The Big Hole in Estate Plans: Digital Assets

The Big Hole in Estate Plans: Digital Assets

Most clients and advisors are acutely aware of the value of a thoughtfully designed estate plan that provides for the eventual disposition of a client’s tangible and financial assets. Despite this, even the most carefully constructed estate plan often overlooks a client’s digital assets.

In today’s society, almost all clients are active online, and may have substantial digital assets with both sentimental and monetary value even if they do not realize that this is the case. Without a clear plan that specifies the client’s wishes, however, both state and federal laws can create roadblocks to accessing digital assets—making it critical that the client include digital assets in any comprehensive estate plan in order to ensure an orderly post-mortem disposition that carries out the client’s wishes.

Uniform Laws Governing Digital Assets

The concept of estate planning for digital assets actually covers an extremely broad range of online assets, ranging from email accounts and social media to PayPal, domain names, intellectual property stored on a computer and virtual currency. While some of these accounts are likely to have only sentimental value, domain names, blogs with advertising and business contact lists contained in email accounts can have monetary value, as well.

Without a clear estate plan contained in legal documents, data privacy laws can prevent the online service provider from allowing the client’s executor or family members to access his or her online accounts. The Uniform Fiduciary Access to Digital Assets Act, which has been passed in most states, provides that an owner of digital assets can specify who will be able to access and dispose of any digital assets after death.

Absent proper planning, the online provider’s terms of service agreement (TOSA) will often control what happens to the account after death. In some cases, this TOSA can even override the client’s specifications that are contained in a will or other document, especially in cases where the service provider provides specifications as to how the account owner can make his or her post-mortem wishes known.

For example, Google provides an “inactive account manager” function that allows the account owner to specify what should happen to the account after it has remained inactive for a period of time. The account owner can list beneficiaries who will be notified that the account will be closed before it is deleted, giving beneficiaries time to download any content contained in the account.

It is important to remember that the instructions the client leaves in his or her online service provider’s tools will trump instructions left in the will, so it is important to include this document among those that should be regularly considered and updated.

An Action Plan for Digital Estate Planning

After a client determines who should be allowed access to his or her digital assets after death, it is important to takes steps to ensure that the heir is able to access the relevant data. Importantly, the client’s will, trust documents and other legal documents should specify a digital fiduciary or executor who will be able to access any given digital asset after death, and should also provide that individual with the ability to reset or recover the client’s passwords.

In order for such a plan to be effective, the client should be advised to make a comprehensive list of his or her digital assets during life, which should also include instructions as to how the appointed person can access those assets after death. To facilitate easy access, the client should list usernames, passwords and the security questions associated with the account password. This information should be stored securely, but should not be included in the client’s actual will, which can be accessed by the public after death.

Depending upon the type of digital assets involved, clients may find a virtual asset instruction letter valuable in their digital estate planning. This letter sets forth all relevant information as to digital accounts and assets to allow the digital fiduciary access (or instructions that certain accounts should be deleted).

Clients should also be advised to regularly back up their digital assets on the cloud or another device, both to protect those assets from a device malfunction but also to allow easier post-mortem access to a digital fiduciary.


A client’s digital estate plan will vary in complexity depending upon the type of digital assets involved. Many clients may be unaware that their digital assets hold monetary value, so it is important that the advisor discuss disposition of digital assets with all clients, even those who do not initially foresee the need for digital estate planning.

What happens to your online accounts when you die?

What happens to your online accounts when you die?

BSides Manchester What happens to the numerous user logins you’ve accumulated after you die or become too infirm to manipulate a keyboard?

Some people have a plan, the digital equivalent of living will, or have chosen “family” option in a password management package such as LastPass or have entrusted a book of passwords to a family member.

But the consequences of doing nothing are not as neutral as some might expect and were spelled out during an informative presentation by Chris Boyd of Malwarebyes at BSides in Manchester on Thursday. The presentation, cheerily titled “The digital entropy of death”, covered what could happen to your carefully curated online presence after you log off.

Chris Boyd at BSides - Pic by John Leyden
The dormant accounts of the deceased can be abused, warns Malwarebytes’ Chris Boyd. Pic: John Leyden

Miscreants are already targeting obviously abandoned profiles. Boyd explained that in some cases it’s easier for fraudsters to gain hold of these accounts than the account-holders’ relatives, because crooks know the systems better and controls – although present – are often deeply embedded on the sites such as Facebook, Twitter et al.

Alongside regular postings asking for help on Facebook due to compromise of dead people’s logins (examples here and here) there’s also the problem of “cloning”.

“Facebook users have reported receiving friend requests from accounts associated with dead friends and family members,” The Independent reports. “Such requests appear to be the result of cloning or hacking scams that see criminals try [to] add people on the site, and then use that friendship as a way of stealing money from them or running other cons.”

