Introduction: the account that keeps on living
There is one category of data that France handles particularly badly: that of the dead.
A social media profile that keeps suggesting friends wish a happy birthday to someone who is no longer there. An inbox still receiving bank reminders, newsletters, and sometimes messages from people who were never told. A subscription debited every month from an account that is being closed. A phone left in a drawer, locked, holding ten years of photographs that no one will ever recover — or, conversely, holding conversations the deceased would never have wanted anyone to read.

On this site we talk a great deal about protecting your anonymity while you are alive: limiting your metadata, compartmentalising your identities, choosing a discreet channel when the situation calls for it. One chapter is missing from that reflection, and it is probably the most uncomfortable one: what becomes of all this when you are no longer around to administer it?
The default answer fails in both directions. Either your family is unable to access anything at all — bills, contracts, family photos, accounts to close — and loses months in red tape. Or they access everything, indiscriminately, including what you had deliberately kept separate from the rest of your life.
This guide proposes a third path: selective transmission. Deciding in advance what passes on, what is erased, and who decides about the rest.
What French law actually says
Contrary to popular belief, there is no automatic "right of inheritance" in France over a deceased person's online accounts. The situation is more subtle — and more favourable to the deceased than people think.
The GDPR stops at death
A starting point that is often overlooked: the General Data Protection Regulation does not apply to deceased persons. Its recital 27 says so explicitly, while leaving member states free to legislate. France has used that option.
Article 85 of the French Data Protection Act
This is the central text, introduced by the Digital Republic Act of 7 October 2016. It sets out three principles that the CNIL regularly restates on its website:
- Anyone may set directives concerning the retention, erasure and disclosure of their data after their death.
- These directives may be general (lodged with a certified trusted third party) or specific (given directly to the data controller, i.e. the platform concerned).
- In the absence of directives, heirs may exercise certain rights — notably having accounts closed, obtaining updates to the data, or accessing the information needed to settle the estate.
The important word is certain. Heirs do not gain a general right of access to content. They obtain what is useful for winding up the estate and organising the mourning process. The distinction is a fine one, often misunderstood by families, and a regular source of litigation.
Private correspondence remains protected
Another little-known point: the privacy of correspondence does not automatically lapse when one of the correspondents dies. The messages exchanged involve another living person, whose data is fully protected by the GDPR. A platform handing over an entire mailbox to heirs would in effect expose the surviving correspondents.
That is why Google, Apple and Meta almost systematically refuse to hand over the raw content of exchanges, even when faced with a legitimate heir's request, outside of a judicial order.
In practice: French law gives you a genuine right to decide. But you have to exercise it beforehand, because afterwards it is the platforms' terms of service that govern.
The three categories to sort before anything else
Before touching a single setting, take stock. Not account by account — that is discouraging and you will give up by line twenty — but by function. Take a sheet of paper, not a document in the cloud.
1. What absolutely must be passed on
This is the "administrative" category. Without it, your family will spend six months writing to customer service departments.
- Banks, life insurance policies, savings, securities accounts
- Energy contracts, internet boxes, mobile plans, insurance policies
- Recurring subscriptions (streaming, software, gyms, monthly boxes)
- Taxes, health insurance top-up, pension fund
- Any cryptocurrencies — without the recovery phrase, the asset is lost for good
- Notary's contact details, location of paper documents
2. What has sentimental value
Photos, videos, family correspondence, creative projects, family trees, voice recordings. This is what families most regret losing — and it is almost always stored with a provider whose access dies with you.
3. What must disappear
The category nobody likes to spell out, and which on its own justifies the entire exercise.
A personal diary. Medical searches. Exchanges with a therapist, a lawyer, a support organisation. An orientation, a belief, a relationship, a project you had not made public. Drafts. Messages sent in a difficult moment. A second online identity, owned but compartmentalised.
None of this is shameful. But privacy is not about having nothing to hide: it is about choosing who sees what. That choice should not be cancelled by your death.
Configuring the tools: what actually exists

