# Data Protection Impact Assessment (DPIA) — Touch2Sign Platform

**Version:** 1.0 · **Date:** July 2026  
**Owner:** Security & Privacy Lead  
**Review:** Annual or on material change to IDV, eWitness, or AI features  
**Status:** Completed baseline assessment — residual risks accepted with documented mitigations

---

## 1. Why a DPIA is required

GDPR Article 35 requires a DPIA when processing is **likely to result in a high risk**, including:

- Systematic monitoring (security logs, signing audit trails)  
- Large-scale processing of identity data  
- Innovative technology (AI document analysis)  
- Use of identity verification and qualified trust services  

This DPIA covers the **Touch2Sign platform** as operated by Touch2Sign Ltd.

---

## 2. Description of processing

### 2.1 Core eSignature

Customers upload documents and invite signers. Touch2Sign stores documents in EU (Ireland), captures signatures (draw/type), records audit events (IP, timestamp, device), and produces evidence PDFs (SCCR).

### 2.2 Identity verification

- **OneID (UK):** Bank-backed verification for AES-level signing  
- **eID Easy (EU/IE):** Qualified trust service for QES  
- **Veriff (optional):** Document + selfie for enhanced ID proofing  

### 2.3 eWitness

Remote deed witnessing: witness SMS OTP, attestation declarations, optional IDV, Witness Trail Report PDF. Ireland flows add QES via eID Easy (hash-based; document stays on Touch2Sign).

### 2.4 AI (optional)

Anthropic API processes document text and signer questions when Aria/Sentinel is enabled by customer.

---

## 3. Necessity and proportionality

| Processing | Necessity | Proportionality |
|------------|-----------|-----------------|
| Audit trail (IP, device) | Required for non-repudiation and eIDAS evidence | Minimum fields; IP truncation under review |
| IDV | Required for AES/QES and regulated workflows | Only when customer enables; hash-only to QTSP for QES |
| eWitness data | Required for deed witnessing evidence | Limited to attestation + identity needed for level chosen |
| AI Q&A | Optional product feature | Customer-controlled; disclosure to signers; can disable |
| Security logs | Required for security and fraud prevention | Retention capped; LIA documented |

---

## 4. Risk assessment

| Risk | Likelihood | Impact | Inherent risk | Mitigations | Residual risk |
|------|------------|--------|---------------|-------------|---------------|
| Unauthorised access to documents | Low | High | Medium | Encryption, RBAC, MFA, AWS security | **Low** |
| IDV provider breach | Low | High | Medium | DPAs, minimise data sent, EU/UK providers | **Low–Medium** |
| Invalid deed / wrong signature level | Medium | High | **High** | QES for IE deeds; UX warnings; customer Terms; eIDAS guide | **Medium** — counsel memo pending |
| AI processing US transfer | Medium | Medium | Medium | SCCs, customer opt-in, minimise content | **Low–Medium** |
| Signer not informed (controller failure) | Medium | Medium | Medium | DPA places notice obligation on Customer | **Medium** (shared) |
| Audit log tampering | Low | High | Medium | Append-only audit, hashes, SCCR | **Low** |
| Excessive retention | Low | Medium | Low | Configurable retention; deletion API | **Low** |

---

## 5. Mitigations implemented

- [x] EU primary hosting (AWS eu-west-1)  
- [x] Encryption at rest and in transit  
- [x] GDPR Art 28 DPA for customers  
- [x] Sub-processor register and DPA §5 list  
- [x] SCCs for Anthropic and Stripe US processing  
- [x] ERSD / disclosure acceptance in signing flow  
- [x] Account deletion and export flows  
- [x] Breach notification procedure (72h)  
- [x] DSAR procedure and register  
- [ ] External legal memo — UK remote witnessing  
- [ ] External legal memo — Ireland QES chain  
- [ ] Formal IP truncation policy in audit logs  

---

## 6. Consultation

| Stakeholder | Input |
|-------------|-------|
| Engineering | Confirmed hash-only QES; retention controls |
| Privacy lead | This DPIA |
| DPO / counsel | Recommended before enterprise “high assurance” marketing |

---

## 7. Decision

**Proceed with processing** subject to:

1. Maintaining mitigations in Section 5  
2. Completing legal memos for eWitness IE/UK before scaled deed marketing  
3. Annual DPIA review  

| Approver | Role | Date |
|----------|------|------|
| _TBC_ | Privacy lead | |
| _TBC_ | CEO | |

---

## 8. Related documents

- [ROPA](/legal/policies/ropa)  
- [LIA — Security logging](../LIA_SECURITY_LOGGING.md)  
- [eIDAS Compliance Guide](/legal/policies/eidas-compliance)  
- [Breach notification](/legal/policies/breach-notification)
