Touch2Sign Policy Library
← All policies

Data Subject Access Request Procedure

Version 1.0 · Draft · Owner: DPO

Download .md →

Data Subject Access Request (DSAR) Procedure

Touch2Sign Ltd

Version: 1.0

Effective date: 11 July 2026

Owner: [DPO / Privacy Lead]

Approved by: Robert — CEO / Managing Director

Next review: 11 July 2027


1. Purpose

Define how Touch2Sign receives, verifies, and responds to requests from individuals exercising rights under GDPR Articles 15–22 and UK GDPR. Ensures responses within statutory timeframes and clarifies Touch2Sign's role as controller vs processor.

2. Scope

Applies to requests from:

  • Signers and witnesses whose personal data Touch2Sign processes
  • Customer organisation users (admins, senders)
  • Former employees (handled under HR policy — separate process)

Covers rights of access, rectification, erasure, restriction, portability, and objection.

3. Contact channel

Channel Detail
Primary email privacy@touch2sign.com
Postal [Touch2Sign Ltd registered address]
Web form Link from Privacy Policy (when published)

All DSARs logged in DSAR Register within 2 business days of receipt.

4. Controller vs processor

Scenario Touch2Sign role Who responds
Signer data processed on behalf of customer (documents, audit trail) Processor Forward to customer controller; assist per DPA §6
Touch2Sign account billing, marketing, website analytics Controller Touch2Sign responds directly
Employee data Controller HR + DPO

When Touch2Sign is processor, the customer organisation is controller and primary respondent. Touch2Sign assists within 30 days and DPA terms.

5. SLA and extensions

Milestone Target
Acknowledgement of receipt 5 business days
Identity verification complete 10 business days
Full response 30 calendar days from receipt
Extension (complex requests) + 60 days with reason notified to data subject
Processor assistance to customer 30 calendar days from customer request

6. Request handling process

Step 1 — Intake and logging

Record in DSAR Register:

Field Description
DSAR ID DSAR-YYYY-NNN
Date received
Requester name and contact
Rights exercised Access / erasure / etc.
Touch2Sign role Controller / processor
Customer org (if applicable)
Status Open / verifying / in progress / closed

Step 2 — Identity verification

Before disclosing personal data:

  • Match requester to records (email verification, signing history, org admin confirmation)
  • Request additional ID only if necessary and proportionate
  • Do not disclose data to unverified third parties
  • For processor requests: confirm requester with customer controller where appropriate

Step 3 — Scope and search

Search relevant systems:

System Data
RDS users, recipients, audit_log, org membership
S3 Signed PDFs linked to requester (if access request)
Cognito Account attributes
Support tickets Tickets referencing requester
Stripe Billing metadata (controller requests only)
Sub-processors Query OneID / eID Easy if IDV data requested — via DPA

Document search scope and any data not found.

Step 4 — Legal review

DPO reviews for exemptions (Art 15(4), manifestly unfounded/excessive requests Art 12(5)), conflicts with other data subjects' rights, and erasure limitations (signature evidence retention).

Step 5 — Response

Provide response in structured, commonly used, machine-readable format where portability requested (JSON or CSV + PDF copies of documents).

Access response includes:

  • Confirmation of processing
  • Categories of data and purposes
  • Recipients or categories (sub-processors summary)
  • Retention period
  • Rights and complaint authority (DPC / ICO)
  • Copy of personal data

Step 6 — Closure

Update DSAR Register; retain record 3 years.

7. Right-specific guidance

Right Touch2Sign action
Access (Art 15) Export personal data; explain processing
Rectification (Art 16) Correct inaccurate account data; notify customer controller for document content
Erasure (Art 17) Per Data Retention Policy; may refuse where signature evidence required
Restriction (Art 18) Flag account pending dispute resolution
Portability (Art 20) Provide machine-readable export where processing automated + consent/contract
Objection (Art 21) Assess; stop marketing; document legitimate interest balancing

8. Refusal and partial response

If request refused or partially fulfilled:

  • Explain reasons within 30 days
  • Inform data subject of right to complain to DPC (Ireland) or ICO (UK)
  • Document rationale in DSAR Register

Manifestly unfounded or excessive requests: charge reasonable fee or refuse per Art 12(5) — DPO + Legal approval required.

9. Customer (controller) coordination

When request concerns signer data for a customer organisation:

  1. Notify customer within 5 business days
  2. Provide tools or exports to assist (DPA §6)
  3. Do not release customer's confidential document content to wrong party
  4. Customer leads communication with data subject unless agreed otherwise

Template available to customers in DPA annex.

10. Fees

First request free. Repeated or manifestly unfounded requests may incur reasonable administrative fee per GDPR Art 12(5).

11. Related documents

  • Privacy Policy
  • Data Processing Agreement
  • Data Retention & Disposal Policy
  • Breach Notification Procedure
  • SUB_PROCESSORS.md

12. Review

Reviewed annually and after significant DSAR volume or regulatory guidance changes.


Approval

Name Role Signature Date
Robert CEO Electronic 11 July 2026
DPO / Privacy Lead

Questions: security@touch2sign.com · privacy@touch2sign.com