Skip to main content
Actionable Guides
9 min read

How to Review a Deceased Person's Online Data (Executor Guide, 2026)

A source-aware executor guide to credit, tax, account, public-record, and data-broker steps after a person's death.

Rahul Kandoriya
Written byRahul Kandoriya·Last updated August 25, 2026
How to Review a Deceased Person's Online Data (Executor Guide, 2026)
How to Review a Deceased Person's Online Data (Executor Guide, 2026)
Coverage scope: The OfflistMe catalog currently records 1000+data-broker workflows. Paid access lets you select workflows at once; you review and send or submit the generated requests, while provider eligibility and outcomes remain outside OfflistMe's control.

After someone dies, their information can remain in public records, people-search profiles, social accounts, credit files, tax records, and services they used while alive. Some of those records must be retained or remain public. Other copies may be removable, but the correct process depends on the provider, the jurisdiction, the estate's authority, and the type of record.

Identity theft involving a deceased person is sometimes described as “ghosting.” The FTC's identity-theft resources explain how to report and recover from identity theft generally. This guide focuses on a careful sequence for executors, administrators, surviving relatives, and other authorized representatives. It is not a substitute for probate, tax, or estate advice.

Key takeaways

  • Start with the official death-reporting, credit, tax, and account processes. Do not assume that deleting a people-search profile updates an official record.
  • Credit-bureau processes for a deceased-person notice, report request, or dispute can require proof of death and proof of authority. A deceased person's file may have different alert or freeze rules, so use each bureau's current instructions.
  • A death certificate does not automatically give every relative authority to access or delete every account. Probate documents, a power or fiduciary appointment, the provider's policy, and local law may matter.
  • Data brokers and people-search sites may have different opt-out, bereavement, or documentation routes. Do not promise that a standard opt-out will be accepted for a deceased person.
  • There is no universal deadline for every downstream copy. Prioritize identity, tax, financial, and account-security actions, then document provider-specific requests and follow-up.

First: confirm who can act

The person who can request information or deletion depends on what is being requested. An executor or court-appointed administrator may have authority over estate property, but access to a personal account can still be governed by the service's terms, privacy law, communications law, or a separate estate process. A surviving spouse, adult child, or other relative may be able to report a death without being authorized to receive account contents.

Before sending sensitive documents, identify:

Request Drafting

Tired of dealing with data exposure?

Choose relevant provider workflows, review the generated drafts in your browser, and send or submit each request yourself. Matching, eligibility, and provider requirements still need checking.

Review Removal Options Free for selected workflows · No opt-out profile stored · No card needed
CheckExamples already identified in this guide
Your roleExecutor, administrator, personal representative, trustee, surviving joint owner, or another relationship
Exact actionReport death, close an account, request a copy, dispute fraud, remove a public listing, or exercise a legal privacy right
Provider proof requirementsDeath certificate, letters testamentary, court order, identification, proof of relationship, or another document
Professional reviewWhether a local probate or estate professional should review the request

Send only the minimum documentation needed. Redact unrelated information where the provider permits it, and use the provider's verified secure upload or postal route. Do not send a Social Security number or death certificate to an unverified email address found in a search result.

Priority 1: report the death and protect credit

The Social Security Administration receives death reports from several sources, including family members, funeral homes, financial institutions, postal authorities, states, and federal agencies. The SSA explains its death-information files and how death information may be provided to authorized organizations. Do not assume that one report updates every private database immediately; confirm important records with the relevant organization.

For suspected identity theft or exposed information, use the FTC's IdentityTheft.gov recovery steps. The FTC recommends contacting the companies where fraud occurred, obtaining credit reports, placing an alert or freeze when appropriate, and preserving an FTC Identity Theft Report.

Contact each nationwide credit bureau through its current deceased-person or fraud route. Ask what it needs to mark the file, request a report, or dispute an account, and whether any alert or freeze process is available. A bureau may use a deceased indicator instead of a freeze or fraud alert for a deceased consumer; current bureau requirements control.

Use AnnualCreditReport.com's deceased-person instructions for the official credit-report route, but confirm eligibility and documentation before submitting a request for someone who died. If an account is fraudulent, contact the creditor and the credit bureaus through known channels. Keep copies of every letter, confirmation, and dispute number.

Priority 2: review tax and fiduciary steps

Tax handling is separate from broker removal. The IRS's deceased-person guidance covers returns, estates, and identity-theft topics. If you are acting as a fiduciary, read the current Form 56 instructions before filing. Form 56 notifies the IRS about a fiduciary relationship; it is not a general authorization to access every account or a substitute for the correct tax form.

If the IRS or another agency sends a notice about possible identity theft, follow the instructions in that notice and the agency's current identity-theft guidance. Do not infer that a credit freeze stops tax fraud, benefits fraud, medical identity theft, or misuse of a bank account. Those systems have separate controls.

Priority 3: secure digital and financial accounts

Make an inventory of email, banking, investment, insurance, utility, subscription, cloud-storage, social-media, domain, and messaging accounts. Do not log in as the deceased unless you have authority under the provider's terms or applicable law.

