Touch2Sign Policy Library
← All policies

Breach Notification Procedure

Version 1.0 · Draft · Owner: DPO

Download .md →

Breach Notification Procedure

Touch2Sign Ltd

Version: 1.0

Effective date: 11 July 2026

Owner: [DPO / Privacy Lead]

Approved by: Robert — CEO / Managing Director

Next review: 11 July 2027


1. Purpose

Define how Touch2Sign assesses personal data breaches and meets notification obligations under GDPR Articles 33–34, UK GDPR, and customer DPA commitments. This procedure complements the Incident Response Plan — IR handles containment; this procedure handles regulatory and data subject notification decisions.

2. Scope

Applies when a security incident may involve:

  • Unauthorised access to personal data
  • Accidental loss or destruction of personal data
  • Unauthorised alteration of personal data
  • Personal data disclosed to unauthorised recipients

Includes breaches at Touch2Sign and sub-processors (AWS, Stripe, OneID, eID Easy, Anthropic, etc.) affecting Touch2Sign customer data.

3. Definitions

Personal data breach (GDPR Art 4(12)): a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

Not every security incident is a personal data breach — e.g. encrypted data exfiltrated with keys intact may not be notifiable if risk to rights and freedoms is unlikely.

4. Roles

Role Responsibility
DPO / Privacy Lead Breach assessment; authority notification; Art 34 decision
Incident Commander Coordinates IR; provides technical facts
CEO / Comms Customer (controller) notification; public statements
Legal counsel Regulatory strategy; high-risk breach advice

Primary contact: privacy@touch2sign.com

5. Timeline overview

Milestone Target
Incident detected → DPO notified 30 minutes (P1/P2)
Initial breach assessment complete 24 hours
Supervisory authority notification (if required) 72 hours from awareness
Customer (controller) notification Without undue delay
Data subject notification (if required) Without undue delay after Art 33

Awareness = when Touch2Sign has a reasonable degree of certainty that a personal data breach has occurred.

6. Breach assessment workflow

Execute in parallel with Incident Response Plan Phase 3.

6.1 Assessment checklist

  • [ ] Did a personal data breach occur? (Art 4(12))
  • [ ] When did Touch2Sign become aware?
  • [ ] What categories of personal data? (names, emails, IDV, document content, IP addresses)
  • [ ] Approximate number of data subjects and records
  • [ ] Likely consequences for data subjects
  • [ ] Risk to rights and freedoms — high or low?
  • [ ] Was data encrypted such that it remains unintelligible to unauthorised parties?
  • [ ] Touch2Sign role: processor (notify customer controllers) or controller (direct Art 33)?
  • [ ] Sub-processor involved? (Contact vendor; document in incident register)

6.2 Notification decision matrix

Scenario ICO / DPC (Art 33) Data subjects (Art 34) Customers (controllers)
Encrypted data lost; keys secure Likely not required Likely not required Inform if contract requires
Email addresses exposed; phishing risk Notify Consider notify Notify without undue delay
Customer documents exposed Notify Likely notify Notify immediately
IDV results exposed Notify Notify Notify immediately
Internal admin error; no external access Document; likely not notify Not required Case by case
Sub-processor breach affecting Touch2Sign data Assess; notify if Touch2Sign is controller Per Art 34 Notify customers as processor

When uncertain, DPO errs toward notification within 72 hours.

7. Supervisory authority notification (72 hours)

7.1 Ireland (DPC) — Touch2Sign Ltd primary establishment

  • Website: https://www.dataprotection.ie/
  • Phone: +353 578 684 800
  • Use official breach notification form

7.2 UK (ICO) — if UK data subjects materially affected

  • Website: https://ico.org.uk/for-organisations/report-a-breach/
  • Phone: 0303 123 1113

7.3 Required content (Art 33(3))

  1. Nature of the personal data breach including categories and approximate numbers
  2. DPO contact details (privacy@touch2sign.com)
  3. Likely consequences of the breach
  4. Measures taken or proposed to address the breach and mitigate harm

If full information unavailable at 72 hours, provide in phases without undue further delay.

8. Customer notification (processor role)

Touch2Sign acts as processor for most customer document and signer data. On breach affecting customer data:

  1. Notify affected customer organisations (controllers) without undue delay per DPA §4
  2. Provide facts needed for their own Art 33/34 obligations
  3. Do not publicly name customers without agreement

Use template from Incident Response Plan §6.2; customise with confirmed facts only.

9. Data subject notification (Art 34)

Required when breach is likely to result in high risk to rights and freedoms of individuals, unless:

  • Data was encrypted (Art 34(3)(a))
  • Subsequent measures eliminate high risk (Art 34(3)(b))
  • Disproportionate effort — public communication instead (Art 34(3)(c))

Notification in clear and plain language:

  • Nature of the breach
  • DPO contact
  • Likely consequences
  • Measures taken and recommended user actions (e.g. change password, beware phishing)

Coordinate with customer controllers — they may lead communication to their signers.

10. Documentation

Every breach assessment recorded regardless of notification outcome:

Field Description
Breach ID BRH-YYYY-NNN (link to INC-YYYY-NNN)
Date aware UTC
Description Factual summary
Data categories
Subjects affected Count / range
Art 33 required? Y/N + rationale
Authority notified DPC / ICO / NA + date
Art 34 required? Y/N
Customers notified Y/N + date
Remediation
Closed date

Retain 3 years minimum.

11. Link to Incident Response Plan

IR Plan section Breach procedure link
§5 Phase 3 — Assessment Use this procedure's checklist
§6.2 Customer template Processor notification
§6.3 ICO/DPC template Supervisory authority
§7 Touch2Sign playbooks Technical facts for assessment
§9 Incident register Link BRH ID to INC ID

Full incident response: INCIDENT_RESPONSE_PLAN.md

12. Related documents

  • Incident Response Plan
  • DSAR Procedure
  • Data Processing Agreement
  • Vendor & Sub-processor Management Policy
  • Information Security Policy

13. Review

Reviewed annually, after any notifiable breach, and when supervisory authority guidance changes.


Approval

Name Role Signature Date
Robert CEO Electronic 11 July 2026
DPO / Privacy Lead

Questions: security@touch2sign.com · privacy@touch2sign.com