Touch2Sign Policy Library
← All policies

Legitimate Interest Assessment — Security Logs

Version 1.0 · Approved · Owner: Privacy Lead

Download .md →

Legitimate Interest Assessment — Security Logging

Version: 1.0 · Date: July 2026

Processing: IP addresses, user agents, authentication events, API access logs

Lawful basis: GDPR Art 6(1)(f) — Legitimate interests

Owner: Security & Privacy Lead


1. Purpose of processing

Touch2Sign collects limited technical data to:

  • Detect and prevent unauthorised access and fraud
  • Investigate security incidents and support breach notification
  • Maintain platform availability and diagnose errors
  • Support non-repudiation evidence in signing audit trails (signer IP as part of audit)

2. Necessity

Without security logging, Touch2Sign cannot:

  • Detect credential stuffing or account takeover
  • Meet DPA commitments to implement appropriate security (Art 32)
  • Respond to supervisory authority or customer audit requests
  • Correlate signing events with suspicious access patterns

Alternative considered: No logging — rejected as disproportionate security risk for an e-signature platform.


3. Balancing test

Factor Assessment
Nature of data IP (may be truncated), user agent, timestamps — not special category
Data subject expectation Users expect SaaS providers to secure accounts; signing audit IP is industry standard
Impact on data subjects Low if retention limited and access restricted
Safeguards RBAC on logs, EU storage, retention 90–365 days (security) / per signing retention (audit), encryption
Opt-out Not practical for core security; signing audit required for service delivery (contract/legal obligation)

Conclusion: Legitimate interest is valid for security logging. Signing audit IP is primarily contract / legal obligation (eIDAS evidence), not LIA alone.


4. Data minimisation actions

  • [x] Restrict log access to authorised staff
  • [x] Store logs in EU region
  • [ ] Implement IP truncation/hashing for non-audit security logs (target: Q4 2026)
  • [x] Document retention in Data retention policy

5. Review

Next review: July 2027 or if logging scope expands (e.g. behavioural analytics).

Approver: _Privacy lead · Date: _

Questions: security@touch2sign.com · privacy@touch2sign.com