Death may end legal personality, but it does not erase a person’s information, dignity or social identity. Medical records, private messages, photographs, biometric identifiers, financial details and social-media accounts may remain accessible for years. Artificial intelligence can also recreate a deceased person’s face, voice and mannerisms. Consequently, violating the privacy of the dead creates harms that conventional privacy law, which is primarily designed to protect living data subjects, is not always equipped to address.
The first challenge is legal uncertainty. Article 31 of the Constitution of Kenya protects every person against the unnecessary disclosure of private information and the improper use of personal data. The Data Protection Act gives practical effect to this right but defines a data subject as an identified or identifiable natural person. Since legal personality ordinarily ends at death, the Act does not clearly state whether its protections continue after death, who may enforce them, or for how long. This uncertainty leaves families, estate administrators, data controllers and regulators without consistent rules.
Kenyan jurisprudence nevertheless suggests that death does not make personal information freely available. In Mwaniki v Attorney General, the High Court found that disclosing information concerning a deceased person’s account or estate without proper legal representation would invade the privacy of the deceased’s estate. The decision supports posthumous privacy, but it also exposes a practical obstacle: relatives may need probate, letters of administration or a court order before gaining access. These safeguards prevent casual disclosure, yet they may delay legitimate efforts to locate assets, settle liabilities or close digital accounts.
A second challenge is the relational nature of posthumous harm. A deceased person cannot experience embarrassment or bring a complaint, but disclosure may deeply injure those who remain. Publishing intimate photographs, medical conditions, private correspondence or graphic images of a body can traumatise relatives, disrupt mourning and damage a family’s reputation. Genetic and health information is especially relational because it may reveal sensitive facts about living family members. Protecting the dead is therefore also a means of protecting the privacy, identity and emotional wellbeing of the living.
Digital persistence magnifies these risks. Social media platforms preserve enormous archives and may continue to recommend old posts, birthdays or memories after a user dies. Families may struggle to obtain access because they lack passwords or because platform terms conflict with succession procedures. At the same time, unrestricted access can defeat confidences the deceased reasonably expected to remain private. The law should distinguish between the authority needed to administer digital property and permission to read or disclose every private communication stored within an account.
Artificial intelligence presents an even sharper challenge. Deepfakes and voice clones can depict dead people saying or doing things they never did. Genealogy and memorial platforms can animate photographs or generate synthetic stories in the deceased’s apparent voice. Although these services may comfort some families, they can distort memory, appropriate identity and turn grief into a commercial product. Consent obtained for one purpose during life should not automatically authorise an entirely new use after death, particularly where the output is misleading, humiliating or profitable.
Posthumous privacy violations also create economic and security harms. Identity numbers, email accounts, banking details and active profiles can be exploited for impersonation, fraud or unlawful enrichment. Misuse may diminish the estate, expose beneficiaries to loss and undermine confidence in institutions that retain personal data. Conversely, excessive secrecy may conceal assets and obstruct estate administration. Effective protection should therefore combine secure preservation, prompt deactivation where appropriate, verified fiduciary access and carefully limited disclosure.
Enforcement is difficult because responsibility is fragmented. A harmful disclosure may involve a hospital, media house, public authority, family member, platform or AI provider operating outside Kenya. It may simultaneously engage privacy, confidentiality, succession, intellectual-property, media-ethics and constitutional principles. Remedies are also unclear: should an administrator complain to the Office of the Data Protection Commissioner, sue on behalf of the estate, or invoke the living family’s own rights? Without clear standing and procedures, harm can spread online faster than a family can obtain relief.
Kenya should respond through practical Posthumous Data Governance Guidelines. The guidelines should identify who may act for the deceased, require proof of authority, preserve purpose limitation and establish special safeguards for medical, biometric, intimate and financial data. They should also address platform accounts, AI-generated likenesses, retention periods, public-interest disclosure and conflicts between testamentary wishes and the rights of survivors. Individuals should be encouraged to leave digital directives in wills or through recognised legacy tools.
Posthumous privacy is not an attempt to silence history, journalism or legitimate public-interest inquiry. It is a demand for justification, proportionality and respect. The central challenge is to balance the deceased’s autonomy and dignity with succession needs free expression, historical record and the legitimate interests of the living.
In a society where personal data outlives the body, privacy cannot simply be treated as disappearing at death. It becomes an enduring responsibility shared by families, institutions, technology companies, regulators and courts.
_____________________________
* This article summarises a working draft of a broader academic paper on the subject of posthumous privacy.