# Data Subject Access Request (DSAR) Procedure

**Touch2Sign Ltd**  
**Version:** 1.0  
**Effective date:** 11 July 2026  
**Owner:** [DPO / Privacy Lead]  
**Approved by:** Robert — CEO / Managing Director  
**Next review:** 11 July 2027

---

## 1. Purpose

Define how Touch2Sign receives, verifies, and responds to requests from individuals exercising rights under GDPR Articles 15–22 and UK GDPR. Ensures responses within statutory timeframes and clarifies Touch2Sign's role as controller vs processor.

## 2. Scope

Applies to requests from:

- Signers and witnesses whose personal data Touch2Sign processes  
- Customer organisation users (admins, senders)  
- Former employees (handled under HR policy — separate process)  

Covers rights of access, rectification, erasure, restriction, portability, and objection.

## 3. Contact channel

| Channel | Detail |
|---------|--------|
| **Primary email** | **privacy@touch2sign.com** |
| **Postal** | [Touch2Sign Ltd registered address] |
| **Web form** | Link from Privacy Policy (when published) |

All DSARs logged in **DSAR Register** within **2 business days** of receipt.

## 4. Controller vs processor

| Scenario | Touch2Sign role | Who responds |
|----------|-----------------|--------------|
| Signer data processed on behalf of customer (documents, audit trail) | **Processor** | Forward to customer controller; assist per DPA §6 |
| Touch2Sign account billing, marketing, website analytics | **Controller** | Touch2Sign responds directly |
| Employee data | **Controller** | HR + DPO |

When Touch2Sign is processor, the **customer organisation** is controller and primary respondent. Touch2Sign assists within **30 days** and DPA terms.

## 5. SLA and extensions

| Milestone | Target |
|-----------|--------|
| Acknowledgement of receipt | **5 business days** |
| Identity verification complete | **10 business days** |
| Full response | **30 calendar days** from receipt |
| Extension (complex requests) | + **60 days** with reason notified to data subject |
| Processor assistance to customer | **30 calendar days** from customer request |

## 6. Request handling process

### Step 1 — Intake and logging

Record in DSAR Register:

| Field | Description |
|-------|-------------|
| DSAR ID | DSAR-YYYY-NNN |
| Date received | |
| Requester name and contact | |
| Rights exercised | Access / erasure / etc. |
| Touch2Sign role | Controller / processor |
| Customer org (if applicable) | |
| Status | Open / verifying / in progress / closed |

### Step 2 — Identity verification

Before disclosing personal data:

- Match requester to records (email verification, signing history, org admin confirmation)  
- Request additional ID only if necessary and proportionate  
- Do not disclose data to unverified third parties  
- For processor requests: confirm requester with customer controller where appropriate  

### Step 3 — Scope and search

Search relevant systems:

| System | Data |
|--------|------|
| RDS | `users`, `recipients`, `audit_log`, org membership |
| S3 | Signed PDFs linked to requester (if access request) |
| Cognito | Account attributes |
| Support tickets | Tickets referencing requester |
| Stripe | Billing metadata (controller requests only) |
| Sub-processors | Query OneID / eID Easy if IDV data requested — via DPA |

Document search scope and any data not found.

### Step 4 — Legal review

DPO reviews for exemptions (Art 15(4), manifestly unfounded/excessive requests Art 12(5)), conflicts with other data subjects' rights, and erasure limitations (signature evidence retention).

### Step 5 — Response

Provide response in **structured, commonly used, machine-readable format** where portability requested (JSON or CSV + PDF copies of documents).

**Access response includes:**

- Confirmation of processing  
- Categories of data and purposes  
- Recipients or categories (sub-processors summary)  
- Retention period  
- Rights and complaint authority (DPC / ICO)  
- Copy of personal data  

### Step 6 — Closure

Update DSAR Register; retain record **3 years**.

## 7. Right-specific guidance

| Right | Touch2Sign action |
|-------|-------------------|
| **Access (Art 15)** | Export personal data; explain processing |
| **Rectification (Art 16)** | Correct inaccurate account data; notify customer controller for document content |
| **Erasure (Art 17)** | Per Data Retention Policy; may refuse where signature evidence required |
| **Restriction (Art 18)** | Flag account pending dispute resolution |
| **Portability (Art 20)** | Provide machine-readable export where processing automated + consent/contract |
| **Objection (Art 21)** | Assess; stop marketing; document legitimate interest balancing |

## 8. Refusal and partial response

If request refused or partially fulfilled:

- Explain reasons within **30 days**  
- Inform data subject of right to complain to DPC (Ireland) or ICO (UK)  
- Document rationale in DSAR Register  

Manifestly unfounded or excessive requests: charge reasonable fee or refuse per Art 12(5) — DPO + Legal approval required.

## 9. Customer (controller) coordination

When request concerns signer data for a customer organisation:

1. Notify customer within **5 business days**  
2. Provide tools or exports to assist (DPA §6)  
3. Do not release customer's confidential document content to wrong party  
4. Customer leads communication with data subject unless agreed otherwise  

Template available to customers in DPA annex.

## 10. Fees

First request free. Repeated or manifestly unfounded requests may incur reasonable administrative fee per GDPR Art 12(5).

## 11. Related documents

- Privacy Policy  
- Data Processing Agreement  
- Data Retention & Disposal Policy  
- Breach Notification Procedure  
- SUB_PROCESSORS.md  

## 12. Review

Reviewed **annually** and after significant DSAR volume or regulatory guidance changes.

---

**Approval**

| Name | Role | Signature | Date |
|------|------|-----------|------|
| Robert | CEO | Electronic | 11 July 2026 |
| | DPO / Privacy Lead | | |
