A will can leave someone your photographs. It cannot leave them your account.

Ownership · Published 25 September 2026 · Updated 25 September 2026 · 11 min read

What Happens to Your Photos When You Die

A few weeks after the funeral, somebody in the family asks the obvious question: can we get Mum’s photographs? Everyone assumes the answer is yes, because the photographs plainly exist — they were on her phone last month, they are in her account now, and the family is the family. The answer turns out to depend on something nobody thought about while she was alive: whether she spent ten minutes, at some point, telling that company who to give them to. If she did, this takes an afternoon. If she did not, it takes a death certificate, sometimes a court order, and it may not work at all.

An account is a permission, not a possession

The instinct behind “it is her account, and we are her family” is that an account is a container, like a box in the loft. Whoever inherits the house inherits the box. That is not how any of these services are built, and the gap is not an oversight — it is the direct consequence of the thing everybody says they want from a photo service, which is that nobody except the owner can get in.

Apple puts the tension in writing on the page it wrote for bereaved families: “Apple considers privacy to be a fundamental human right, and our users expect Apple to help keep their information private and secure at all times.” Read that as a statement of company values and it is a press line. Read it as a description of a lock and it tells you exactly what you are up against. The lock is doing its job. The job includes keeping out people who loved her.

So the question stops being who inherits the photographs and becomes who is authorized to unlock the account. Those are different questions with different answers, decided in different places — one in a will, the other in a settings screen that most people have never opened.

Everything in this article is what the four largest custodians publish about their own processes, read in September 2026 and quoted rather than paraphrased. None of it is legal advice, and the rules around digital assets differ considerably from one country to another. What does not differ is the company policy, and the policy is usually the thing that decides the outcome first.

What each service lets you arrange in advance

All four have built something. They are not equivalent, and the differences matter more than the similarities.

Google calls its version Inactive Account Manager, and describes it as “a way for users to share parts of their account data or notify someone if they’ve been inactive for a certain period of time.” You can, in Google’s words, “select up to 10 people to receive this data, and choose to share all or only specific data types. You can also share different data with different people.” It runs on a timer rather than on a death: Google says it looks at “your last sign-ins, your recent activity in My Activity, usage of Gmail (e.g., the Gmail app on your phone), and Android check-ins,” and triggers only after the account has been idle for a period you choose.

Two details are easy to skim past. The person you name is asked for a phone number, and Google explains why plainly: “We’ll use the phone number for the sole purpose of ensuring that only the trusted contact can actually download your data.” And they are told nothing until it fires — “they will not receive any notification during setup.” If the number changes in the intervening decade, the plan quietly stops working and nobody finds out.

Apple uses a different model. A Legacy Contact is “someone you choose to have access to certain data in your Apple Account after your death,” and the data “might include photos, messages, notes, files, device backups, and more.” There are limits worth knowing before you rely on it: “Inaccessible data includes movies, music, books, or subscriptions you purchased with your Apple Account, and data stored in your iCloud Keychain (payment information, passwords, and passkeys).”

What makes Apple’s version unusually robust is that it is built on a key rather than on a promise. Apple’s own security documentation describes the mechanism: “Apple stores the encrypted packet and the beneficiary keeps the AES key,” and that key “is saved automatically on supported devices but it can also be printed and stored offline for use.” A piece of paper in a drawer is a legitimate part of the design. After the death, the contact needs two things — “The access key that you generate when you choose them as your Legacy Contact” and “Your death certificate.”

There is a sharp edge on Apple’s version that is not obvious: you can name more than one person, and “any one of them can individually make decisions about your account data after your death, including permanently deleting it.” Naming several people is not a safety net. It is several independent sets of hands.

Microsoft’s equivalent covers files rather than the whole account. OneDrive Digital Legacy “allows you to grant read-only access to your next of kin, or a contact you trust to your OneDrive, so that in event of your death, they can view your files and photos.” The setup produces a code, and Microsoft is refreshingly practical about where that code should live: “You can share the Digital legacy code straight away, write it down in your Will, or give it to a third party such as lawyer or estate executor. The sharing code does not change and does not expire.” When the code is used there is a deliberate delay — the contact enters it and must “wait 72 hours” before access opens. One condition to plan around: “Your trusted contact must have a Microsoft account.”

