Someone Died and Their Laptop, Photos and Email Are Locked: What to Do First
September 10, 2026
The laptop is usually the easy part. It is the accounts that quietly close behind you — and two of them are already on a timer.
This is one of the calls we take most often and write about least. Somebody has died — a parent, a spouse, a business partner — and a week or a month later the family is sitting at a kitchen table with a laptop that wants a password nobody knows, a phone that keeps buzzing, and a growing list of accounts that have to be dealt with by somebody. Nobody planned for this part. Almost nobody has been told which bits are urgent.
What follows is the technology side of it, in the order that actually matters, with the rules quoted from the companies that make them rather than paraphrased from a forum. It is deliberately not legal advice, and there is a point below where the honest answer is talk to a probate attorney — we will say so plainly when we get there. Everything else here is the practical part: which things you should not do this week, which clocks are already running, and what is genuinely recoverable versus what is gone for good.
One thing worth saying at the top, because families torture themselves over it: if you cannot get into something, it is very often not because you missed a step. Modern accounts and modern laptops are built specifically to resist exactly what you are trying to do. That is a feature working correctly at the worst possible moment.
Start here, because two clocks are already running
The single most useful thing in this article is the thing nobody mentions at a funeral: doing nothing is not neutral. Accounts left untouched do not sit patiently. They expire, and the expiry takes the contents with it.
Microsoft publishes the timetable on its own support page for exactly this situation. In its words: "Outlook.com and OneDrive accounts will be frozen after 1 year and any email messages and files stored on OneDrive will be deleted shortly after. Microsoft accounts expire after two (2) years of inactivity." Read that first sentence twice. One year of nobody signing in, and the mail and the OneDrive files — which for a lot of people is where the photographs actually live — are on a deletion path. That clock started the last time they signed in, not the day of the funeral.
Google has its own version. On its Inactive Account Manager page, Google states that if no plan was set up, "Google reserves the right to delete an inactive Google Account and its activity and data if you're inactive across Google for at least two years." Two years is longer than Microsoft's one, but it covers Gmail, Drive and Google Photos, which for many households is the entire photographic record of the last fifteen years.
So the practical consequence is this: if there is any account you can still get into — because the password is written down, because the browser remembers it, because the phone is unlocked — the highest-value hour of your week is spent downloading the contents of that account now, before anyone gets clever about legal routes. Both companies offer a download-your-data export. Get the data out first. Argue about the account later. An account you have already emptied is one you no longer need permission for.
The part everyone gets backwards
Families arrive at this with one assumption, and it is almost always the wrong way round. The assumption is that the locked laptop is the hard problem and the online accounts will sort themselves out with a phone call and a death certificate.
It is the reverse. If the laptop is not encrypted, the data on it can often be read within the hour by anyone competent, without a password, because the password only guards the way in through Windows — not the drive itself. That is a genuinely good outcome and it is why an unencrypted machine is the best case in this whole article.
The accounts are the hard part. They are the thing that no amount of technical skill opens, because they are not on the table in front of you — they are on somebody else's servers, governed by policies written by lawyers, and every one of the big three has concluded that handing accounts to grieving relatives on request would be catastrophic for everyone else's security. They are right about that. It just means the answer to "can you get into Dad's email" is a policy question and not a repair question.
Which leads to the piece of advice that reframes the whole week: stop thinking about getting into accounts and start thinking about getting data out of the places you can still reach. The phone in the drawer, the tablet on the nightstand, the computer that is still signed in, the external drive in the closet, the router that still has their devices connected. Every one of those is a copy of something, and copies are not governed by anybody's policy.
The most valuable object in the house is their phone
If you take one instruction from this page, take this one. Find their phone. Charge it. Keep it charged. Do not factory reset it, do not hand it to a carrier as a trade-in, do not let a well-meaning relative "wipe it for the grandkids," and do not cancel the mobile line for at least a few weeks.
The reason is two-factor authentication. Nearly every account they had now sends a code to that phone or that number, or holds the login inside an authenticator app installed on it. A phone you can unlock is not just a phone — it is the key to the email, and the email is the key to almost everything else, because password resets land there. A phone that is still receiving texts, even locked, can still deliver a code you can read on the lock screen.
Cancelling the mobile line is the single most common irreversible mistake we see, and it is always done for a sensible reason: it is a monthly bill for a person who is gone. But the moment that number is released, every account that uses it for verification becomes materially harder or impossible to reach, and the number itself will eventually be recycled to a stranger. If the estate can carry the bill for a couple of months, it should. If it truly cannot, port the number to a cheap prepaid plan first so it stays alive and stays yours.
