Soares, Goulart & Caetano Advogados

September 09, 2026

Digital Inheritance and Business Succession: How to Preserve Assets, Privacy, and Business Continuity

Back to articles
Digital Inheritance and Business Succession: How to Preserve Assets, Privacy, and Business Continuity

When digital access becomes a corporate risk

A company's operations can depend on elements that do not clearly appear on the balance sheet: internet domains, institutional profiles, cloud accounts, code repositories, digital certificates, crypto-asset wallets, software licenses, customer databases, and administrative credentials. When these resources are tied to a founder's personal email, phone, or device, that person's death or incapacity can interrupt sales, payments, communication, and support long before any discussion of the division of company shares (partilha de quotas) even begins. Digital inheritance (herança digital), therefore, is not just a family law topic. It is part of corporate governance, information security, and business succession planning.

The problem is often described simply as a missing password, but the legal issue is broader. It is necessary to determine who legally owns the asset, whether it can be transferred, what data may be accessed, which contracts limit transferability, and who is authorized to act on behalf of the company or the estate (espólio). Technical access does not equate to ownership, and ownership does not guarantee immediate access. This distinction explains why an organization may legally own a piece of software and still be unable to manage it if the main account is registered under an individual's name.

Assets, privacy, and continuity

Not all digital assets follow the same legal regime

Digital assets with economic value—such as crypto-assets, platform credits, domains, monetized accounts, and rights to exploit software or content—generally can be included in an estate. On the other hand, intimate messages, private photographs, and personal communications are tied to personality rights (direitos da personalidade) and do not become freely accessible simply because someone has died. Between these two extremes lie hybrid assets, such as a professional account that combines commercial audience, contracts, personal conversations, and customer data. In these cases, classification depends on the content, ownership, purpose, and the rights of third parties involved.

In the corporate context, the term “digital assets” also requires precision. A database may represent significant economic value, but the personal data it contains is not property that can be freely disposed of in an absolute sense. Its processing remains subject to purpose limitation, necessity, security, and the other requirements of the Brazilian General Data Protection Law (LGPD) whenever it involves living individuals. Likewise, software licenses, profiles, and platform accounts may be governed by contracts that restrict assignment or sharing. Succession planning must distinguish between the economic asset, the protected content, the access credential, and the contractual relationship that enables its use.

The current legal framework and its points of tension

There is still no specific, comprehensive Brazilian law governing digital inheritance. The current approach results from combining several sets of rules. Article 1,784 of the Civil Code establishes the immediate transfer of the estate to the heirs upon death, while Articles 11, 12, 20, and 21 protect personality rights, including in certain cases after death. The Constitution guarantees the right to inheritance while also protecting privacy, private life, and the confidentiality of communications. The Brazilian Civil Rights Framework for the Internet (Marco Civil da Internet), particularly Article 7, also protects stored private communications and requires a court order for their disclosure.

The LGPD was designed to apply to data related to natural persons, and Technical Note No. 3/2023, issued by Brazil's National Data Protection Authority (ANPD), reflects the administrative understanding that the law does not directly apply to the data of deceased individuals. This does not create a legal vacuum, however. A deceased person's files may contain data belonging to living customers, employees, family members, and partners, as well as trade secrets and confidential communications. Any company that recovers or receives such files must limit access, document the purpose of use, and apply controls proportional to the risk involved.

The STJ precedent and the “digital estate administrator”

In Special Appeal (Recurso Especial) 2,124,424/SP, the Third Panel of the Superior Court of Justice (STJ) addressed, by majority vote, a request for access to password-protected devices within the context of a probate proceeding (inventário). The court ordered the opening of a parallel incident aimed at identifying, classifying, and valuing digital assets. In this procedure, a specialized professional—referred to as a “digital estate administrator” (inventariante digital)—may examine the device and produce a report so that the judge can decide which elements are of an economic nature and can be transferred, while preserving content that touches on the privacy of the deceased or third parties.

The ruling offers a screening method, not a blanket authorization for heirs to search through accounts and devices. Nor does it automatically turn the digital estate administrator into a company manager, a representative of the estate, or the owner of the assets. Their role is technical, limited by the court, and subject to confidentiality. Moreover, the decision was not issued as a binding precedent under the repetitive appeals system and addressed a specific factual situation. Its application to corporate accounts, cloud services, or business credentials will depend on proof of ownership, the contracts involved, and the need to protect third-party data.

