Touch2Sign Policy Library
← All policies

Minimum Compliance Pack

Version 1.0 · Approved · Owner: Privacy Lead

Download .md →

Minimum Compliance Pack — Touch2Sign

Purpose: Single checklist for basic GDPR, privacy, and eIDAS compliance — enough to onboard customers, respond to due diligence, and avoid common gaps.

Owner: Security & Privacy Lead

Last updated: July 2026

Status: Operational baseline (legal counsel review recommended before enterprise claims)


How to use this pack

  1. Work through Section A (customer-facing) — all items must be live on the website.
  2. Work through Section B (internal GDPR) — keep registers updated quarterly.
  3. Work through Section C (eIDAS) — product + customer guidance in place.
  4. Schedule Section D (counsel sign-off) before marketing “fully compliant” language.

Section A — Customer-facing (must be published)

# Document Location Status
A1 Privacy Policy /privacy ✅ Live
A2 Terms of Service /terms ✅ Live
A3 Data Processing Agreement (GDPR Art 28) /legal/dpa ✅ Live
A4 Cookie Policy /legal/policies/cookie-policy ✅ Draft v1.0
A5 Trust & Security page /trust-security ✅ Live
A6 Policy Library hub /legal/policies ✅ Live

Contacts (must be monitored):

Role Email
Privacy / DSAR / breach privacy@touch2sign.com
Legal / DPA legal@touch2sign.com
Security incidents security@touch2sign.com

Section B — GDPR / UK GDPR (internal + auditable)

# Document Location Status
B1 Record of Processing Activities (ROPA) ROPA.md · /legal/policies/ropa ✅ v1.0
B2 Data Protection Impact Assessment (DPIA) DPIA_PLATFORM.md · /legal/policies/dpia ✅ v1.0
B3 Legitimate Interest Assessment (security logs) LIA_SECURITY_LOGGING.md ✅ v1.0
B4 Sub-processor register SUB_PROCESSORS.md ✅ Maintain quarterly
B5 International transfer register INTERNATIONAL_TRANSFER_REGISTER.md ✅ v1.0
B6 DSAR procedure /legal/policies/dsar ✅ Draft v1.0
B7 DSAR register (log) DSAR_REGISTER.md ✅ Template — log each request
B8 Breach notification procedure /legal/policies/breach-notification ✅ Draft v1.0
B9 Breach register (log) BREACH_REGISTER.md ✅ Template — log all incidents
B10 Incident response plan /legal/policies/incident-response ✅ Draft v1.0
B11 Data retention & disposal /legal/policies/data-retention ✅ Draft v1.0

GDPR roles

Role Touch2Sign position
Processor Signing workflows, document storage, IDV on customer instruction
Controller Account registration, billing, support, security logging, marketing

Section C — eIDAS / UK electronic signatures

# Document / control Location Status
C1 eIDAS compliance guide EIDAS_COMPLIANCE_GUIDE.md · /legal/policies/eidas-compliance ✅ v1.0
C2 Signature levels (SES / AES / QES) Product — OneID, eID Easy ✅ Built
C3 Audit trail & SCCR evidence Signing pipeline ✅ Built
C4 eWitness (UK + IE) Witness portal, trail PDF, QES ASiC-E ✅ Built
C5 7-year default retention Org settings ✅ Built
C6 Customer responsibility in Terms /terms §5 ✅ Updated
C7 UK remote deed legal memo External counsel ☐ Pending
C8 Ireland QES chain legal memo External counsel ☐ Pending

Approved marketing language: “eIDAS-aligned” · “designed for eIDAS workflows” · “supports SES, AES, and QES via qualified trust service providers”

Do not claim: “eIDAS certified” · “legally valid in all circumstances” · “ISO 27001 certified” (programme in progress)


Section D — Counsel & CEO sign-off (recommended)

Item Owner Target
Privacy Policy legal review Legal Before enterprise sales
Terms + DPA legal review Legal Before enterprise sales
UK eWitness opinion (LP(MP)A) External counsel Before IE/UK deed marketing
Ireland QES platform opinion External counsel Before IE deed scale
CEO approval — draft policies v1.0 CEO 30 days
Tabletop breach exercise Security lead 90 days

Section E — Nice-to-have (not minimum)

SOC 2 Type II · ISO 27001 certification · HIPAA BAA · Full 20-policy ISMS publication · Penetration test report

See FULL_COMPLIANCE_PLAN.md and ROADMAP.md.


Quarterly maintenance (30 minutes)


Quick links

Audience Start here
Internal team This document
Customers / prospects /trust-security → Policy Library
Due diligence ROPA + DPIA + DPA + Sub-processors
Developers

Questions: security@touch2sign.com · privacy@touch2sign.com