WHAT IT IS
Cloud privacy controls
Protecting PII in public clouds
CURRENT VERSION
ISO/IEC 27018:2025
Updates the 2019 edition
CERTIFIABLE?
Yes - with ISO 27001
Added to your ISO 27001 scope
BEST FOR
Public cloud PII processors
Providers handling personal data within cloud environments
STANDARD EXPLANATION
What is ISO 27018?
ISO/IEC 27018 is a code of practice for protecting personally identifiable information — PII — in public cloud environments. It's aimed squarely at cloud providers acting as PII processors: organisations handling personal data on behalf of their customers. Like ISO 27017, it builds on ISO/IEC 27002 and aligns with established privacy principles, adding a focused set of privacy-specific controls on top of a standard management system.
Those controls address what matters most when someone else's personal data lives in your cloud: respecting consent, being transparent about how PII is handled, restrictions on using your customers' PII for your own purposes such as advertising, disclosing any sub-processors you use, supporting the return and deletion of data, and notifying customers of breaches. In short, it's how a cloud processor demonstrates it takes privacy seriously — and it maps closely to obligations under regulations like the GDPR.
The current edition is ISO/IEC 27018:2025, which updates the long-standing 2019 edition (itself a minor revision of the original 2014) and brings the standard into line with ISO/IEC 27002:2022, adding extended implementation guidance.
Like ISO 27017, ISO 27018 isn't certified on its own. It extends an ISO 27001 certification. For a cloud business handling customer personal data, it's one of the clearest ways to prove good privacy practice to cautious, privacy-conscious buyers.
WHY PEOPLE COME TO US FOR IT
Do you actually need ISO 27018?
It's most relevant to cloud and SaaS providers that handle other people's personal data. The trigger usually looks like one of these.
01
You process customers' personal data in the cloud. You're a SaaS or cloud provider, and your customers are asking exactly how you protect the PII they hand you.
02
Privacy is becoming a deal factor. Enterprise or regulated customers want assurance about personal data that goes beyond a generic security certificate.
03
You want to evidence GDPR-aligned practice. A recognised framework that maps to privacy obligations is easier to point to than a folder of your own policies.
HOW WE HELP
Two ways in. Same principle throughout.
Whether we're independently auditing your SMS or helping you build it, you stay involved and walk away understanding it. Here's how that splits for ISO 20000.
Audit & Assessment · Independent
We assess your PII cloud controls against it.
Impartial, evidence-based work against the 2025 edition — a clear read on how you handle personal data in the cloud.
-
Gap analysis against ISO/IEC 27018:2025
-
Review of consent, transparency, and deletion handling
-
Readiness to add 27018 to your ISO 27001 scope
-
A view on how your controls map to the GDPR
Implementation Support · Collaborative
We help you put the necessary controls in place.
Hands-on help applying the privacy controls, with your team driving the work.
-
Implementing the PII-protection controls
-
Sub-processor disclosure, data return and deletion
-
Breach handling and transparency measures
-
Preparing for your 27001-plus-27018 audit
COMMON QUESTIONS
ISO 27017 questions we hear a lot
Can I get certified to ISO 27018 on its own?
No — like ISO 27017. It isn't a standalone certifiable standard — it extends ISO 27001. When you implement its controls, your ISO 27001 certificate references 27017 in its scope statement. So it always rides alongside a 27001 certification.
Who is ISO 27018 actually for?
Public cloud providers acting as PII processors — that is, organisations handling personal data on behalf of their customers. Its guidance can also be useful to organisations acting as controllers, but the controls are written from the processor's point of view.
Is ISO 27018 the same as GDPR compliance?
No. It maps closely to privacy obligations and helps demonstrate good PII handling, but it isn't a substitute for meeting the law itself. Think of it as strong, recognised evidence of good practice rather than a legal guarantee — and note this is practical compliance support, not legal advice.
What's the current version?
ISO/IEC 27018:2025, which updates the 2019 edition and aligns the standard with ISO/IEC 27002:2022, adding extended implementation guidance. The 2019 edition had itself been a minor revision of the original 2014 standard.
How is it different from ISO 27701?
ISO 27701 is a broader privacy information management system for any organisation. ISO 27018 is narrower and specific: privacy controls for cloud providers processing PII. They can complement each other, with 27018 focused on the cloud-processor side.
How does it relate to ISO 27017?
ISO 27017 covers cloud security in general; ISO 27018 focuses specifically on protecting personal data (PII) in the cloud. They're complementary, and cloud providers often implement both together as extensions to the same ISO 27001 system.
RELATED STANDARDS
Often comes up alongside
ISO 27001
The security half of the MSP conversation - extremely common to run both together.
Information Security
ISO 27017
The security-focused companion - very often implemented together with ISO 27018
Cloud Security
ISO 27701
A broader privacy management system, where cloud privacy is one piece.

