1
1
When a cherished individual departs, a myriad of profound questions arise, particularly concerning their digital existence. Who bears the responsibility of downloading crucial files from their cloud storage accounts? Who will monitor their email inbox for vital communications? Who ultimately decides the fate of the countless photos and videos residing on their social media profiles? And what if the weight of these complex and often emotionally charged tasks falls squarely upon your shoulders?
The stark reality is that death is an inevitable part of life, yet a significant majority of individuals have not adequately planned for what should happen to their digital assets once they are gone. Even when a person takes the proactive step of creating a plan, the surviving loved ones may still encounter considerable limitations in their ability to execute those wishes. The sheer volume of digital assets accumulated over a lifetime can transform the process of tying up loose ends into an overwhelming nightmare for the living. Nevertheless, armed with greater knowledge and a clearer understanding of the landscape, you can better prepare for your own digital estate, thereby easing the burden on those you leave behind, and simplifying the management of someone else’s.
Taking Comprehensive Inventory
The most significant factor determining the complexity and workload involved in managing the online accounts and digital assets of someone who has become incapacitated or deceased is whether they engaged in any form of estate planning. Without a documented record of a person’s digital assets and explicit instructions regarding their disposition, it becomes virtually impossible for anyone to discern their wishes or even identify all the accounts that exist. This isn’t merely a matter of memorializing a Facebook profile or downloading sentimental photographs from iCloud. Digital assets frequently possess substantial monetary value, alongside their sentimental worth. Consider, for instance, a person whose social media accounts generate ongoing dividends or revenue through content creation, sponsorships, or advertising. How will a designated beneficiary collect these future proceeds, and should the account be maintained actively or wound down?
The burgeoning world of cryptocurrency presents another unique challenge. If a person’s digital currency is stored in a private wallet and no one possesses the corresponding private key, that money is effectively lost forever, an irretrievable sum in the vast digital expanse. However, the scenario changes if a third-party custodian, such as popular platforms like Coinbase or PayPal, holds the cryptocurrency. At present, Bitcoin and other cryptocurrencies are universally considered "digital assets" and, as such, demand careful consideration and specific provisions when undertaking any form of estate planning. This underscores the need for meticulous documentation that extends beyond traditional assets.
Navigating the Complexities of Law
In the United States, the realm of digital inheritance is primarily governed by state law, mirroring the framework for traditional probate and estate matters. This legal landscape was significantly shaped by Benjamin Orzeske, chief counsel at the Uniform Law Commission. Orzeske and his organization were instrumental in developing a critical piece of state legislation known as the Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA). This comprehensive act has been widely adopted, enacted in 48 states, Washington, D.C., and the U.S. Virgin Islands. As of this writing, Massachusetts has adopted RUFADAA but has yet to officially enact it, while Louisiana opted to forge its own path with a similar, albeit distinct, state law.
"At the heart of RUFADAA is this recognition that digital property is in some ways different from traditional, tangible property," Orzeske explains, highlighting the nuanced distinction that necessitated new legal frameworks. He offers a compelling analogy comparing physical mail to email. When an individual passes away, their physical mail is typically forwarded to a designated fiduciary, who then receives incoming communications, bills, and payments. If they receive a bill for a magazine subscription, for example, they possess the necessary information to cancel it. Receiving physical mail effectively grants the fiduciary appropriate information and access to manage the deceased’s accounts and estate moving forward. Email, however, operates on a fundamentally different principle. The fiduciary doesn’t merely receive new incoming messages; they could potentially gain access to a searchable history of all past communications, a trove of personal information that the deceased person almost certainly expected to remain private.
The real point of legal conflict, according to Orzeske, lies in the Stored Communications Act, a federal law that dictates that companies handling our online assets cannot release their contents without explicit permission from the original account holder. RUFADAA, therefore, endeavors to strike a delicate balance, granting survivors certain necessary rights while steadfastly retaining the original asset holder’s inherent right to privacy.
Under the provisions of RUFADAA, a named trusted person is legally empowered to close accounts. However, obtaining the actual "contents"—meaning the bodies of emails, private messages, videos, photos, attachments, and other substantive data—is only permissible if the decedent specifically "grants the authority to the personal representative fiduciary," clarifies Catherine Hodder, a senior attorney editor at FindLaw, an informational website dedicated to demystifying legal issues for a general audience. The crucial method for bestowing this permission upon a trusted individual is to document it in writing, ideally within a legally binding will or a similar estate planning instrument. It is imperative to clearly name the individual and precisely delineate what digital assets and access you wish them to have. However, Hodder issues a critical warning: never list usernames or passwords within a will, as "the will is a public document" and such sensitive information would become openly accessible. If the fiduciary is not explicitly granted permission to receive the contents of a digital asset, they may still be able to obtain a "catalog" of metadata, as Orzeske points out. Using email as an example once more, this metadata could include all the times and dates that emails were sent and received, potentially information about the sender or recipient, but crucially, it would still exclude the private body of the emails themselves.
