# Legitimate Interest Assessment — Security Logging

**Version:** 1.0 · **Date:** July 2026  
**Processing:** IP addresses, user agents, authentication events, API access logs  
**Lawful basis:** GDPR Art 6(1)(f) — Legitimate interests  
**Owner:** Security & Privacy Lead

---

## 1. Purpose of processing

Touch2Sign collects limited technical data to:

- Detect and prevent unauthorised access and fraud  
- Investigate security incidents and support breach notification  
- Maintain platform availability and diagnose errors  
- Support non-repudiation evidence in signing audit trails (signer IP as part of audit)

---

## 2. Necessity

Without security logging, Touch2Sign cannot:

- Detect credential stuffing or account takeover  
- Meet DPA commitments to implement appropriate security (Art 32)  
- Respond to supervisory authority or customer audit requests  
- Correlate signing events with suspicious access patterns  

Alternative considered: **No logging** — rejected as disproportionate security risk for an e-signature platform.

---

## 3. Balancing test

| Factor | Assessment |
|--------|------------|
| **Nature of data** | IP (may be truncated), user agent, timestamps — not special category |
| **Data subject expectation** | Users expect SaaS providers to secure accounts; signing audit IP is industry standard |
| **Impact on data subjects** | Low if retention limited and access restricted |
| **Safeguards** | RBAC on logs, EU storage, retention 90–365 days (security) / per signing retention (audit), encryption |
| **Opt-out** | Not practical for core security; signing audit required for service delivery (contract/legal obligation) |

**Conclusion:** Legitimate interest is **valid** for security logging. Signing audit IP is primarily **contract / legal obligation** (eIDAS evidence), not LIA alone.

---

## 4. Data minimisation actions

- [x] Restrict log access to authorised staff  
- [x] Store logs in EU region  
- [ ] Implement IP truncation/hashing for non-audit security logs (target: Q4 2026)  
- [x] Document retention in [Data retention policy](/legal/policies/data-retention)

---

## 5. Review

**Next review:** July 2027 or if logging scope expands (e.g. behavioural analytics).

**Approver:** _Privacy lead · Date: _
