Case study

Data inheritance: an estate you cannot inventory

A shoebox of photographs passes to the family with the house. Forty thousand photographs on somebody else's server do not. Under Databanking, what should happen to your data after your death is written once, as policy — and executed by your custodian.

Our digital estate

One's photographs used to fit in an album, and the album was inherited along with the furniture. Today we generate thousands of photographs and videos, tens of thousands of messages, and years of documents — almost none of it on an object anyone can put in a box. It sits with Apple, Google, Microsoft, a bank, a password manager, a dozen services nobody else in the family has heard of. Possession has become access, and access does not descend with the estate.

The practical consequence is that survivors inherit an investigation rather than an estate. Two-factor codes sit behind a fingerprint nobody else has. Credentials left in a sealed envelope may still fail at a second factor, and using them can breach the provider's terms of service. Every platform runs its own survivor procedure, several of which impose further identity or account requirements of their own. And before any of that, nobody knows which accounts existed in the first place. What one can do today is keep a list by hand and hope it is current when it is needed. That is diligence, but not a mechanism.

What the law already provides

Several legal systems have already worked out important parts of what should happen. What is missing is a common mechanism through which the instruction can be expressed and carried out across services.

In the United States, the Revised Uniform Fiduciary Access to Digital Assets Act, enacted in 48 states, the District of Columbia and the US Virgin Islands, sets a three-tier order of priority. A direction actually made through a provider's own online tool outranks a contrary will; where no such direction was made, the will outranks the provider's terms of service. It also draws a distinction that will be familiar to readers of this site: a fiduciary may obtain the catalogue of a person's communications — who, when — by default, but the content only where the deceased expressly said so.

In the European Union the position is stranger. Under Recital 27, the GDPR does not apply to the personal data of the dead, although the records concerned usually contain personal data of living people, which remains protected. Member states are left to legislate as they see fit. France did, and on this point came closest to what is proposed here: a person may define general directives on the retention, erasure and communication of their data after death, to be lodged with a digital trusted third party certified by the CNIL. The implementing decrees for that mechanism have never been issued, so in practice directives are lodged with a notary instead. Germany arrived by a different route, through inheritance law: its Federal Court of Justice held in 2018 that a social-media account passes to the heirs by universal succession, contract and content together.

The United Kingdom has no comparable post-mortem data regime, and its recent digital-asset legislation does not supply one. The Property (Digital Assets etc) Act 2025 confirms, for England, Wales and Northern Ireland, that a thing is not barred from being personal property merely because it falls outside the two traditional categories; it does not extend to Scotland. The Digital Assets (Scotland) Act 2026, in force since 1 July 2026, classifies digital assets as incorporeal moveables, but defines them so as to require rivalrousness, which leaves emails and the photographs in a social-media account outside the definition altogether. Neither Act says anything about who may reach a deceased person's accounts.

How EU law compares with this proposal more broadly →

The same instruction, written once

Every one of these regimes assumes a place to lodge the owner's wishes. Today that place is per-custodian, which is what makes the advice in the trade so awkward. A setting configured through a provider's own tool outranks a later will, so a choice made carelessly years ago can quietly defeat a solicitor's drafting, while accounts opened since are governed by a will that was written before they existed. Keeping a dozen providers consistent with each other, and with the will, is left entirely to the owner.

Under Databanking there is one such instrument, and it already exists for other reasons: the data policy attached to the account. Inheritance provisions are ordinary clauses within it: on my death, my spouse gains access to the family photographs and the household documents; my correspondence is retained but sealed for twenty years. Housekeeping needs no clause at all: subscriptions and dormant accounts are closed by default, automatically, unless the policy says otherwise. These are not exotic requests, and they are not wholly unavailable today: several providers offer selective legacy controls, naming more than one recipient or holding back categories such as stored passwords and purchases. But each does it its own way, at its own granularity, and none of them can express a rule that spans the others.

This is the catalogue/content distinction of RUFADAA, generalised. A sandbox that can already answer "is this person over 18?" without disclosing a date of birth can equally answer an executor's questions ("does an account exist with this provider?", "is there an unpaid liability?") without opening the correspondence that would otherwise come with the keys. The executor's legitimate task is administrative, and many administrative questions need a specific fact rather than the run of the file.

Two-panel diagram. Left, headed Today: an executor at the centre of six separate custodians — cloud storage, email, photos, social media, a bank and subscriptions — each reached by its own enquiry, marked with a question mark. Right, headed Under Databanking: death or incapacity is attested outside the Databank, the attestation enters the owner's account, and the data policy written there executes, transferring access, beginning embargoes and running deletions.
The same instructions, in both cases. On the left they have to be carried to each custodian in turn, by someone who first has to work out which custodians there are.

Automatic execution

Death or incapacity is determined outside the databank, medically and legally, as it always has been. Once determined, it becomes a datum in the owner's databank account: an attestation deposited there by an authorised registrar. By design, that triggers the execution of the policy the owner had written. Deletions run, access rights transfer, embargoes take effect, standing authorisations lapse. Nobody has to find the accounts, because nothing was scattered. Nothing is left to be negotiated, because the custodian is contractually bound and regulated.

The relationship with the databank is itself inherited, as the German ruling suggests it would be, so the protections that came with it continue for the estate rather than lapsing at death.

Wishes, and who gets to overrule them

There is a further asymmetry worth naming. An instruction to destroy material after death is, at present, honoured entirely at the discretion of whoever holds it. Literary history is full of manuscripts their authors asked to have burned and which were published anyway, sometimes by heirs who believed they were serving a larger duty, sometimes for money. Whatever one thinks of the individual decisions, the structural point stands: the dead cannot enforce anything, and instructions that survive on goodwill alone survive only as long as the goodwill.

A custodian bound by an executable policy changes that. The rule such a policy needs is simple enough to state: the clause executes by default, remains challengeable in court, and the material is held rather than destroyed while a challenge is live.

← Back to the case studies