Touch2Sign Policy Library
← All policies

Data Protection Impact Assessment (DPIA)

Version 1.0 · Approved · Owner: Privacy Lead

Download .md →

Data Protection Impact Assessment (DPIA) — Touch2Sign Platform

Version: 1.0 · Date: July 2026

Owner: Security & Privacy Lead

Review: Annual or on material change to IDV, eWitness, or AI features

Status: Completed baseline assessment — residual risks accepted with documented mitigations


1. Why a DPIA is required

GDPR Article 35 requires a DPIA when processing is likely to result in a high risk, including:

  • Systematic monitoring (security logs, signing audit trails)
  • Large-scale processing of identity data
  • Innovative technology (AI document analysis)
  • Use of identity verification and qualified trust services

This DPIA covers the Touch2Sign platform as operated by Touch2Sign Ltd.


2. Description of processing

2.1 Core eSignature

Customers upload documents and invite signers. Touch2Sign stores documents in EU (Ireland), captures signatures (draw/type), records audit events (IP, timestamp, device), and produces evidence PDFs (SCCR).

2.2 Identity verification

  • OneID (UK): Bank-backed verification for AES-level signing
  • eID Easy (EU/IE): Qualified trust service for QES
  • Veriff (optional): Document + selfie for enhanced ID proofing

2.3 eWitness

Remote deed witnessing: witness SMS OTP, attestation declarations, optional IDV, Witness Trail Report PDF. Ireland flows add QES via eID Easy (hash-based; document stays on Touch2Sign).

2.4 AI (optional)

Anthropic API processes document text and signer questions when Aria/Sentinel is enabled by customer.


3. Necessity and proportionality

Processing Necessity Proportionality
Audit trail (IP, device) Required for non-repudiation and eIDAS evidence Minimum fields; IP truncation under review
IDV Required for AES/QES and regulated workflows Only when customer enables; hash-only to QTSP for QES
eWitness data Required for deed witnessing evidence Limited to attestation + identity needed for level chosen
AI Q&A Optional product feature Customer-controlled; disclosure to signers; can disable
Security logs Required for security and fraud prevention Retention capped; LIA documented

4. Risk assessment

Risk Likelihood Impact Inherent risk Mitigations Residual risk
Unauthorised access to documents Low High Medium Encryption, RBAC, MFA, AWS security Low
IDV provider breach Low High Medium DPAs, minimise data sent, EU/UK providers Low–Medium
Invalid deed / wrong signature level Medium High High QES for IE deeds; UX warnings; customer Terms; eIDAS guide Medium — counsel memo pending
AI processing US transfer Medium Medium Medium SCCs, customer opt-in, minimise content Low–Medium
Signer not informed (controller failure) Medium Medium Medium DPA places notice obligation on Customer Medium (shared)
Audit log tampering Low High Medium Append-only audit, hashes, SCCR Low
Excessive retention Low Medium Low Configurable retention; deletion API Low

5. Mitigations implemented

  • [x] EU primary hosting (AWS eu-west-1)
  • [x] Encryption at rest and in transit
  • [x] GDPR Art 28 DPA for customers
  • [x] Sub-processor register and DPA §5 list
  • [x] SCCs for Anthropic and Stripe US processing
  • [x] ERSD / disclosure acceptance in signing flow
  • [x] Account deletion and export flows
  • [x] Breach notification procedure (72h)
  • [x] DSAR procedure and register
  • [ ] External legal memo — UK remote witnessing
  • [ ] External legal memo — Ireland QES chain
  • [ ] Formal IP truncation policy in audit logs

6. Consultation

Stakeholder Input
Engineering Confirmed hash-only QES; retention controls
Privacy lead This DPIA
DPO / counsel Recommended before enterprise “high assurance” marketing

7. Decision

Proceed with processing subject to:

  1. Maintaining mitigations in Section 5
  2. Completing legal memos for eWitness IE/UK before scaled deed marketing
  3. Annual DPIA review
Approver Role Date
_TBC_ Privacy lead
_TBC_ CEO

8. Related documents

Questions: security@touch2sign.com · privacy@touch2sign.com