# Minimum Compliance Pack — Touch2Sign

**Purpose:** Single checklist for **basic** GDPR, privacy, and eIDAS compliance — enough to onboard customers, respond to due diligence, and avoid common gaps.  
**Owner:** Security & Privacy Lead  
**Last updated:** July 2026  
**Status:** Operational baseline (legal counsel review recommended before enterprise claims)

---

## How to use this pack

1. Work through **Section A** (customer-facing) — all items must be live on the website.  
2. Work through **Section B** (internal GDPR) — keep registers updated quarterly.  
3. Work through **Section C** (eIDAS) — product + customer guidance in place.  
4. Schedule **Section D** (counsel sign-off) before marketing “fully compliant” language.

---

## Section A — Customer-facing (must be published)

| # | Document | Location | Status |
|---|----------|----------|--------|
| A1 | **Privacy Policy** | [/privacy](/privacy) | ✅ Live |
| A2 | **Terms of Service** | [/terms](/terms) | ✅ Live |
| A3 | **Data Processing Agreement (GDPR Art 28)** | [/legal/dpa](/legal/dpa) | ✅ Live |
| A4 | **Cookie Policy** | [/legal/policies/cookie-policy](/legal/policies/cookie-policy) | ✅ Draft v1.0 |
| A5 | **Trust & Security page** | [/trust-security](/trust-security) | ✅ Live |
| A6 | **Policy Library hub** | [/legal/policies](/legal/policies) | ✅ Live |

**Contacts (must be monitored):**

| Role | Email |
|------|-------|
| Privacy / DSAR / breach | privacy@touch2sign.com |
| Legal / DPA | legal@touch2sign.com |
| Security incidents | security@touch2sign.com |

---

## Section B — GDPR / UK GDPR (internal + auditable)

| # | Document | Location | Status |
|---|----------|----------|--------|
| B1 | **Record of Processing Activities (ROPA)** | [ROPA.md](./ROPA.md) · [/legal/policies/ropa](/legal/policies/ropa) | ✅ v1.0 |
| B2 | **Data Protection Impact Assessment (DPIA)** | [DPIA_PLATFORM.md](./DPIA_PLATFORM.md) · [/legal/policies/dpia](/legal/policies/dpia) | ✅ v1.0 |
| B3 | **Legitimate Interest Assessment (security logs)** | [LIA_SECURITY_LOGGING.md](./LIA_SECURITY_LOGGING.md) | ✅ v1.0 |
| B4 | **Sub-processor register** | [SUB_PROCESSORS.md](./SUB_PROCESSORS.md) | ✅ Maintain quarterly |
| B5 | **International transfer register** | [INTERNATIONAL_TRANSFER_REGISTER.md](./INTERNATIONAL_TRANSFER_REGISTER.md) | ✅ v1.0 |
| B6 | **DSAR procedure** | [/legal/policies/dsar](/legal/policies/dsar) | ✅ Draft v1.0 |
| B7 | **DSAR register (log)** | [DSAR_REGISTER.md](./DSAR_REGISTER.md) | ✅ Template — log each request |
| B8 | **Breach notification procedure** | [/legal/policies/breach-notification](/legal/policies/breach-notification) | ✅ Draft v1.0 |
| B9 | **Breach register (log)** | [BREACH_REGISTER.md](./BREACH_REGISTER.md) | ✅ Template — log all incidents |
| B10 | **Incident response plan** | [/legal/policies/incident-response](/legal/policies/incident-response) | ✅ Draft v1.0 |
| B11 | **Data retention & disposal** | [/legal/policies/data-retention](/legal/policies/data-retention) | ✅ Draft v1.0 |

### GDPR roles

| Role | Touch2Sign position |
|------|---------------------|
| **Processor** | Signing workflows, document storage, IDV on customer instruction |
| **Controller** | Account registration, billing, support, security logging, marketing |

---

## Section C — eIDAS / UK electronic signatures

| # | Document / control | Location | Status |
|---|------------------|----------|--------|
| C1 | **eIDAS compliance guide** | [EIDAS_COMPLIANCE_GUIDE.md](./EIDAS_COMPLIANCE_GUIDE.md) · [/legal/policies/eidas-compliance](/legal/policies/eidas-compliance) | ✅ v1.0 |
| C2 | **Signature levels (SES / AES / QES)** | Product — OneID, eID Easy | ✅ Built |
| C3 | **Audit trail & SCCR evidence** | Signing pipeline | ✅ Built |
| C4 | **eWitness (UK + IE)** | Witness portal, trail PDF, QES ASiC-E | ✅ Built |
| C5 | **7-year default retention** | Org settings | ✅ Built |
| C6 | **Customer responsibility in Terms** | [/terms](/terms) §5 | ✅ Updated |
| C7 | **UK remote deed legal memo** | External counsel | ☐ Pending |
| C8 | **Ireland QES chain legal memo** | External counsel | ☐ Pending |

**Approved marketing language:** “eIDAS-aligned” · “designed for eIDAS workflows” · “supports SES, AES, and QES via qualified trust service providers”  
**Do not claim:** “eIDAS certified” · “legally valid in all circumstances” · “ISO 27001 certified” (programme in progress)

---

## Section D — Counsel & CEO sign-off (recommended)

| Item | Owner | Target |
|------|-------|--------|
| Privacy Policy legal review | Legal | Before enterprise sales |
| Terms + DPA legal review | Legal | Before enterprise sales |
| UK eWitness opinion (LP(MP)A) | External counsel | Before IE/UK deed marketing |
| Ireland QES platform opinion | External counsel | Before IE deed scale |
| CEO approval — draft policies v1.0 | CEO | 30 days |
| Tabletop breach exercise | Security lead | 90 days |

---

## Section E — Nice-to-have (not minimum)

SOC 2 Type II · ISO 27001 certification · HIPAA BAA · Full 20-policy ISMS publication · Penetration test report

See [FULL_COMPLIANCE_PLAN.md](./FULL_COMPLIANCE_PLAN.md) and [ROADMAP.md](./ROADMAP.md).

---

## Quarterly maintenance (30 minutes)

- [ ] Review [SUB_PROCESSORS.md](./SUB_PROCESSORS.md) — any new vendors?
- [ ] Update DPA §5 table if sub-processors changed (30-day customer notice)
- [ ] Check [BREACH_REGISTER.md](./BREACH_REGISTER.md) and [DSAR_REGISTER.md](./DSAR_REGISTER.md)
- [ ] Confirm privacy@ and legal@ mailboxes monitored
- [ ] Re-read [EIDAS_COMPLIANCE_GUIDE.md](./EIDAS_COMPLIANCE_GUIDE.md) if product/marketing changed

---

## Quick links

| Audience | Start here |
|----------|------------|
| **Internal team** | This document |
| **Customers / prospects** | [/trust-security](/trust-security) → Policy Library |
| **Due diligence** | ROPA + DPIA + DPA + Sub-processors |
| **Developers** | [EIDAS_READINESS.md](./EIDAS_READINESS.md) · [GDPR_READINESS.md](./GDPR_READINESS.md)
