Version 1.0 · Draft · Owner: DPO
Download .md →Touch2Sign Ltd
Version: 1.0
Effective date: 11 July 2026
Owner: [DPO / Privacy Lead]
Approved by: Robert — CEO / Managing Director
Next review: 11 July 2027
Define how Touch2Sign assesses personal data breaches and meets notification obligations under GDPR Articles 33–34, UK GDPR, and customer DPA commitments. This procedure complements the Incident Response Plan — IR handles containment; this procedure handles regulatory and data subject notification decisions.
Applies when a security incident may involve:
Includes breaches at Touch2Sign and sub-processors (AWS, Stripe, OneID, eID Easy, Anthropic, etc.) affecting Touch2Sign customer data.
Personal data breach (GDPR Art 4(12)): a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Not every security incident is a personal data breach — e.g. encrypted data exfiltrated with keys intact may not be notifiable if risk to rights and freedoms is unlikely.
| Role | Responsibility | DPO / Privacy Lead | Breach assessment; authority notification; Art 34 decision |
|---|---|
| Incident Commander | Coordinates IR; provides technical facts |
| CEO / Comms | Customer (controller) notification; public statements |
| Legal counsel | Regulatory strategy; high-risk breach advice |
Primary contact: privacy@touch2sign.com
| Milestone | Target | Incident detected → DPO notified | 30 minutes (P1/P2) |
|---|---|
| Initial breach assessment complete | 24 hours |
| Supervisory authority notification (if required) | 72 hours from awareness |
| Customer (controller) notification | Without undue delay |
| Data subject notification (if required) | Without undue delay after Art 33 |
Awareness = when Touch2Sign has a reasonable degree of certainty that a personal data breach has occurred.
Execute in parallel with Incident Response Plan Phase 3.
| Scenario | ICO / DPC (Art 33) | Data subjects (Art 34) | Customers (controllers) | Encrypted data lost; keys secure | Likely not required | Likely not required | Inform if contract requires |
|---|---|---|---|
| Email addresses exposed; phishing risk | Notify | Consider notify | Notify without undue delay |
| Customer documents exposed | Notify | Likely notify | Notify immediately |
| IDV results exposed | Notify | Notify | Notify immediately |
| Internal admin error; no external access | Document; likely not notify | Not required | Case by case |
| Sub-processor breach affecting Touch2Sign data | Assess; notify if Touch2Sign is controller | Per Art 34 | Notify customers as processor |
When uncertain, DPO errs toward notification within 72 hours.
If full information unavailable at 72 hours, provide in phases without undue further delay.
Touch2Sign acts as processor for most customer document and signer data. On breach affecting customer data:
Use template from Incident Response Plan §6.2; customise with confirmed facts only.
Required when breach is likely to result in high risk to rights and freedoms of individuals, unless:
Notification in clear and plain language:
Coordinate with customer controllers — they may lead communication to their signers.
Every breach assessment recorded regardless of notification outcome:
| Field | Description | Breach ID | BRH-YYYY-NNN (link to INC-YYYY-NNN) |
|---|---|
| Date aware | UTC |
| Description | Factual summary |
| Data categories | |
| Subjects affected | Count / range |
| Art 33 required? | Y/N + rationale |
| Authority notified | DPC / ICO / NA + date |
| Art 34 required? | Y/N |
| Customers notified | Y/N + date |
| Remediation | |
| Closed date |
Retain 3 years minimum.
| IR Plan section | Breach procedure link | §5 Phase 3 — Assessment | Use this procedure's checklist |
|---|---|
| §6.2 Customer template | Processor notification |
| §6.3 ICO/DPC template | Supervisory authority |
| §7 Touch2Sign playbooks | Technical facts for assessment |
| §9 Incident register | Link BRH ID to INC ID |
Full incident response: INCIDENT_RESPONSE_PLAN.md
Reviewed annually, after any notifiable breach, and when supervisory authority guidance changes.
Approval
| Name | Role | Signature | Date | Robert | CEO | Electronic | 11 July 2026 |
|---|---|---|---|
| DPO / Privacy Lead |
Questions: security@touch2sign.com · privacy@touch2sign.com