Home/Services/Certification/ISO/IEC 27018:2019

ISO/IEC 27018:2019

Code of practice for the protection of personally identifiable information (PII) in public clouds acting as PII processors.

Overview
What is ISO/IEC 27018?

ISO/IEC 27018 is an international standard that provides privacy and data protection guidance for organizations processing personally identifiable information (PII) within public cloud environments. The standard establishes additional privacy controls intended to help cloud service providers protect personal data and support transparency, accountability, and responsible processing practices on behalf of cloud service customers.

ISO/IEC 27018 is a code of practice — a guidance standard — not a management system standard against which organizations can be independently certified. It provides cloud-specific privacy controls and implementation guidance that organizations can incorporate into their information security or privacy management framework. The standard focuses on the protection of personal data entrusted to cloud service providers and helps organizations demonstrate responsible handling of customer information in cloud environments.

The standard is commonly implemented alongside ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27701 as part of a broader cloud security and privacy framework. It extends the privacy-relevant controls in ISO/IEC 27002 with cloud-specific guidance, addressing the unique challenges of protecting PII in multi-tenant, geographically distributed public cloud environments.

Key Themes
What does the standard focus on?
Protection of Personal Data
The standard provides specific guidance on controls for protecting PII held in public cloud environments, covering the lifecycle of personal data from collection through retention, use, disclosure, and disposal — including confidentiality, integrity, and prevention of unauthorized use.
Cloud Privacy Controls
ISO/IEC 27018 extends the control set in ISO/IEC 27002 with cloud-specific privacy controls addressing the unique challenges of processing PII in multi-tenant public cloud environments, including data access, storage, transmission, and processing by cloud service providers.
Transparency and Accountability
The standard emphasizes that cloud service providers should be transparent about how they process personal data, which sub-processors they engage, where data is stored, and how privacy incidents are detected and handled — supporting meaningful accountability to cloud service customers.
Consent and Processing Controls
ISO/IEC 27018 addresses the requirement that cloud service providers process PII only in accordance with the instructions of the cloud service customer — including controls that prevent the use of personal data for marketing, profiling, or purposes beyond those agreed in the service arrangement.
Data Subject Rights
The standard provides guidance on how cloud service providers can support cloud service customers in fulfilling obligations related to data subject rights, including rights of access, correction, deletion, restriction of processing, and objection — enabling customers to respond to data subject requests effectively.
Data Retention and Disposal
ISO/IEC 27018 includes guidance on the retention and disposal of personal data in cloud environments, including the return or deletion of PII upon termination of service arrangements and the secure destruction of data held on cloud infrastructure, including backup copies.
Cross-Border Data Considerations
The standard addresses challenges associated with the cross-border transfer and processing of personal data in cloud environments, where data may be stored or processed across multiple jurisdictions subject to different data protection requirements, including transparency obligations regarding geographic data locations.
Privacy Governance
ISO/IEC 27018 supports the governance of privacy in cloud environments through structured controls, accountability mechanisms, and management processes that enable organizations to demonstrate responsible handling of personal data processed through public cloud services.
Applicability
Who typically uses ISO/IEC 27018?
Cloud Service Providers
Organizations that supply cloud computing services to external customers where personal data is processed. ISO/IEC 27018 provides cloud-specific privacy controls directly relevant to providers acting as PII processors under customer instruction.
Software as a Service Providers
SaaS providers processing personal data on behalf of customers — including personal employee data, customer records, health information, and other categories of PII — are among the primary audiences for ISO/IEC 27018, given their direct handling of customer personal data at the application layer.
