practice operating without legal constraint and one that affects Indian users whose data is processed by globally operating platforms. This is the point at which the findings above converge, and it is where the discussion in Part 5 begins.
5. Discussion
The findings above point to one conclusion: India needs a posthumous privacy framework, and the appropriate place to build it is constitutional law rather than succession law. This section develops that argument in five steps. It begins by asking whether the right to privacy identified in Puttaswamy can, as a matter of constitutional principle, survive death. It then examines the specific failure of the DPDP Act and the deficiencies of the existing alternatives. It outlines what a purpose-based framework for posthumous privacy should look like in the Indian context before considering why AI-driven digital resurrection warrants regulatory attention beyond that general framework. It concludes by addressing the question of limits a right that persists indefinitely after death is, in its own way, as problematic as a right that does not survive death at all.
5.1 Will the Puttaswamy Right Survive Death?
The right to privacy recognized in Puttaswamy (2017) is not a simple, unitary right: the nine-judge bench delivered six separate opinions. The Court was unanimous as to the existence of the right, but the opinions did not converge on a single rationale for it. Read together, however, the judgments ground the right in at least three values: dignity, autonomy, and informational self-determination. Chandrachud J.’s opinion is the most analytically precise on this point, holding that privacy is not merely the right to be let alone but the right to control the narrative of one’s own life to decide what information about oneself enters the public domain and on what terms (Puttaswamy, 2017). Kaul J. addressed the connection between privacy and identity, describing the right as the capacity of an individual to create and sustain a self that cannot be reduced to what others say about them.
This paper asks whether these values survive death in any legally cognisable form. The orthodox position is that they do not: Article 21 protects the life and personal liberty of a “person,” and legal personality in Indian law, as elsewhere, is generally understood to terminate at death. That orthodox position, however, produces conclusions that are difficult to accept. Taken to its logical end, it would permit a company to publish a deceased person’s most intimate private communications the day after their death without legal consequence; it would permit a hospital to sell a dead patient’s medical records; and it would permit an AI company to train a chatbot on a deceased person’s private messages and sell access to it to the deceased’s own family, without incurring liability under any provision of Indian law. These are not hypothetical absurdities; they are the practical consequences the existing legal vacuum already permits, and they are difficult to defend on any coherent account of what privacy law exists to protect.
The more defensible position, and the one this paper advances, is that the Puttaswamy right does not survive death as a personal right held by the deceased, but that what survives is a protective interest, cognisable by the deceased’s legal heirs or nominated data trustees, in data that retains privacy-relevant characteristics. This is not a novel legal device. Indian law already recognizes analogous posthumous interests in adjacent areas: criminal defamation under the Indian Penal Code expressly extends to imputations concerning a deceased person where the imputation would harm the person’s reputation if living and is intended to be hurtful to the feelings of their family or near relatives (Indian Penal Code, 1860, s. 499, Explanation 1); succession law gives continuing legal effect to a testator’s wishes after their death; and copyright law affords the author’s moral rights some measure of protection independent of continued life, though the precise post-mortem scope of these rights requires further verification. Extending a cognate principle to personal data is not a departure from existing Indian law but a natural extension of it.
Indian constitutional jurisprudence has, in an adjacent context, already recognised that the value of dignity does not simply vanish at the threshold of death. In recognising a right to die with dignity, the Supreme Court in Common Cause v. Union of India, (2018) 5 SCC 1, building on Gian Kaur v. State of Punjab, (1996) 2 SCC 648, treated dignity as a value attaching to the process and manner of dying itself, not merely to a life while it is lived. This is not authority for a posthumous privacy right the death addressed in that line of cases is the dying person’s own act, not events after death has occurred but it is a domestic illustration that Indian constitutional doctrine already treats dignity as extending beyond the strictly biological boundary of continued life, which lends the analogical argument made here more traction than a comparison to foreign dignity jurisprudence alone would provide.
5.2 The Silence of the DPDP Act and Why It Is Unsustainable
The DPDP Act was, in several respects, a significant legislative achievement. It gave data protection statutory footing in India for the first time, established the Data Protection Board as an adjudicatory body, and introduced concepts such as “data fiduciary,” “data principal,” and layered consent that align Indian law with internationally recognised frameworks (Government of India, 2023). Its silence on posthumous data is, for that reason, more striking rather than less.
