Digital assets — email, cloud storage, social media, domain names, loyalty points, and cryptocurrency — require deliberate planning because federal privacy and anti-hacking laws (the Stored Communications Act and Computer Fraud and Abuse Act) can bar fiduciary access absent authorization. The Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA), adopted in nearly every state, supplies the framework.
- An online tool provided by the custodian (e.g., Google Inactive Account Manager, Facebook Legacy Contact) controls if the user used it — and overrides the will.
- If no online tool, the user's estate-planning documents (will, trust, POA) control, provided they grant access.
- If neither, the custodian's terms-of-service agreement governs — often denying access.
Practice tip
Advise clients to complete custodial online tools where available AND grant explicit authority in the will, trust, and POA. RUFADAA also distinguishes 'content of electronic communications' (needs express consent) from a 'catalogue' (metadata), so grant authority over content expressly.
- Self-custodied crypto is lost forever without the private keys or seed phrase — the estate plan must ensure secure, retrievable access without exposing keys during life.
- Never put private keys or passwords directly in a will (it becomes a public record on probate); use a secure inventory and a separate, secured credential store referenced by the plan.
- Address exchange accounts (subject to their own terms), tax basis tracking, and the fiduciary's authority and competence to handle digital assets.
Key takeaways
- RUFADAA prioritizes custodial online tools, then estate documents, then terms of service — plan at all three levels.
- Grant express authority over the content of electronic communications in the will, trust, and POA.
- For crypto, secure the keys and provide retrievable access — never expose keys in a probate document.
Authorities
- Revised Uniform Fiduciary Access to Digital Assets Act (2015)
- Stored Communications Act, 18 U.S.C. 2701-2712; Computer Fraud and Abuse Act, 18 U.S.C. 1030