Good news: the main platforms now offer built-in mechanisms. They are free, take about fifteen minutes, and nobody activates them.
| Service | Mechanism | Where to find it |
|---|---|---|
| Inactive Account Manager | Google Account settings → Data & privacy | |
| Apple | Legacy Contact | Settings → Apple ID → Legacy Contact |
| Meta (Facebook) | Legacy contact or automatic deletion | Settings → General → Memorialisation |
| Memorialised account on request | Dedicated form after death | |
| Microsoft | No dedicated mechanism, estate procedure | Microsoft Support |
Google's Inactive Account Manager
By far the most powerful and the least known. You set an inactivity period (3, 6, 12 or 18 months), a list of contacts to be notified and — crucially — you choose precisely which services are shared. You can pass on Google Photos and Drive without passing on Gmail. You can also schedule the outright deletion of the account once the period has elapsed.
This is exactly the granularity that the sorting logic described above calls for.
Apple's Legacy Contact
Introduced with iOS 15.2, it lets you designate up to five people who will receive an access key. On death, armed with that key and a death certificate, the legacy contact gains access to photos, notes, documents and backups — but not to the password keychain, licensed purchases or health data. That exclusion is deliberate and rather well judged.
The blind spot: everything else
Your online bank, your secondary inbox, your forums, your web host, your domain names, your encrypted storage, your secure messaging account. No automatic mechanism at all. This is where manual organisation comes in.
The two-key safe method
The natural reflex — writing all your passwords in a "just in case" file — is the worst possible solution. Such a file exposes you far more while you are alive than it protects your family afterwards.
The robust method rests on a clean separation between the container and access to the container.
Step 1: centralise in a password manager
A serious password manager (Bitwarden, KeePassXC, 1Password, Proton Pass) solves two problems at once: it secures your day-to-day life and it creates a single point of transmission. Several offer native "emergency access": a designated contact requests access, you receive a notification, and if you do not refuse within a period you have set (30 days, for example), access opens.
It is elegant, but it assumes the contact knows the mechanism exists.
Step 2: put the master key on a physical medium, offline
The master password itself must exist nowhere online. Two media work well:
- Paper, in a small fireproof home safe, or with a notary. It is mundane, but paper does not suffer firmware failures.
- Metal, for critical recovery phrases: an engraved steel backup plate withstands fire and water, which a sheet stashed in a kitchen drawer does not.
For the files themselves — photos, archives, scanned notarial documents — a hardware-encrypted USB drive with a physical PIN pad lets you assemble a capsule handed to a third party without that third party being able to open it alone.
Step 3: separate the two halves
The principle is simple: nobody should hold both the medium and the code. The medium with a relative, the code with the notary. Or the other way round. This separation protects you from premature consultation and protects your family from suspicion in the event of an inheritance dispute.
Step 4: document, don't just store
A manager stuffed with 300 entries and no explanation remains unreadable to someone discovering the tool at the worst moment of their life. Write a one-page note — in a hardback notebook or in an encrypted note inside the vault — explaining where everything is, in what order to proceed, who to contact, and above all what you do not wish to see opened.
That last sentence has no binding legal force, but it carries considerable moral weight. Families almost always respect it.
The digital will: what is valid and what is not

Under French law, a "digital will" in the sense of an electronically drafted and signed document does not exist. Article 970 of the Civil Code requires a holographic will to be entirely handwritten, dated and signed by the testator. A text file, however detailed, is not a will.
What you can do, however:
- Write a handwritten holographic will mentioning your digital directives and appointing someone to carry them out. Lodged with a notary, it is registered in the Central Register of Wills (FCDDV) and will be found.
- Lodge general directives with a trusted third party certified by the CNIL, as provided for by article 85. The French ecosystem of such third parties remains embryonic, but the framework exists.
- Record specific directives directly with each platform (the mechanisms in the table above). These are the most effective in practice, because they are executed automatically.
- Write a non-binding letter of intent, attached to the will, explaining your reasoning. An elasticated document folder, filed with identity papers and family records, is the storage families most often find.
Beware of a common trap: handing over a password is not handing over a right. Accessing an account with the deceased's credentials remains, formally, impersonation. Banks know this and freeze accounts as soon as they are notified of a death. It is therefore better for your heirs to have the information (which bank, which contract number) rather than merely the access.
The special case of sensitive communications
Some people use, for good reasons, channels deliberately dissociated from their main identity: a dedicated encrypted messaging service, a disposable email address, an anonymous SMS to report a situation without exposing their number. Journalists, healthcare workers, victims of violence, charity volunteers, whistleblowers — or simply people who keep their spheres separate.
For these uses the rule is different, and it fits in one sentence: what was meant to stay compartmentalised during your lifetime must disappear, not be handed on.
In concrete terms:
- Do not document these accounts in the family vault. Documentation creates exposure.
- Favour services with automatic deletion after inactivity, or activate scheduled deletion where it exists.
- If people depend on that channel (a victim you are supporting, a source), plan a handover to an organisation, not to a relative: a charity, an employer, a colleague. Continuity must be institutional.
- An anonymous SMS service, by design, keeps no conversation thread attached to your identity: that is precisely the point of a channel that does not outlive its use.
Checklist: two hours, once and for all
- Activate Google's Inactive Account Manager with service-by-service selection
- Designate an Apple Legacy Contact (up to 5 people)
- Choose on Facebook and Instagram between a memorialised account and deletion
- Install a password manager and migrate essential accounts into it
- Set up emergency access with a waiting period of at least 30 days
- Write the master password on paper and place it in a fireproof safe or with the notary
- Physically separate the medium and the code between two custodians
- Write the one-page note: where, in what order, what not to open
- Mention the existence of these directives in a handwritten holographic will
- Delete or schedule the shutdown of compartmentalised accounts
- Tell the person concerned that they have been designated — the step forgotten in nine cases out of ten
- Review the whole thing once a year, on a fixed date
Conclusion: anonymity is not a privilege of the living
Digital death reveals, in fast-forward, everything we let pile up. Accounts we no longer use, backups we never sorted, correspondence we never reread and which describes us more faithfully than we would like.
Preparing your digital estate is not a morbid exercise. It is the same gesture as logging out on a shared computer, or choosing not to give your number to a stranger: a decision about who sees what.
French law grants you that right, more broadly than most European legislation. The platforms provide the tools. All that is missing is two hours on a Sunday afternoon — and the very uncomfortable acceptance that this question concerns you too.
Sources and references
- CNIL — "Mort numérique : peut-on demander l'effacement des informations d'une personne décédée ?" and practical guidance on article 85 of the French Data Protection Act
- Law no. 2016-1321 of 7 October 2016 for a Digital Republic, article 63
- Regulation (EU) 2016/679 (GDPR), recital 27
- French Civil Code, articles 970 et seq. (form of the holographic will)
- Conseil supérieur du notariat — Central Register of Wills
- Help centres of Google, Apple and Meta concerning the accounts of deceased persons