That silence cannot be justified on the ground that posthumous data is an insignificant issue. India’s internet penetration rate exceeds 50 percent, and its digital population is the largest in the world. Every one of these individuals will eventually die, while the health data, financial data, communications, and biometric data they generate will outlive them. The legislature’s silence on governing this data is better understood as a policy choice than as a mere omission, and its effect is to leave governance of this data to private platforms whose practices are inconsistent and largely unaccountable.
The GDPR’s approach is instructive by contrast: rather than legislate on posthumous data directly, it explicitly acknowledges the governance gap and preserves member-state discretion to close it. Recital 27 provides that the Regulation does not apply to deceased persons but permits member states to legislate for the processing of their personal data (European Parliament & Council of the European Union, 2016). This is not a substantive rule, but it is an acknowledgment that posthumous data governance is a legitimate and important question an acknowledgment the DPDP Act does not contain. The Joint Parliamentary Committee’s 2021 recommendation for further consultation has not been acted upon, and the governance gap remains formally unacknowledged in Indian law.
5.3 Towards a Purpose-Driven Posthumous Privacy Regime for India
This paper proposes a framework with three components: a dignity-based threshold test for posthumous privacy; a tiered access system loosely modelled on RUFADAA but expanded to encompass privacy rights rather than access alone; and a time limitation intended to prevent posthumous control from becoming an open-ended constraint on the lawful use of data.
The dignity threshold test turns on a single question: does the processing or disclosure of this data retain the potential to affect the dignity or identity of the deceased individual or of surviving family members? The answer depends on the nature of the data, and no fixed rule can determine it in advance. Medical data, private communications, and biometric data would generally meet this threshold; data the deceased voluntarily made public during their lifetime generally would not.
The tiered access regime distinguishes between three categories of user. Nominated data trustee’s persons designated by the deceased during their lifetime, analogous to a digital will should hold the broadest access rights, including access to private communications, authority to instruct platforms to delete data, and authority to consent to secondary processing. Legal heirs, absent such nomination, should hold more limited rights, sufficient for estate administration but not extending to data the deceased did not wish to disclose during their lifetime. Researchers, journalists, and historians should have access only where a genuine public interest justifies it, and only under appropriate safeguards, including anonymisation.
The time limitation is arguably the most consequential element of the proposed regime. A posthumous privacy right that persists indefinitely creates its own difficulties, discussed further in section 5.5. Fixing an ideal duration is difficult, and any figure will be somewhat arbitrary; a period of twenty-five years comparable to periods used for certain categories of information under the Right to Information Act, 2005 offers a defensible starting point, subject to extension for especially sensitive categories of data, such as medical records or data revealing sex or religion, and to reduction or inapplicability for data of lesser sensitivity.
5.4 The AI Problem and the Limits of Ordinary Privacy Law
AI-based digital resurrection technologies require regulatory attention that a well-crafted posthumous privacy framework, on its own, cannot supply. The difficulty is not merely that these technologies use posthumous data that aspect is addressed by the tiered access scheme and dignity threshold proposed above. The difficulty is that these technologies use posthumous data to create something new: a simulation of the dead person, presented to a living audience as a form of continuation. This raises a question of identity, not merely of privacy.
This paper does not claim to resolve that question definitively. Three observations, however, are warranted. First, the absence of any regulatory regime for afterlife technologies in India means this dilemma is currently being resolved by market participants alone, which is plainly suboptimal. Second, the criteria proposed by Hollanek and Nowaczyk-BasiÅ„ska consent, transparency, and limited commercial exploitation offer a workable starting point for regulation, and are compatible with the purpose-based approach advocated here (Hollanek & Nowaczyk-BasiÅ„ska, 2024). Third, the Data Protection Board established under the DPDP Act is well placed to take the lead in formulating guidelines on the posthumous use of AI technologies, should the Act be amended to bring deceased individuals’ data within its jurisdiction.
5.5 Balancing Posthumous Privacy Against Competing Interests
Any right is relative, and a posthumous right to privacy is no exception. Three categories of competing interest warrant particular attention. The first concerns legal heirs: families may have legitimate financial and emotional interests in accessing a deceased relative’s digital legacy, and a workable posthumous privacy regime must not render such access unreasonably difficult.
