Everybody Is Already a Custodian. Three Built Something.
Everybody is already a custodian under RUFADAA. Three of them built tools for it. There is a provision in American estate law that outranks your will. It costs nothing to use. It takes four minutes to set. And it reaches almost nothing.
Not because it was drafted badly. Because it was drafted as an invitation. Almost nobody accepted.
The Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA) created a tier of authority that beats written estate documents. Then it left implementation to companies that never showed up. Three did. The rest didn’t. The result is a legal framework that works brilliantly in theory and barely exists in practice.
This matters to financial advisors and wealth managers because your clients hold digital assets worth protecting, and the legal tools you assume exist often don’t. Understanding what RUFADAA actually says, versus what people think it says, changes how you approach digital inheritance planning.

The Hierarchy That Changes Everything
The Revised Uniform Fiduciary Access to Digital Assets Act has been adopted in 47 states and the District of Columbia. Section 4 sets a priority order for who may reach a person’s digital records after they die.
First, a direction the user gives through an online tool provided by the custodian, in an agreement separate from the terms of service.
Second, a direction in a will, trust, or power of attorney.
Third, the provider’s terms of service.
The first tier beats the second. A setting you configure outranks a document you paid an attorney to draft.
That is a significant thing for a statute to say, and the drafters said it deliberately. A direction given in the moment, in the place where the asset lives, is better evidence of what a person wanted than a clause in a document they signed years earlier and never revisited.
This hierarchy matters because it determines how quickly an executor can access accounts. Tier 1 directions can transfer access in days. Tier 2 directions require probate court documentation and can take months. The difference between these timelines affects everything from paying bills to preventing account closures.
A setting you configure outranks a document you paid an attorney to draft. That is a significant thing for a statute to say, and the drafters said it deliberately.

The Word That Does All the Work
Read the first tier again. An online tool provided by the custodian.
Then read how the act defines a custodian.
A person that carries, maintains, processes, receives, or stores a digital asset of a user.
That is the whole definition. There is no requirement that the custodian be the provider of the account the direction concerns. There is no requirement that it be a large company, a communications provider, or anything else. It stores a digital asset of a user. That is the test.
The act does say the arrangement has to be an account, meaning a terms of service agreement under which the custodian stores the user’s digital asset. And the drafters’ own example of something that is not a custodian is an employer, excluded precisely because it never entered a terms of service agreement with the user.
So the boundary the drafters drew was about whether there is an agreement, not about who the company is.
This definition is broader than most practitioners realize. It includes any service that stores digital records under a terms of service agreement. Your client’s bank qualifies. Their insurance company qualifies. Their domain registrar qualifies. Every subscription service they use qualifies.
The definition was written this way intentionally. The drafters wanted to create space for any party willing to facilitate digital asset transfer. They wrote the statute to accommodate innovation, not restrict it to existing providers.

Everybody Is Already a Custodian: Three Companies Accepted
Google’s Inactive Account Manager. Apple’s Legacy Contact. Facebook’s Legacy Contact.
That is close to the entire list.
Not three categories. Three companies.
Your bank is a custodian. It carries, maintains, processes, receives, and stores your digital assets, and you have a terms of service agreement with it. It offers no online tool.
Your wireless carrier is a custodian. Your utility. Your insurer. Your domain registrar. Your payroll provider. Your cloud storage. Every subscription service you have ever signed up for.
All custodians under the definition. None of them built anything.
Microsoft is the clearest case. Four hundred million email users, unambiguously a custodian, and its process for a deceased user’s account is a Next of Kin request requiring legal documentation. That is Tier 2, at one of the largest email providers on earth.
Nothing in the act requires any of them to offer a tool. The language is permissive throughout. A custodian may provide one. The Cardozo Law Review describes it exactly that way: custodians can create an online tool.
This gap creates real problems for executors. When your client dies, their executor faces dozens of accounts. Three of them have a streamlined process. The rest require legal documentation, waiting periods, and often multiple rounds of correspondence. Some providers refuse access entirely and offer only data exports.