The same logic applies to their main email address. It is tempting to close it early. Do not. Bills, subscriptions, insurance, brokerage statements, the utility account, the alarm monitoring, the vet — all of it announces itself by email eventually, and for the first year that inbox is the most reliable inventory of the deceased's financial life that exists. Watch it, do not delete it.
The locked laptop, and the honest answer about encryption
Now the machine itself. There are two entirely different situations and it is worth finding out which one you are in before anyone spends money.
Case one is a computer that is password-protected but not encrypted — common on older Windows machines, especially ones set up with a local account rather than a Microsoft account. Here the drive can be removed and read on another computer, and the photos, documents and tax records come off intact. No password required, no bypass, nothing dubious. This is ordinary data-recovery work and any competent shop, including ours, does it as a matter of routine.
Case two is an encrypted computer, and this is now the default rather than the exception on modern hardware. Microsoft's own device-encryption page states it plainly: "When you first sign in or set up a device with a Microsoft account, or work or school account, Device Encryption is turned on and a recovery key is attached to that account. If you're using a local account, Device Encryption isn't turned on automatically." So the newer the PC and the more likely it was set up with a Microsoft account at the shop counter, the more likely the drive is encrypted — and pulling that drive out produces nothing but noise.
There is a way in, and it is an oddly hopeful one. The recovery key is a 48-digit number and it is stored in the Microsoft account. If you can reach that account — which loops right back to the phone and the email address — you can go to the recovery-key page inside the account, read out the key, and unlock the machine with it. The account is the master key to the laptop, which is why the account work comes first and the laptop work comes second.
And if the key cannot be found, we are obliged to give you Microsoft's answer rather than a comforting one: "Microsoft Support doesn't have the ability to retrieve, provide, or recreate a lost BitLocker recovery key." There is no back door, no escalation, no paid service that changes this. The only remaining option Microsoft describes is resetting the device, and it says what that costs: "Resetting your device will remove all of your files." A Mac with FileVault on, or any recent Mac with Apple silicon, sits in the same place — the data is mathematically tied to a passcode nobody living knows.
This is the moment where a certain kind of business will offer to crack it for a fee. They cannot. Anyone quoting you a price to break BitLocker or FileVault on a modern machine is either misunderstanding the job or taking money for a reset they will perform and then describe as a failed recovery. If you are already deep in grief and someone offers you certainty here, that is precisely when to be suspicious.
What Apple, Google and Microsoft will actually do
Each of the three has a published process, and they differ enough that it is worth knowing which door you are standing at.
Apple has the most usable system of the three, and it hinges on something the deceased had to do while alive. Apple calls it a Legacy Contact: "someone you choose to have access to certain data in your Apple Account after your death." If they set one up, that person was given an access key, and Apple's requirement is straightforward — "Your Legacy Contact must have both the access key and your death certificate to request access after you pass away." The access key may be printed, saved in a photo, or sitting in estate paperwork, so it is worth looking for before assuming it does not exist. Apple also notes the contact "don't need to have an Apple Account or an Apple device," so it may be a person outside the family's Apple orbit entirely.
What comes across matters too, and Apple is specific: the data "might include photos, messages, notes, files, device backups, and more," while "inaccessible data includes movies, music, books, or subscriptions you purchased with your Apple Account, and data stored in your iCloud Keychain (payment information, passwords, and passkeys)." That last exclusion is the one that surprises people and it deserves its own sentence: the passwords do not come across. Even a successful legacy request hands you the photos and not the keyring. Apple adds that "Some data might be end-to-end encrypted and Apple isn't able to decrypt it."
Without a Legacy Contact, Apple's route is a court order, and it is not a formality. Apple says the order "must name you as the rightful inheritor of your loved one's personal information" and that "Only one person can request access to a deceased person's Apple Account" — a detail siblings should settle among themselves early rather than late. The order has to specify the deceased's name and Apple Account, the name of the next of kin requesting access, that the decedent was the user of all accounts associated with the Apple Account, that the requestor is "the decedent's legal personal representative, agent, or heir," and that Apple is ordered by the court to assist. In other words: a lawyer and a judge, not a support call.
Google draws the line in a different place. Its page for requests about a deceased user says the company can "work with immediate family members and representatives to close the account of a deceased person where appropriate" and that "In certain circumstances we may provide content from a deceased user's account" — but it is unambiguous about the thing families actually ask for: "We cannot provide passwords or other login details." There are three separate requests you can file — close the account, request funds from it, or obtain data from it — and Google says any decision "will be made only after a careful review."