Meta is the odd one out, because a Facebook legacy contact is not given the photographs at all. Facebook lists what that person can do — write a pinned post, update the profile picture and cover photo, request removal of the account, and “Download a copy of what you’ve shared on Facebook, if you have this feature turned on.” Then it lists what they cannot do, and the list is short and absolute: “Log in to your account. Read your messages. Remove any of your friends or make new friend requests.”

That conditional clause — if you have this feature turned on — is the whole thing. Appointing a legacy contact and leaving the download permission off gives your family someone who can change your profile picture and nothing else.
Service What you can arrange in advance What that person can actually do
Google Account Inactive Account Manager: up to 10 people, each given whichever data types you pick Receives an email with a link to download the data you chose, after the idle period you set
Apple Account Legacy Contact, holding an access key that can be printed and kept offline With the key and a death certificate, reaches photos, messages, notes, files and device backups — not Keychain, not purchased media
Microsoft / OneDrive Digital Legacy: one trusted contact, holding a code that “does not change and does not expire” Read-only view of OneDrive files and photos, 72 hours after the code is submitted
Facebook A legacy contact for a memorialized profile, plus a separate download permission Cannot log in and cannot read messages. Downloads what you shared only if the permission was enabled

Set against a photo library, three of those four are partial by design. Google hands over an export of the data types you ticked. Microsoft covers OneDrive, which may or may not be where the photographs live. Facebook hands over what was posted, which is a heavily compressed public selection rather than an archive. Only Apple’s route is really aimed at the whole library, and only on the condition that the person made an arrangement using a device signed in to that account.

What happens when nothing was arranged

This is the ordinary case. Almost nobody sets these things up, and the companies know it — Google says so in as many words: “We recognize that many people pass away without leaving clear instructions about how to manage their online accounts.”

From there the routes stop being product features and start being legal processes.

Apple says it “requires and verifies legal documentation before we can assist with a deceased person’s account. This generally includes a death certificate, and might also require a court order or other documentation.” Where a court order is the route — Apple names the U.S., Israel “and other locales” — it has to do specific work: “The court order must name you as the rightful inheritor of your loved one’s personal information.” And a sentence families should read before they start arguing among themselves: “Only one person can request access to a deceased person’s Apple Account.” Apple also notes a ceiling on what any of this can reach: “Some data might be end-to-end encrypted and Apple isn’t able to decrypt it.” Nobody can order a company to hand over something it cannot read.

Microsoft is the bluntest of the four. It “must first be formally served with a valid subpoena or court order to consider whether it is able to lawfully release a deceased or incapacitated user’s information,” and it will not take those by fax or email. It then declines to promise an outcome even then: “Please understand that Microsoft may be unable to provide the account content and sending a request or providing a subpoena or court order does not guarantee that we will be able to assist you.” There are documented national exceptions — in Germany, for instance, Microsoft lists a paperwork route that includes a death certificate, the deceased person’s identity document, and a certificate of inheritance or equivalent court document.

Google sits between the two. It says it can “work with immediate family members and representatives to close the account of a deceased person where appropriate,” and that “in certain circumstances we may provide content from a deceased user’s account” — a decision “made only after a careful review.” One line rules out the shortcut most families try first: “We cannot provide passwords or other login details.”

None of these companies is being obstructive for its own sake, and it is worth saying so plainly. The same policy that frustrates a grieving daughter is the policy that stops a stranger with a forged letter emptying a stranger’s photo library. The cost of that protection is simply not distributed evenly, and the people who pay it are not the ones who chose it.

The clock nobody mentions

Every account described above is also sitting on a timer that has nothing to do with bereavement, and this is the part that turns a solvable problem into a permanent loss.

Microsoft’s page for families states the timings directly. “Outlook.com and OneDrive accounts will be frozen after 1 year and any email messages and files stored on OneDrive will be deleted shortly after. Microsoft accounts expire after two (2) years of inactivity.” If you do have the password and use it to close the account deliberately, there is a grace period: “you can reopen it within 60 days by signing in again… However, after those 60 days have passed, we permanently delete the account and its data.”

Google’s policy is stated as a definition: “An inactive Google Account is an account that has not been used within a 2-year period. Google reserves the right to delete an inactive Google Account and its activity and data if you are inactive across Google for at least two years.” Notices go somewhere, but look at where: “Email notifications to your Google Account” and “Notifications to your recovery email, if any exists.” Both of those arrive in inboxes nobody living is reading.

