- Many Windows PCs and Macs encrypt their data automatically. Without the password or a recovery key, the files can’t be recovered.
- Look for a printed recovery key in the person’s papers before trying anything else.
- Microsoft can’t recreate a lost recovery key, and Apple warns files can be lost for good.
- Using a dead person’s password is a legal grey area in the UK and the US. Treat it with care.
Leave the computer as it is, and don’t start resetting things. A reset can’t be undone. First find out whether the files are encrypted and whether a recovery key exists somewhere.
Windows PCs
On many Windows computers, Device Encryption switches on automatically when someone first signs in with a Microsoft account, and the recovery key is saved to that account. Microsoft lists the places a BitLocker recovery key might be:
- the person’s Microsoft account (aka.ms/myrecoverykey)
- a work or school account (aka.ms/aadrecoverykey), if it was a work machine
- printed on paper
- saved to a USB stick
A printout or USB stick in the person’s papers is the realistic find for a family. Microsoft is blunt about the rest: its support team “doesn’t have the ability to retrieve, provide, or recreate a lost BitLocker recovery key”. Without the key, the only option is a reset that removes all files.
If the key sits only in the Microsoft account, you’re back to Microsoft’s deceased-user process. Microsoft says it must be formally served with a valid subpoena or court order before it will consider releasing information.
Germany has its own route for heirs. Microsoft’s page lists none for the UK. See our Microsoft guide for how that works.
If it was a work laptop, contact the employer. The recovery key may be held in the work or school account.
Mac computers
Macs with Apple silicon or a T2 chip encrypt data by default. FileVault can be unlocked with the user’s Apple Account or a recovery key. Apple lists these ways to reset a Mac login password:
- The person’s Apple Account.
- The 24-character FileVault recovery key.
- Another administrator account on the same Mac.
On macOS Tahoe 26 and later, the recovery key may be stored in the Passwords app on the owner’s other devices. Apple warns that if both the password and the recovery key are lost, “your files and settings will be lost forever”. The last resort, erasing the Mac, removes every user account and its data.
If you are the person’s Apple Legacy Contact, you may find much of what was on the Mac in their iCloud Drive, iCloud Photos and backups, without touching the computer at all.
Before you erase anything
- Search the person’s papers for printed recovery keys, a password book, or a letter of instruction.
- Check for external drives and USB sticks. Backups may hold the files you want.
- Write down what the computer is for (bank letters, a business, photos) so you can ask the right company for copies.
The legal position: untested, not settled
Families often know the password. Using it is not as simple as it sounds, and the law hasn’t caught up.
In the UK, the Computer Misuse Act 1990 makes it an offence to access a computer or data knowing the access is unauthorised. Access is unauthorised if you aren’t entitled to control it and don’t have consent from someone who is. A Law Society private client article says using an online account after someone’s death without authority falls under section 1, and that this authority has to come from the provider, not from the person who died.
Other commentators call the area ambiguous: a 2015 Law Society of Scotland Journal article asked whether an executor who knows the password is breaking the Act. We found no reported prosecution of a relative or executor for this. Treat it as a legal risk that hasn’t been tested in court, not a settled rule either way.
A 2021 to 2022 bill to give next of kin access to devices did not become law, so there is no statutory right of access.
In the US, most states have adopted the Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA) or a version of it. It says a fiduciary, such as an executor acting within their duties, is an “authorized user” for the purposes of computer-fraud and unauthorised-access laws. The fiduciary may not impersonate the user.
The Uniform Law Commission’s own comment warns that federal courts applying the Computer Fraud and Abuse Act may not treat this as decisive. So even a formally appointed executor has protection under state law with an open question at federal level. Our United States page explains RUFADAA.
Never guess passwords or try to get round encryption. Guessing can trigger lockouts or erasure, and getting round security can breach the provider’s terms and computer-misuse law. If a lot depends on what’s on the machine, a solicitor or attorney can confirm what you’re allowed to do in your situation.