What happens to your online accounts after you die? A plan that does not share passwords
Photos, documents, domains and subscriptions do not organise themselves. A simple digital-legacy plan can help loved ones without leaving a master password on paper.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 4 September 2026
- READING TIME
- 8 min read
- TOPIC
- Human Security
With a family photo album, everyone knows where the pictures are. A phone and cloud account are less obvious. Photographs may belong to one login, bills may arrive at an email address nobody knows, and a paid domain or subscription may disappear with its owner’s payment card.
It is not an easy conversation, but a digital plan does not need to be a technical manual or a key to somebody’s entire life. It should answer three questions: what exists, what matters and how a trusted person begins the correct process.
Do not begin with a password on paper
Leaving one password for email and banking feels simple, but it creates new risks. The note may be found too early, the password may change, and access to an account is not the same as the legal right to every piece of data inside it. Sharing a password also bypasses the processes providers have created for loved ones.
A better plan separates information from access. An inventory tells the family which accounts, devices and services exist. Official provider features decide who may receive data and under which conditions. Legal documents and advice from the appropriate professional cover ownership, money and decisions that go beyond online accounts.
Two examples of official tools
Apple lets a user select one or more people as a Legacy Contact. After the account owner’s death, the chosen person can request access to certain data using the shared access key and a death certificate. The scope may include photos, messages, notes, files and device backups, but excludes items such as passwords, passkeys and payment details stored in iCloud Keychain.
Google provides Inactive Account Manager. A user selects an inactivity period, the people to notify and the types of data to share. Up to ten people can be selected, with different data assigned to different contacts. The plan can be edited or disabled later.
Neither tool is a universal “digital will”. Each applies to particular services and data, and requirements may vary by country. They do not replace a will, company agreement or instructions for a bank account. They do demonstrate an important principle: loved ones can be prepared without receiving the owner’s current password.
A one-page inventory
Do not put passwords in it. List categories and directions instead:
- the main email address and mobile provider;
- where family photos and documents are stored;
- paid domains, hosting, cloud services and important subscriptions;
- social profiles that should be closed or preserved;
- work devices and an employer contact;
- the password manager—only the service name and its official emergency process;
- the location of a will, agreements and access keys created by official legacy features.
For each item, add the intention: preserve photographs, close a profile, transfer management of a domain or end a payment. A service list without decisions transfers the hardest choices to the family.
Choose a person—and speak to them
Do not nominate somebody without a conversation. Explain what they may be asked to do, where the key or documents are kept and whom they should consult. One person does not need to handle everything. A relative may look after family memories while a business colleague handles company matters.
Discuss privacy boundaries as well. Access to photographs does not necessarily create a need to read every private message. Apple notes that each nominated Legacy Contact can independently make decisions about the account data, including deleting it permanently. The choice therefore requires genuine trust, not merely a family connection.
A business needs a separate plan
An owner’s personal account should not be the only administrator of a company domain, advertising account, cloud service or social profile. Business access should belong to the organisation, have at least two responsible people and include a documented ownership-change process.
This is not only a plan for death. The same arrangement helps during sudden illness, an accident or prolonged absence. It does not require access to an employee’s private mailbox; it requires personal and company accounts to be separated properly.
Once a year: a ten-minute review
Check whether the chosen person is still appropriate, their phone number and email are current, the access key exists and the inventory does not contain abandoned services. Make a current backup of irreplaceable family material. Google says it reserves the right to delete an account and its data after at least two years of inactivity, so leaving no instructions carries its own risk.
Source facts and Breachroad’s conclusion
Apple documents the Legacy Contact data scope, access key and death-certificate requirement, and the exclusions for passwords and payment information. Google documents the inactivity period, contact and data choices, and its inactive-account policy. The one-page inventory, separation of roles and annual review are Breachroad recommendations.
A digital plan is not about handing everything to one person. It removes guesswork at a difficult time. Our guides to password managers and the 3-2-1 backup approach are useful next steps. In an organisation, cybersecurity training for employees can begin a wider conversation about safe cover arrangements, company-owned accounts and responsibility for access.