The Shortcomings of Built-In Tools
Many of the prominent technology companies that serve as custodians of our digital assets, referred to as "data custodians" in legal parlance, have developed their own built-in tools designed to allow users to assign a trusted person to access their accounts upon their death or incapacitation. Google, for instance, introduced its Inactive Account Manager as early as 2013, providing a mechanism for users to dictate the fate of their data. Apple and Meta frequently employ the term "legacy contact" in some of their platforms, though for Instagram, users must specifically seek out "memorialization" settings. While enabling these platform-specific features might initially appear to be the most straightforward method for transferring access to your digital accounts, in practical application, these tools often leave much to be desired in terms of comprehensive functionality and ease of use.
Consider a practical example: if you wish to grant someone permission to download your Instagram content after your passing, that designated person must also maintain an active Instagram account. More importantly, someone must still take the initiative to contact Instagram and formally declare that the account holder has died in the first place. This raises a fundamental question: how exactly does one initiate that process reliably across diverse platforms? Mike Kiser, a co-chair of the Death in the Digital Estate Community Group at the OpenID Foundation, succinctly points out that "there is no defined way to tell a provider that someone has died or lost capacity" across the entire digital ecosystem. His group is actively working towards the long-term objective of developing standardized protocols and guidance for users to effectively manage their digital estates, addressing this critical gap.
Beyond these systemic issues, numerous other hurdles and unforeseen problems can arise on a case-by-case basis. What happens, for instance, if you never provided your real name or accurate date of birth to any of these companies? How can your designated trusted contact definitively prove that an online account was indeed held by you, particularly when discrepancies exist between official documents and platform registration details? These scenarios highlight the limitations of relying solely on platform-specific tools without a broader, legally recognized framework.
Even DIY Solutions Can End in Failure
For years, tech-savvy individuals have attempted to devise their own do-it-yourself solutions for managing their digital estates. Some opt to leave a physical, printed document in a secure location, meticulously listing all their accounts and the corresponding credentials required to access them. Others leverage the legacy tools integrated into modern password managers, which are generally considered one of the more secure options for sharing login information. However, even the most thoughtfully constructed DIY solutions can ultimately fall short when put to the test.
Kiser recounts a revealing anecdote about one of his colleagues who diligently created a comprehensive DIY system for passing on his digital assets. When his colleague decided to test the system from the perspective of his designated trusted person, "He failed in step one," Kiser notes, illustrating the unforeseen complexities that can arise. In my own research for this story, I experimented with my personal digital estate and quickly realized that my two-factor authentication (2FA) app is protected by biometrics, typically a fingerprint or facial scan. This crucial security layer meant that even if my trusted person possessed all my login credentials via a password manager, they would be unable to progress beyond the initial login stage without my physical presence or biometric authentication.
There is also the often-overlooked, sticky issue of potentially violating a data custodian’s terms of service (ToS). Logging into someone else’s account, even with their consent, often constitutes a breach of these agreements. While it remains a separate question whether a company would ever actively press charges in such a scenario, it is not difficult to imagine instances where they might, particularly when high-profile celebrities or public figures are involved, or in cases of suspected malicious activity. A more probable and common scenario involves disagreements among loved ones regarding how to manage a decedent’s digital assets and accounts. If the deceased’s wishes are clearly articulated and legally documented within a will, family in-fighting over digital property might still occur, but the designated fiduciary at least possesses the legal protection and clear directive to act according to the decedent’s intentions, providing a solid foundation for their decisions. Another practical, albeit partial, solution is to create a comprehensive local backup of all your data that someone can easily access. This involves exporting and transferring everything to an unencrypted USB drive or external hard drive. While this offers a convenient way to preserve data, it requires regular, diligent exports and backups of everything you wish to include, and it does not address the crucial problem of terminating any online accounts you want closed after your passing.
What’s Best for Now?
Despite the array of existing options, every current solution for managing digital assets after death remains imperfect, fraught with potential pitfalls and limitations. Nevertheless, the most robust and legally sound approach appears to be naming a fiduciary or a trusted person explicitly in your last will and testament. Subsequently, you should meticulously document your specific wishes in that will or a similar legally binding document, striving for as much detail as possible. This should include a comprehensive list of the digital accounts and assets you possess, the name(s) of the person or people who should receive them, and precise instructions detailing what actions they should undertake.
If you choose this route, it is absolutely paramount to keep your list of passwords and login credentials entirely separate from your will. These sensitive details should only be shared directly and securely with the specific individuals who will require them, using methods far more secure than a public document. Furthermore, it is generally advisable not to enable those built-in legacy features offered by your online accounts. According to Kiser, the platform’s own online controls and terms of service typically take precedence over external instructions, and thus could potentially override or complicate the wishes you have carefully laid out in your will.
Most important of all, the dynamic nature of our digital lives necessitates that you update your final instructions and estate planning documents regularly. This should occur whenever you make any significant changes to your online accounts, acquire new digital assets, or move existing assets around, ensuring your digital estate plan remains current and reflective of your true intentions.