Version 1.0 · Approved · Owner: Privacy Lead
Download .md →Version: 1.0 · Date: July 2026
Owner: Security & Privacy Lead
Review: Annual or on material change to IDV, eWitness, or AI features
Status: Completed baseline assessment — residual risks accepted with documented mitigations
GDPR Article 35 requires a DPIA when processing is likely to result in a high risk, including:
This DPIA covers the Touch2Sign platform as operated by Touch2Sign Ltd.
Customers upload documents and invite signers. Touch2Sign stores documents in EU (Ireland), captures signatures (draw/type), records audit events (IP, timestamp, device), and produces evidence PDFs (SCCR).
Remote deed witnessing: witness SMS OTP, attestation declarations, optional IDV, Witness Trail Report PDF. Ireland flows add QES via eID Easy (hash-based; document stays on Touch2Sign).
Anthropic API processes document text and signer questions when Aria/Sentinel is enabled by customer.
| Processing | Necessity | Proportionality | Audit trail (IP, device) | Required for non-repudiation and eIDAS evidence | Minimum fields; IP truncation under review |
|---|---|---|
| IDV | Required for AES/QES and regulated workflows | Only when customer enables; hash-only to QTSP for QES |
| eWitness data | Required for deed witnessing evidence | Limited to attestation + identity needed for level chosen |
| AI Q&A | Optional product feature | Customer-controlled; disclosure to signers; can disable |
| Security logs | Required for security and fraud prevention | Retention capped; LIA documented |
| Risk | Likelihood | Impact | Inherent risk | Mitigations | Residual risk | Unauthorised access to documents | Low | High | Medium | Encryption, RBAC, MFA, AWS security | Low |
|---|---|---|---|---|---|
| IDV provider breach | Low | High | Medium | DPAs, minimise data sent, EU/UK providers | Low–Medium |
| Invalid deed / wrong signature level | Medium | High | High | QES for IE deeds; UX warnings; customer Terms; eIDAS guide | Medium — counsel memo pending |
| AI processing US transfer | Medium | Medium | Medium | SCCs, customer opt-in, minimise content | Low–Medium |
| Signer not informed (controller failure) | Medium | Medium | Medium | DPA places notice obligation on Customer | Medium (shared) |
| Audit log tampering | Low | High | Medium | Append-only audit, hashes, SCCR | Low |
| Excessive retention | Low | Medium | Low | Configurable retention; deletion API | Low |
| Stakeholder | Input | Engineering | Confirmed hash-only QES; retention controls |
|---|---|
| Privacy lead | This DPIA |
| DPO / counsel | Recommended before enterprise “high assurance” marketing |
Proceed with processing subject to:
| Approver | Role | Date | _TBC_ | Privacy lead |
|---|---|---|
| _TBC_ | CEO |
Questions: security@touch2sign.com · privacy@touch2sign.com