Home About Services Pricing Stories Articles Resources FAQ Contact
Start your Digital Directive →
← All articles
Digital security

The Privacy Act Stops Protecting You the Moment You Die

Zack van Zyl· 16 September 2026· 4 min read
The Privacy Act Stops Protecting You the Moment You Die

Here is a fact that most Australians have never had reason to learn, and that every executor eventually discovers the hard way: the Privacy Act does not protect dead people.

Not partially. Not with caveats. The Privacy Act 1988 (Cth) defines an "individual" as a natural person, and the settled position, reflected in Australian Law Reform Commission analysis and in how the regulator applies the scheme, is that this means a living natural person. Once someone dies, the Australian Privacy Principles stop applying to their information, and so does the Notifiable Data Breaches scheme built on top of them.

Which means that if an organisation holding your late father's date of birth, driver's licence number, address history and Medicare details is breached next year, nobody is legally obliged to tell his family. There is no notification duty, because there is no protected individual left to notify.

The scale of what this exposes

This would be a footnote if Australian breaches were rare. They are not.

The Office of the Australian Information Commissioner recorded 1,205 notifiable data breach notifications in calendar year 2025, an all-time high since the scheme commenced in 2018, and an eight per cent rise on 2024's 1,112. Health service providers were the most-breached sector, accounting for 225 notifications, or roughly 19 per cent of the total. Malicious or criminal attacks drove 716 of them, close to 59 per cent.

Read that sector breakdown again with an estate in mind. Health providers, financial services, government agencies, these are precisely the organisations that hold the deepest, most identity-complete records about a person, and precisely the records that do not get deleted the moment someone dies. Medical records are retained for years under state health records legislation. Financial institutions retain identity verification records for seven years under anti-money-laundering obligations. Government agencies retain under archival law.

A deceased Australian's most sensitive personal information keeps sitting in databases for years after the funeral. It just stops being anyone's legal responsibility to warn you about.

Why this matters more than it sounds

The instinctive response is that it does not matter, the person is gone, and privacy is for the living. That is the reasoning behind the exclusion, and in the abstract it has some force. In practice, it collapses on contact with how identity fraud actually works.

A deceased person's identity is, from a fraudster's perspective, close to ideal raw material. The identity documents are real and verifiable. The credit history is genuine. And critically, nobody is monitoring it. A living victim notices a strange transaction, a credit enquiry, a letter about an account they never opened. A dead person notices nothing, and the family is usually not looking, they are dealing with probate, superannuation forms and a funeral.

The window is generous, too. Data flows between organisations slowly. An account closed at one institution does not automatically close at another. Dormant accounts stay dormant rather than being deleted. Fraud committed against a deceased person's identity can run for months before anyone connects it to an estate.

And the harm does not land on the deceased. It lands on the estate and the beneficiaries, the people who have to unwind a fraudulent account, prove a debt was not incurred by the deceased, or explain to a bank why a credit application in their late mother's name is not their problem.

The gap sits alongside a second gap

This one compounds with something we have written about before: Australia has no statutory scheme giving executors access to a deceased person's digital records. The NSW Law Reform Commission recommended creating one in its December 2019 Report 147, tabled in the NSW Parliament on 5 March 2020, running to 17 recommendations including a standalone statutory access scheme. It was picked up by the Meeting of Attorneys-General in November 2021 as a national priority, with NSW leading. As at August 2026, no Australian state or territory has legislated.

Stack the two together and the executor's position is genuinely absurd. You have no statutory right to access the deceased's accounts. You also have no right to be told when those accounts are breached. You are responsible for administering an estate whose digital perimeter you can neither see into nor be warned about.

The Privacy Act Review conducted by the Attorney-General's Department considered extending protections to deceased persons' information. No amendment had been enacted as at August 2026. Tranche two of the privacy reforms, the one carrying the more structural changes, remains pending.

What an executor can actually do

The law is not going to help in the near term, so the practical work falls to families. Some of it is genuinely effective.

  1. Use the Australian Death Notification Service early. The free service at deathnotification.gov.au notifies a large group of participating organisations, government agencies, banks, insurers, super funds, utilities and telcos, of a death in a single step. It does not close accounts or release records, but it starts the clock at dozens of organisations at once rather than one letter at a time.
  2. Place a deceased-person flag with the credit bureaus. Illion, Equifax and Experian each accept notification of a death and can flag the credit file, which blocks new credit applications in that name. This is the single highest-value hour an executor can spend, and almost nobody knows to do it.
  3. Close, do not abandon. A cancelled card is not a closed account. An unused email address is a password reset channel for everything still linked to it. Close accounts explicitly and confirm the closure in writing.
  4. Close the email account last. It is the recovery route for everything else. Work outward from it, then shut it.
  5. Keep the paperwork. Grant of probate, death certificate, and a log of what you closed and when. If a fraudulent account surfaces in eighteen months, that dated log is the evidence that resolves it quickly.

And what you can do now, while it is still your data

The protection the Privacy Act withdraws at death is protection you can only substitute for in advance. Every account that does not exist when you die is an account that cannot be breached, cannot be hijacked, and cannot generate a problem your family has to solve without you.

So the useful work is unglamorous: know what you hold, close what you do not need, and leave a record of the rest that identifies which organisations hold your information, what each account is for, and what should happen to it. Not passwords handed over wholesale, an inventory, maintained, with instructions attached.

Australian law treats your personal information as worth protecting right up until the moment you can no longer protect it yourself. That is a strange place to draw the line. Until Parliament moves it, the only thing standing between your data and the people who profit from unattended identities is the plan you leave behind.

Your digital life, held safe for the people you love.

NYLK builds the Directive that makes sure the people you love aren't locked out.

Start your Digital Directive →