[Mohammed Ibrahim Faisal is a fourth-year law student at PES University. In this piece, the author examines the growing digital afterlife industry, where thanabots simulate the deceased using their lifetime personal data, and analyses whether India’s constitutional and data protection framework can accommodate postmortem privacy in this context. The piece argues that the extinguishment of privacy upon death under the actio personalis moritur cum persona principle is untenable given the deceased’s continued digital existence; it finds that the DPDPA’s nominee and consent framework is structurally inadequate to safeguard their dignity. The author proposes a dignity-based approach coupled with a risk-assessment-based intermediary liability framework.]
Introduction
At a time when one out of every six people globally uses generative AI tools, such use has grown into emotional reliance. Consequently, the safety mechanisms surrounding these applications have been brought into sharp focus, most notably in Raine v. OpenAI Inc. and Garcia v. Character AI. In the latter, a settlement was recently reached amid child-suicide allegations. Thanatechnology in this context raises significant concerns owing to AI models that digitally revive and simulate the deceased. Several Digital afterlife platforms and the Meta patent merely highlight the need to regulate such radical technologies.
This piece argues that such transformative technology requires recognition of postmortem privacy in India, where it is currently deemed extinguished upon death. It argues that the continued digital existence of the deceased through thanabots renders this position untenable. It moreover demonstrates that the existing nominee and consent framework under the Digital Personal Data Protection (“DPDPA”) Act, 2023, is inadequate in protecting the privacy of the deceased. The author outlines the rise of thanabots (Part I), critiques India’s non-recognition of postmortem privacy (Part II), analyses the DPDPA’s nominee and consent frameworks (Part III and IV respectively) and concludes by proposing a dignity-based approach and risk-assessment-based framework to recognise postmortem privacy.
Thanabots and the Digital Afterlife:
To understand the dangers posed by thanatechnology, it is useful to understand its origin and contemporary backdrop. The term thanatechnology, coined in 1997 by Carla Sofka, refers to technological applications aimed at understanding death through the dimension of grief management mechanisms. The advent of generative AI models developed by platforms such as Here After, Character AI, Project December, and You, Only Virtual, has dramatically altered the grief process by creating audio-visual digital simulations of the deceased capable of interacting with their loved ones; such AI models are colloquially termed “thanabots”. The above-mentioned platforms, amongst numerous others, embody the growth of a digital afterlife industry globally valued at roughly $22 billion as of 2024, and is projected to triple by 2034.
The Meta patent US12513102B2 bears significant implications in this regard. Meta’s stated aim is to prevent harm from a user’s prolonged absence, with the clone bearing abilities to like, comment, and respond as the deceased would. While Meta does not plan to deploy this model, the consequences of such technologies loom large owing to the limited understanding behind their functioning; industry behemoths such as Microsoft, moreover, have been granted patents for similar AI models.
Thanabots seek to preserve the memory of the deceased digitally, a form of memorialization distinct from traditional modes such as archives and memoirs. User simulation, however, presents new challenges in the domain of postmortem privacy, as the deceased cannot speak for their own interests, requiring a robust legal framework to recognise and exercise this right.
Given that India is the world’s largest market for generative AI app downloads and adoption, it is paramount to assess the readiness of the data protection and constitutional regime in India concerning postmortem privacy. Particularly at a time when the country is witnessing the rise of multimodal models such as Sarvam AI, which is capable of voice cloning and audio-visual syncing.
Postmortem Privacy and the Constitutional Position:
AI simulation challenges the current constitutional position and the extent to which the right to privacy is extended posthumously. While the Supreme Court recognised the fundamental right to privacy under Article 21 of the Constitution in Puttaswamy (Para 25, Abhay Manohar Sapre J.), such a right, however, was held to extinguish upon the death of the individual following the principle of actio personalis moritur cum persona (personal action dies with the person). In an earlier judgment in Melepurath Sankunni Ezhuthassan (Para 5, D.P.Madon J.), the Supreme Court upheld this principle, a decision relied upon subsequently in Krishna Kishore Singh (Para 19.8.3, C. Hari Shankar J.) and Deepa Jayakumar (Para 35, R.Subbiah J.).
Postmortem privacy, according to Harbinja, can be defined as the right of individuals to preserve and exercise control over their reputation, dignity, integrity and memory after death. The current legal framework offers limited protection for personality rights, defamation, moral rights, dignity (with respect to mortal remains) and inheritability under estate law. Postmortem privacy in the digital era comprises three main aspects – the right to be forgotten, informational autonomy and harm prevention to protect the dignity of the deceased.