Then there is the exceptions list, which is where this gets genuinely strange. A Google Account counts as active, despite two silent years, if any of these are true — among them:

  • “Your Google Account was used to make a purchase of a Google product, app, service, or subscription that is current or ongoing.”
  • “Your Google Account contains a gift card with a monetary balance.”
  • “Your Google Account has been used to purchase a digital item, for example, a book or movie.”
Read those three together and the rule underneath them is visible: a commercial relationship is what keeps an account alive. An unspent gift card protects forty years of family photographs. Being loved and missed does not.

We are not suggesting anyone is being cynical here — there are obvious reasons a company cannot delete an account holding something paid for. But it does tell you where the safety net is, and it is not underneath the photographs. Nothing in either policy treats a library of family pictures as the thing most worth keeping. The technology press covers this as a storage policy story; for a family two years into probate it is a deletion date.

The other half of the mismatch is human. Estates take months. Grief takes longer, and the box of someone’s digital life is usually the last thing anyone feels able to open. One year to a freeze, two to deletion, sounds generous in a meeting room and is nothing at all at the kitchen table.

The one request that cannot be undone

If you take a single practical thing from this article, take this one, because it is the mistake that is easiest to make and impossible to repair.

When a family contacts a service after a death, the request that feels natural is the tidy one: please close the account. It reads as the responsible, respectful step. Google’s own page warns against doing it first, in a sentence that is doing a great deal of work:

“If you select to close the Google account, Google is unable to process any request to turn over the contents of the account at a later date. If you have already submitted a request for the contents of the account please wait for that request to be complete before submitting any subsequent requests.”

In other words the order is one-way. Ask for the contents first and you can still close the account afterwards. Close it first and the photographs are gone as an option, permanently, no matter what documentation anybody produces later. Two requests, one sequence that works, and the intuitive order is the wrong one.

The same logic applies wherever an account can be closed, including the case where a family member does know the password and is trying to be helpful. Closing an account is not a neutral tidying action. It is the last step, not the first.

What actually arrives, and what state it is in

Say it works. The access key was found, or the trusted contact clicked the link, or the request was granted. What lands is not a photo library. It is an export — a set of downloads that has to be turned back into something a person can look through.

That matters more for old photographs than for recent ones, because exports are where dates go wrong. The capture date lives inside the file in Exif; the album structure, the descriptions and often the correct timestamps live beside it in separate files; and a route that rebuilds images rather than copying them can strip the internal date entirely. The result is a folder of thousands of pictures that all appear to have been taken on the day they were downloaded — which, for an inherited library, is the day it stopped being possible to ask anyone when the photographs were taken.

We have written about that failure in its own right, in what photo exports actually give you and why photos arrive with the wrong dates. The point here is narrower: budget for it. Getting the files out is the first job, not the last one, and an inherited archive almost always needs its chronology put back before it is worth anything to anyone.

It is also worth knowing what is missing. Facebook returns what was posted, not what was taken — the resized public version of a photograph, not the original. A service that stored optimized copies may return exactly those. An archive assembled from shares and exports is a real archive, and it is not the same archive the person had.

Five things widely believed that are not true

Each of these is said with total confidence in comment threads, and each one has cost a family photographs.

  1. “My will covers it.” A will directs an estate; it does not authenticate anyone to a company. Where documentation is the route, Apple asks for a court order that “must name you as the rightful inheritor,” and Microsoft asks to be “formally served with a valid subpoena or court order”. Microsoft’s own suggestion is to put the access code in the will — the will carries the key, rather than replacing it.
  2. “Next of kin can just ask.” Microsoft’s position when nothing was arranged is that it “is generally unable to provide information to non-account holders,” and it does not guarantee a result even when served properly. Being family establishes who should have the photographs. It does not establish who can be let in.
  3. “It is in the cloud, so it is safe indefinitely.” Both Google and Microsoft publish two-year inactivity rules, and Microsoft freezes an unattended account at one year with deletion “shortly after”. Nothing about cloud storage implies storage forever; what it implies is storage for as long as the account is in use.
  4. “A legacy contact can get into the account.” Sometimes, and sometimes not remotely. Facebook’s list of what a legacy contact cannot do begins “Log in to your account.” Microsoft’s digital legacy access is read-only. The name suggests a spare key; several of these are closer to a window.
  5. “I have written the password down, so we are fine.” Better than nothing, and still not a plan. Two-step verification sends its code to a phone that will be disconnected. Apple notes that devices locked with a passcode “are protected by passcode encryption, and Apple can’t help remove the passcode lock without erasing the device.” A password on paper is a credential, not a permission, and it can stop working without anybody touching it.

