Password Vaults in Estate Planning — How to Pass Down Access Safely
A 67-year-old retiree in Ottawa dies, leaving an executor who quickly discovers a problem. The deceased's email account is two-factor protected. The bank requires email verification for any online access change. Her brokerage account uses a separate password. Her phone is locked, and Apple cannot unlock it. The result — six weeks of phone calls, in-person bank visits, and customer-support escalations to gain access to the digital systems the deceased used daily. Most of that friction would have been eliminated by a single 30-minute setup of a password manager with an emergency contact configured.
For Canadian executors, the password-vault gap is the most common point of operational friction in modern estate administration. This guide walks through how to use password managers as part of a Canadian estate plan, the emergency-access features of the major services, and the Life Discovery Kit setup that ties them together. For broader digital-legacy planning, see digital legacy planning in Canada and our pillar on estate planning in Canada.
Why this matters more than it used to
A generation ago, an executor could reasonably administer an estate by gathering paper statements from the deceased's filing cabinet, opening the safe deposit box, and calling the three or four institutions the deceased used. Today, the same executor faces:
- 30 to 100 online accounts with stored credentials
- Two-factor authentication on banking, brokerage, and email accounts
- Subscription services charging recurring fees
- Cloud storage with photos and documents
- Social media accounts with content the family wants
- Crypto wallets with potentially significant value
- Apps that store unique data (notes, journals, fitness tracking)
Every one of these has its own access path. Without a unified password vault, the executor's first six months become a customer-service archaeology project. With one — and the vault is configured to grant the executor access — the administration becomes systematic.
The major password managers and their estate features
Each major password manager handles the death-of-account-holder scenario differently. The four most commonly used in Canada:
1Password — Emergency Kit
1Password generates an Emergency Kit at signup. The Kit is a one-page PDF containing your Secret Key, your sign-in details, and a space to write your master password (you fill that in manually). The intended use — print it, store it securely (safe deposit box, fireproof safe, with your lawyer), and tell your executor where to find it.
After death, the executor retrieves the Kit and uses it to sign into your 1Password account. Once signed in, they have full vault access.
The strength of this approach — security is in the physical custody of the Kit, not in any digital trust path. No one (including 1Password) can grant access without the Kit. The trade-off — the Kit is the single point of failure; lose it, and the vault is unreachable.
Bitwarden — Emergency Access
Bitwarden offers a built-in Emergency Access feature on its paid tiers.[2] You designate trusted Bitwarden users (they need their own Bitwarden accounts) and a wait time (1 day, 2 days, 1 week, 2 weeks, 1 month). They request access through Bitwarden's interface; you receive notification and can deny within the wait window; absent denial, they receive access.
Two access modes — view-only (read your passwords) or takeover (reset your master password and become the account owner). View-only is the typical estate-planning choice.
The strength — fully digital, no physical artifact to lose. The trade-off — your designated person needs a Bitwarden account.
Dashlane — vault export and account recovery key
Dashlane previously offered a Bitwarden-style Emergency Contact feature with a waiting period, but that feature has been discontinued.[3] The current approach is manual: generate a DASH file (an encrypted export of your entire vault) protected by a password you choose, and share the file and its password with a trusted contact through separate channels — for example, store the file with your Life Discovery Kit and give the password to your executor a different way. Alternatively, Dashlane's account recovery key can be shared with a trusted contact, who can use it to help regain access if you're ever locked out.
Because there's no built-in waiting period or notification system, the safeguard is entirely in how and when you choose to share the file or key — there's no automated request-and-deny flow to fall back on.
LastPass — Emergency Access
Same model as Bitwarden's Emergency Access. Designate contacts; configure a wait period; access is granted if you don't deny the request in time.
Note — LastPass has had multiple high-profile security incidents in recent years. Many Canadian security professionals have shifted away from LastPass to one of the alternatives above.
The setup that works for Canadian estate planning
A practical configuration for a Canadian setting up a password manager for estate purposes:
Step one — choose the manager and migrate your passwords. Pick one of the major options. Migrate every account from whatever you currently use (browser passwords, paper notebook, Apple Keychain) into the manager. This is the long step, often spread over a few weeks.
