Guides

What Not to Publish: Privacy and Ethics in Family History

KleioBase EditorialAugust 28, 202615 min read
Share

Genealogy has an unusual property among research disciplines. Almost everyone you study is a person who never consented to being studied, and a meaningful number of them are still alive.

The dead cannot object. That is the comfortable part, and it is where most of the hobby lives. The uncomfortable part is that a family tree is not a tree of dead people. It runs forward to your living cousins, their children, their addresses, their birthdates, and occasionally to facts about their parentage that they do not know. Publish it and you have published them.

This is a practical guide to where the lines are: what the law requires, what the professional standards require on top of that, and what to do in the cases where both fall silent.

One caveat, stated once. This is orientation, not legal advice, and the details vary by jurisdiction. If a specific situation carries real consequences, get advice for your own country.

The dead are mostly outside data protection law

GDPR Recital 27 is unusually direct:

This Regulation does not apply to the personal data of deceased persons. Member States may provide for rules regarding the processing of personal data of deceased persons.

So your ancestors are not "data subjects" in EU law, and neither is a person who died in 1901 nor one who died last year. Nothing in the GDPR stops you publishing an 1880 birth record.

The second sentence is the one people skip. Member states may legislate, and a dozen of them have: Bulgaria, the Czech Republic, Denmark, Estonia, France, Italy, Latvia, Lithuania, Portugal, Slovakia, Slovenia and Spain all provide some form of post-mortem protection, generally by letting relatives or people with a legitimate interest exercise rights over a deceased person's data. The shapes differ considerably. "The dead have no data rights" is accurate at EU level and unreliable at national level.

The living are fully protected, and the family exemption may not save you

Your living relatives are ordinary data subjects with ordinary rights. Their names, dates, addresses and family relationships are personal data in exactly the normal sense.

The obvious defence is the household exemption: the GDPR does not apply to processing "by a natural person in the course of a purely personal or household activity". A family tree sounds like the definition of a household activity.

The problem is that a court has already ruled on almost exactly this. In Bodil Lindqvist (C-101/01, decided 6 November 2003), a volunteer catechist in a Swedish parish put up web pages about herself and eighteen colleagues, describing their jobs and hobbies and giving family circumstances and telephone numbers, and mentioning in one case that a colleague had injured her foot and was working half-time on medical grounds. The Court of Justice held that the exemption covers only activities carried out in the course of private or family life, which "is clearly not the case with the processing of personal data consisting in publication on the internet so that those data are made accessible to an indefinite number of people".

Read that against what a public online family tree does. A private tree on your own machine, or shared with your aunt, is comfortably within personal and household activity. The same tree published to a site anyone can browse, containing living people's dates of birth and family relationships, is on the far side of the line the Court drew - regardless of how personal your motive was. Lindqvist's motive was as personal as it gets.

This does not mean public trees are illegal. It means the exemption you were relying on is narrower than it sounds, and the practical protection is to not publish living people's details in the first place.

The United States has no equivalent, with one exception

There is no general US analogue. Public records are broadly public, and genealogy has largely benefited from that.

The exception genealogists actually feel is the Social Security Death Master File. Section 203 of the Bipartisan Budget Act of 2013 barred disclosure of a decedent's DMF record for the three calendar years following death, except to entities certified by the Secretary of Commerce as having a legitimate fraud-prevention purpose. That is why the Social Security Death Index appears to stop three years short of the present. It is a fraud measure rather than a privacy measure, but it is a useful reminder that the identity value of a dead person's data does not expire on the day they die.

Legality is the wrong target. Most of what causes harm in this field is entirely legal.

The National Genealogical Society standards for sharing information ask that researchers respect restrictions on sharing that arise from the rights of another "as an author, originator or compiler; as a living private person; or as a party to a mutual agreement". Note the middle clause: being alive and private is on its own a basis for restriction.

The Board for Certification of Genealogists Code of Ethics binds certified genealogists to keep personal and genealogical information confidential absent written consent, and its DNA provisions require informed consent from test takers, protection of their privacy, and a commitment to refrain from publishing information derived from DNA results that may cause harm.

That last phrase is the most useful sentence in the professional literature, because it names the actual test. Not "is this record public". Not "is this technically permitted". Would publishing it cause harm to a living person?

A default policy you can apply

Rules beat case-by-case judgement, because case-by-case judgement is made at 11pm when you are excited about a discovery.

