NO.262 Post-Mortem Privacy and Security
May 11 - 14, 2027 (Check-in: May 10, 2027 )
Organizers
- Dr Andrew A. Adams
- Centre for Business Information Ethics, Meiji University, Japan
- Prof Akiko Orita
- College of Human and Symbiotic Studies, Kanto Gakuin University, Japan
- Mr Bruce Schneier
- Kennedy School of Governance, Harvard University, US.
Overview
Shonan Meeting Proposal
As society becomes more cyber-physical, and in particular as our legal and social identities are more and more bound up in digital systems, the issues of what happens when a person dies becomes increasingly tricky and time consuming to handle. Issues around the digital privacy of the deceased have been studied since around 2010, but both the law and practice remain somewhat unclear. Various issues remain, including the different attitudes towards death and the deceased between different cultures, particularly within different religious frames. So, even if the law of a particular country handles the privacy rights of the deceased clearly, this may be at odds with the deeply held cultural expectations of the now-deceased before their death and of their surviving family and other contacts. A Google scholar search on the phrase “post-mortem privacy” for example, provides 815 hits. Other terms of course may be used, but this is a very small set of results for a search on the broadly inclusive Google Scholar search system.
The security issues that arise are even more significantly under-studied. A similar Google search on “post-mortem security” returns only 38 hits, and many of these use “post-mortem” in the more figurative sense of a post-incident investigation, rather than the security implications of the death of a user. As with many other areas of security, the organisational and user interface processes that are created to deal with the death of a user open up security issues for users who may still in fact be alive (denial of service by death reporting), for the surviving relatives who need to close down or memorialise accounts, for the platform (who must balance “zombie” accounts and the denial of service problem), and for third parties (zombie accounts maintained by people other than the deceased may be abused for fraud or other illegitimate purposes).
The goal of this meeting is to bring together privacy and security experts from a range of countries, including Japan as well as other Asian countries such as South Korea, Malaysia, and Singapore, as well as European countries, the US and Canada. The mix of attendees is aimed to include people with knowledge of a variety of religious framing for social and legal issues (such as Islamic law scholars from Malaysia). The academic disciplinary mix covers philosophy, law, social science, psychology, economics, systems engineering and information security. In addition to academic participants, representatives of online platforms such as Google, Meta and Rakuten will be invited to provide their experience of the front line of creating and implementing policies for post-mortem processes (drawing on the organisers’ existing connections in those organisations) as well as representatives of digital rights groups such as the EFF.
The meeting is intended to build on a JSPS project in digital legacy which started in April 2025 and which by the time of the meeting in 2027 is expected to provide an additional framework (particularly in post-mortem security). By drawing on the multi-cultural, interdisciplinary expertise of the attendees, the meeting will seek to identify gaps in the current knowledge not only of what to do and how to do it, but what the expectations of ordinary people are, and how those are supported or hampered by legal, organisational and technical systems.
The meeting will be run on an unconference style, with the exact topics and formats to be decided by attendees after confirmation of attendance. Electronic discussions before the meeting will be used to avoid wasting too much time at the meeting in meta-discussion. The list below shows some of the areas of discussion that would likely come up, probably for parallel working groups which then reconvene in plenary for broader viewpoints.
Example Areas for Discussion
- Social and Religious Models of Deceased People’s relationship to their data
- Security Risks of Zombie Accounts (accounts of dead people pwned by attackers)
- Denial of Service by False Death Report
- Privacy Invasion by False Death Report
- Best Practices for Managing Accounts of Deceased Users
- Joint Accounts for Elderly and Terminal Users