ISO/IEC 27018 is an international code of practice for protecting personally identifiable information, or PII, in public cloud services where the provider acts as a PII processor. It extends the security controls of ISO/IEC 27002 with privacy-specific guidance so cloud providers can handle customer data responsibly and transparently.
First published in 2014 and revised in 2019 and again in 2025, ISO 27018 was among the first international standards to address privacy in cloud computing. It applies to any organization that processes PII on behalf of others through the cloud, from global hyperscalers to small niche SaaS vendors. The standard does not replace an information security management system; it plugs privacy controls into one you already run. That positioning matters because it keeps ISO 27018 lightweight to adopt: if your ISO 27001 programme is already running, adding these controls is an extension rather than a fresh certification project. It also means the standard speaks directly to the processor role that most cloud vendors actually occupy, rather than trying to cover every party in the data lifecycle at once.
What ISO 27018 actually covers
ISO 27018 is designed to be used alongside ISO/IEC 27002, drawing on the privacy principles of ISO/IEC 29100. It provides commonly accepted control objectives, controls, and guidelines for public cloud environments. Crucially, it targets a single role in the data supply chain: the cloud provider acting as a processor, not as a controller. That focus is what makes it so practical for cloud vendors answering customer due-diligence questionnaires.
The standard adds an extended control set specifically for public cloud PII protection. In the 2025 revision this appears as an annex covering additional safeguards such as secure erasure of temporary files and notification when PII is disclosed. These controls sit on top of, rather than inside, the ISO 27001 management system, which is why ISO 27018 does not carry management system requirements of its own. In practice, an auditor assessing a cloud provider against ISO 27018 will look for evidence that these privacy controls are operating alongside the security controls of ISO 27002, and that the provider can show a clear line from customer instructions to the technical measures protecting the data. That evidence-based focus is what turns the standard from a statement of intent into an assurance a customer can rely on.
The privacy controls ISO 27018 adds
The extended controls translate abstract privacy principles into obligations a cloud processor can operationalize. They concentrate on consent, transparency, accountability, and giving the customer, who remains the controller, meaningful oversight of their own data.
- Consent: PII is processed only for purposes the customer has agreed to, not repurposed for advertising or the provider's own aims
- Transparency: the provider discloses sub-processors, data locations, and the possibility of law-enforcement access
- Disclosure notification: customers are informed of any request to hand over PII, unless prohibited by law
- Data return and secure erasure: PII and temporary files are returned or securely deleted at the end of the contract
- Purpose limitation and data minimization: PII is not used beyond the documented instructions of the customer
- Accountability: breaches involving PII are logged, and the provider supports the customer in meeting notification duties
- Access rights support: the provider helps the customer respond to individuals exercising rights over their data
According to ISO, the 2025 revision of ISO/IEC 27018 keeps its scope on public clouds acting as PII processors and adds an extended control set including secure erasure of temporary files and PII disclosure notification. Source: iso.org, ISO/IEC 27018:2025.
How it complements ISO 27001, 27002, 27017, and 27701
ISO 27018 rarely stands alone. It builds on ISO/IEC 27001, the certifiable management system for information security, and on ISO/IEC 27002, the catalogue of security controls it extends. Where ISO 27018 differs from its sibling standards is scope and structure, and understanding that difference prevents a lot of wasted certification effort.
- ISO 27017 covers cloud security more broadly, spanning access control, incident response, and shared responsibility for both providers and customers
- ISO 27018 narrows the lens to privacy of PII in public clouds acting as processors
- ISO 27701 is far broader still, adding a full Privacy Information Management System that flexes into an existing ISO 27001 ISMS and covers all processing, not just cloud
A useful way to sequence them: certify ISO 27001 first, layer ISO 27017 for cloud security and ISO 27018 for cloud privacy, then adopt ISO 27701 when you need a certifiable privacy management system across the whole organization. Our companion guide on ISO 27701 explains how a PIMS extends the ISMS, and our ISO 27017 post walks through the shared-responsibility model in more depth.
How ISO 27018 supports GDPR processor obligations
Under the GDPR, a processor must act only on the documented instructions of the controller, assist with data-subject rights, notify breaches, and support the return or deletion of data. ISO 27018 maps particularly well to these Article 28 processor duties, because its controls were written around exactly the consent, transparency, and accountability themes that Article 28 demands.
That said, ISO 27018 is not a certification of GDPR compliance and does not cover controller obligations. If demonstrating Article 28 processor compliance to cloud customers is the primary goal, ISO 27018 is the most targeted path and answers vendor questionnaires on data location, sub-processor management, and PII isolation with audited evidence. Organizations that need a holistic, verifiable privacy programme across every processing activity should pair it with ISO 27701, as covered in our ISO 27701 walkthrough.
ISO 27018 does not add management system requirements of its own. It relies on the ISO 27001 ISMS for governance and supplies only the extended, privacy-specific control set for the public cloud processor role.
For cloud providers, the business case is straightforward. An ISO 27018 audit gives prospective customers independent assurance that their PII will be handled lawfully, transparently, and only as instructed, shortening sales cycles and strengthening the contractual position under GDPR and comparable laws such as Brazil's LGPD. It also gives sales and security teams a single, credible artefact to hand over when a prospect asks how personal data is protected, replacing bespoke answers to endless security questionnaires. Built on ISO 27001 and used with ISO 27017 and ISO 27701, it forms a coherent privacy and security stack for anyone processing personal data in the public cloud, letting a provider layer security, cloud, and privacy assurance in a way that customers immediately recognize and trust.