For anyone living, publish name and relationship at most. Not the birth date. Not the address. Not the maiden name of a living woman. The reason is specific rather than paranoid: full name plus date of birth plus mother's maiden name is the identity-verification triad long used by financial institutions, and a public family tree assembles all three by design. This has been measured. Researchers using publicly available records have shown that the guessing difficulty of a mother's maiden name collapses from an average of close to 13 bits of entropy to below 6.9 bits for more than a quarter of the people targeted, and to zero for a substantial number of them. Genealogists assemble exactly the dataset that attack depends on.

Photographs of living people, and especially of minors, need explicit permission. A photograph also carries two separate rights: the copyright, which belongs to the photographer, and the interests of the person depicted. Inheriting a print does not give you either.

Treat the 100-year rule as a heuristic, not a law. The common convention - assume anyone born within roughly the last hundred years may be living unless you have a death record - is a sensible default and nothing more. Platforms do not even agree on the number: FamilySearch treats someone as living if they were born within 110 years and have no death date. It is a starting point for redaction, not a legal safe harbour.

Ask, and take no for an answer. A relative who declines to appear in your tree does not owe you a reason, and "but it is already in public records" is not a rebuttal. Aggregation is the harm. Each fact may be individually findable; you are the one collecting them into one page.

Consent does not travel. Your aunt agreeing to appear does not cover her children. Consent given for a private tree does not cover publishing it. Consent given in 2019 does not cover a site with different sharing defaults in 2026.

Deceased does not mean unlimited. A person who died in 2014 has living children who can be embarrassed, and a recent death certificate carries a home address and a cause of death. Depending on the state and on which version of the certificate you hold, it may also carry a Social Security number, which is exactly why jurisdictions have started stripping it: Massachusetts passed a law in November 2025 redacting SSNs from death certificates in public records. Check what is on the image before you share it, and redact the identifiers.

The hard cases

The rules above cover the routine. These are the ones that actually come up, and that almost nothing written for genealogists addresses.

Adoption and misattributed parentage

Every serious tree eventually runs into a parentage that is not what the documents say. Estimates of how often vary enormously with population and method - published figures span a very wide range - but most general-population studies land somewhere around 1 to 3%. Across a documented tree of a few hundred people, the probability that this affects nobody is small.

Three rules, and they are firm.

It is the affected person's news to receive first. If you discover through documents or DNA that someone's father is not their father, that person hears it before your cousins, before the Facebook group, and before it appears in a shared tree. If they are not the one who went looking, they may not want to know at all.

It is their news to tell. Once told, what happens next is their decision, including the decision to tell nobody. You do not get to publish it because it is genealogically interesting. It is not a fact about your research; it is a fact about their life.

Never annotate it in a shared tree. A note reading "biological father unknown, see DNA" in a tree that fifteen relatives can read is an outing, however neutrally you phrased it. If your tool cannot hold a private note, the note does not go in the tool.

The same applies to adoption. An adoptee's birth family is their information to seek or not seek, and reuniting people who did not ask to be reunited has caused real harm in real families.

DNA matches are people

A DNA match is a living person who tested for their own reasons, which may not include your project. Their name, their match list, their ethnicity estimate and the amount of DNA you share are their data, not yours. Do not publish match names or screenshots, do not post them to groups, and do not add a match to a public tree because you worked out where they fit.

If you manage kits for relatives, they consented to a test, not to becoming a research asset. Confirm they understand what a match list exposes, including the possibility that it exposes something about their own parentage.

Records that hurt the living about the dead

Criminal convictions, illegitimacy, workhouse and asylum admissions, institutional records, bankruptcies, desertion. These are legitimate historical records and part of an honest family history. They also land on living grandchildren.

The workable rule: publish the record, not the verdict. Cite what the document says and let it say it. "Admitted to the county asylum, 12 March 1898" is a sourced fact. "Great-grandmother was mentally ill" is you diagnosing a stranger across a century, using a document created by a system whose categories were not medical and frequently not kind. Women were institutionalised for reasons that would not survive ten seconds of modern scrutiny. The record is evidence of what the institution recorded, which is not the same as evidence of what was true.

Consider also the status of records created without their subject's participation - institutional registers, colonial administrative records, documents produced about people who had no standing to correct them. They are often the only surviving trace of a life and are worth preserving and publishing for exactly that reason. But they are records of what an authority asserted, and they deserve to be framed that way rather than reproduced as neutral fact.