What to do about it, in about half an hour

There are two separate jobs here, and they are worth doing in this order.

First, use what already exists. Each of the four arrangements above takes a few minutes and costs nothing. Set the Google one and name real people. Add an Apple Legacy Contact and print the access key, because Apple designed it to be printable for exactly this reason. Turn on OneDrive Digital Legacy and put the code where the will is. On Facebook, appoint the contact and enable the download permission, which is a separate switch. Then tell somebody you have done it, because a plan nobody knows about is indistinguishable from no plan.

Second, and more useful than all four combined: keep a copy that needs nobody’s permission. Everything in this article is a procedure for getting photographs out of somewhere they are being held for you. A folder of original files on a drive in the house is not held by anyone. There is no death certificate, no access key, no trusted contact, no inactivity policy and no request that can be refused. Somebody plugs it in.

That is not an argument against cloud services, which are excellent at the job they do — a copy in your house burns down with your house, which is exactly why the two belong together. It is an argument about where the master lives. Our note on choosing a library drive covers the practical side, and cloud sync is not a backup covers why a mirrored copy is not a second copy.

The test is a plain one, and you can apply it this evening. If you were not here next week, could somebody in this family look at these photographs without asking permission from a company? If the answer is no, the fix is not a better arrangement with the company. It is a copy that sits outside the question entirely.

Ten minutes, four settings

Set the arrangement each service already offers, print the one key that can be printed, and make sure one copy of the photographs lives somewhere that needs no permission at all. Then tell one other person where it is.

When a photo service shuts down Choosing a library drive

Frequently asked questions

What happens to my Google Photos when I die?

Nothing immediately, and then the inactivity policy applies. Google defines an inactive account as one that has not been used within a two-year period and reserves the right to delete it along with its activity and data. If you set up Inactive Account Manager beforehand you can name up to ten people to receive the data types you choose, and they are emailed a download link once the idle period you set has passed. If you set nothing up, Google says it may provide content from a deceased user's account in certain circumstances, after a careful review, but it cannot provide passwords or login details.

Can my family access my iCloud photos after I die?

If you added a Legacy Contact, yes. Apple describes a Legacy Contact as someone you choose to have access to certain data in your Apple Account after your death, which might include photos, messages, notes, files and device backups. They need two things to request it: the access key generated when you named them, and your death certificate. Without a Legacy Contact, Apple requires and verifies legal documentation, generally a death certificate and possibly a court order, and only one person can request access to a given account.

Does a will give my family access to my online accounts?

Not by itself. A will directs who should inherit, but the companies authenticate people through their own processes. Microsoft says it must first be formally served with a valid subpoena or court order before it will consider releasing a deceased user's information, and that doing so does not guarantee it will be able to assist. Apple asks for a court order naming the requester as the rightful inheritor. The useful move is to put an access key or code in the will, which is what Microsoft suggests for its OneDrive digital legacy code. Rules around digital assets vary by country, so this is not legal advice.

How long do photos stay in an account after someone dies?

Less time than most families expect. Microsoft states that Outlook.com and OneDrive accounts will be frozen after one year of inactivity and that files stored on OneDrive will be deleted shortly after, with Microsoft accounts expiring after two years. Google reserves the right to delete an account and its data after two years of inactivity. Notifications about pending deletion are sent to the account itself and to its recovery email, neither of which anyone is likely to be reading.

Can a Facebook legacy contact see my photos?

Only in a limited way. Facebook's legacy contact can write a pinned post, update the profile and cover photos, request removal of the account, and download a copy of what you shared — but that last one works only if you turned the feature on. They explicitly cannot log in to the account or read messages. What they can download is what was posted publicly, which is a resized selection rather than your original files.

What is the simplest way to make sure my family keeps the photographs?

Keep one copy of the originals somewhere that does not require anyone's permission to open, and tell a family member where it is. Every process described in this article exists because the photographs are held by a company on your behalf; a drive in a drawer is held by nobody, has no inactivity policy, and needs no death certificate. Set up the account arrangements as well, since they cost nothing, but treat them as the second line rather than the first.