Dying Without Leaving Everything Behind: Organising Your Digital Estate

Back to the blog
21 September 202613 min read

Introduction: the phone ringing in a drawer

Three weeks after the funeral, your father's inbox is still receiving DIY newsletters. His streaming subscription renews automatically. A dating site sends him profile suggestions. And on Facebook, an algorithm invites his former colleagues to wish him a happy birthday.

Nobody did anything malicious. It's simply that nothing was planned. And the platforms themselves have no reason to stop on their own.

Person browsing a website on a laptop resting on their lap

Death doesn't delete data: it makes it orphaned. It carries on existing, being stored, sometimes exploited, and above all it becomes accessible to people who would never have seen it while you were alive — a spouse, a child, a notary, sometimes an employer, sometimes a stranger who buys a poorly wiped computer.

The question isn't morbid, it's practical. You spend time protecting your privacy from companies and government agencies. It would be a shame if all that work collapsed the day you can no longer decide anything.

This guide explains what French law already provides for, what platforms are willing to do, and how to organise all of it in a single evening, without a lawyer.


What French law says (and it says a lot)

The GDPR stops at death

First point, and a counter-intuitive one: the GDPR only protects the living. Recital 27 explicitly states that it does not apply to the data of deceased persons, while leaving Member States free to legislate. France has done so, and rather well.

Article 85 of the French Data Protection Act

This is the centrepiece. Introduced by the Digital Republic Act of 7 October 2016 (loi pour une République numérique), it is now codified in Article 85 of the French Data Protection Act (loi Informatique et Libertés). It sets out a simple principle:

Any person may issue directives concerning the storage, erasure and communication of their personal data after their death.

In practical terms, you can decide in advance:

  • that a given account be erased;
  • that certain data be retained and passed on to a designated person;
  • that other data never be communicated, including to your heirs.

The CNIL, which documents this framework on its website under the heading "digital death" (mort numérique), distinguishes two types of directives:

TypeScopeWhere to lodge them
General directivesAll your data, across every serviceWith a certified digital trusted third party
Specific directivesOne particular service (an email provider, a social network)With the service itself, which is required to collect them

Specific directives take precedence over general ones for the service concerned. They can be amended or revoked at any time, and a service cannot make your consent to them a condition of use.

Where no directives exist

If you have made no arrangements, your heirs may exercise certain rights: obtaining the closure of accounts, objecting to their processing, or asserting matters necessary to settle the estate. They may also access data "relating to the memory of the deceased".

In other words: without directives, it's your family who decides. Sometimes that's exactly what you wanted. Sometimes it's a disaster.

Does the confidentiality of correspondence survive?

A delicate question, and one regularly raised before the courts. Emails, text messages and private messages fall under the confidentiality of correspondence. Operators and messaging services generally refuse to give heirs access to message content, and limit themselves to closing the account. This is the consistent position of the major players, and it has been upheld in several European disputes.

So don't count on your heirs to "naturally" recover your exchanges. And conversely: don't count on that confidentiality to protect whatever sits on an unlocked device left on a bedside table. The law protects the pipes, not the screens left switched on.


Mapping out what you leave behind

Before organising, you need to take stock. Most people massively underestimate their footprint.

The four layers of a digital legacy

LayerExamplesMain risk
Active accountsEmail, social media, online banking, subscriptionsOngoing direct debits, identity theft
Stored contentPhotos, documents, notes, conversation historiesUnwanted revelations to loved ones
Physical devicesPhone, computer, hard drives, router, USB sticksFull access, with no filter or sorting
Traces held by third partiesCustomer databases, loyalty cards, insurers, data brokersMarketing calls aimed at the family, resale

Make the list. On paper, preferably, not in a file called "passwords.docx" on your desktop.

A person's hand resting on the trackpad of a silver laptop, black keyboard in close-up

A simple hardback notebook does the job perfectly for drawing up the inventory — provided it contains no passwords in plain text, only the list of services and the instruction you want for each one ("close", "pass on to X", "never open").

