How to Set Up Trusted Contacts for a Parent
The Difference Between Having Passwords and Having Authority
Many families operate on informal password sharing — a sticky note on the monitor, a notebook in the kitchen drawer, passwords texted between family members. This works until it doesn't. The parent changes a password and forgets to update the list. A platform detects an unfamiliar device and locks the account. Or worst case, a family member uses shared credentials to access accounts without the parent's knowledge, creating legal exposure under anti-hacking statutes.
The better approach is using the formal trusted contact and emergency access features that major platforms now offer. These give designated family members a documented, authorized pathway to access accounts — one that survives incapacity, satisfies platform terms of service, and protects both the parent and the caregiver legally.
Apple Legacy Contact
Apple's Legacy Contact feature lets your parent designate someone who can access their Apple account data after death. It's found under Settings → Apple ID → Sign-In & Security → Legacy Contact.
When your parent adds you as a Legacy Contact, Apple generates a unique access key — an 88-character code. Store this key in your own password manager or print it and keep it in a secure location. After your parent's death, you submit this key along with a death certificate through digital-legacy.apple.com. Apple then grants access to iCloud photos, notes, files, mail, messages, calendars, and device backups.
What Legacy Contact does not cover: Keychain passwords, payment information, subscriptions, and purchased media (books, movies, music) are explicitly excluded. The access window expires three years after approval.
Limitations for living parents: Legacy Contact is a post-death mechanism only. If your parent is alive but incapacitated, Legacy Contact won't help. For that scenario, you need the parent's device passcode and Apple ID password — or a court order.
Google Inactive Account Manager
Google's Inactive Account Manager (myaccount.google.com/inactive) is the most flexible trusted contact tool among major platforms because it activates automatically after a configurable period of inactivity — not just after death.
Your parent sets an inactivity timer (3 to 18 months) and designates up to ten trusted contacts. When the timer expires, Google sends a verification text to the parent's phone. If the parent doesn't respond, each designated contact receives an email notification and can download the data categories the parent authorized — Gmail, Drive, Photos, YouTube, and more.
Setup takes five minutes. Log into the parent's Google account → My Account → Data & Privacy → scroll to "Make a plan for your digital legacy" → Start. Walk through the wizard: choose the inactivity period (3 months is reasonable for most caregiving situations), add trusted contacts with their email addresses, and select which data categories each contact can access.
The auto-delete option: The same wizard offers the option to automatically delete the account after the inactivity period. For most parents, leave auto-delete OFF — you want the data preserved, not destroyed.
Free Download
Get the Managing a Parent's Digital Life and Passwords — Quick-Start Checklist
Everything in this article as a printable checklist — plus action plans and reference guides you can start using today.
Password Manager Emergency Access
If your parent uses a password manager, its emergency access feature is arguably the most valuable trusted contact tool available, because it gives access to every credential in the vault — not just one platform.
Bitwarden Emergency Access: Your parent invites you as an emergency contact through the Bitwarden web vault (Settings → Emergency Access → Invite). They choose an access level ("View" for read-only access to vault items, or "Takeover" which lets you reset the master password) and a wait time (1 to 30 days). When you initiate an emergency access request, Bitwarden notifies the parent. If the parent doesn't reject the request within the wait period, access is granted automatically.
1Password Emergency Kit: 1Password doesn't have a formal emergency access protocol. Instead, it generates a printable Emergency Kit PDF containing the account email, secret key, and a space for the master password. If your parent fills in the master password and stores the Emergency Kit securely (a fireproof safe, a sealed envelope with a trusted attorney), any authorized person with that document can access the full vault.
Browser-based password managers (Chrome, Safari/Keychain): These lack formal emergency access features. Chrome passwords are accessible to anyone who can log into the parent's Google account — which is why Google's Inactive Account Manager matters so much. Apple Keychain is locked to the parent's Apple devices and Apple ID, with no separate emergency access path.
Bank and Brokerage Trusted Contacts
Since 2018, SEC regulations have required broker-dealers to request that account holders designate a trusted contact person. Many banks have adopted similar practices voluntarily.
A bank trusted contact is NOT the same as an authorized signer or power of attorney agent. The trusted contact's role is narrow: the institution can reach out to them if they suspect the account holder is being financially exploited, has diminished capacity, or can't be reached. The trusted contact cannot view the account, make transactions, or receive account information — they simply serve as a secondary point of contact for the institution's fraud prevention team.
Despite the limited authority, this designation matters. It creates a documented, pre-authorized pathway for the bank to contact you if something goes wrong, rather than being blocked by privacy rules from reaching out to anyone.
How to set it up: Call each financial institution and ask to add a trusted contact person. Most banks and brokerages can do this over the phone with the account holder present, or via a form available online or at a branch.
The Legal Side of Password Sharing
Using a parent's passwords without formal authorization can create legal exposure, even when intentions are good. The federal Computer Fraud and Abuse Act criminalizes "unauthorized access" to protected computers. The Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA), adopted by 46 states, establishes a strict priority hierarchy: platform-level settings (like Legacy Contact or Inactive Account Manager) override even a will or power of attorney.
This means that configuring platform trusted contacts isn't just convenient — it's legally protective. A formal trusted contact designation through Apple, Google, or a password manager constitutes documented authorization that shields the caregiver from accusations of unauthorized access.
For parents who are still sharing passwords informally, the transition to formal trusted contact designations can happen gradually. Set up one platform at a time during a regular visit. The informal password list stays as a backup, but the formal mechanisms become the primary access pathway.
The Managing a Parent's Digital Life toolkit includes step-by-step setup guides for every major platform's trusted contact and legacy features, plus the legal authorization templates that ensure your access is documented and defensible.
Get Your Free Managing a Parent's Digital Life and Passwords — Quick-Start Checklist
Download the Managing a Parent's Digital Life and Passwords — Quick-Start Checklist — a printable guide with checklists, scripts, and action plans you can start using today.