Step two — turn on two-factor authentication for the password manager itself. Use an authenticator app (Authy, Google Authenticator, 1Password's built-in) rather than SMS where possible.
Step three — configure emergency access. Designate your spouse, executor, or trusted digital contact. For Bitwarden or LastPass, pick a waiting period that balances your privacy (you can deny suspicious requests during the window) against your executor's need for prompt access (24 hours to 7 days is the common range). For 1Password or Dashlane, this step means deciding where the Emergency Kit or DASH export/recovery key will be stored instead.
Step four — generate any required artifacts. For 1Password, print the Emergency Kit and store it securely. For Bitwarden, the emergency access is purely digital so no artifact is required. For Dashlane, generate the DASH export file (or note the location of your account recovery key) and plan separately how and when your executor will get the file and its password.
Step five — document the existence of the vault in your Life Discovery Kit. A simple entry — "I use [vault name] for password management. My executor should follow the emergency-access process at [URL] using their own account. The waiting period is [N] days." For 1Password, add "My Emergency Kit is located at [location]."
Step six — test recovery once a year. Have your designated contact actually walk through the emergency-access process (without completing the final access step). Many "configured" recovery plans fail at this stage because of changed passwords, expired authenticator apps, or stale contact information.
Categories of credentials and what to do with each
Not every password belongs in the same category from the executor's perspective. A useful internal classification:
Critical — executor needs immediately. Email accounts, online banking, brokerage, mortgage, tax software, primary phone provider. These are the accounts the executor needs to start administering the estate.
Useful — executor needs eventually. Insurance portals, utility accounts, government service portals (CRA My Account, Service Canada), subscription services to cancel.
Personal — executor may not need. Social media, photo services, fitness apps, dating apps, personal forums.
Sensitive — handle with discretion. Adult content subscriptions, accounts that contain personal correspondence not intended for the executor, accounts tied to private financial arrangements (a hidden account for an emergency, a separate brokerage from a former relationship, etc.).
For the sensitive category, some Canadians use a separate vault (a personal Bitwarden organization, a second 1Password account) that is not configured for emergency access — the contents remain unreachable after death by design. This is a personal decision; the trade-off is that any value or content in the sensitive vault is permanently lost.
Two-factor authentication and recovery codes
Password managers handle passwords well; they handle two-factor authentication less uniformly. Three patterns:
- 2FA codes inside the password manager. 1Password, Bitwarden, and Dashlane can generate TOTP codes alongside passwords. This means the executor with vault access has both the password and the 2FA — the cleanest pattern for estate purposes.
- 2FA codes in a separate authenticator app. Authy, Google Authenticator, Microsoft Authenticator. If 2FA codes live only in the authenticator app on the deceased's phone, the executor needs the phone unlocked to use them. Some authenticator apps support backup; some do not.
- SMS 2FA. The executor needs access to the deceased's phone number, which often expires within months of death. SMS 2FA is the most fragile pattern for estate purposes.
The defensive practice — consolidate 2FA into the password manager where possible, and store backup recovery codes (one-time codes that each service generates as a fallback) in the password manager's secure-note section.
What goes in the Life Discovery Kit
The Life Discovery Kit is the executor-facing document that complements the will. For password vault planning, the LDK entries:
- The name of the password manager and the URL.
- The form of emergency access (digital emergency-contact, physical Emergency Kit, etc.) and where to find any physical artifacts.
- The intended waiting period for emergency access.
- A note that the master password is intentionally not recorded in the LDK (because the recovery path bypasses the master password).
- For the sensitive category — a brief note that some accounts are intentionally not accessible (so the executor does not waste time searching for credentials that were intentionally withheld).
This level of detail in the LDK saves the executor hundreds of hours of recovery work.
Pitfalls to avoid
A few patterns that look like password-vault planning but fail in practice:
Master password in the will. Wills become public. Never.
Master password emailed to a "trusted family member." Email accounts get compromised, archived, forwarded. The plain-text master password sitting in someone's inbox is the worst-case scenario.
No 2FA on the password vault. A vault without 2FA is one master-password compromise away from total loss. Always enable.
