Passwords and a Will: What Not to Do
Why passwords should never be written in your will, and the safe way to leave access instructions for family.
In short
- A will becomes public after probate is granted, so anything written in it can be read by anyone
- Never write passwords, PINs or security answers directly into your will
- Keep a separate, private list of accounts and access instructions, updated regularly
- Your will can simply refer to the fact that such a list exists and where to find it
- Password managers with an emergency access or legacy contact feature are a practical modern option
- Check each provider's own policy, since many services have specific rules about accessing a deceased person's account
It might seem sensible to write your passwords straight into your will, so your executor has everything they need in one place. This is one of the more common and understandable mistakes people make when thinking about digital assets, and it is important to know why it is actually a bad idea before you do it.
A will becomes a public document once probate is granted, meaning anyone can obtain a copy from the Probate Registry for a small fee. Anything written in it, including passwords, becomes visible to whoever chooses to look, long after you intended it to matter. This guide explains the safe alternative: keeping access details separate from your will, updated regularly, and pointing your executor towards them without exposing the details themselves.
This is practical, common-sense guidance rather than a substitute for advice on more complex digital estates, such as cryptocurrency holdings or business accounts, which may need specialist input.
Why a will is the wrong place for passwords
Once someone dies and their executor applies for probate (or letters of administration if there is no will), the will itself becomes a matter of public record. Anyone at all can request a copy from the Probate Registry, usually for a small fee, and there is no vetting of who is asking or why.
This means any password, PIN, security question answer, or other sensitive access detail written directly into your will is effectively published to the world at exactly the point in time it might still be useful to a fraudster, since accounts are often left unattended and unmonitored for some time after a death. It is precisely the wrong place to keep this kind of information.
The safe alternative: a separate, private list
Instead, keep a separate document, updated regularly, listing your important digital accounts (email, banking, social media, subscriptions, cloud storage) and how to access them, or at least enough information for your executor to know an account exists and start the process of accessing or closing it. This document should be kept somewhere secure and private, not filed alongside your will.
Options include a physical document kept in a safe or with a trusted person, a secure digital file, or a dedicated password manager. Whichever method you choose, tell your executor, or a trusted family member, that it exists and roughly where to find it, without revealing the actual contents until it is needed.
How your will can point to the list without exposing it
Your will itself can simply note that you maintain a separate record of digital account information and instruct your executor to locate it through a nominated trusted person or storage method, without ever quoting a single password or security detail within the will's own text.
This keeps the will focused on what it is meant to do, direct legally binding instructions about your estate, while making sure your executor knows the practical information exists and where the trail begins.
Password managers and legacy contact features
Many password managers now offer an emergency access or legacy contact feature, allowing a nominated person to request access to your stored passwords after a waiting period, sometimes with additional verification. This can be a genuinely practical modern solution, since it keeps everything centrally organised and updates automatically as you change passwords, unlike a static written list that quickly goes out of date.
If you use this kind of feature, make sure your executor or nominated contact knows it exists and understands roughly how the request and waiting period process works, so there are no surprises when the time comes.
Each provider has its own rules
Even with the right password, access to a deceased person's account is not guaranteed, since many providers, including major email, social media and financial platforms, have their own terms of service and formal processes for dealing with a deceased user's account, sometimes requiring a death certificate or grant of probate rather than simply a password.
Our guides on digital assets and wills and online accounts after death cover how different types of platform typically handle this, and our digital legacy checklist sets out a practical list of accounts and information worth recording for your executor.
Questions people ask
Related guidance
- Digital Assets and Your WillHow to deal with digital assets sensibly in a will, and why passwords and account details belong in a separate secure record instead.
- Digital Legacy ChecklistA thorough checklist for organising your digital life, so the people you leave behind know what exists and where to find it.
- What Happens to Online Accounts When You Die?Why online accounts generally cannot be inherited as property, and how executors can still deal with them sensibly.
- Subscriptions After Death: Cancelling and Closing AccountsSubscriptions do not cancel themselves; executors need to track them down and close them.
More in Digital assets.
Make your will online
Answer a few simple questions and we prepare your will ready to sign. Single will £69, mirror wills £89. One-off payment, lifetime access.
Start free, pay only when you are ready. Prices in pounds.
This guidance covers the law of England and Wales and is general information, not legal advice about your circumstances. The rules in Scotland and Northern Ireland differ.