Right to dignity in particular assumes great importance as it was held to be an integral element of the right to life in Common Cause (Paras 152, 153 and 156, Dipak Misra, CJ). The recent decision in Harish Rana ( Paras 48 and 229-231, J.B.Pardiwala, J.) moreover recognises the importance of dignity as a concept and its inherent flexibility, which is best left undefined. The Supreme Court applied some elements of the substituted judgment standard to the best-interest framework, where it stepped into the position of the patient to assess what he would have done if he had the capacity to make a decision. While these cases concerned passive euthanasia, this piece argues that the standard could equally apply to postmortem privacy, to protect the dignity of the deceased who can no longer speak for themselves amid continued digital simulation. When the current legal framework extends the right to privacy during lifetime and at the threshold of death, emerging thanatechnology necessitates continuation of this right posthumously.
The conception of the right to privacy under common law has broadly favoured propertization. The proposed NO FAKES Act in the United States is a novel step in this direction. It aims to protect the intellectual property rights of individuals, covering audiovisual replicas synthetically created by AI models.
Germany’s stance can be understood from the decision in Mephisto (1971) (Para 6), where the Federal Constitutional Court upheld the right to dignity of the deceased under Article 1 of the German Basic Law whilst balancing artistic freedom and expression. The decision in Princess Soraya (1973) (Paras 27, 36-38) assumes particular significance as the Court upheld the right to dignity and recognised the concept of non-material damages even in the absence of a physical injury. Having established a case for recognition of postmortem privacy, it is essential to analyse the efficacy of the existing framework under the DPDPA.
An Inefficacious Nominee under the DPDPA:
Section 14 of the DPDPA becomes relevant as the Data Principal (defined under Section 2 (j) of the Act) reserves the right to appoint a nominee in the event of death or incapacity during her lifetime – the provision for nomination is novel given that the Recital 27 of the General Data Protection Regulation (GDPR) expressly excludes personal data of the deceased from its ambit, leaving it open to member states. The role of the nominee must, however, be understood in light of the decision in Sarbati Devi (Paras 5 and 12, E.S. Venkataramiah J.), which held that a nominee does not acquire any beneficial interest through nomination. A similar logic can be extended to the present case, where a nominee under the DPDPA acts as guardian of the deceased’s personal data without inheriting economic or commercial rights over it, which vest in the legal heirs as per estate law.
Data Fiduciaries (defined under Section 2 (i) of the DPDPA) such as Google, Apple and Facebook have independently incorporated features such as Inoperative Account Manager, Legacy Contact, and Memorialization, respectively, which could now satisfy the nomination mechanism contemplated by Rule 14(4) of the DPDP Rules, 2025. Such a nomination, however, is largely dependent on terms determined by Data Fiduciaries and restricts effective control over the deceased’s personal data, as intermediaries such as Meta provide limited account access.
While a civil action related to economic interests of the personal data under inheritance/succession laws may be pursued by the legal heirs, they are effectively prevented from managing the personal data of their loved ones, as the DPDPA does not contemplate conflict between the legal heirs and the nominee. This omission is especially costly for AI models, which continue operating on the deceased’s original consent regardless of whether a nominee exists, obscuring the nominee’s actual role despite similar powers as Data Principals under Section 14.
Without an appointed nominee, legal heirs lack a remedy, as grievance redressal complaints under Section 13 of the DPDPA can only be filed by a Data Principal. This remains unaddressed by Section 27 of the DPDPA as well, the Act must therefore include a process for the removal of a nominee on valid grounds.
Notably, a Civil Court in Sadhna Shaishav Shah (Para 8, Himanshu Choudhary, 3rd ASCJ), recently held that a deceased’s phone and digital data constituted a digital asset and were capable of being transferred as property. In doing so, the Court granted Letters of Administration of the deceased man’s phone and cloud storage to his daughter. Crucially, it held that in the absence of a nominee appointed under Section 14 of the DPDPA, the legal heirs would administer the estate, consistent with the extinguished-right position, but did not clarify the position of nominees vis-à-vis the legal heirs. Furthermore, the judgment highlighted that the role of the legal heirs was confined to the limited purpose of managing the deceased’s estate. This bears relevance in the case of thanabots, given that consent is meant to operate after-life, a conflict discussed in the following section.
Inadequacy of consent in Posthumous Data Processing:
The ease of consent withdrawal under Section 6(4) of the DPDPA assumes particular importance, given that AI models simulate the user based on consent obtained under Section 6(1), but such consent would be incomplete given the evolving nature of AI models.
