They should follow each platform’s process, because the options differ. Some services allow memorialisation, others require proof of authority and proof of death before removal, and some only permit deactivation through formal forms. The safest approach is to prepare instructions in advance and store them with the estate plan so account handling is orderly and legally supportable.
Why families need a documented plan before a death occurs
Post-death account handling is not just an administrative task. Social media profiles, cloud storage, and email accounts can contain personal data, financial records, photos, ongoing subscriptions, and access to other services. If the family has no documented instructions, platform decisions can become slower, inconsistent, or impossible to reverse. The practical issue is less about technology than about lawful authority, verification, and preserving the deceased person’s intent. In practice, many families discover the platform rules only after the account is already inaccessible.
For that reason, account-handling instructions should sit alongside the estate plan, not be improvised during bereavement. Families may need to show proof of death, proof of relationship, or proof of executor authority, and those requirements vary by service. The most useful external reference here is the general identity-verification discipline in NIST SP 800-63 Digital Identity Guidelines, because it illustrates why services insist on evidence before granting account action. That verification barrier is deliberate, but it means preparation matters.
How platform procedures shape what families can actually do
After a death, families usually face one of four outcomes: memorialisation, restricted access for an authorised representative, account deletion, or continued preservation for records and sentimental value. The exact path depends on the service provider and on the documents the family can produce. Some platforms will only respond to a formal request; others will accept a death certificate plus proof of authority from an executor, administrator, or next of kin. Cloud services can be even more sensitive because they may hold shared photos, documents, or business-related files that are not obviously “personal” until someone has to sort ownership and access.
The operational challenge is that access rights do not automatically transfer on death. If a family member knows the password but lacks authority, the provider may still refuse account changes. If a family member has authority but no clear inventory of accounts, important data can be lost before the request is even made. That is why families should keep an up-to-date list of accounts, note whether two-factor authentication is enabled, and record where recovery methods are stored. Where cloud services are used for shared family material, it is wise to identify which accounts are personal, which are joint, and which contain assets that must be preserved before deletion.
For context on identity assurance and document handling, NIST’s digital identity guidance is useful, and for broader resilience thinking around access-controlled services, the ENISA Threat Landscape helps readers understand how trust in accounts and credentials affects downstream control. The guidance becomes less reliable when the deceased person used many overlapping recovery paths, shared passwords informally, or left no record of the provider-specific process.
- Identify every major account category: social, cloud, email, finance, and subscription services.
- Record who is legally authorised to request action on each account.
- Keep copies of the death certificate, executor papers, and any platform-specific forms.
- Separate preservation needs from deletion needs before contacting providers.
Common edge cases families often overlook
Tighter account control often increases friction, requiring families to balance privacy, legal authority, and speed against the wish to preserve memories or recover files. The hardest cases usually involve shared cloud storage, business-linked social profiles, or accounts that were used for password recovery across many other services.
One common edge case is the account that looks personal but is actually operationally important, such as a cloud drive used to store family documents or a social account that administers a group or page. Another is the account that cannot be accessed because the deceased relied on a device-bound second factor or a recovery email that no one can reach. In those cases, families should expect the provider’s formal process to matter more than informal access knowledge. There is also a consensus gap across platforms: some support memorialisation, some support limited data release, and some prioritise removal. Families should not assume a single universal rule exists.
Where there is disagreement among relatives, the safest legal path is to follow the estate representative’s authority and the provider’s documented process, rather than relying on whoever has a remembered password. That approach can feel slower, but it reduces the chance of unauthorised deletion, unlawful access, or later disputes about what should have been preserved. The guidance breaks down when the estate has no clear representative or when the deceased left no account inventory at all.
Risk and Threat Considerations
Post-death account handling creates privacy, confidentiality, and fraud risk because the accounts may still contain personal messages, stored credentials, financial links, or recovery paths to other services. It also creates an impersonation risk if a deceased person’s profile remains active and unmanaged, since stale accounts can be exploited for deceptive messaging or social engineering.
Failure mechanism: The risk materialises when access authority is unclear, recovery methods remain live, or a platform accepts actions from someone who can prove possession of a device but not legal authority. Attackers or opportunistic actors can exploit abandoned accounts, reused credentials, or weak recovery controls to access data, request resets, or impersonate the deceased.
Impact: Sensitive files can be exposed, family privacy can be breached, and other connected services can be put at risk if the account was a recovery channel. In some cases, the consequence is not just data loss but prolonged control ambiguity that prevents timely deletion, preservation, or lawful transfer of digital assets.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | IAL — Identity Assurance Level | Platforms require identity evidence before post-death account changes. |
| Recommendation — Match executor requests to the provider's identity-evidence requirements before submitting account actions. | ||
| NIST CSF 2.0 | PR.AA-1 — Identities and Credentials Managed | Estate handling depends on controlled accounts, recovery paths, and credential lifecycle. |
| PR.DS-5 — Data Protection Measures | Post-death handling often requires preserving or deleting personal data according to intent. | |
| Recommendation — Inventory and govern deceased-account credentials and recovery methods before requesting provider action. Preserve or delete stored data according to documented instructions and legal authority. | ||
| CIS Controls v8 | 5.1 — Establish and Maintain an Inventory of Accounts | Families need a complete account inventory to avoid missing cloud and social services. |
| 5.3 — Disable Dormant Accounts | Unused or abandoned accounts create lingering access and privacy exposure after death. | |
| Recommendation — Maintain a current account inventory so estate representatives can act on every relevant service. Remove or disable no-longer-needed accounts promptly to reduce exposure and impersonation risk. | ||
Practitioner Guidance
What to prioritise: Families should first determine which accounts contain irreplaceable data, which are publicly visible, and which can trigger access to other services. That ordering matters because a cloud account with documents or shared photos usually has a higher preservation priority than a social profile that only needs memorialisation or removal.
What to verify: Before contacting any provider, verify who has legal authority, what proof the platform requires, and whether the deceased person left instructions that conflict with informal family assumptions. The strongest requests are usually the ones that combine death evidence, authority evidence, and a clear statement of the requested action.
Common mistake: Families often try to solve the problem by using a known password or an unlocked device, but that may not satisfy the provider and can create later dispute over unauthorised access. The better practice is to treat platform process as the governing path, with estate instructions reducing delay rather than replacing legal proof.
Practitioner takeaway: The most reliable post-death account strategy is not “recover access first” but “preserve intent, prove authority, and then follow the platform’s rule set in the right order.”
Related resources from NHI Mgmt Group
- Who is accountable when cloud access is not revoked after someone leaves?
- How should security teams govern social media accounts that do not support standard IAM integration?
- Why do shared social media accounts create a governance risk?
- How should security teams govern social media accounts that sit outside IAM?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org