Skip to main content
All guides
Digital legacy

Who owns your data after you die? It depends where you lived

Most data-protection law guards the living, not the dead: how the UK and EU position differs from India's DPDP Act, and why you should check what applies.

LifeWyn editorial teamPublished 2026-09-06 · reviewed 2026-09-067 min readv1United Kingdom, India

Not independently reviewed.

You die. Your data doesn't.

Ask who owns your data after you die and you have already half-asked the wrong question. Most of what we call our data isn't owned the way a house or a bank balance is owned. It's held by companies under rules about how they may use it, and a lot of those rules rest on one quiet assumption: that the person the data describes is still alive to have rights over it. When that stops being true, the rulebook doesn't always have a next page.

So the useful question isn't really about ownership. It's about protection and access, which are two different things and can point in opposite directions. Protection is whether privacy law still treats your emails, your search history, your medical records as yours once you're gone. Access is whether anyone you left behind can actually get into the account they sit in. A regime can drop the first while doing nothing about the second, and that is roughly where much of the world sits today.

The answer also changes with where you lived and which company holds the data. There is no single global position. What follows sets two very different approaches side by side, the UK and EU model against India's newer statute, to show how much daylight lies between them. None of this is advice on your situation, and the detail shifts over time and by provider, so treat it as a map of the terrain rather than a ruling, and check what applies where you live.

The UK and EU: privacy law generally stops at death

Start with the widest-reaching privacy regime most people brush against. The EU's General Data Protection Regulation, and the UK version that mirrors it, are built to protect living individuals. The GDPR's own recitals are explicit that it doesn't extend to the personal data of the dead, and it leaves each member state free to set its own rules for that data if it wants to. At the European level, in other words, the deceased sit outside the frame by design.

The UK lands in the same place. The ICO, Britain's data-protection regulator, describes personal data as information about a living, identifiable person, and that line is what decides whether the UK GDPR and the Data Protection Act 2018 bite at all. Once someone has died, information about them generally falls outside that definition, so the familiar tools people expect, the right to see what a company holds, to have it corrected or deleted, aren't the route a grieving family reaches for. Those rights belonged to the living person.

That leaves a real gap, and it's worth naming plainly. National law can fill parts of it, through confidentiality, defamation or specific rules on things like health records, so "outside GDPR" isn't the same as "a free-for-all". But there's no tidy, single successor right to a dead relative's data across the UK and EU. What a family can actually retrieve tends to come down to each company's own bereavement process rather than a statutory demand. The specifics vary by country and change over time, so check what applies where you live instead of assuming a right exists.

India's DPDP Act: a nominee who can act after you're gone

India took a noticeably different turn. Its Digital Personal Data Protection Act, passed in 2023, does the thing the European model deliberately left to individual countries: it writes the deceased into the statute itself. The Act's definition of a Data Principal, the person the data is about, is drawn to include, on that person's death or incapacity, a nominee they appointed. The dead person's stand-in is built into who counts.

The mechanism is the right to nominate, at Section 14. It lets you name someone to exercise your data rights if you die or can no longer act for yourself, so a chosen person steps into your shoes rather than the rights simply evaporating. Commentators reading the Act have called this India's first real statutory acknowledgement of what happens to personal data after death, which tells you how unusual an explicit provision like this still is. The finer detail of how a nomination is made and honoured sits in rules made under the Act, and that machinery has been filling in over time.

It's easy to over-read, though, so hold two things apart. A data nominee under the DPDP framework is about exercising data rights, asking to see, correct or delete the personal data. It is not the same as inheriting an asset or a bank balance, which runs on succession and nomination rules of its own. The two can name different people and answer different questions. If you're in India, the sharper move is to know which of your nominations is which, and to check the current position under the Act and its rules rather than assuming one form covers everything.

Why the regimes differ so much, and what that means for you

The gap between these two approaches isn't an accident of drafting. Europe treats data protection as a personal right that belongs to a living person and, in the main, ends with them, leaving the afterlife to national law if a country cares to legislate. India, arriving later and having watched how messy the silence got elsewhere, chose to write a successor straight into the data law. Neither is obviously wrong. They're answers to the same problem from different starting points, and they leave your family in quite different positions.

For anyone whose digital life crosses borders, and that's most people now, the awkward part is that more than one regime can be in play at once. Where you lived, where a company is based, where its servers sit and what its own terms say can all pull in different directions. A single inbox might be governed by rules that say nothing about your death, or by a nominee provision from another country that does, depending on who's holding it. No single rule sorts it out for you.

The honest takeaway isn't something you can memorise. It's a habit. Assume the law alone won't reliably hand your accounts to the people you'd want, because across large parts of the world it was never built to. Then find out, provider by provider and country by country, what actually applies to the accounts that matter to you. That last step is the one people skip, and it's the one that decides whether your family inherits a plan or a locked door.

What you can actually do about it

Since the law is patchy and varies by place, the reliable lever is the one in your own hands: leave a clear record and use the tools each provider already gives you. Plenty of the big platforms have their own way to pass on or wind down an account, whether a legacy contact, an inactive-account setting or a nominated person, and where a regime like India's offers a data nominee, that's worth using too. None of these switch themselves on. You arrange them while you're well; a family doesn't find them waiting for them.

Underneath the individual settings, keep one current index of what exists: the accounts, where they live, and what you'd want done with each. That record is what turns a scattered set of provider rules into something a person can actually follow. It also covers the ground the law leaves bare, because a family that knows an account exists and who to ask is in a far stronger position than one guessing in the dark, whichever regime happens to apply.

This is the layer a zero-knowledge vault like LifeWyn is built to hold. Your inventory, your access notes and your wishes stay encrypted while you're alive, and are released to the people you named once it's verified they should have them. It doesn't override anyone's law, and it's no substitute for checking what applies where you live. What it does is make sure the people you trust aren't left dependent on whether the local rulebook happened to have a next page.

Questions people ask

Does GDPR still protect my personal data after I die?
Generally no, at the European level. The GDPR's recitals say it doesn't apply to the personal data of deceased people, and the UK GDPR works the same way because the ICO describes personal data as information about a living individual. Member states and national law can add their own rules for the dead, and some do through other routes, so the picture varies by country. Check what applies where you live rather than assuming the usual data rights carry over.
In India, does naming a data nominee mean my family owns my data?
Not exactly. India's DPDP Act includes a right to nominate, at Section 14, that lets a nominee exercise your data rights, such as access, correction and erasure, if you die or can't act. That handles the data; it isn't the same as inheriting an asset, which runs on separate succession and nomination rules. The two can name different people. Confirm the current position under the Act and the rules made under it before you rely on any single form.
My accounts span several countries. Whose rules apply?
Possibly more than one set at once. Where you lived, where the company is based, where the data sits and what the provider's own terms say can each pull differently, and nothing settles it universally. The dependable move is to treat the law as unreliable cover, check each important provider's own process, and leave a clear record of what exists and who should reach it. That record is what your family can follow whichever regime turns out to govern a given account.

Related

Sources

Describes how things generally work in the country named, at the date of last review. Rules change and individual circumstances differ — this is not legal, tax or financial advice.

Cite this

LifeWyn editorial team (2026). Who owns your data after you die? It depends where you lived. LifeWyn, v1, last reviewed 2026-09-06. https://www.lifewyn.com/guides/who-owns-your-data-after-you-die