Digital Estate Planning: Who Gets Your Passwords When You’re Gone

Affiliate disclosure: Some links in this article are affiliate links, meaning I may earn a commission if you buy through them, at no extra cost to you. I only recommend products I’ve evaluated myself, and commissions never decide what I recommend.

Here’s a situation estate attorneys see often: A woman’s husband passed away. She needed to access his phone, just a four-digit code standing between her and years of photos, banking apps, everything. She tried every combination she could think of. She called Apple. She called the carrier. She called the police. Nobody could help her, because none of them are allowed to, not without the right documentation, not even for a grieving spouse.

This happens more than people realize. You’d think having the password would be enough. Often it isn’t.

Why “just having the password” doesn’t actually work

Two problems show up constantly, and neither has anything to do with forgetting a password.

The first is two-factor authentication. You type the correct password, and the account still asks for a code, sent to a phone that’s now locked, or a number that’s been disconnected. The password was right. The account is still out of reach.

The second is more legal than technical. Most platforms explicitly prohibit logging into someone else’s account, even with permission, even after they’ve died. It’s written into the terms of service almost everywhere. Using a family member’s exact login, even with good intentions, isn’t the sanctioned path. The actual process runs through each company directly: a death certificate, sometimes a copy of the will, sometimes additional legal documentation, submitted to the platform itself.

The one legal detail worth actually knowing

Most states have adopted something called the Revised Uniform Fiduciary Access to Digital Assets Act, RUFADAA for short. It’s the law that lets an executor legally access digital accounts after someone dies. Here’s the part that trips people up: it only works if your estate documents explicitly say so. A will that doesn’t mention digital assets can leave even a court-appointed executor with less authority than they need, locked out on a technicality nobody thought to close.

One more important point. Your will becomes a public document once it enters probate. It is reviewed as part of a court process. That makes it exactly the wrong place to list actual passwords. The will should name who has authority. The passwords themselves belong somewhere else entirely. Some place secure, private and separate from any document a court might eventually read.

The tools most people don’t know exist

Apple, Google, and Facebook all have features built for exactly this situation, and almost nobody uses them. A Carnegie Mellon research team studying how older adults handle digital estate planning found that awareness of these tools was close to zero among the people they interviewed. Not because the tools are bad. Because barely anyone knows they’re there.

Apple’s Legacy Contact lives under Settings, then Sign-In & Security. You designate someone, and Apple generates an Access Key for them. After you’re gone, that person uses the key along with a death certificate to gain access, exactly the documented process platforms actually require, built directly into the phone.

Google’s Inactive Account Manager does something similar for Gmail, Drive, and Photos. You set a timeout, somewhere between three and eighteen months of inactivity, and choose who gets notified and what they can access once that window passes.

Facebook offers a memorialization setting, letting you decide in advance whether your profile becomes a memorial page or gets removed entirely, and who’s allowed to manage it.

None of these take more than a few minutes to set up. All of them sit quietly unused by most people, simply because nobody told them to look.

Where a password manager’s emergency access fits in

This is the part that connects directly back to choosing a password manager in the first place. NordPass includes an Emergency Access feature, built for precisely this situation. You designate a trusted contact directly inside the app. If something happens to you, they can request access to your vault, and after a waiting period you control, they get in, no probate, no waiting on a company’s internal legal team to process paperwork.

Emergency Access gets a trusted person into your password vault. It doesn’t override RUFADAA, and it doesn’t replace the platform-specific legacy tools above, since some of those cover more than just passwords, photos, files, entire account histories. Emergency Access is the fastest, simplest layer. The legacy features are the more complete ones. Setting up both isn’t redundant. It’s just thorough.

What to actually do, in order

Make a real inventory. Every account that holds money, memories, or anything that matters. Most people have far more of these than they’d guess, check the connected-apps section of your email account and you’ll likely find services you forgot you ever signed up for.

Set legacy contacts on the big platforms. Apple, Google, Facebook, whichever you actually use. Five minutes each, done once, sitting there ready if it’s ever needed.

Turn on Emergency Access in your password manager, and actually tell the person you’ve designated. A feature that is not shared cannot help anyone.

Keep the inventory and instructions somewhere secure, but not inside your will. A sealed document with your estate paperwork, a note in a fireproof box, anywhere physically secure that isn’t a public court filing.

Talk to an estate attorney about the legal language, specifically making sure your will or trust explicitly grants your executor authority over digital assets. This is the one piece that requires a professional, not a blog post. RUFADAA only helps if the paperwork says so.

The bottom line

None of this is complicated once it’s actually done. The hard part is that almost nobody does it, not because it’s difficult, but because it’s uncomfortable to sit down and plan for a day you’d rather not think about. The couple who left a full list of accounts before a vacation, the kind of thing that struck one researcher as unusual, shouldn’t be unusual at all. It should be the baseline.


This pairs naturally with our guides on setting up your first password manager and removing your information from people-search sites. Together, they cover both sides of the same problem, protecting your accounts while you’re here, and making sure the people you trust aren’t locked out once you’re not.

Scroll to Top