Platform as a Service Providers
PaaS providers whose platforms are used by customers to develop, deploy, and operate applications that process personal data, where privacy governance must extend across both the platform infrastructure and the customer application environments deployed on it.
Infrastructure as a Service Providers
IaaS providers offering virtualised computing, storage, and networking resources used by customers to process personal data, where the provider retains responsibility for the physical and virtualisation infrastructure and must ensure it meets appropriate privacy protection standards.
Managed Service Providers
Organizations managing cloud infrastructure, applications, or services on behalf of customers where personal data is accessed, processed, or stored as part of service delivery — and where privacy obligations arise from both the managed service arrangement and applicable data protection legislation.
Data Hosting Providers
Organizations providing data hosting, storage, and backup services in cloud environments, where personal data is entrusted by customers and must be protected throughout its lifecycle, including during backup, recovery, and service termination.
Technology Companies Processing Personal Data
Technology companies processing personal data through cloud-delivered services — including product companies, platform businesses, and API providers — whose services involve the processing of customer or user PII on behalf of business customers.
Organizations Providing Cloud-Based Applications
Application developers and publishers delivering cloud-based software products that process personal data on behalf of business customers acting as data controllers, where the application provider is acting as a PII processor subject to data processing obligations.
Organizations Acting as PII Processors
Any organization that acts as a PII processor under applicable data protection legislation — processing personal data on behalf of another organization in a public cloud environment — and to which cloud-specific privacy controls and processor obligations apply.
Benefits
Why organizations adopt ISO/IEC 27018
Improved Privacy Governance
A structured approach to cloud privacy governance enables organizations to manage privacy risks systematically, embed cloud-specific privacy controls into their broader management framework, and demonstrate responsible oversight of personal data processing in cloud environments.
Enhanced Protection of Personal Data
Cloud-specific controls for protecting PII across its lifecycle — covering storage, transmission, access, use, and disposal — strengthen the protection of personal data processed in public cloud environments beyond what general information security controls address.
Greater Customer Trust
Demonstrating that cloud privacy practices align with ISO/IEC 27018 guidance supports customer confidence that personal data entrusted to cloud service providers is handled responsibly, transparently, and in accordance with internationally recognized standards of care.
Improved Transparency
ISO/IEC 27018 encourages cloud service providers to be transparent about their data processing activities, sub-processor relationships, geographic data locations, and privacy incident handling — supporting informed decision-making by cloud service customers and their data subjects.
Support for Privacy Compliance Programs
Implementing ISO/IEC 27018 guidance provides structured, documented controls for the protection of PII in cloud environments that may support compliance with data protection legislation, regulatory guidance, and contractual privacy obligations applicable to cloud processing activities.
Stronger Cloud Privacy Controls
Cloud-specific privacy controls extend general data protection practices with targeted guidance for public cloud environments — addressing multi-tenancy, geographic distribution, sub-processor management, and the division of privacy responsibility between providers and customers.
Improved Stakeholder Confidence
Alignment with ISO/IEC 27018 provides evidence to customers, regulators, and other stakeholders that cloud privacy practices meet an internationally recognized standard of care for the protection of personal data processed in public cloud environments.
Support for Responsible Data Processing
Controls for consent management, data subject rights, retention, sub-processor governance, and disposal support responsible data processing practices that respect the rights of individuals whose personal data is entrusted to cloud service providers.
Regulatory Context
Why is ISO/IEC 27018 important?