Microsoft is the strictest of the three and says so without much cushioning. Its position is that "Microsoft must first be formally served with a valid subpoena or court order to consider whether it is able to lawfully release a deceased or incapacitated user's information," that such orders must be served on its registered agent in your state rather than faxed or emailed, and — the sentence to read before spending money on any of this — "Microsoft may be unable to provide the account content and sending a request or providing a subpoena or court order does not guarantee that we will be able to assist you." Closing the account is far easier than opening it: if you have the credentials you can close it yourself, and if you do not, it closes on its own after two years.
The California rule almost nobody knows: a setting outranks a will
Here is the part that genuinely surprises people, including people who have already paid for an estate plan. California has a law about this, and it has been on the books since January 1, 2017: the Revised Uniform Fiduciary Access to Digital Assets Act, at Probate Code sections 870 through 884, added by Assembly Bill 691.
Section 873 is the one that matters to a family, and it is short enough to read directly. Subdivision (a) says: "A user may use an online tool to direct the custodian to disclose to a designated recipient or not disclose some or all of the user's digital assets, including the content of electronic communications. If the online tool allows the user to modify or delete a direction at all times, a direction regarding disclosure using an online tool overrides a contrary direction by the user in a will, trust, power of attorney, or other record."
An "online tool" is the statute's name for exactly the settings we have been describing — Apple's Legacy Contact, Google's Inactive Account Manager, the equivalent controls at other providers. So the sentence says something remarkable: the five minutes somebody spent in Settings can outrank the paragraph their attorney drafted. Not supplement it. Override it.
Subdivision (b) covers the other case: if no online tool was used, or the provider does not offer one, the person "may allow or prohibit in a will, trust, power of attorney, or other record the disclosure to a fiduciary" of their digital assets. And subdivision (c) adds a protection worth knowing about: "A user's direction under subdivision (a) or (b) overrides a contrary provision in a terms-of-service agreement."
Two practical consequences follow. First, when you sit down with a probate attorney, tell them which online tools the deceased did or did not use, because that fact changes the analysis before the will does. Second — and this is the part to act on — if you are reading this and thinking about your own family, the highest-leverage thing you can do is not a document. It is a setting.
This is the point where we hand off. Whether a particular account is part of the estate, who has authority to act, and what a court will actually order are legal questions, and California probate is not a field for confident amateurs. We are a computer shop; find a probate attorney. What we can tell you is which technical facts to bring to that meeting, and the list above is it.
A first-week order of operations
Compressed into the sequence we would actually follow, assuming the immediate human things are handled and somebody has finally got a spare afternoon.
One: gather the hardware in one place and plug it all in. Phone, tablet, laptop, desktop, any external drives, any backup drive sitting behind the router, any old computer in the garage. Charge everything. The garage machine is frequently where the pre-2015 photographs are, precisely because nobody has touched it.
Two: while things are charging, write down what you already have access to — a password on a note in a drawer, a browser that stays signed in, a tablet with no passcode, the phone if it can be unlocked. This inventory is your actual working capital and it is usually larger than families expect.
Three: use that access to export, immediately, before touching anything else. Download the mail archive. Download the photo library. Copy the documents folder to a drive you own. Do this even if you are certain the account is safe, because of the clocks in the first section.
Four: keep the phone number and the primary email address alive, as above. Set a reminder to check that inbox weekly for a year.
Five: only now deal with the locked machine. Look for the recovery key inside whatever account you did get into. If the key is there, the laptop opens. If it is not, get a professional opinion on whether the drive is even encrypted before assuming the worst — plenty of older machines are not, and that changes everything.
Six: inventory the recurring charges. Streaming services, cloud storage, domain renewals, the website hosting for a small business, the alarm monitoring, the backup subscription. Some of these should be cancelled and some absolutely should not be cancelled yet — cancelling cloud storage before you have downloaded what is in it deletes the very thing you were trying to save. Sort out the download first, the cancellation second.
Seven: if they ran a business, treat the domain name and the business email as urgent rather than administrative. A lapsed domain takes the company email address down with it, and recovering a domain after it expires is a different and much worse problem than renewing it before it does. We have written separately about what happens when a domain quietly expires and about what to do when an employee leaves and their mailbox leaves with them; both of those pieces apply almost unchanged here.
The scam wave that follows an obituary
This is unpleasant to write about and we are going to write about it anyway, because we have watched it happen to customers and forewarning helps.
Obituaries are public documents, and they are published with a name, a town, a spouse's name and often a list of surviving relatives. That is a targeting package. In the weeks after a death, the surviving spouse — frequently an older person, newly alone, and dealing with a hundred unfamiliar administrative tasks — becomes a specific and identifiable target rather than a random one.
