Professional-review draft: This supporting article is not approved for publication. It requires review by a named South African estates attorney and information-security professional. A registered tax practitioner must review the crypto and tax references.

A digital inventory should help an executor find an asset or account without exposing the credential that protects it. That distinction is easy to lose when people write a single list containing email addresses, passwords, device PINs and wallet recovery phrases.

The safer structure has three records: an inventory of what exists, an instruction record describing the intended outcome, and a separately protected recovery record. The digital estate planning hub explains how those records fit the will, executor appointment, provider tools, privacy and crypto tax evidence.

What belongs in the inventory

Record enough information to identify the item and the person or entity that owns it. Useful fields include:

  • Provider and non-secret identifier: the service name, account purpose and user name or reference that does not grant access.
  • Owner: the individual, company, trust or another person whose property or contractual right is involved.
  • Category: estate property, licensed account, personal content, business record, subscription, debt or an item that still needs professional classification.
  • Value and evidence: the valuation source, statements, transaction history, invoices, copyright or other ownership records.
  • Desired outcome: preserve, transfer, export, memorialise, close, cancel or refer to the executor.
  • Recovery pointer: the location of the protected method, not the password or key itself.

What must stay out of it

Do not place passwords, PINs, seed phrases, private keys, authenticator backup codes or answers to recovery questions in the inventory or will. Keep those secrets in a protected vault or other controlled system. Record who may locate that system, what proof of authority is required and what happens if the first trusted person cannot act.

A login does not prove legal authority. The Cybercrimes Act addresses unlawful access and certain unlawful uses of passwords or access codes. A provider may also require Letters of Executorship or Authority, identity documents, a death certificate or formal legal process.

Separate personal and business systems

Domains, hosting, source code, online stores, customer databases and advertising accounts may belong to a company even when the owner created them under a personal email address. Record the legal owner and current administrators. Where the provider permits it, use role-based company access and more than one authorised administrator.

The inventory may contain information about living customers, employees or correspondents. POPIA defines personal information by reference to an identifiable living natural person and, where applicable, an existing juristic person. Confidentiality, contract and intellectual-property duties can also apply.

Add provider legacy settings

Record whether Apple Legacy Contact, Google Inactive Account Manager, Facebook legacy contact or another provider feature is configured, who was chosen and when the setting was last checked. These tools have different powers and documentation rules. None replaces the will, executor appointment or secure recovery record.

Give crypto its own evidence pack

SARS states that a crypto asset is movable property in the deceased estate, valued at fair market value at death for estate-duty purposes and declared in the relevant tax and estate records. Keep acquisition and disposal history, base-cost evidence, custody type, wallet or exchange identifiers and the valuation source. Store the recovery secret separately.

Set review triggers

Review the inventory after changing the will, executor, primary email, phone number, password manager, device, wallet custody, business administrator or provider. Date each review and identify who maintains the record. Do not rely on a promise that a platform setting or recovery route will remain available.

Editorial record and sources

Author: Muhammad Khan, Director and Information Officer, K2023120042 (South Africa) (Pty) Ltd t/a willandtrust.co.za. Business and editorial role only. No legal, tax, fiduciary, cybersecurity or forensic credential is claimed.

Review status: Named professional reviewers, credentials, professional bodies and review dates are not yet assigned. Official sources checked 3 August 2026 include the Administration of Estates Act 66 of 1965, Cybercrimes Act 19 of 2020, Protection of Personal Information Act 4 of 2013, SARS deceased-estate and crypto guidance, FSCA crypto guidance, and current Apple, Google, Meta and Microsoft deceased-account pages.

Scope: This article is an inventory method. It does not decide ownership, grant access, interpret provider terms, recover a wallet, preserve evidence, calculate tax or provide legal, tax, security or financial advice.