What That Produces
In 2020 Michael Kitces wrote that these tools were still in their infancy, and that it was reasonable to expect many more custodians would incorporate them in the coming years.
Six years later it is the same three companies.
Meanwhile a YouGov survey of 2,000 adults found that 3 percent of people have ever used the digital legacy tools offered by providers such as Google and Apple.
So the tier that outranks a will is available at three companies and used by three people in a hundred.
For every other account a person holds, the executor is in Tier 2. A written request, a certified death certificate, letters of appointment, and up to sixty days for the custodian to respond. Per provider. With the custodian free to choose whether to grant account access, partial access, or simply hand over a data export.
The statute compels disclosure. It does not compel access.
This distinction matters more than most advisors realize. An executor might receive a spreadsheet of transactions but no ability to log in and close the account. They might get read-only access but no way to transfer funds. They might get nothing at all if the provider decides the documentation is insufficient.
The process varies wildly by provider. One bank might respond in two weeks. Another takes eight. Some require notarized copies. Some accept scanned documents. There is no standard, and executors learn the differences by trial and error.

The Category With No Custodian at All
There is a second set of records in this story, and it is easy to miss because nobody stores it.
A person’s credentials. Recovery codes. Authenticator seeds. The answers to security questions. The instructions for reaching a hardware wallet.
Those are electronic records in which the individual holds a right or interest, which is the act’s definition of a digital asset. They exist independently of any account. They are not the property of Google or Chase or Verizon, and none of those companies has ever seen them.
Until somebody stores them, they have no custodian. Which means no online tool direction over them is possible, because there is nobody to provide the tool.
That is a strange thing to notice about a statute adopted almost everywhere. The most access-critical records a person holds sit outside the framework entirely, not because the act excludes them, but because nobody stepped into the role.
This creates the worst possible outcome. The records an executor needs most, the credentials that unlock everything else, have no legal pathway for transfer. They sit in password managers, encrypted notes, or written on paper in a safe deposit box. The executor who needs them has no standing to demand them from anyone, because no custodian holds them.
For advisors, this means the most valuable part of what to leave family besides a will often has no legal protection at all. Your client can designate beneficiaries for their bank accounts, but the password that unlocks their password manager has no equivalent designation.