Social media accounts are, of course, just the tip of the iceberg. Most people these days run 100+ accounts, as figures from password management software apps show. These figures are only increasing over time. Some sites are managing the inevitability of their users shuffling off this mortal coil with features designed to deactivate accounts after months of inactivity or other features, Boyd explained in a recent blog post:

Many sites now offer a way for relatives and executors to memorialise, or just delete, an account. In other circumstances, services would rather you ‘self-manage’ and plan ahead for your own demise (cheerful!) by setting a ticking timer. If the account is inactive for the specified length of time, then into the great digital ether it goes.

While a lot of services don’t openly advertise what to do in the event of a death on their website, they will give advice should you contact them, whether social network, email service, or web host. When there’s no option available, though, people will forge their own path and take care of their so-called ‘digital estate planning’ themselves.

Users would be ill-advised to leave everything to their next of kin. “Do some pre-handover diligence, and take some time to ensure everything is locked down tight,” Boyd explained. “If there’s anything hugely important you need them to know, tell them in advance.”

People may have bought digital purchases tied to certain platforms. Games on Steam, or music on iTunes or Spotify.

“Legally, when you go, so do your files (in as much as anything you can’t download and keep locally is gone forever),” Boyd explained. “That’s because you’re buying into a licence to use a thing, as opposed to buying the thing itself.”

Here’s a video of his presentation, if you want to see more…

There’s nothing stopping someone from passing on a login to a family member so they can continue to make use of all the purchased content, at least for now. Boyd predicted that at some point, all of our digital accounts tied to financial purchases will have some sort of average human lifespan timer attached to them.

Millennials mark the first generation not to know life before an always-on, everywhere internet, which will become the norm from now on. “Younger generations absolutely will demand reforms to the way we think about digital content, ownership, and inheritance,” Boyd concluded. ®

As well as the inevitable rise and fall of social media site (e.g. MySpace), and web 2.0 services there is also the issue of link rot, the phenomenon of more and more URLs not working over time. This issue is covered by Boyd in another recent blog post here.

Is It Safe To Share The Password To Your Bank Account With An App?

Digital Death Clean: How To Wipe Your Ex Out Of Your Life

I have a bit of a slash-and-burn preference when it comes to managing recent exes; as in, I try to push them far away from my eyes, ears, screens, and general orbit. Breakup etiquette varies by the individual, of course, but I’m a big believer in ceasing Facebook friendship (or, at the very least, unfollowing). It’s weird to feel nostalgic for the time when that was enough to banish an ex from your pixelated portals—now, the measure is only one facet in a series of controlled burn tactics.

Even after unfriending, then unfollowing on Instagram and Twitter, there’s still work to be done to scrub all those timelines of your ex. Enter: the Digital Death Clean. It sounds metal because it is—and it works. Let’s look at how to rid your internet and phone of crummy former flings once and for all.

Yes, in theory, simply ending a Facebook friendship should mean you never have to see said unfriended person on your feed ever again. And yet! It’s not exhaustive; namely, your search history never forgets. Until you tell it to. Clear your Facebook search history by clicking into the search bar. From there, hit edit, and clear searches. Gone! This is a good option if you don’t want to be so extreme as to full-on block them from ever viewing your profile (and you theirs).

Again, blocking is always an option, but the mute button is a little less visceral. Fam, this function has been around since 2014. Head to their account (which you perhaps have already unfollowed), click the three dots next to the follow button, and select mute. From there, you shouldn’t see any interactions they have had with your mutuals. Tight.

You got options here: As with Twitter, you can mute their account (toggle to their account, hit the three dots in the top right corner, mash mute). Or, as with Facebook, you can reset your search history back to a clean slate—which, TBH, doesn’t seem like a bad idea every now and then regardless of recent heartbreak. To do the latter: Go to your profile, hit the gear icon on an iPhone or the three dots on an Android (both in the top right corner, aka “settings”), tap search history, and then clear.

In case you have a momentary lapse and want to “check in” on their account, know that this will intro their handle back into your search history. Throw some proverbial Clorox on any possibility of that by permanently hiding their handle. Visit the search page, hit the search bar, tap top or people, tap and hold the account(s) you want to avoid, and then mash “hide.”

And, assuming you want to avoid any future orbiting instances, block them from viewing your Insta stories like so: Pull up any of your existing stories, hit the “more” option in the bottom right corner, select story settings from the pop-up menu, then “hide story from” and select their account. That golden content is a privilege, not a right. (Note: If they don’t follow you, this option won’t work. Perhaps consider going private for a spell or something? Remember that public profiles—including stories—are public to, uh, the public.)

Knock that baby outta your friends list first, then—you might not like this one—change your story setting to friends-only. Unfortunately, if you keep that and your contact settings open to everyone, that means even non-friends can pay you a virtual visit—including someone who possibly did you pretty dirty in the past (I mean your ex[es]).

It should be illegal that unfriending someone on Facebook doesn’t automatically abolish them from your Venmo as well. Alas. Visit their profile, hit the three dots in the top right corner (noticing a trend now, eh?), select block. You have absolutely no need to keep up with their paying a roommate for electricity each month—let alone any current or future transactions with A Hot Person. Life is hard enough; don’t add in the extra energy suck of paranoia regarding who “Katie N.” is and what the hell all those random emojis mean.