No test of the recovery path. Plans that have never been tested fail at the moment they are needed. Annual recovery drills work.
Trusting the cloud only. Cloud-based password managers occasionally have outages, security incidents, or service shutdowns. Keep an offline backup of critical credentials (printed Emergency Kit, encrypted USB drive in a safe) as a second layer.
Canadian privacy considerations
PIPEDA[4] applies to personal information during the user's lifetime. After death, personal-information protection varies by province. Most major password managers are US-based, processing Canadian users' data subject to their own terms of service. The emergency-access mechanism operates under those terms.
A practical implication — the password manager's terms generally control the post-death process, and the user's consent during life (configuring the emergency contact) is the legal basis for the eventual access. A Canadian will or probate certificate is not directly relevant to the password manager — the user's pre-configured trust is what matters.
For more on related digital planning, see Apple Digital Legacy, Google Inactive Account Manager, and cryptocurrency in your estate plan.
What we focus on at It's Simple Will
The password-vault setup is one of the highest-leverage digital estate-planning steps available — 30 minutes of configuration prevents months of executor friction. Pair the vault setup with a Canadian will at app.itssimplewill.ca and the Life Discovery Kit that records where your vault is, who has emergency access, and any physical artifacts (Emergency Kit, recovery codes) the executor needs to find. The will gives the executor legal authority; the vault setup gives them operational access; the LDK is the bridge between the two.
Citations & sources
- [1]1Password security model — 1Password
- [2]Bitwarden — emergency access — Bitwarden
- [3]Dashlane — share your data with a trusted person — Dashlane Support
- [4]Personal Information Protection and Electronic Documents Act (PIPEDA), SC 2000, c 5 — Justice Laws Website, Government of Canada
Frequently asked questions
Which password managers offer emergency access for estate planning?
Bitwarden and LastPass offer named emergency-contact features with a waiting period during which you can deny the request. 1Password uses a different approach — an Emergency Kit you print at signup containing the recovery information, which you store securely (with your will, in a safe, with your lawyer). Dashlane discontinued its waiting-period emergency-contact feature and now relies on manually sharing an encrypted vault export (a DASH file) or an account recovery key with a trusted person. NordPass, Keeper, and 1Password Business also have variations. The specific mechanics matter; pick the one whose process matches your risk tolerance.
How does the waiting-period emergency access work?
You designate a trusted contact and a waiting period (commonly 24 hours, 48 hours, 7 days, or 30 days depending on the service). After your death, the contact submits a request through the password manager's interface. The service sends notifications to you (email, SMS) for the duration of the waiting period. If you do not deny the request, access is granted at the end of the period. The contact can then view or export your stored credentials.
What if I can't trust anyone with full emergency access?
Two patterns help. First — split the trust by storing different categories in different vaults (a personal vault for everyday accounts, a financial vault for banking, a digital-legacy vault specifically for your executor). Second — use the 1Password Emergency Kit pattern, where the kit lives with the will or in a safe deposit box rather than being pre-distributed to a person. The trusted-vault contents are unreachable until the executor physically obtains the kit after death.
Should I put my master password in my will?
No — wills become public on probate. The master password should never be in the will itself. Acceptable alternatives — store it in a sealed envelope with your lawyer, store it in a safe deposit box with documented access for the executor, or use the password manager's own emergency-access feature so the master password is never disclosed to anyone (the manager grants the contact a separate access path).
What's the difference between an emergency contact and a Legacy Contact for the password manager itself?
An "emergency contact" in a password manager is a person you designate within the manager's settings to request access after a waiting period — operationally specific to that service. A "Legacy Contact" (as used by Apple) is a similar concept for the underlying platform's stored data. Some password managers describe their feature as "emergency access," "trusted contacts," or "beneficiary access" — the terminology varies but the function is similar.
Can my executor reset the master password if they have a death certificate?
Generally no. Password managers built on zero-knowledge architecture (1Password, Bitwarden, Dashlane) cannot reset master passwords because they do not know them — only the encrypted vault is stored on their servers. A death certificate alone gives the service no path to your data. This is the security feature that makes the emergency-access pre-configuration so important.