The blind spot: devices

People think about accounts and forget the hardware. Yet an inherited phone resold without a full reset, an old hard drive donated to a recycling centre, a laptop handed to a cousin "who'll know how to wipe it": these are the three most common post-mortem leak scenarios.

For media you know to be sensitive and no longer want in circulation, the only genuinely reliable method with a mechanical drive remains physical destruction; a shredder that handles cards and CDs takes care of optical media and chip cards. For SSDs and phones, full-disk encryption enabled while you're alive is enough: without the key, the content is just noise.


The tools platforms already offer

Good news: several major services have built the mechanism in, sometimes even before French law required it.

The inactive account manager

Some ecosystems offer an inactivity mechanism: if you don't log in for a period you set (3, 6, 12 or 18 months), the service notifies designated contacts, optionally passes on a selection of your data, then deletes the account. In practice, this is the most effective digital succession tool in existence: it requires no death certificate, no procedure, no steps from your family.

One caveat: it triggers on inactivity, not on death. A long hospital stay, an extended trip, or a change of main email address can set it off by mistake. Choose a long period and check that the reminder address is still active.

Legacy contacts on social networks

The major social networks offer two options: turning the profile into a memorialised account (frozen, no further logins, with an explicit notice) or permanent deletion. You can designate in advance the person authorised to manage that switch.

A memorialised account has one advantage: it stops the automatic birthday reminders and friend suggestions, which are the main source of pain for those left behind. Deletion, on the other hand, is better from a privacy standpoint: there's nothing left to compromise in a future data breach.

The platforms that provide nothing

The majority of services, in reality. Forums, online shops, mobility apps, classified-ad sites, online health services. For those, there's only one strategy: don't leave a dormant account there. An account you no longer use is an account to close now, not to bequeath.


Getting organised: the one-evening method

Step 1 — Sort through your live accounts

Open your password manager (or your inbox, searching for "welcome", "confirm your registration", "your account"). Sort each service into three piles:

  • To close right away: anything you no longer use.
  • To pass on: anything useful to your family (shared subscriptions, family photos, administrative documents).
  • To erase on your death: everything else, by default.

This sorting isn't an end-of-life exercise: it immediately reduces your exposure to data breaches, here and now.

Step 2 — Centralise access, not secrets

This is the heart of the problem. Your heirs need to be able to get in somewhere in order to carry out your wishes, without you leaving your passwords lying around while you're alive.

The standard solution: a password manager with an emergency access feature. The principle is elegant: a designated contact can request access; if you don't refuse within a period you've set (often 7 to 30 days), they obtain the credentials. Alive, you refuse with one click. Dead, the clock runs out.

For the master password — the one that must never be stored digitally — the old-fashioned medium still works: a sheet of paper, a sealed envelope, and a small combination safe for documents in a wardrobe, or a bank safe deposit box if the size of the estate warrants it. Some prefer an engraved steel backup plate, originally designed for cryptocurrency wallet recovery phrases: impervious to fire and water, it's a sensible medium for information that has to survive twenty years.

Step 3 — Write the directives

No heavy formalism is required. A dated, signed document explicitly referring to Article 85 of the French Data Protection Act is enough to express your wishes. State:

  1. The identity of the person responsible for carrying them out (with contact details).
  2. The list of services concerned and the instruction for each.
  3. What must under no circumstances be communicated, even to family.
  4. The date and your signature.

Lodge a copy with your notary if you have one, and keep another with your important papers. Remember to review it every couple of years: half the services listed will have changed names or disappeared.

Step 4 — Tell the person you've designated

The step most often missed. A perfect directive that nobody knows exists is worthless. The conversation is short: "There's a document in the blue folder. If I die, read it before you touch my computer."

Woman sitting and typing on a laptop resting on her lap, next to a cup of tea

That single sentence protects your privacy more effectively than any setting.