This incident aligns with Article 612 of the Code of Civil Procedure, under which the probate judge resolves legal questions when the relevant facts are documented, while referring matters requiring further evidence to ordinary proceedings. The STJ's solution seeks to prevent a missing password from wiping out transferable assets, without allowing indiscriminate access. For businesses, the key takeaway is less procedural than preventive: relying on a future court-ordered expert examination to locate critical assets already represents a continuity failure.

The company is legally distinct from its shareholders, but credentials can blur everything

Article 49-A of the Civil Code establishes that a legal entity is distinct from its shareholders or administrators. As a result, a founder's death transfers their ownership stake in the company, not the assets belonging to the company itself. In limited liability companies (sociedades limitadas), Article 1,028 provides, as a general rule, for the liquidation of the deceased partner's quota, unless the company's articles of association state otherwise, the company opts for dissolution, or an agreement is reached with the heirs to replace the deceased partner. Articles of association and shareholders' agreements should coordinate succession, management, valuation of the departing partner's share, and continuity of decision-making.

This legal separation loses practical effectiveness when corporate assets are registered under an individual's tax ID (CPF), personal email, or private device. A domain may expire, a two-factor authentication method may disappear along with the administrator's phone, a code repository may be left without a maintainer, and a self-custodied wallet may become unrecoverable without its private key. Disputes may also arise between heirs and remaining shareholders over software authorship, ownership of channels, and the use of mixed files. Potential damages include service outages, revenue loss, contractual breaches, security incidents, and a decline in the company's overall value.

Digital succession planning as corporate governance

The most consistent response starts with a full inventory of digital assets, identifying the legal owner, administrator, provider, location, value, criticality, renewal deadlines, and recovery method for each one. This map should cover domains, cloud services, email accounts, social media, source code, certificates, digital signatures, digital financial accounts, cryptographic keys, and systems that support daily operations. The company should then transfer corporate registrations into its own name whenever legally and contractually possible, adopt institutional accounts, and ensure that more than one authorized administrator has access to critical functions.

Credentials should never be included in articles of association, shareholders' agreements, or wills, since these documents can circulate or become public. The proper approach is to legally define who may activate the continuity plan, while keeping secrets in a secure system with strong authentication, access logs, tested recovery procedures, segregation of duties, and periodic updates. For crypto-asset private keys, the architecture may require specialized custody, multi-signature arrangements, or controlled information splitting. No single model fits every company, and setting up a holding company does not, by itself, resolve technical, tax, accounting, and regulatory risks.

Corporate documents must align with actual technological practices. Articles of association, shareholders' agreements, powers of attorney, security policies, intellectual property assignment agreements, vendor contracts, and incident response plans should all specify powers, replacement procedures, and protocols in the event of death, incapacity, or departure. For an entrepreneur's personal assets, a will and other estate planning instruments may record the intended distribution and point to where a secure access protocol can be found, while still respecting the mandatory share (legítima) reserved for necessary heirs. Testamentary intent, however, cannot unilaterally override platform terms of service or authorize the violation of third parties' privacy.

Regulatory trends: meaningful progress, but not yet in force

Bill No. 4/2025, which proposes a broad update to the Civil Code and includes a dedicated section on Digital Civil Law, remained under review in the Senate as of September 2026, being analyzed by a temporary committee. The proposal confirms a broader trend toward more explicitly regulating digital assets and relationships, but its text may still change. Companies should not treat the bill's provisions as current law, nor should they postpone governance measures while waiting for the reform to pass.

Another source of uncertainty lies in the terms of service of global providers. Rules regarding memorialization, account closure, data recovery, or non-transferability vary between services and may involve foreign law. These clauses do not automatically override rights recognized under Brazilian law, but they do affect the practical and litigation path forward. Corporate contracting should prioritize business-tier plans, designated backup administrators, data export options, portability, continuity provisions, and clearly documented succession procedures.

Digital continuity requires decisions made during one's lifetime

The STJ precedent reduces the risk that a password will permanently block access to a transferable asset, but its procedure is a judicial remedy applied after the fact, subject to cost, delay, expert examination, and privacy safeguards. For entrepreneurs and executives, the priority should be preventing business operations from depending on a single person's digital identity. Separating personal and business assets, documenting ownership, securely distributing access, and integrating technology into corporate and estate planning instruments protects value and reduces conflict.

Digital succession planning should be reviewed whenever there is a change of control, adoption of a new platform, a significant acquisition of digital assets, or a change in family or corporate structure. Since every organization combines a unique mix of contracts, data, intellectual property, and risks, preventive assessment by legal and technical professionals allows for building a proportional protocol, without guarantees of outcome and without excessive access to protected information. This content is for informational purposes only and does not replace legal analysis of a specific situation.

Written by Eduardo Caetano de Carvalho