The second concerns scholars and historians. The records that individuals generate through everyday technology use in the twenty-first century constitute a substantial archive of social and cultural history, and an overly broad posthumous privacy regime risks impeding legitimate historical scholarship to the detriment of the public interest. This is precisely why the time limitation and the public-interest exception form part of the tiered access framework proposed above.
The third, and arguably the most important, concerns the interests of the living. The protection of a long-dead person’s privacy cannot ultimately be justified from the perspective of the dead, who have no interests in any meaningful philosophical sense; it must instead be justified from the perspective of family members who may be harmed by disclosures concerning a deceased relative, of communities whose willingness to share data depends on an assurance that it will continue to be treated respectfully after its subject’s death, and of individuals presently generating the data that will constitute their own digital legacy.
6. Conclusion
The problem examined in this paper is straightforward to state and difficult to resolve: personal data outlives the person who generated it, and Indian law does not currently say what should happen to it. This is not a peripheral gap. It leaves families without a lawful basis to access the accounts of relatives who have died, permits data fiduciaries to process a deceased person’s information without statutory constraint, and leaves the emerging practice of AI-driven digital resurrection entirely unregulated. Because the data in question medical records, private communications, biometric identifiers is precisely the category of information to which the Constitution affords its highest privacy protection during a person’s lifetime, the absence of any posthumous framework sits uneasily with the dignity rationale the Supreme Court has placed at the centre of Article 21.
This paper has argued that the right recognised in Puttaswamy (2017) does not survive death as a personal right of the deceased, but that a protective interest, grounded in dignity and exercisable by heirs or nominated data trustees, can and should be recognised in its place. The DPDP Act’s silence on this question is not a neutral omission; it is, in effect, a policy choice to leave posthumous data governance to the private terms of service of technology platforms a body of private ordering that is inconsistent across platforms and unaccountable to any public process. Neither the Information Technology Act, 2000, nor the Indian Succession Act, 1925, was designed with this problem in mind, and neither supplies an adequate substitute.
6.1 Immediately Feasible Measures
Some of the reforms proposed in this paper do not require new legislation and could be pursued relatively quickly. The Data Protection Board, acting within its existing regulatory mandate under the DPDP Act, could issue guidance clarifying how data fiduciaries should treat requests concerning deceased data principals, pending any statutory amendment. Platforms operating in India could be encouraged, through regulatory guidance rather than new primary legislation, to offer clearer and more consistent digital-legacy and nomination tools of the kind already provided, in varying forms, by Google and Facebook, so that Indian users are given the opportunity to designate a data trustee during their lifetime rather than leaving the matter to inconsistent platform discretion after death. Courts, in the ordinary exercise of interpretation, could also draw on the reasoning in Puttaswamy to recognise a limited dignity-based interest of heirs in appropriate cases without waiting for Parliament to act following, in this respect, the example of jurisdictions where courts have resolved digital-inheritance disputes through existing succession doctrine rather than new statute.
6.2 Long-Term Legislative Reform
Other elements of the framework proposed in this paper cannot be achieved through interpretation or regulatory guidance alone and require legislative action. The DPDP Act would need to be amended to bring deceased data principals within its scope, at least to the extent of recognising a data trustee’s or heir’s standing to seek access, correction, or erasure. The tiered access and dignity-threshold framework proposed in Part 5 would benefit from express statutory recognition rather than reliance on regulatory guidance or judicial analogy alone, both of which are more easily reversed. Most urgently, the use of a deceased person’s data to train AI systems that reconstruct their voice, personality, or likeness currently has no legal basis or limit under Indian law, and requires a dedicated statutory response along the lines proposed by Hollanek and Nowaczyk-BasiÅ„ska  informed consent obtained during life, disclosure to users that they are interacting with a simulation, and limits on commercial exploitation  rather than continued reliance on market self-regulation (Hollanek & Nowaczyk-BasiÅ„ska, 2024).
India’s data protection framework is still young enough that this gap can be closed deliberately rather than in response to a crisis. Data generated today by India’s more than 900 million internet users will remain in existence for decades after those users have died. The tendency of law to lag behind technology is not unique to this problem, but the scale of India’s digital population makes the cost of continued delay considerably higher here than elsewhere.
References
Banta, N. M. (2015). Death and digital assets. Cleveland State Law Review, 63(3), 1–46.
