Everything you own used to be findable in a drawer: bank statements, photo albums, the deed to the house. Today the statements are behind a login, the photos are in a cloud account, and the drawer is protected by 2FA. When someone dies without a plan, their family inherits a locked vault with no key - And unlike the bank of 1990, there's often no branch manager who can open it. Grief counselors and estate lawyers now describe digital lockout as a routine part of modern bereavement: memorial photos unreachable, bills silently autopaying from accounts nobody can see, a lifetime of email holding the answers to every "did Dad have a policy with…?" question.

The uncomfortable truth is that the security working for you today works against your family later. Strong encryption doesn't have a bereavement exception. This guide is about building a plan that bridges that gap - Without weakening your security while you're alive.

Why families usually can't just "get access"

Three walls stand between your heirs and your accounts. First, provider policy and law: privacy statutes and terms of service generally prohibit companies from handing over account credentials, even to next of kin with a death certificate. In the US, the widely adopted RUFADAA framework lets fiduciaries request access to digital assets, but providers can still limit what they release - Often metadata or memorialization rather than login access - And the process takes months of paperwork.

Second, encryption. Anything end-to-end encrypted - A password manager vault, encrypted backups, crypto wallets - Is mathematically inaccessible without the secret. A vault sealed with AES-256 encryption cannot be opened by the vendor, a court order, or a grieving spouse; that's the entire point of the design. Chainalysis has estimated that millions of Bitcoin are permanently stranded, a meaningful share through lost keys and death without succession - The most expensive digital-legacy failures ever recorded.

Third, 2FA on a dead person's phone. Even where a password is known, the second factor often lives on a device that gets wiped, locked, or returned to a carrier. A family that knows the email password but can't receive the verification code is still locked out - One more reason the 2FA backup codes you saved belong in your legacy plan too.

The official tools: legacy contacts and inactivity switches

The major platforms quietly solved a slice of this problem, and their tools take minutes to configure:

Platform Feature What your person gets Where to set it
Apple Legacy Contact iCloud data - Photos, notes, backups - Via access key + death certificate Settings → [your name] → Sign-In & Security
Google Inactive Account Manager Chosen data (Gmail, Photos, Drive) after 3–18 months of inactivity myaccount.google.com → Data & privacy
Facebook Legacy Contact / memorialization Manage memorialized profile; optional archive download Settings → Memorialization
Microsoft Next-of-kin process Limited; account closure and some data by request Support process, not a setting
Password managers Emergency access / family recovery Full vault after a waiting period, or shared-folder access Varies by product

Set up the Apple and Google switches this week if you do nothing else from this article: they cover photos and email - The two things families mourn losing most - And they require no lawyer, no cost, and no sharing of any password today.

The password manager: your single point of handover

The real unlock is structural. If every credential you own lives in one encrypted vault, your legacy problem collapses from "hundreds of accounts" to "one master credential and a second factor." That's the same consolidation argument made in our password manager guide, with an extra payoff at end of life.

Most serious managers offer a purpose-built handover feature. Emergency access (Bitwarden, 1Password's recovery options, Dashlane and others) lets you designate a trusted person who can request access; you get a waiting period - Say 7 or 30 days - To deny the request while alive, after which the vault opens to them. It's a dead man's switch with cryptographic teeth: no secret changes hands until it's needed. Alternatively, a family plan with shared collections gives a partner ongoing access to joint credentials - The healthy-household version of what our guide to sharing passwords safely recommends - While your personal vault stays personal.

If your credentials are scattered - Some in a browser, some memorized, some on paper - Consolidation is step zero. An organized Password Wallet that holds every login in one encrypted place is what turns your digital estate from an archaeology project into a handover.

Rule of thumb: your family should need to receive exactly two things - One master credential and the location of your instructions. If your plan requires more than that, simplify it; if it requires less, something is exposed today.

Building the plan: a one-afternoon checklist

  1. Inventory what matters. Email, financial accounts, photo storage, domains, crypto, subscriptions, social media. Flag the three or four that would genuinely hurt to lose.
  2. Consolidate into the vault. While you're entering accounts, fix the weak and reused passwords you find - Generate replacements with a proper password generator as you go.
  3. Configure platform legacy tools (Apple, Google, Facebook) and your manager's emergency access.
  4. Write a one-page instruction letter. Where the vault is, who the emergency contact is, where 2FA recovery codes live, what to cancel, what to preserve. No passwords in this letter - It's a map, not a key.
  5. Handle the exceptions. Crypto keys and other bearer secrets need offline succession: a sealed envelope in a home safe or safe-deposit box, or a metal seed backup, referenced (not contained) in your estate documents.
  6. Tell your person. A perfect plan nobody knows about is indistinguishable from no plan.
  7. Revisit yearly - Emergency contacts drift, accounts accumulate, platforms change their tools.
Adults with any digital estate plan in place
roughly 1 in 4

Surveys by estate-planning services consistently find that only a minority of adults have documented any plan for their digital accounts - A smaller share than have written a will at all.

What to keep out of the plan

Two anti-patterns undo everything. Passwords in the will: probate makes wills public record in most jurisdictions, so credentials written there are effectively published - And they'll be years stale by the time anyone reads them anyway. Reference the existence and location of your instructions instead. The shared spreadsheet of everything: an unencrypted file of all passwords, emailed to a sibling "just in case," is a standing breach waiting for either party's inbox to be compromised. If your household already runs shared credentials for streaming and utilities, do it through a manager's shared vault as described in our guide to password management for families - The same structure then doubles as your legacy plan.

Also skip the "just tell them to log in as me" approach for anything regulated. Accessing a deceased person's bank or brokerage account with their credentials - Even as an heir with good intentions - Can violate provider terms and, in some jurisdictions, computer-access law. Financial institutions have real death processes; use the vault to find the accounts, then go through the front door.

FAQ

Can my family get into my accounts with a death certificate?

Usually not into them - Most providers will close an account or release limited data to a verified executor, but handing over login access is rare and slow. Apple and Google honor access only through their pre-configured legacy tools; without those, families face support queues, notarized paperwork, and frequent refusal. The certificate opens processes, not passwords.

Legal, but a bad idea: wills filed for probate become public documents, and anything written in one should be treated as published. Estate attorneys instead recommend a separate, private letter of instruction - Referenced by the will but not part of it - Pointing to your password manager and emergency-access arrangements.

What happens to my password manager vault if I die without setting up emergency access?

With a zero-knowledge manager, the vault is cryptographically sealed: the company cannot decrypt it for your heirs no matter what documents they present. Some products offer a printed recovery kit that would work if your family finds it; otherwise the vault's contents are simply gone. That five-minute emergency-access setup is the difference.

What about my cryptocurrency?

Crypto is the hardest case: keys are bearer instruments, there's no support desk, and loss is permanent. Store seed phrases offline in a location your executor can reach (safe, safe-deposit box), reference that location in your estate instructions, and consider multi-signature or inheritance-specific custody services for large holdings. Never store a seed phrase in the will itself or in unencrypted cloud notes.

Should my legacy contact get access to everything?

Not necessarily - Access can be layered. Platform legacy tools let you choose which data categories they receive; password managers let you share specific collections rather than the whole vault; and you can keep private journals or correspondence in accounts you deliberately let die. A digital legacy plan is as much about deciding what shouldn't survive you as what should.