The secret that is somebody's present

Some things you will find are not history to the people they concern. A first marriage nobody mentions, a child given up, a wartime allegiance, a name changed to escape something. Where the people involved are dead and their children are dead, this is history. Where a living person built their life around a version of events, you are not uncovering the past. You are editing their present.

You may still be right to write it. Just do it knowing which of the two you are doing.

Sharing without publishing

Most of the tension here comes from treating "keep it private" and "publish it to the world" as the only options. They are not, and the middle is where most genealogy should live.

  • A private tree shared with named people covers the overwhelming majority of collaboration.
  • A link to one person rather than to your whole tree limits exposure to what the recipient actually needs.
  • Expiring links mean a link shared onward stops working.
  • A password turns "anyone with the URL" into "anyone you gave the password to".
  • A redacted export lets you hand a file to a relative or a client without handing over living people's details.

If you do publish publicly, publish two trees: a full private one and a public one that stops at people born more than a century ago.

Three questions before you post anything

Is anyone in this still alive - including people I did not mean to include? Trees are the obvious case. Record images are the missed one. A census page contains the neighbours. A death certificate contains the informant. A 1955 photograph contains people who are alive now.

If this person read it tomorrow, would they be learning something about themselves from me? If the answer is yes, stop. That conversation happens privately or not at all.

Can I take it back? Almost never. Public trees are copied, scraped, mirrored and merged into other people's trees within days. There is no recall. Treat every publication as permanent, because in practice it is.

How KleioBase handles this

We built the privacy controls around the assumption that most of what needs protecting is living people inside an otherwise historical dataset.

Living or deceased is a real status on every profile, not a guess made at display time. Anyone marked Deceased is treated as historical. Anyone marked Living is treated as protected. Where the status is unknown, KleioBase infers a possibility from the dates: no recorded death, and either born within the last hundred years or with no known birth year at all.

Sharing a profile is gated on that status. A share link is a public read-only page for one person, with a chosen expiry and an optional password. If the profile is marked Living, both the consent confirmation and the password become mandatory - you must confirm you have that person's consent, or their guardian's if they are a minor, before the link can be created at all. If the profile only might be living, you confirm either that they are deceased or that you have consent. And marking someone Living after you have already shared them takes the existing link down immediately, even if it had not expired, because the decision should apply retroactively rather than only to future links.

Exports can redact living people. A checkbox on GEDCOM export and on the PDF report leaves living relatives' details out, and it tells you in advance how many people would be redacted so you can see the cost before deciding. A redacted person still appears, so the tree stays connected and grandchildren still link to grandparents, but their entry carries only surname, sex, and position in the family. Dates, places, facts, notes, citations, alternate names, associates and photos are all left out, and where either partner is redacted the marriage and divorce details go too. Recorded negative evidence is withheld as well, on the reasoning that what you searched for and did not find about a living person is still information about that person.

Redaction is off by default, deliberately. Silently removing people from a file the user believes is complete is its own failure mode.

Inference about living people can be switched off. A setting called "Infer historical context from relatives" fills a missing religion, nationality or caste from a person's nearest relative in order to choose which historical events appear on their timeline. That is useful for a thinly documented 18th-century ancestor and questionable for a living cousin, so it can be turned off entirely, which restricts every timeline to what is directly recorded about that person. If you research for clients, professional use covers why you may want it off.

One honest limitation, because it matters. Redaction covers tree data. It does not redact record transcriptions or images. If a census image in your export shows a living neighbour, or a transcription quotes a living informant, redaction will not remove it. Review what you are including before an export leaves your household. We would rather state that plainly than let a checkbox imply a guarantee it does not make.

The standard worth holding

The people in your tree cannot review what you write about them. The dead have no recourse and the living usually never find out. That absence of accountability is exactly why the discipline has to be self-imposed.

A useful test: would you be comfortable if the subject read it? For the 1840 farmer, that question is a curiosity. For your cousin's daughter, it is the whole thing.

Publish the history. Protect the living. When you are not sure which one you are looking at, the answer is that they are alive.

Start building your family history

Upload a record and let KleioBase transcribe, translate, and connect it - all in one place, with a research partner that remembers everything you find.

Get started

We use cookies and similar technologies. Essential cookies keep the site working. We only load analytics (PostHog) and marketing (Meta Pixel) with your consent. See our Privacy Policy.