Organizations increasingly process personal data through cloud services. As cloud adoption has expanded, the regulatory, contractual, and stakeholder expectations placed on cloud service providers — particularly those acting as PII processors — have intensified significantly. ISO/IEC 27018 provides practical, internationally recognized guidance for protecting personal data in public cloud environments and supporting responsible privacy management practices.

Privacy obligations are driven by a range of regulatory and contractual sources. The standard may support organizations in demonstrating privacy accountability and good practice, but it does not replace legal or regulatory requirements. Organizations must assess their specific obligations under applicable data protection legislation and use ISO/IEC 27018 as one input to their broader compliance and governance program.

FAQ
Common questions
ISO/IEC 27018 is an international standard that provides privacy and data protection guidance for organizations processing personally identifiable information (PII) within public cloud environments. It establishes additional privacy controls intended to help cloud service providers protect personal data and support transparency, accountability, and responsible processing practices on behalf of cloud service customers. The standard is part of the ISO/IEC 27000 family and is designed to be used alongside ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27701 as part of a broader cloud security and privacy framework.
No. ISO/IEC 27018 is a code of practice — a guidance standard — not a management system standard against which organizations can be independently certified in the same way as ISO/IEC 27001. The standard provides cloud-specific privacy controls and implementation guidance that organizations can incorporate into their information security or privacy management framework. Some organizations reference ISO/IEC 27018 in contractual arrangements or supplier assurance assessments, but it does not carry its own standalone certification scheme.
ISO/IEC 27701 is an extension to ISO/IEC 27001 that specifies requirements for a Privacy Information Management System. Organizations can be certified against ISO/IEC 27701 as an extension of their ISO/IEC 27001 certification — providing a formally audited and certifiable privacy management system framework for both PII controllers and processors. ISO/IEC 27018 is a code of practice that provides targeted cloud-specific privacy controls for the protection of PII in public cloud environments. The two standards are complementary: ISO/IEC 27701 provides the certifiable PIMS governance structure, while ISO/IEC 27018 provides specific cloud-context guidance that can be integrated into that framework.
ISO/IEC 27017 provides cloud-specific information security controls and guidance for both cloud service providers and cloud service customers, with a broad focus on security governance, shared responsibility models, virtual environment security, and cloud service administration. ISO/IEC 27018 specifically addresses the protection of personally identifiable information in public cloud environments, extending privacy-relevant controls for cloud contexts. The two standards are complementary: ISO/IEC 27017 addresses cloud security broadly, while ISO/IEC 27018 focuses on the privacy dimension — specifically the protection of PII entrusted to cloud service providers acting as processors.
ISO/IEC 27018 is primarily intended for cloud service providers that act as PII processors — organizations that process personal data on behalf of cloud service customers. It is relevant to SaaS, PaaS, and IaaS providers, managed service providers, data hosting organizations, and technology companies whose cloud services involve the processing of personal data. Cloud service customers may also use the standard as a reference when evaluating the privacy practices of cloud providers, specifying contractual privacy requirements, or conducting supplier due diligence assessments.
Yes. Cloud service customers can use ISO/IEC 27018 as a reference standard when assessing the privacy practices of cloud service providers, specifying contractual privacy requirements, and conducting supplier due diligence. The standard provides a structured basis for evaluating whether a cloud provider’s privacy practices meet recognized international guidance for the protection of PII in cloud environments. Customers can also reference ISO/IEC 27018 in their own privacy governance documentation to demonstrate that their cloud provider selection and oversight processes are aligned with recognized standards.
Yes. ISO/IEC 27018 is designed for cloud service providers acting as PII processors. The standard provides specific guidance on implementing privacy controls for protecting PII across its lifecycle in cloud environments — covering storage, access, transmission, disclosure, retention, and disposal. Cloud providers can use ISO/IEC 27018 to structure their privacy governance, demonstrate responsible handling of customer PII, support customer due diligence assessments of their privacy practices, and provide evidence of alignment with internationally recognized cloud privacy guidance.
ISO/IEC 27018 provides a structured framework for implementing cloud-specific privacy controls that may be relevant to compliance with data protection legislation and contractual privacy obligations. Implementing the standard’s guidance may support an organization’s compliance posture, particularly where cloud processing of personal data is in scope for data protection regulatory requirements. However, alignment with ISO/IEC 27018 is not in itself a demonstration of legal compliance; organizations must assess their specific regulatory obligations and use the standard as one input to their compliance and privacy governance program.
No formal prerequisite exists, but ISO/IEC 27018 is designed to be used alongside an information security management framework. Organizations that have implemented ISO/IEC 27001 — and particularly those that have extended their ISMS under ISO/IEC 27701 — will find the most comprehensive and effective integration of ISO/IEC 27018 guidance into their existing control framework and management system. Organizations without an established ISMS may still apply ISO/IEC 27018 guidance for cloud privacy purposes, though the governance structure provided by ISO/IEC 27001 offers the most effective context for doing so.
Organizations can begin by identifying the personal data processing activities that occur within their public cloud services, understanding the privacy responsibilities that apply to them as cloud service providers or PII processors, and reviewing existing privacy controls and data processing arrangements against the guidance in ISO/IEC 27018. Ensuring that processing agreements, privacy notices, and operational procedures accurately reflect the protections required — including controls over consent, data subject rights, retention, sub-processor management, and geographic transparency — is a practical starting point. Organizations with an existing ISMS or PIMS should assess how ISO/IEC 27018 guidance can be incorporated into their established management framework.
Related Standards
Standards commonly used alongside ISO/IEC 27018