The shapes to expect: a call or email about an unpaid debt of the deceased that must be settled immediately, a "your account has been compromised" message arriving in the middle of a period when the person genuinely is dealing with accounts, a fake charity connected to the illness, and the one that works best of all — someone offering to help with exactly the problem this article describes, for a fee, paid by gift card or transfer.
The defence is a rule rather than a checklist, and it should be given to the surviving spouse out loud: in this period, nothing is urgent enough to do on the phone with someone who called you. Not a debt, not an account, not a locked computer. Hang up, and call back on a number from a statement, or ask a family member. It costs nothing to be a day late on a real matter, and it costs everything to be five minutes early on a fake one. Our write-ups on the AI voice-clone calls that impersonate a relative and the recovery scams aimed at people who have already lost money both fit this moment exactly.
Twenty minutes that will spare your own family all of this
If you have read this far because you are in the middle of it, this section is for later. If you are reading it because it made you think about your own household, do it this week — it is genuinely twenty minutes and it is the single highest-return tech task in this entire article.
On Apple: add a Legacy Contact. It lives in Settings, under your name, in Sign-In and Security. Apple's guidance is blunt about the follow-through — "The access key is extremely important" — so once you have generated it, print it and put it with your will, rather than leaving it only on the phone that will be locked.
On Google: set up Inactive Account Manager. You choose how long Google waits, and Google says "You can select up to 10 people to receive this data, and choose to share all or only specific data types." One detail worth knowing, because it removes the awkwardness: Google confirms that "Contacts will only receive notification once your account has been inactive for the specified amount of time -- they will not receive any notification during setup." Nobody gets told they were named until it matters.
On the Windows machine: find out whether it is encrypted, and if it is, make sure the recovery key is somewhere outside the computer it unlocks. Printed, in the same envelope as the rest. We have a full guide to BitLocker and the ways it locks people out of their own machines; the death of the account owner is simply the most permanent version of that.
And the thing that beats all of the above: one sheet of paper, in a safe or a fireproof box, listing the phone passcode, the computer password, the main email address and its password, and where the backup drive is. Not a spreadsheet on the desktop of the encrypted computer. Paper. Every technical control described in this article can be defeated in ten seconds by a family member who knows the passcode, which is the whole point — these systems are not designed to keep families out, they are designed to keep strangers out, and the difference between the two is information you can choose to leave behind.
While you are at it, make sure a backup exists at all. Everything above assumes the photographs are somewhere. The families who come out of this best are not the ones with the best legal paperwork — they are the ones where somebody, years earlier, set up a backup that nobody thought about again.
What a repair shop can and cannot do, and what we will not do
We think it is worth being explicit about the boundaries, because vagueness here costs grieving people money.
Things we can genuinely do: read an unencrypted drive and get the files off it, including from a machine that will no longer boot. Image a drive before anyone experiments on it, which is the right first move on anything irreplaceable. Recover photos from an old phone, an SD card or a camera. Find and read the recovery key inside an account you have lawful access to. Get an old desktop in the garage running long enough to pull twenty years of pictures off it. Set up the surviving spouse's own devices afterwards, which is often the part that actually matters day to day, and lock them down against the scam wave above.
Things nobody can do: break BitLocker or FileVault without the key, remove Apple's Activation Lock without the original credentials or Apple's involvement, or persuade Apple, Google or Microsoft to release an account on a technician's say-so. We would rather tell you that in a five-minute phone call than after an invoice.
And the thing we will not do: help anyone get into a device or an account they have no right to be in. We ask who you are to the deceased, and for anything beyond routine data recovery from a machine in your possession we will point you at the published process and, where it belongs, at an attorney. That policy protects the customer with a genuine claim just as much as it protects everyone else, and it is worth asking any shop you call whether they have one.
We look after home and small-business technology across Southern California and the Coachella Valley — Pasadena, Arcadia and Monrovia, Orange County and Riverside, and the desert communities from Palm Springs to Palm Desert and Rancho Mirage, where a larger share of our customers are retired and where this call comes more often than anywhere else we work. If you are in the middle of this, the most useful thing you can do before calling anybody is the first-week list above: gather the hardware, keep the phone alive, and get data out of everything you can still reach. Whatever comes next is easier once that is done.
Keep reading
- BitLocker: Great for Protecting Your Data — Until It Locks You Out
- Backups: The One Thing Everyone Skips Until It's Too Late
- An Employee Left and Their Email Left With Them: What to Do, in the Right Order
- That Panicked Call From a Loved One Might Be AI: The Voice-Clone "Grandparent" Scam
- The Website and the Email Went Down at the Same Time. Check the Domain Before Anything Else.
Free calculators
Service areas we cover
We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.
Call (626) 655-0020