Which Is the Point
None of this is a drafting failure. Sections 7 and 8 provide a complete procedure for every account. Slow and imperfect, and it exists.
The observation is narrower and more useful than that.
The act is more capable than practice has recognized. Everyone reads the first tier as something only the company holding your account can offer. The text does not say that, and the definition it does give is broad enough to reach any party that stores a user’s records under an agreement.
So a tier that beats a will has sat available for a decade, and almost nobody has built into it, because of an assumption that was never written down.
Fixing that does not require a new statute. It requires somebody to be the custodian of the records that currently have none.
That is what we do at Vesperly, and I would rather explain the reasoning than the product, because the reasoning is the interesting part.
The statutory framework already exists. The definition of custodian already covers any party that stores digital assets under an agreement. What was missing was not legal authority. What was missing was someone willing to step into the role for the records that matter most.
For financial advisors, this changes how you think about succession planning. You can now tell clients there is a legal pathway for transferring credentials, not just accounts. You can point to a custodian who stores those records and provides the online tool the statute describes. The gap that existed for a decade is closing, not because the law changed, but because someone read what it actually said.
What Is Still Open
Whether a designation over stored credentials reads as a first-tier online tool direction or a second-tier record is genuinely contested among practitioners who have written on this. I have had that argument with attorneys on both sides of it, and one of them moved.
Whether the fiduciary protections in Section 15 reach a designated recipient who is not the court-appointed personal representative is unresolved.
Whether Section 15(c), which makes a fiduciary’s authority subject to the governing instrument, caps what a recipient may do despite the Section 4 priority, has never been litigated.
A decade in, there is essentially no published case law on designated recipients at all.
Which means every argument in this piece, including mine, is built from statutory text and inference. There is nothing else to build from yet.
That absence is worth noticing on its own.
The lack of case law tells you something about how rarely these tools are used. When only three companies offer them, and only 3 percent of users configure them, disputes never reach court. The legal questions remain theoretical because the practical use is so limited.
For advisors, this means you are working in an area where best practices are still forming. The statute provides a framework. The case law will come. In the meantime, you make decisions based on statutory text, commentary from the drafters, and consultation with attorneys who specialize in this area.
That uncertainty is not a reason to avoid the tools. It is a reason to document your reasoning, work with qualified counsel, and help your clients make informed decisions about which tier of authority they want to rely on.
Frequently Asked Questions
What is RUFADAA and how does it affect digital asset transfer?
RUFADAA is the Revised Uniform Fiduciary Access to Digital Assets Act, adopted in 47 states. It creates a three-tier priority system for accessing digital accounts after death, with online tool designations outranking even written wills. This means a setting you configure with a custodian beats instructions in your estate documents.
Which companies offer Tier 1 online tools for digital legacy planning?
Only three major companies currently offer Tier 1 online tools: Google (Inactive Account Manager), Apple (Legacy Contact), and Facebook (Legacy Contact). Despite thousands of companies qualifying as custodians under RUFADAA’s definition, virtually no other providers have built these tools. Most accounts still require Tier 2 probate documentation for executor access.
What qualifies as a custodian under RUFADAA?
A custodian is any person or company that carries, maintains, processes, receives, or stores a digital asset of a user under a terms of service agreement. This includes banks, insurance companies, utilities, domain registrars, cloud storage providers, and every subscription service. The definition is intentionally broad and does not require the custodian to be the original account provider.
Why don’t more companies offer digital legacy tools?
RUFADAA’s language is permissive, not mandatory. Custodians may provide online tools but are not required to. Most companies assume only the original account provider can offer these tools, though the statute’s definition of custodian is broad enough to include any party storing digital assets under an agreement. This misreading has left the Tier 1 framework largely unused for a decade.
What happens to passwords and credentials under RUFADAA?
Passwords, recovery codes, authenticator seeds, and wallet instructions are digital assets under RUFADAA’s definition, but they typically have no custodian. Until someone stores them under a terms of service agreement, no online tool designation is possible. This creates a gap where the most access-critical records have no legal pathway for transfer under Tier 1.
How long does Tier 2 account access take compared to Tier 1?
Tier 1 online tool designations can transfer access in days. Tier 2 requires a written request, certified death certificate, letters of appointment, and up to 60 days per provider for response. Executors must repeat this process for every account, and providers can choose to grant full access, partial access, or only data exports. The difference is months of delay across dozens of accounts.
Is there any case law on RUFADAA designated recipients?
After a decade, there is essentially no published case law on designated recipients under RUFADAA. Questions about whether stored credentials qualify as Tier 1 directions, whether Section 15 protections extend to non-court-appointed recipients, and how Section 15(c) affects Tier 1 priority remain unresolved. All current guidance comes from statutory text and inference, not litigation.
The tier that beats a will has existed for ten years. Three companies built into it. The rest assumed someone else had to.
That assumption was never in the statute. The definition of custodian is broad enough to include anyone storing digital assets under an agreement. What was missing was not legal authority. What was missing was someone willing to read the statute as written and step into the role for the records that need it most.
For advisors working with clients on succession planning, this changes the conversation. You can now point to a legal framework that works, a definition that includes credential storage, and a tier of authority that outranks traditional estate documents. The gap is closing because someone finally accepted the invitation the drafters wrote a decade ago.
Ready to help your clients protect their digital assets with a custodian that actually built something? Learn how Vesperly provides the Tier 1 online tool framework that RUFADAA made possible but almost nobody implemented.
Jason Lysak is the founder of Vesperly, a verified legal succession platform that gives an executor lawful access to a deceased person’s accounts and records. He has consulted the attorney who chaired the Uniform Law Commission committee that drafted RUFADAA, the chair of ACTEC’s Digital Property Committee, and several ACTEC Fellows on the questions discussed here. Nothing in this article is legal advice.