Even if the training purpose is disclosed to the nominee through the consent manager (defined under Section 2 (g) of the DPDPA ) or the Data Fiduciary, it would remain ambiguous because the Data Principals would be incapable of understanding how the AI model would process their data and simulate them due to the black-box paradigm.
The deceased Data Principal’s consent specifically extends to postmortem use of her training data, and nominees cannot act against this consent despite exercising similar powers as Data Principals. Section 6(5), moreover, provides that the legality of data already processed before withdrawal of consent would not be affected.
The nominee, furthermore, cannot retroactively withdraw consent, but can only prospectively halt the ongoing data processing and simulation, as there is no practical mechanism to unlearn the deceased Data Principal’s data from AI models. This remains unaddressed despite Section 8(7)(a) requiring an erasure obligation post-withdrawal.
Rule 8, read with the Third Schedule of the DPDP Rules, 2025, requires erasure of data within 3 years of the Data Principal’s last interaction or exercise of rights, implying that inactive social media accounts must be deleted within this stipulated time. Thanabots render the timeline redundant as the deceased Data Principal consented to the postmortem use of personal data during her lifetime.
As of the date of writing, only Section 2 of the DPDPA is in force; specific enforcement timelines for other provisions of the DPDPA can be found in MeitY Gazette Notification G.S.R. 843(E) and Rule 1 (4) of the DPDP Rules. The gaps outlined above are therefore a pre-enforcement critique indicating the need for timely intervention.
Existing legal framework and liability of AI systems:
AI models such as the Meta patent would constitute “synthetically generated information” (SGI) as defined under Rule 2(1)(wa) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. The definition under Rule 2 covers audio-visual information artificially/algorithmically created portraying any individual in a manner that appears real. Rule 3 (3)(a)(i)(IV) moreover requires intermediaries offering a platform for SGI to undertake measures preventing content that “falsely depicts or portrays any natural person”. Intermediaries offering thanabots as a service would not fall within this provision, as AI models are trained on data obtained with the user’s consent. Rule 4 (1A) partially addresses this problem by requiring labels for SGI, but core issues surrounding withdrawal of consent and the dignity of the deceased remain unaddressed.
A patchwork of existing laws in India across Section 66E of the IT Act, 2000 (requiring a ‘private area’ and absence of consent) and Section 356 of BNSS (requires proving intent or knowledge) is structurally unsuitable for AI systems. Explanation 1 under Section 356, however, becomes relevant in the present case as it includes defamation imputed to a deceased person, or when such an imputation would harm the reputation of the deceased if living; this reflects the State’s intent to prevent emotional harm to the near relatives of the deceased, as held in Raj Kumar Saini (Paras 9 and 11, Sanjay Kumar J.). A similar dignity-based framework could address the emotional agony caused to relatives of the deceased arising either from improper representation by thanabots or from actions of third-party users.
The AI Governance Guidelines 2025 provide a principle-based approach and hence do not create any enforceable obligations on intermediaries (pages 51-55 of the Guidelines point toward the existing legal framework in India). Article 50 of the European Union Artificial Intelligence Act 2024 (EU AI Act), meanwhile, would cover AI models that generate or manipulate audio-visual content simulating individuals. Given that such models are used for emotional reasoning, they would be classified as High-risk AI systems under Article 6 read with Annex III of the Act, which requires assessment and oversight mechanisms before deployment.
Conclusion:
The rise of thanabots necessitates a significant policy rethink, requiring accountability to legal heirs, the just exercise of powers, and the adoption of Explainable AI (XAI) mechanisms to enable meaningful and informed consent. Commercial and dignity-based interests in privacy can be exercised through existing legal recognition of standing for immediate family (Raj Kumar Saini) and non-material damages for dignity harms (Princess Soraya), though legislative reinforcement remains necessary. A liability model could similarly factor in damages for anguish caused by improper representation of the deceased by intermediaries and third-party users.
A dignity-based approach recognised in Common Cause and Harish Rana could be extended to recognise postmortem privacy in India. Lastly, while the need for a broad-based artificial intelligence law in India is apparent, amendments to the definition of synthetically generated information under the Intermediary Guidelines, 2026, framed under Section 79 of the IT Act 2000, and recognition of digital estates under Estate laws would be imperative.
Incorporating a multi-level risk assessment, as in the EU AI Act, 2024, would ensure accountability of intermediaries in the development and deployment of thanatechnology; such an assessment should be based on the nature of risk rather than the number of users. The State’s approach must be guided by regulation and oversight to address the legal and ethical concerns emerging from the digital afterlife industry.