# Breach Notification Procedure

**Touch2Sign Ltd**  
**Version:** 1.0  
**Effective date:** 11 July 2026  
**Owner:** [DPO / Privacy Lead]  
**Approved by:** Robert — CEO / Managing Director  
**Next review:** 11 July 2027

---

## 1. Purpose

Define how Touch2Sign assesses personal data breaches and meets notification obligations under GDPR Articles 33–34, UK GDPR, and customer DPA commitments. This procedure complements the **Incident Response Plan** — IR handles containment; this procedure handles regulatory and data subject notification decisions.

## 2. Scope

Applies when a security incident may involve:

- Unauthorised access to personal data  
- Accidental loss or destruction of personal data  
- Unauthorised alteration of personal data  
- Personal data disclosed to unauthorised recipients  

Includes breaches at Touch2Sign and sub-processors (AWS, Stripe, OneID, eID Easy, Anthropic, etc.) affecting Touch2Sign customer data.

## 3. Definitions

**Personal data breach** (GDPR Art 4(12)): a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

Not every security incident is a personal data breach — e.g. encrypted data exfiltrated with keys intact may not be notifiable if risk to rights and freedoms is unlikely.

## 4. Roles

| Role | Responsibility |
|------|----------------|
| **DPO / Privacy Lead** | Breach assessment; authority notification; Art 34 decision |
| **Incident Commander** | Coordinates IR; provides technical facts |
| **CEO / Comms** | Customer (controller) notification; public statements |
| **Legal counsel** | Regulatory strategy; high-risk breach advice |

Primary contact: **privacy@touch2sign.com**

## 5. Timeline overview

| Milestone | Target |
|-----------|--------|
| Incident detected → DPO notified | **30 minutes** (P1/P2) |
| Initial breach assessment complete | **24 hours** |
| Supervisory authority notification (if required) | **72 hours** from awareness |
| Customer (controller) notification | **Without undue delay** |
| Data subject notification (if required) | **Without undue delay** after Art 33 |

**Awareness** = when Touch2Sign has a reasonable degree of certainty that a personal data breach has occurred.

## 6. Breach assessment workflow

Execute in parallel with **Incident Response Plan** Phase 3.

### 6.1 Assessment checklist

- [ ] Did a personal data breach occur? (Art 4(12))  
- [ ] When did Touch2Sign become aware?  
- [ ] What categories of personal data? (names, emails, IDV, document content, IP addresses)  
- [ ] Approximate number of data subjects and records  
- [ ] Likely consequences for data subjects  
- [ ] Risk to rights and freedoms — **high** or **low**?  
- [ ] Was data encrypted such that it remains unintelligible to unauthorised parties?  
- [ ] Touch2Sign role: **processor** (notify customer controllers) or **controller** (direct Art 33)?  
- [ ] Sub-processor involved? (Contact vendor; document in incident register)  

### 6.2 Notification decision matrix

| Scenario | ICO / DPC (Art 33) | Data subjects (Art 34) | Customers (controllers) |
|----------|-------------------|------------------------|-------------------------|
| Encrypted data lost; keys secure | Likely not required | Likely not required | Inform if contract requires |
| Email addresses exposed; phishing risk | **Notify** | Consider notify | **Notify without undue delay** |
| Customer documents exposed | **Notify** | **Likely notify** | **Notify immediately** |
| IDV results exposed | **Notify** | **Notify** | **Notify immediately** |
| Internal admin error; no external access | Document; likely not notify | Not required | Case by case |
| Sub-processor breach affecting Touch2Sign data | Assess; **notify if Touch2Sign is controller** | Per Art 34 | **Notify customers** as processor |

When uncertain, DPO errs toward notification within 72 hours.

## 7. Supervisory authority notification (72 hours)

### 7.1 Ireland (DPC) — Touch2Sign Ltd primary establishment

- **Website:** https://www.dataprotection.ie/  
- **Phone:** +353 578 684 800  
- Use official breach notification form  

### 7.2 UK (ICO) — if UK data subjects materially affected

- **Website:** https://ico.org.uk/for-organisations/report-a-breach/  
- **Phone:** 0303 123 1113  

### 7.3 Required content (Art 33(3))

1. Nature of the personal data breach including categories and approximate numbers  
2. DPO contact details (**privacy@touch2sign.com**)  
3. Likely consequences of the breach  
4. Measures taken or proposed to address the breach and mitigate harm  

If full information unavailable at 72 hours, provide in phases without undue further delay.

## 8. Customer notification (processor role)

Touch2Sign acts as **processor** for most customer document and signer data. On breach affecting customer data:

1. Notify affected **customer organisations (controllers)** without undue delay per DPA §4  
2. Provide facts needed for their own Art 33/34 obligations  
3. Do not publicly name customers without agreement  

Use template from **Incident Response Plan** §6.2; customise with confirmed facts only.

## 9. Data subject notification (Art 34)

Required when breach is **likely to result in high risk** to rights and freedoms of individuals, unless:

- Data was encrypted (Art 34(3)(a))  
- Subsequent measures eliminate high risk (Art 34(3)(b))  
- Disproportionate effort — public communication instead (Art 34(3)(c))  

Notification in clear and plain language:

- Nature of the breach  
- DPO contact  
- Likely consequences  
- Measures taken and recommended user actions (e.g. change password, beware phishing)  

Coordinate with customer controllers — they may lead communication to their signers.

## 10. Documentation

Every breach assessment recorded regardless of notification outcome:

| Field | Description |
|-------|-------------|
| Breach ID | BRH-YYYY-NNN (link to INC-YYYY-NNN) |
| Date aware | UTC |
| Description | Factual summary |
| Data categories | |
| Subjects affected | Count / range |
| Art 33 required? | Y/N + rationale |
| Authority notified | DPC / ICO / NA + date |
| Art 34 required? | Y/N |
| Customers notified | Y/N + date |
| Remediation | |
| Closed date | |

Retain **3 years** minimum.

## 11. Link to Incident Response Plan

| IR Plan section | Breach procedure link |
|-----------------|-------------------------|
| §5 Phase 3 — Assessment | Use this procedure's checklist |
| §6.2 Customer template | Processor notification |
| §6.3 ICO/DPC template | Supervisory authority |
| §7 Touch2Sign playbooks | Technical facts for assessment |
| §9 Incident register | Link BRH ID to INC ID |

Full incident response: **`INCIDENT_RESPONSE_PLAN.md`**

## 12. Related documents

- Incident Response Plan  
- DSAR Procedure  
- Data Processing Agreement  
- Vendor & Sub-processor Management Policy  
- Information Security Policy  

## 13. Review

Reviewed **annually**, after any notifiable breach, and when supervisory authority guidance changes.

---

**Approval**

| Name | Role | Signature | Date |
|------|------|-----------|------|
| Robert | CEO | Electronic | 11 July 2026 |
| | DPO / Privacy Lead | | |