The other side: when you're the one left behind

You inherit a phone, an inbox, an account. A few pointers.

What you can request

  • Closure of accounts with each service, on production of a death certificate and proof of your status as an heir.
  • Erasure of data held in companies' files, relying on Article 85.
  • An end to marketing addressed to the deceased: organisations must stop, on pain of a complaint to the CNIL.
  • Removal from prospecting files, in particular with data brokers and commercial mailing lists.

What you won't easily obtain

The content of private correspondence. Operators and messaging services object to it, and the courts most often side with them. There's no point insisting by letter: the route is judicial, lengthy and rarely successful.

What you should do, even if you're not required to

Switch it off. Many heirs keep an inbox active for years "just in case", sometimes reusing the deceased's password on other services. That's an unmonitored account, with old credentials, often present in several public data breaches. It's an open door onto your own family.

Before reselling or giving away a device, follow the full procedure: factory reset, disconnection of linked accounts, removal of the SIM card and memory cards. For external hard drives found in a box, a hard drive adapter enclosure lets you read them and then wipe them properly before disposal.


The subject nobody ever raises: what you don't want anyone to find

Let's be blunt, because this is the real reason this guide exists.

Almost everyone has, somewhere, something that was never meant for their mother, their children or their partner. Messages with an ex. An anxious medical search. An account on a political forum. Administrative steps taken in secret. A fraught work exchange. Nothing illegal, nothing shameful — simply private, in the strictest sense.

While you're alive, that separation holds thanks to a PIN code and a habit. Afterwards, it holds on to nothing at all.

Three common-sense principles:

The sorting happens now. What you delete today won't be read tomorrow. No legal mechanism does better than actual deletion.

Don't store what you don't want to pass on. Genuinely sensitive conversations are better handled through ephemeral or non-identifying channels — auto-deleting messaging, or sending an anonymous text message when it's a one-off message that has no business appearing in a history.

Separate the containers. One account for administrative and family life, another for what concerns only you. The first can be passed on without harm, the second is explicitly marked "to be erased" in your directives.


Summary: the checklist

ActionTimePriority
Inventory your active accounts45 min●●●
Close dormant accounts1 hr●●●
Enable encryption on your phone and computer15 min●●●
Set up emergency access in your password manager20 min●●●
Enable the inactive account manager wherever it exists10 min●●
Designate a legacy contact on social networks10 min●●
Write your Article 85 directives, dated and signed30 min●●●
Store the master password physically and securely15 min●●●
Tell the person you've designated5 min●●●
Review and updateevery 2 years●●

Further reading

  • CNIL — factsheet "Mort numérique : peut-on demander l'effacement des informations d'une personne décédée ?" and the page dedicated to post-mortem directives.
  • Law no. 78-17 of 6 January 1978 as amended, Article 85 (Légifrance).
  • Law no. 2016-1321 of 7 October 2016 for a Digital Republic.
  • GDPR, recital 27, on the exclusion of deceased persons from its scope.
  • Service-Public.fr — "Décès" section, for the list of bodies to notify.

Conclusion: deciding while you still can

Organising your digital estate isn't a funereal exercise. It's the logical final step in a privacy protection approach: having learned to limit what companies, public bodies and those close to you know about you, what remains is to decide what they will know when you're no longer there to arbitrate.

French law gives you a tool that's rare in Europe: the right to write your own rules, service by service, and to make them enforceable. Most people never use it, often simply because they don't know it exists.

One evening. A notebook, an envelope, a few settings. And the certainty that what truly belonged to you won't end up in a drawer, switched on, available to the first curious passer-by.

#Vie privée#Confidentialité#Anonymat#RGPD#CNIL#Cadre légal#Sécurité

On the same topic

// Anonymous SMS · Hidden number · To France

Envoyez votre message, gardez l'anonymat

Votre numéro reste masqué, aucune inscription, aucune trace. Rédigez, confirmez, et votre SMS part de façon totalement anonyme.

Envoyer un SMS anonyme