Bundesgerichtshof [BGH] [Federal Court of Justice], Judgment of 2018, III ZR 183/17 (Ger.).
Ciani, J., & Pagallo, U. (2025). No peace after death? The impact of AI-driven memorial chatbots on privacy and data protection. Information, 16(6), 426. https://doi.org/10.3390/info16060426
Common Cause v. Union of India, (2018) 5 SCC 1 (India).
European Parliament & Council of the European Union. (2016). Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). Official Journal of the European Union, L119, 1–88.
Floridi, L., & Öhman, C. (2017). The political economy of death in the age of information: A critical approach to the digital afterlife industry. Minds and Machines, 27(4), 639–662. https://doi.org/10.1007/s11023-017-9445-2
Gian Kaur v. State of Punjab, (1996) 2 SCC 648 (India).
Google. (n.d.). Inactive Account Manager. Google Account Help. Retrieved June 2026, from https://support.google.com/accounts
Government of India. (1860). The Indian Penal Code, 1860 (Act No. 45 of 1860).
Government of India. (1925). The Indian Succession Act, 1925 (Act No. 39 of 1925).
Government of India. (2000). The Information Technology Act, 2000 (Act No. 21 of 2000).
Government of India. (2011). Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
Government of India. (2023). The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023).
Harbinja, E. (2017a). Post-mortem privacy 2.0: Theory, law and technology. International Review of Law, Computers & Technology, 31(1), 26–49. https://doi.org/10.1080/13600869.2017.1275116
Harbinja, E. (2017b). Post-mortem privacy: Trustworthiness as a personal information governance approach for digital estate management. SCRIPTed, 14(2), 1–23.
Harbinja, E. (2023). Digital death, digital assets and post-mortem privacy. International Journal of Law and Information Technology, 31(4), 413–436. https://doi.org/10.1093/ijlit/eaad014
Harbinja, E., McVey, M., & Edwards, L. (2024). Post-mortem privacy and digital legacy: A qualitative enquiry. SCRIPTed, 21(2), 188–220. https://doi.org/10.2966/scrip.210224.188
Hollanek, T., & Nowaczyk-Basińska, K. (2024). Griefbots, deadbots, postmortem avatars: On responsible applications of generative AI in the digital afterlife industry. Philosophy & Technology, 37(2), 63. https://doi.org/10.1007/s13347-024-00744-w Hutchinson, T., & Duncan, N. (2012). Defining and describing what we do: Doctrinal legal research. Deakin Law Review, 17(1), 83–119.
Indian Penal Code, 1860, s. 499, Explanation 1 (India).
Joint Committee on the Personal Data Protection Bill, 2019. (2021). Report of the Joint Committee on the Personal Data Protection Bill, 2019. Lok Sabha Secretariat, Parliament of India.
Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (India).
Kutler, N. (2011). Protecting your online you: A new approach to handling your online persona after death. Buffalo Law Review, 59(3), 991–1023.
McCallig, D. (2014). Facebook after death: An evolving policy in a social network. International Journal of Law and Information Technology, 22(2), 107–140. https://doi.org/10.1093/ijlit/eau001
Meta. (n.d.). Memorialization Policy. Meta Help Center. Retrieved June 2026, from https://www.facebook.com/help
Morse, T., & Birnhack, M. (2022). The posthumous privacy paradox: Privacy preferences and behavior regarding digital remains. New Media & Society, 24(1), 1–20. https://doi.org/10.1177/14614448211037363
Morse, T., Harbinja, E., & Edwards, L. (2025). Digital remains and post-mortem privacy in the UK: What do users want? International Review of Law, Computers & Technology, 39(1), 1–22. https://doi.org/10.1080/13600869.2025.2506164 Öhman, C., & Watson, D. (2019). Are the dead taking over Facebook? A Big Data approach to the future of death online. Big Data & Society, 6(1), 1–13. https://doi.org/10.1177/2053951719842540
Smolensky, K. R. (2009). Rights of the dead. Hofstra Law Review, 37(3), 763–803.
Springer Nature. (2026). The making of digital ghosts: Designing ethical AI afterlives. Ethics and Information Technology, 28(1). https://doi.org/10.1007/s10676-026-09910-4 Uniform Law Commission. (2015). Revised Uniform Fiduciary Access to Digital Assets Act.


