Soares, Goulart & Caetano Advogados

July 20, 2026

Digital succession and business continuity: how to protect assets, data, and operations after the death of partners and managers

Back to articles
Digital succession and business continuity: how to protect assets, data, and operations after the death of partners and managers

Digital transformation has caused a significant portion of many companies' value to exist in virtual environments. Domains, email accounts, business profiles, monetized channels, crypto asset wallets, cloud systems, code repositories, software licenses, databases, and administrative credentials can be essential for generating revenue and ensuring operational continuity. When a partner, founder, or manager dies, the absence of clear rules regarding these resources can paralyze activities, destroy economic value, and intensify conflicts among heirs, other partners, clients, and digital platforms.

In this context, digital succession is no longer an issue restricted to private life. For business owners and managers, it must be treated as a matter of governance, business continuity, data protection, and estate planning. The legal challenge lies in reconciling the transfer of assets with the deceased's privacy, the confidentiality of communications, the rights of third parties, and contracts signed with technology providers.

A company also leaves behind a digital inheritance

Digital inheritance may include assets of a patrimonial, existential, or hybrid nature. Patrimonial assets are those with identifiable economic value, such as crypto assets, platform credits, copyrights, domains, business files, and monetized accounts. Existential assets are contents linked to personality, such as private messages, personal photographs, and intimate records. Hybrid assets combine both dimensions, a situation frequently found in the profiles of founders, influencers, and professionals whose personal image becomes intertwined with the brand and business activity.

This classification is decisive because not all content accessible through a password can be transferred in the same way. An heir may be entitled to the economic value of a given asset without gaining unrestricted access to the private communications contained in the same account. It is also necessary to distinguish between ownership of the content, the usage license granted by the platform, the right over the data, and the mere technical possibility of logging into the system.

The current legal framework

Article 1,784 of the Brazilian Civil Code establishes the principle of saisine, according to which the estate is transferred to the heirs at the moment of death. This legal transfer, however, does not automatically resolve technical access to digital assets nor does it override personality rights, confidentiality duties, and contractual restrictions. The Brazilian Internet Civil Framework (Marco Civil da Internet) protects the confidentiality of data and communications, while the General Data Protection Law (LGPD) does not expressly regulate the succession of data belonging to deceased persons. Even so, the LGPD remains fully relevant when accounts and files contain data belonging to clients, employees, suppliers, or other living individuals.

In the corporate context, the principle of asset segregation set out in Article 49-A of the Civil Code requires separating the assets of the legal entity from the personal assets of its partners. In principle, a domain, software, or database belonging to the company does not form part of the founder's personal estate. What enters the probate estate are the founder's quotas or shares and any personal rights. The problem arises when business assets were informally contracted in the partner's name, paid for with a personal credit card, or protected solely by the partner's phone and two-factor authentication.

The death of a partner must also be analyzed in light of the company's articles of association. Article 1,028 of the Civil Code establishes, as a general rule, the liquidation of the deceased partner's quota, unless the articles of association provide otherwise, the company is dissolved, or an agreement is reached with the heirs. For this reason, clauses regarding the entry of successors, the calculation of amounts owed, provisional management, voting rights, and the transfer of intellectual property must align with the rules governing access to digital assets.

The business risk hidden in personal accounts

The greatest vulnerability usually lies outside legal documents. It is common for only the founder to hold the master password to the cloud provider, the private key to a digital wallet, access to the advertising panel, the administrator account of the marketplace, or the repository containing the product's code. In such cases, the transfer of quotas does not guarantee the resumption of operations. The company may find itself unable to bill clients, pay suppliers, serve customers, renew a domain, or comply with regulatory obligations.

Improvised access by family members or employees also creates risks. Using the deceased's credentials without authorization may violate terms of use, expose private conversations, compromise evidence, generate a security incident, and reveal personal data belonging to third parties. The appropriate business response is not to share passwords indiscriminately, but to create an institutional architecture for access, recovery, and auditing, with clear segregation between corporate and personal content.

The Superior Court of Justice's guidance on the digital estate administrator

In Special Appeal (REsp) 2,124,424, decided by the Third Panel of the Superior Court of Justice (STJ) in September 2025, the majority recognized the need for a controlled procedure to examine the digital files of a deceased person. The solution adopted provides for the involvement of a specialized professional, bound by confidentiality, to identify and classify content, with the judge deciding what is patrimonial in nature and may be transferred and what must remain protected due to involving privacy or personality rights.

Although the case originated from a family dispute, its reasoning is relevant to businesses. The decision signals that inheritance law does not authorize indiscriminate access to equipment and accounts. In situations where business and personal files are mixed together, preserving evidence, limiting access, and judicial supervision may be essential. For risk management purposes, this reinforces the importance of keeping corporate assets in institutional environments, with documented ownership and audit trails.

Civil Code reform and regulatory trends

Bill of Law 4 of 2025, which proposes a broad update to the Civil Code, creates a specific framework for Digital Civil Law and remains under review in the Senate as of July 2026. The proposal seeks to define digital assets, regulate the destination of accounts and content, and distinguish economically valuable assets from situations protected by privacy and the confidentiality of communications. Since the text may still be amended, companies should not wait for the reform to organize their governance.

The regulatory trend points toward requiring greater precision in identifying the account holder, expressing intent, and establishing post-mortem access procedures. Platforms are also likely to face increasing responsibility to offer transparent mechanisms for memorialization, deletion, limited transfer, and data preservation. For business groups operating in multiple countries, contracts with foreign providers may still involve rules on jurisdiction, data localization, and international cooperation.

Digital estate planning as governance

A consistent business succession plan should begin with an inventory of digital assets and confirmation of their legal ownership. Next, it is necessary to classify what is corporate, personal, or hybrid, document the chain of intellectual property ownership, review platform contracts, and establish continuity procedures. Critical accounts should use institutional emails, company-managed authentication, role-based access profiles, backups, and secure recovery mechanisms.

Corporate and estate planning documents must be coordinated. Articles of association, shareholders' agreements, wills, donations, family protocols, and internal policies can define the succession of quotas, temporary management, and the destination of assets. Credentials should not be disclosed within the will itself, which may become accessible during the probate process. It is safer to indicate the existence and location of a digital vault or protected instructions, with clear release rules and access logs. A standard power of attorney generally becomes void upon death and does not replace proper estate planning.

Criteria for economic valuation and tax treatment of assets should also be established, including for purposes of probate and ITCMD (Tax on Causa Mortis Transfer and Donation), in accordance with applicable state legislation. Crypto assets, copyrights, platform revenues, and assets held in custody abroad may require technical reports and analysis of conflicting laws. In terms of privacy, access should follow the principles of necessity, purpose limitation, security, and accountability, especially when third-party data is involved.

Digital succession is now a concrete component of business continuity. The absence of planning can cause a legally sound company to lose access to the resources that sustain its operations, while excessive access can violate privacy, confidentiality, and personality rights. The safest path is to integrate inheritance law, corporate law, data protection, intellectual property, and information security into a single strategy.

For business owners and managers, the most effective measure is to act before the succession event occurs, separating personal and corporate assets, formalizing ownership, and creating contingency procedures. Given the legislative gap and evolving case law, preventive legal counsel helps transform scattered digital assets into a governance structure capable of preserving value, reducing conflicts, and protecting business continuity.

Written by Eduardo Caetano de Carvalho