Is your old bae jamming hot, new, very clear sex bangers now? Ones you don’t recall them ever enjoying before? You’ll feel crummy. Is old bae jamming old songs that y’all used to call “ours”? You’ll feel crummy then, too. There is no winning. Unfortunately, Spotify does not offer blocking functionality, so you will just have to unfollow (go to their profile, hit the button that says “following” till it confirms by reading “follow”) until the app remedies that oversight—which, hopefully, Spotify will be pressured to do soon. In some troubling stalking scenarios, some users have reported people monitoring their song listening to further harass them. At least Spotify ended its inbox feature?

iPhone contact
Something sorta fun is that Apple has made it a headache to swiftly and fully delete a contact from its memory. I have anecdotal evidence that just because you delete a contact does not mean it is actually gone; as such, sometimes as little as three letters (combined with three margs) can resurrect a phone number from the dead. No, thank you! Also, heaven forbid you date two Chrises in a row (but really). Click through recent calls or text messages till you land on their number. Tap their number and scroll through options like call, FaceTime, etc., until you land on “remove from recents.” SMASH IT. (Bonus: From here, you can also permanently remove their birthday from your calendars.)

Android user? No worries—look for info on how to do the same on your device here.

iMessage predictive text
Talk about new beginnings. Kinda sucks how radical your only option is here—but not as much as every time you start to type “whatever,” and the word quickly rearranges to form a loathsome ex’s last name. You need to reset your keyboard dictionary, bb. To do this: Go into your iPhone settings, hit general, then reset, and—finally—”reset keyboard dictionary.” Most phones prompt your passcode before allowing such a nuclear blast. Yes, you will have to manually re-enter the “shrug” to “¯\_(ツ)_/¯” but, on the bright side, you are now free to “whatever” your brains out without reliving the time dude left skid marks on your sheets yet refused to accept blame.

And that, friend, is true freedom.



How to Handle Digital Assets of the Deceased

Criminals have perfected the art of taking over dead peoples’ online accounts

When you die, your relatives will be sad and (depending on the circumstances of your death) possibly left scrambling to make arrangements for your remains, effects, and estate.

The digital afterlife of your online accounts has gotten less fraught since I wrote about it six years ago, with digital platforms and login managers adding in tools and policies to preserve or manage online accounts after your death.

But chances are that when your loved ones are trying to figure out what to do with you and all you leave behind, they’re not going to be skilled operators of these digital memorial systems. They will be slow to adopt them and will struggle to use them.

But criminals have had plenty of dead people to practice on, and have become virtuoso hijackers of the internet of the dead. They’ve also figured out that duplicating the accounts of dead people is an excellent way to make plausible seeming fakes that are likely to last longer than hijacked identities of the living.

Chris Boyd’s Manchester B-Sides presentation on The Digital Entropy of Death builds on his recent written work on the subject. It’s an eye-opening look into the possible security risks of digital death, along with some practical advice for “taking ownership of your digital accounts before somebody else does.”

The manner in which they hand over the password manager account is incredibly important, too. Is it a physical thing? A login written on paper? Something digital? Is it secure? Maybe it’s a hard drive. Is it encrypted? How will it be updated with new logins/ changes to passwords? Does the relative live nearby if it’s physical? If they live far away, would something purely online make more sense?

These are all important questions that need to be thrashed out long before handing account information over, and it’s probably a bit much to put the onus on the recipient to start bolting security gates you may have left wide open. Do some pre-handover diligence, and make some time to ensure everything is locked down tight. If there’s anything hugely important you need them to know, tell them in advance—don’t hand over a hard drive and ask them why they didn’t make a backup two months after the thing has fallen into the bathtub.



Benefits of a Digital Legacy

Benefits of a Digital Legacy

What is a Digital Legacy? A Digital Legacy is your virtual, secure, safe deposit box. It contains your key information, wishes and life documents in a centralized online portal.

This is your tool for managing all of your life documents and leaving your legacy organized for your heirs.

Benefits of a Digital Legacy

  • At the click of a mouse, you have a customized, easy solution that will help you and your family manage personal data.
  • Eliminate time and worry locating important information.
  • Prepare caretakers for an emergency with important contact information and personal family data.
  • Store immediate as well as extended family member’s personal information.
  • Upload and store images of key documents, i.e. Driver’s License, Social Security Card, Birth Certificate, Will, Trust, etc. to reduce time finalizing estate paperwork and related costs with easy retrieval when you need them.
  • Designate contacts & meeting locations

Find out more >>


Go Paperless with Your Digital Legacy! A Digital Legacy is your virtual, secure, safe deposit box. It contains your key information, wishes and life documents in a centralized online portal. This is your tool for managing all your life documents, leaving your legacy organized for your heirs. I’m offering a 10% discount for any bookings confirmed by August 30, 2018. Contact me via phone at 925-206-0103 or by email to schedule your inventory today.