Back to notes
·6 min read·LegacyShield Team

GDPR Right to Be Forgotten After Death — What Your Family Can Actually Do

GDPR gives you the right to erase your personal data. But does that right survive your death? What your family can — and cannot — demand companies delete after you're gone.

GDPR right to be forgotten deathdata deletion after deathGDPR right erasure inheritanceposthumous data deletionright to be forgotten family

A Right That Dies With You

You've heard of GDPR. Maybe you've even clicked one of those "Erase My Data" links on a website, half expecting nothing to happen. In the EU, that's a real right — Article 17 of the General Data Protection Regulation gives you the power to demand companies delete your personal data, in many circumstances.

But here's what almost nobody talks about: that right is yours personally. When you die, it doesn't automatically transfer to your family.

Think about what that means. Your medical records. Your browsing history. Your private messages. Your photos uploaded to social platforms. Your location data from years of using your phone. Everything a company has ever collected about you — your family may have almost no legal right to demand it be deleted, sealed, or even accessed.

This isn't a loophole. It's a deliberate feature of European privacy law. And it has consequences your family will face at the worst possible time.

What GDPR Actually Says About Death

Article 17 gives living individuals the right to erasure. But GDPR's Article 1 is clear: it protects natural persons — living human beings. The moment you die, you're no longer a natural person in the legal sense, and most GDPR protections simply stop applying.

This creates a strange legal vacuum. Your data doesn't disappear when you die — companies keep it. But your family often can't control what happens to it.

There are exceptions:

  • Some EU member states have passed their own rules. France, Italy, and Germany have extended certain rights to heirs — but the specifics vary dramatically.
  • Companies may honor requests voluntarily. Facebook, Google, and Apple have bereavement processes, but these are policy decisions, not legal obligations under GDPR.
  • Sensitive data rules may help. Health data, for instance, has stronger protections and some countries allow families to request deletion for specific medical records.

But the baseline answer — "does my family have the right to demand my data be erased?" — is mostly no, at least not as a clean legal right.

The Data That Lingers After Death

Here's what actually remains after someone dies:

Social media profiles sit active for months or years unless a family member finds the right bereavement form and navigates it successfully. In the meantime, the platform may still show your "memories," recommend you to mutual friends, or even serve ads to people who visit your profile.

E-commerce purchase history stays on record indefinitely. Amazon knows every book you ever bought, every product you ever searched. That data doesn't expire.

Health apps and wearables hold months or years of biometric data — heart rate, sleep patterns, stress levels — data that could be sensitive for family members (think genetic-adjacent health indicators).

Banking and financial apps retain transaction data for regulatory reasons, but the retention schedule is often 10+ years.

Email — every message you ever sent or received sits in servers somewhere. Gmail, Outlook, iCloud — they hold it all.

And here's the uncomfortable truth: most companies, when confronted with a death certificate and a family member's request for erasure, will respond with some version of "we're sorry for your loss, but we cannot fulfill this request."

Country-Specific Realities in the EU

The picture isn't entirely bleak. Several EU countries have passed legislation extending digital rights to heirs:

France has led Europe here. Under the Loi pour une République Numérique (2016), French residents can designate a "digital heir" who can instruct platforms on what to do with their data after death — including requesting deletion. Without a designation, family members can still request data deletion for "legitimate reasons."

Germany has taken a different path. German courts have ruled that heirs inherit digital accounts and their contents (Bundesgerichtshof, 2018 decision) — meaning the data belongs to the estate. But data deletion rights remain murky.

Spain, Italy, and the Netherlands follow the baseline GDPR more closely, with limited extensions for heirs.

If you live as an expat across EU borders, this creates a real question: which country's rules apply to your data? The answer depends on where the company is established and where you were resident — and it's rarely straightforward.

What This Means for Your Family Practically

Your family will face this in a fog of grief, often six to twelve months into an already exhausting process of closing accounts, dealing with banks, and managing your estate.

They'll encounter:

  • Platforms that ignore deletion requests from family members who can't prove GDPR standing
  • Data brokers who have your data but who definitely don't feel obligated to delete it for grieving relatives
  • Search engines that may continue surfacing your name in uncomfortable contexts
  • Healthcare portals that refuse to confirm or deny the existence of your records to anyone but you

The practical impact can be more than inconvenience. Sensitive medical data could surface during estate disputes. Old professional records could affect how someone is remembered. Photos in cloud storage could create family conflict over who controls them.

What You Can Do Now

This is fixable — but only if you act while you're alive.

1. Designate a digital executor in your will. In jurisdictions that recognize this (France most clearly, but the concept is gaining legal traction), a designated digital executor has much stronger standing to make deletion requests on your behalf.

2. Identify your highest-sensitivity data and document it. Health app data, private messages, financial account contents — make a list of what exists, where it lives, and what you'd want done with it.

3. Use platforms' own legacy tools. Google has Inactive Account Manager. Facebook has Legacy Contact. Apple has Legacy Contact. These tools don't give your family deletion rights under GDPR, but they do give a path to memorialization, data download, or account closure under company policy.

4. Download and delete what you can while alive. If you have data on platforms you no longer use, request deletion now. Your right to erasure as a living person is much stronger.

5. Leave written instructions. A clear, signed document stating your wishes for data deletion — even without legal force — will help your family make the case to reluctant companies.

6. Consider encrypted, self-hosted alternatives. For your most sensitive data, tools that are stored locally or with end-to-end encryption by default mean there's no company holding it at all.

The Bigger Tension

The right to be forgotten is one of GDPR's most human provisions. It acknowledges that people should be able to control their digital footprint — to escape old mistakes, old versions of themselves, data collected without meaningful consent.

But privacy law, as it currently stands, draws a hard line at death. The person has gone, but the data remains — and the systems that hold it were never designed with death in mind.

Your family deserves to manage your legacy on their terms, not struggle through corporate bereavement forms while grieving. The only way to give them that is to plan ahead.

Start building your digital legacy plan today — so the right to be forgotten doesn't die before you use it.

§ Custody begins

Place your documents in custody — free.

Zero-knowledge encryption, designated heirs, EU-only infrastructure.

Open a vault