Digital estate

Digital legacy in Canada: what happens to your accounts and passwords

Most of a household's life now sits behind a login. Here's what an executor can actually reach, and what only you can prepare.

A generation ago an executor could reconstruct a life from the mail. Statements arrived, policies renewed on paper, photographs sat in albums. Today the statements are paperless, the policy is a PDF in an inbox, and twenty years of family photographs are in a cloud account protected by a password nobody else knows and a code sent to a phone nobody can unlock. This is the single largest practical change in estate administration in decades, and almost nobody prepares for it.

The uncomfortable legal position

Digital assets sit awkwardly in Canadian law. A useful distinction is between the asset and the account. Things with real economic value — cryptocurrency, a domain name, a monetized channel, files you own — are generally property and generally form part of the estate. The account itself is usually a licence governed by a contract with the platform, and that contract frequently says the account is non-transferable and terminates on death.

The Uniform Law Conference of Canada produced a Uniform Access to Digital Assets by Fiduciaries Act to give executors a clearer right of access, and provinces have adopted it unevenly. Federal and provincial privacy law, and criminal provisions on unauthorized use of a computer, sit over top. The practical result is that an executor's authority over an online account is far less settled than their authority over a bank account, and it varies by where you live and which company you are dealing with. Ask a lawyer in your province about your specific situation.

What the major platforms actually allow

Platform policies change; confirm the current process with each company. In broad strokes, there are three patterns.

Three patterns for account handling after death
PatternHow it worksWhat families should know
Set it up in advanceSome services let you nominate someone now — a legacy or inactive-account contact who receives specified data or control after a period of inactivity or a verified death.By far the best outcome, and it takes minutes. It only works if configured while you are alive. This is the single highest-value hour in this entire subject.
Apply after the factOthers have a bereavement or deceased-user process: submit a death certificate and proof you are the estate representative. The outcome is usually memorialization, closure, or limited data release — rarely full access.Slow, document-heavy, and the answer is often narrower than the family expects. Content is frequently withheld even when the account is closed.
No access, everSome accounts simply terminate, and the provider will not release contents to anyone. Self-custodied cryptocurrency is the extreme case: without the seed phrase the asset is gone permanently, with no appeal to anybody.The only protection is having recorded what is needed beforehand, somewhere secure that a named person can eventually reach.

The inventory to make

  1. 1The primary email account. Start here. It is the recovery route for nearly everything else, and losing it usually means losing the rest.
  2. 2Devices and how they unlock — phone, laptop, tablet — including the PIN or passcode, because two-factor codes arrive on them.
  3. 3Cloud storage and photographs, and whether anything is only on one device.
  4. 4Financial and government logins: banking, investments, CRA My Account, My Service Canada Account.
  5. 5Subscriptions and recurring charges, which continue billing an estate for years unless cancelled.
  6. 6Anything with value: domains, a small business, a monetized account, loyalty points, cryptocurrency and where its keys are.
  7. 7Social accounts, and what you would want done with each — memorialized, closed, or left alone.
  8. 8Whether a password manager exists, and whether its emergency access is configured for the right person.

How to record credentials without creating a new risk

The instinct is to write the passwords in a document. Please do not. A spreadsheet in a shared drive, a note in an inbox, or a printed list in a drawer is a standing security problem for as long as you live, and every one of those has been the cause of a real loss.

  • Use a password manager for the credentials themselves, and configure its emergency access feature for the person who would need it.
  • Or store them encrypted in a service built for it, where they are unreadable to anyone until access is deliberately released.
  • Record the map separately from the keys: what accounts exist and who should handle them is far less sensitive than the passwords, and far more often the missing piece.
  • Never email credentials, never put them in a will — a probated will can become a public document — and never leave them in plain text anywhere.

In Life Box, credentials are encrypted at rest and treated as a separate, more tightly controlled class of information than documents. Nothing is visible to anyone else while you are alive, and release requires a verified claim reviewed by a person.

Say what you want to happen

The technical access question is only half of it. Families argue about digital remains more than they expect to: whether an account should be memorialized or deleted, whether messages should be read, who gets the photographs, whether a business account continues. Writing down what you want takes a paragraph and removes an argument at a moment when nobody has the capacity for one.

Speak to a lawyer or notary in your province about how to reference digital assets in your estate documents. Keep the actual credentials out of the will itself.

Record it once, securely

Life Box keeps your accounts, encrypted credentials and instructions together, and releases them only to the person you name, after their claim is verified.

Related: what a digital Life Box is, the Canadian executor checklist and the estate planning checklist for Canada.