top of page

ISO/IEC 27018

Privacy controls for protecting personal data in public clouds — built for providers who process PII on behalf of their customers. We help you assess against it and operationalise it alongside your ISO 27001 system.

WHAT IT IS

Cloud privacy controls

Protecting PII in public clouds

CURRENT VERSION

ISO/IEC 27018:2025

Updates the 2019 edition

CERTIFIABLE?

Yes - with ISO 27001

Added to your ISO 27001 scope

BEST FOR

Public cloud PII processors

Providers handling personal data within cloud environments

STANDARD EXPLANATION

What is ISO 27018?

ISO/IEC 27018 is a code of practice for protecting personally identifiable information — PII — in public cloud environments. It's aimed squarely at cloud providers acting as PII processors: organisations handling personal data on behalf of their customers. Like ISO 27017, it builds on ISO/IEC 27002 and aligns with established privacy principles, adding a focused set of privacy-specific controls on top of a standard management system.

Those controls address what matters most when someone else's personal data lives in your cloud: respecting consent, being transparent about how PII is handled, restrictions on using your customers' PII for your own purposes such as advertising, disclosing any sub-processors you use, supporting the return and deletion of data, and notifying customers of breaches. In short, it's how a cloud processor demonstrates it takes privacy seriously — and it maps closely to obligations under regulations like the GDPR.

The current edition is ISO/IEC 27018:2025, which updates the long-standing 2019 edition (itself a minor revision of the original 2014) and brings the standard into line with ISO/IEC 27002:2022, adding extended implementation guidance.

Like ISO 27017, ISO 27018 isn't certified on its own. It extends an ISO 27001 certification. For a cloud business handling customer personal data, it's one of the clearest ways to prove good privacy practice to cautious, privacy-conscious buyers.

WHY PEOPLE COME TO US FOR IT

Do you actually need ISO 27018?

It's most relevant to cloud and SaaS providers that handle other people's personal data. The trigger usually looks like one of these.

01

You process customers' personal data in the cloud. You're a SaaS or cloud provider, and your customers are asking exactly how you protect the PII they hand you.

02

Privacy is becoming a deal factor. Enterprise or regulated customers want assurance about personal data that goes beyond a generic security certificate.

03

You want to evidence GDPR-aligned practice. A recognised framework that maps to privacy obligations is easier to point to than a folder of your own policies.

HOW WE HELP

Two ways in. Same principle throughout.

Whether we're independently auditing your SMS or helping you build it, you stay involved and walk away understanding it. Here's how that splits for ISO 20000.

Audit & Assessment · Independent

We assess your PII cloud controls against it.

Impartial, evidence-based work against the 2025 edition — a clear read on how you handle personal data in the cloud.

  • Gap analysis against ISO/IEC 27018:2025

  • Review of consent, transparency, and deletion handling

  • Readiness to add 27018 to your ISO 27001 scope

  • A view on how your controls map to the GDPR

Implementation Support · Collaborative

We help you put the necessary controls in place.

Hands-on help applying the privacy controls, with your team driving the work.

  • Implementing the PII-protection controls

​​

  • Sub-processor disclosure, data return and deletion

  • Breach handling and transparency measures

  • Preparing for your 27001-plus-27018 audit

​COMMON QUESTIONS

ISO 27017 questions we hear a lot

Can I get certified to ISO 27018 on its own?

No — like ISO 27017. It isn't a standalone certifiable standard — it extends ISO 27001. When you implement its controls, your ISO 27001 certificate references 27017 in its scope statement. So it always rides alongside a 27001 certification.

Who is ISO 27018 actually for?

Public cloud providers acting as PII processors — that is, organisations handling personal data on behalf of their customers. Its guidance can also be useful to organisations acting as controllers, but the controls are written from the processor's point of view.

Is ISO 27018 the same as GDPR compliance?

No. It maps closely to privacy obligations and helps demonstrate good PII handling, but it isn't a substitute for meeting the law itself. Think of it as strong, recognised evidence of good practice rather than a legal guarantee — and note this is practical compliance support, not legal advice.

What's the current version?

ISO/IEC 27018:2025, which updates the 2019 edition and aligns the standard with ISO/IEC 27002:2022, adding extended implementation guidance. The 2019 edition had itself been a minor revision of the original 2014 standard.

How is it different from ISO 27701?

ISO 27701 is a broader privacy information management system for any organisation. ISO 27018 is narrower and specific: privacy controls for cloud providers processing PII. They can complement each other, with 27018 focused on the cloud-processor side.

How does it relate to ISO 27017?

ISO 27017 covers cloud security in general; ISO 27018 focuses specifically on protecting personal data (PII) in the cloud. They're complementary, and cloud providers often implement both together as extensions to the same ISO 27001 system.

RELATED STANDARDS

Often comes up alongside

ISO 27001

The security half of the MSP conversation - extremely common to run both together.

Information Security
ISO 27017

The security-focused companion - very often implemented together with ISO 27018

Cloud Security
ISO 27701

A broader privacy management system, where cloud privacy is one piece.

Privacy Management

If you need a clear view of where you stand - let's talk.

A 30-minute discovery call costs nothing. We'll tell you whether we're the right fit, what the work would involve, and what you'd get out of it. No pitch, no pressure.

bottom of page