Version 1.0 · Approved · Owner: Privacy Lead
Download .md →Purpose: Single checklist for basic GDPR, privacy, and eIDAS compliance — enough to onboard customers, respond to due diligence, and avoid common gaps.
Owner: Security & Privacy Lead
Last updated: July 2026
Status: Operational baseline (legal counsel review recommended before enterprise claims)
| # | Document | Location | Status | A1 | Privacy Policy | /privacy | ✅ Live |
|---|---|---|---|
| A2 | Terms of Service | /terms | ✅ Live |
| A3 | Data Processing Agreement (GDPR Art 28) | /legal/dpa | ✅ Live |
| A4 | Cookie Policy | /legal/policies/cookie-policy | ✅ Draft v1.0 |
| A5 | Trust & Security page | /trust-security | ✅ Live |
| A6 | Policy Library hub | /legal/policies | ✅ Live |
Contacts (must be monitored):
| Role | Privacy / DSAR / breach | privacy@touch2sign.com |
|---|---|
| Legal / DPA | legal@touch2sign.com |
| Security incidents | security@touch2sign.com |
| # | Document | Location | Status | B1 | Record of Processing Activities (ROPA) | ROPA.md · /legal/policies/ropa | ✅ v1.0 |
|---|---|---|---|
| B2 | Data Protection Impact Assessment (DPIA) | DPIA_PLATFORM.md · /legal/policies/dpia | ✅ v1.0 |
| B3 | Legitimate Interest Assessment (security logs) | LIA_SECURITY_LOGGING.md | ✅ v1.0 |
| B4 | Sub-processor register | SUB_PROCESSORS.md | ✅ Maintain quarterly |
| B5 | International transfer register | INTERNATIONAL_TRANSFER_REGISTER.md | ✅ v1.0 |
| B6 | DSAR procedure | /legal/policies/dsar | ✅ Draft v1.0 |
| B7 | DSAR register (log) | DSAR_REGISTER.md | ✅ Template — log each request |
| B8 | Breach notification procedure | /legal/policies/breach-notification | ✅ Draft v1.0 |
| B9 | Breach register (log) | BREACH_REGISTER.md | ✅ Template — log all incidents |
| B10 | Incident response plan | /legal/policies/incident-response | ✅ Draft v1.0 |
| B11 | Data retention & disposal | /legal/policies/data-retention | ✅ Draft v1.0 |
| Role | Touch2Sign position | Processor | Signing workflows, document storage, IDV on customer instruction |
|---|---|
| Controller | Account registration, billing, support, security logging, marketing |
| # | Document / control | Location | Status | C1 | eIDAS compliance guide | EIDAS_COMPLIANCE_GUIDE.md · /legal/policies/eidas-compliance | ✅ v1.0 |
|---|---|---|---|
| C2 | Signature levels (SES / AES / QES) | Product — OneID, eID Easy | ✅ Built |
| C3 | Audit trail & SCCR evidence | Signing pipeline | ✅ Built |
| C4 | eWitness (UK + IE) | Witness portal, trail PDF, QES ASiC-E | ✅ Built |
| C5 | 7-year default retention | Org settings | ✅ Built |
| C6 | Customer responsibility in Terms | /terms §5 | ✅ Updated |
| C7 | UK remote deed legal memo | External counsel | ☐ Pending |
| C8 | Ireland QES chain legal memo | External counsel | ☐ Pending |
Approved marketing language: “eIDAS-aligned” · “designed for eIDAS workflows” · “supports SES, AES, and QES via qualified trust service providers”
Do not claim: “eIDAS certified” · “legally valid in all circumstances” · “ISO 27001 certified” (programme in progress)
| Item | Owner | Target | Privacy Policy legal review | Legal | Before enterprise sales |
|---|---|---|
| Terms + DPA legal review | Legal | Before enterprise sales |
| UK eWitness opinion (LP(MP)A) | External counsel | Before IE/UK deed marketing |
| Ireland QES platform opinion | External counsel | Before IE deed scale |
| CEO approval — draft policies v1.0 | CEO | 30 days |
| Tabletop breach exercise | Security lead | 90 days |
SOC 2 Type II · ISO 27001 certification · HIPAA BAA · Full 20-policy ISMS publication · Penetration test report
See FULL_COMPLIANCE_PLAN.md and ROADMAP.md.
| Audience | Start here | Internal team | This document |
|---|---|
| Customers / prospects | /trust-security → Policy Library |
| Due diligence | ROPA + DPIA + DPA + Sub-processors |
| Developers |
Questions: security@touch2sign.com · privacy@touch2sign.com