Is the personal data of the deceased protected?

Resources
    Is the personal data of the deceased protected?
    Posted on: 08/05/2026

    Recently, social networks in Vietnam have recorded the widespread spread of information about the private life of a deceased student – from letters written to family, health status to personal circumstances before death[1]. These contents, although shared for various purposes, from memorials to expressing emotions, quickly attracted great attention from the community. However, besides the sympathetic reactions, the case also raises a notable legal question: is the personal data of a deceased person protected?

     

    Rights such as the right to know, the right to consent, the right to access, correct or delete data are all tied to the individual's ability to express his or her own will

     

    Vietnam's current personal data protection legal framework is mainly designed around the data subject being a living person. "Data subject" is understood as the individual to whom personal data is reflected. Rights such as the right to know, the right to consent, the right to access, correct or delete data are all tied to the individual's ability to express his or her own will. This leads to an important consequence: when an individual dies, the ability to legally exercise their data rights is almost non-existent, while their data continues to exist and can be exploited.

    Strong protection of the living, but unclear to the deceased

    Decree 356/2025/ND-CP only lists information on "date, month and year of death" as a form of personal data, but there is also no regulation to clarify the overall handling of the data of the deceased. As a result, the law does not answer the core questions: whether personal data will continue to be protected after the death of the subject, if so, what is the scope of protection, and who has the right to make requests related to that data.

    This gap is even more obvious when compared with the Civil Code 2015. According to regulations, an individual's civil legal capacity terminates when he or she dies. However, the law still maintains a mechanism to protect some moral rights after death, especially the right to honor, dignity and reputation, allowing relatives to request protection when these values are violated.

    However, this mechanism is mainly "post-check" and only applies to traditional personal values, which is not enough to process modern forms of digital data such as online accounts, emails, biometric data or digital content stored on technology platforms.

    This shows that Vietnamese law does not completely "neglect" the dead, but the current approach is still traditional, focusing on honor and image, rather than digital data.

    International has multiple approaches, but the same goal

    In the world, there is no unified approach to the issue of personal data of the deceased, but the general trend is not to let this field fall into a "legal gap".

    In Europe, the General Data Protection Regulation (GDPR) does not apply to the data of deceased people. However, the GDPR also allows member states to develop their own regulations on this issue. In fact, many countries have taken advantage of this "opening" to design post-mortem data protection mechanisms.

    France is a prime example. The country's law allows each individual, while alive, to give instructions on how to handle his or her data after death, including storage, deletion, or transfer. Without instructions, relatives can exercise certain rights in relation to the data of the deceased. Meanwhile, Spain goes even further by allowing a relative or heir to request access, correction or deletion of the deceased's data, unless the person while alive had the will to the contrary. This approach creates a clear mechanism for the right holder and the scope of rights, which helps to minimize disputes and increase the feasibility of enforcement.

    What these models have in common is the recognition that personal data does not "disappear" with the death of a person, and therefore a legal mechanism is needed to regulate the processing of data in the post-mortem period.

     

    Source: The Saigon Times

     

    Directions to complete the legal "gap"

    From the above analysis, we can all agree that from a theoretical or practical perspective, the protection of personal data of the deceased is necessary. Because protecting the personal data of the deceased is not only to protect the "rights" of the deceased, which is a concept that is difficult to define legally, but also to protect the interests of the living, especially their families and loved ones.

    To address this issue, Vietnam does not necessarily extend the full personal data rights of the living to the deceased. A more appropriate approach is to establish a separate mechanism for post-mortem data, with a clearly defined scope, subject of request, and processing responsibilities.

    Firstly, it is necessary to establish the concept of "post-mortem data" in the law on personal data protection.

    This concept can be understood as personal data related to a deceased person, including data generated by the person while alive and data generated or processed after the person's death. Establishing this concept will create a foundation for distinguishing posthumous data from ordinary personal data, while avoiding the mechanized application of the rights of the living to the deceased.

    Second, it is necessary to clearly define the subject who has the right to request the processing of post-mortem data.

    The law can design the order of priority in the direction of: the person appointed by the individual before death; spouse; children; parents; heirs or other legal representatives. This mechanism not only respects the will of the individual while still alive, but also creates a clear legal basis for relatives to request the removal, restriction of access, correction or prevention of data exploitation contrary to the dignity of the deceased.

    Third, it is necessary to specify the scope of postuter data to be protected according to the level of risk.

    Not all information related to the deceased needs to be protected equally. Legislation should prioritize the protection of sensitive data groups, including health information, biometric data, personal correspondence, private messages, private photos, online account data, data about children in the family, or information related to the circumstances of death. A risk-based approach will help balance the protection of privacy and society's right to legitimate access to information.

    Fourth, it is necessary to establish a speedy processing mechanism for requests to remove or restrict access.

    For post-mortem data that is sensitive or has the risk of causing serious harm to relatives, social media platforms, websites and online service providers should be obliged to receive, respond and process within a clear time limit. This mechanism should be accompanied by responsibility for handling, complaint channels and emergency measures in case information is spreading rapidly.

    Fifth, it is necessary to clarify the responsibilities of data processing subjects.

    Publishers, media outlets, social media platforms, data storage organizations, and content miners should be obliged to check the legality, necessity and impact of the use of data related to the deceased. For cases of using data for commercial purposes, promoting or creating interactive content, the law needs to set stricter requirements for consent or requests from eligible relatives.

    Sixth, it is necessary to ensure reasonable exceptions for the public interest.

    The protection of posthumous data should not become a tool that hinders journalism, research, investigation, or archival activity of historical value. However, these exceptions need to be placed on the principle of minimizing data, respecting the dignity of the bereaved, limiting the unnecessary disclosure of sensitive information, and avoiding harm to relatives.

    In the digital era, death is no longer the end of information. A person's personal data, from social media accounts, emails to health records, continues to exist, store, and can be spread or exploited after the person's death. Vietnamese law has certain provisions on personal protection after death. However, the gap between these two areas still exists, especially in the digital environment. Filling this gap is not only a legal step forward, but also an expression of respect for human dignity – a value that should not end with biological life.

    Lawyer Nguyen Van Phuc

    HM&P Law Firm

    Read more: 

    Part 1: Bảo vệ dữ liệu cá nhân – Phần 1: Thông tin của người đã mất có được chia sẻ?

    Part 2Bảo vệ dữ liệu cá nhân – Phần 2: cần lấp ‘khoảng trống’ pháp luật