For each service, look for a current bereavement, memorialization, estate, account-closure, or privacy request. Ask whether the service can:

  • close the account;
  • memorialize it without exposing private content;
  • transfer an asset or subscription to the estate;
  • export information to an authorized representative; or
  • remove a public profile while retaining records required by law or contract.

Changing a password or forwarding email can affect the estate and other account holders. Coordinate with the estate professional and the provider instead of using a relative's credentials or bypassing security checks.

Priority 4: inventory public and commercial copies

Search the person's name, former addresses, phone numbers, usernames, business names, and common misspellings. Keep a private inventory with:

  • the exact URL and provider name;
  • the fields exposed;
  • the date observed;
  • the source or attribution shown by the provider;
  • the action requested; and
  • the confirmation or response.

Separate official records from independent copies. A court record, property record, obituary, professional-license record, or government filing may have a different correction or sealing process from a people-search profile that copied it. Removing a downstream profile does not change the underlying record.

Do not publish the death certificate, full Social Security number, or estate documents while documenting a listing. Save screenshots privately and redact unnecessary details before sharing evidence with a provider.

How to request removal from a data broker

Use the provider's current privacy, opt-out, deceased-person, or authorized-agent route. A concise request can say:

I am requesting review of a public profile for [name], who died on [date]. I am acting as [role]. The profile URL is [URL]. Please explain what proof of death and authority you require, identify any information you can remove or suppress, and confirm the scope of your response. I have attached only the documentation required by your current process.

The provider may require identity verification, a death certificate, proof of authority, or a different route for an account or public-record listing. It may also refuse to remove information where a legal, public-record, fraud-prevention, or other exception applies. Do not state that a law guarantees deletion unless the facts and applicable law have been reviewed.

If you use OfflistMe, it can create browser-local, user-reviewed drafts for supported provider workflows. The executor or authorized representative submits each request and chooses what documentation to provide. Provider coverage, matching, proof requirements, and outcomes vary; a catalog entry is not a promise that a provider accepts a deceased-person request.

Search-engine and social-profile cleanup

Search engines generally index pages; they do not control the source page. If a provider removes a page, use the search engine's current outdated-content or personal-information route when the result remains stale. A search removal can affect a result without deleting the source.

For social networks and cloud services, use the platform's official memorialization or deceased-user process. Public memorial content may remain available under the platform's rules, while account access and private messages require separate authority. Do not assume that a parent company uses one process across all products.

What not to assume

  • There is no universal “48-hour” window that determines whether a deceased person's identity will be misused.
  • There is no verified, universal propagation time from the SSA or a credit bureau to every data broker.
  • A credit alert or freeze does not protect every tax, benefits, medical, banking, account-takeover, or public-record pathway.
  • A death certificate alone does not establish the same rights for every provider, state, or account type.
  • Data-broker removal does not erase credit-bureau, government, court, property, tax, or breach records.
  • A provider's status label or email confirmation does not prove that every copy has disappeared from the internet.

A practical monitoring plan

Choose a cadence based on the estate, risk, open accounts, and notices received rather than using a fixed universal schedule. At each review:

  1. Check for new creditor, bank, tax, or benefits notices.
  2. Review the credit-report and fraud-response status through the official channels.
  3. Recheck the specific public listings in your inventory.
  4. Follow up with providers that have not answered or that identify a documentation gap.
  5. Record the next action and protect the estate documents you used.

If fraud is found, use IdentityTheft.gov, contact the affected business, notify the relevant credit bureau, and consider a police report when required by the business or appropriate for the case. For tax issues, follow IRS instructions; for bank or investment issues, use the institution's fraud department and regulator route.

Frequently asked questions

Can a relative remove a deceased person's data?

Sometimes, but authority depends on the provider, account type, jurisdiction, and requested action. A relative may report a death without being entitled to access private account contents. Ask the provider what proof it requires.

Should I send a full death certificate to every broker?

No. Use a verified provider route and send only the documentation required for the specific request. Redact unrelated information where permitted and avoid unverified email addresses.

Does removing a people-search profile stop identity theft?

No. It may reduce one public source of profile information, but it does not control credit files, tax systems, financial accounts, public records, breach data, or copies already collected elsewhere.

How long will removal take?

There is no reliable universal timeline. Provider response times, documentation review, matching, source updates, and search-engine refreshes vary. Save the request and follow the provider's current instructions.

Can I use a data-removal service for an estate?

You may compare services, but verify whether the service accepts representative requests, what documents it stores, whether it acts as an agent, and who sends the request. A user-reviewed first-party draft workflow can reduce data sharing with the service, but it does not bypass provider requirements.

Sources and limits

These sources establish process boundaries, not a universal estate checklist or a guarantee of removal. Estate authority, provider documentation, credit-file actions, account access, public-record treatment, and downstream results depend on the person, jurisdiction, record, and provider. No request is submitted by this guide.

Related guides

Take back your privacy today

Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.

Review Provider Routes

Free to review provider routes · Optional one-time unlock from $9.00 · No subscription