Implementing ISO standards? Don't overlook GDPR. Try Cookiebot free →

ISO 27018

Cloud Privacy - Protection of PII in Public Clouds

Technology & Innovation Published: 2025

ISO 27018:2025 at a glance

Current edition
ISO/IEC 27018:2025 - Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors
Published
2025
Status
Published
Type of standard
Guidance
Certifiable
No — used for reference and implementation, not certification
Previous edition
ISO/IEC 27018:2019
Official ISO page
View ISO 27018:2025 on iso.org
Last verified

Overview

Guidance on protecting personally identifiable information in public cloud services where the provider acts as a PII processor; third edition published 2025

ISO/IEC 27018 gives guidelines for protecting personally identifiable information (PII) in public cloud computing environments where the cloud service provider acts as a PII processor — that is, where the provider processes personal data on behalf of, and under the instructions of, its customer. The third edition, ISO/IEC 27018:2025, was published in August 2025 and replaces ISO/IEC 27018:2019. Its principal changes are alignment with the restructured ISO/IEC 27002:2022 control set and the addition of a further annex.

The document builds on two foundations: the control set of ISO/IEC 27002, with cloud-and-privacy-specific implementation guidance, and the privacy principles of ISO/IEC 29100. It is deliberately scoped to the processor role, which is why it maps so closely to the obligations imposed on processors by data protection law — for example Article 28 of the GDPR and equivalent provisions elsewhere.

The distinctive content addresses the questions a controller needs answered before entrusting personal data to a public cloud: PII may only be processed according to the customer's instructions; PII must not be used for the provider's own advertising or marketing purposes without express consent; the provider must be transparent about the use and identity of subcontractors and about the countries in which PII may be stored or processed; and the provider must support the customer in meeting obligations such as responding to data subject requests.

Further guidance covers: notification to the customer of data breaches and of legally binding requests for disclosure (such as law enforcement demands), unless disclosure is prohibited; records of PII processing operations; secure erasure, return and disposal of PII and of temporary files; restriction on the creation of hardcopy; encryption of PII transmitted over public networks; controls over portable media and physical media in transit; confidentiality obligations for personnel with access to PII; and limitation of and logging of administrator access.

ISO/IEC 27018 is guidance, not a requirements standard, so there is no standalone accredited certification against it. As with ISO/IEC 27017, certification bodies commonly assess ISO/IEC 27018 as an extension to an ISO/IEC 27001 certification, and major cloud providers publish such attestations. Where an organization needs certifiable privacy governance in its own right, the relevant standard is ISO/IEC 27701, which specifies requirements for a privacy information management system.

Because it addresses only the processor role, ISO/IEC 27018 does not cover the obligations of PII controllers, and it does not by itself demonstrate compliance with any specific data protection law. It is best understood as a well-recognised, auditable articulation of what good processor behaviour looks like in a public cloud, used alongside ISO/IEC 27001, ISO/IEC 27017 and ISO/IEC 27701.

Purpose

To establish commonly accepted control objectives, controls and guidance for public cloud service providers acting as PII processors, so that customers entrusting personal data to the cloud have a clear and assessable basis for evaluating provider practices.

Key Benefits

  • Addresses the processor role directly, matching the obligations data protection law places on cloud providers
  • Prohibits use of customer PII for the provider's own advertising or marketing without express consent
  • Requires transparency about subcontractors and about the locations where PII is processed or stored
  • Provides clear expectations for breach notification and for handling law enforcement disclosure requests
  • Covers secure deletion, return and disposal of PII including temporary files and media
  • Widely recognised by enterprise procurement and privacy teams as cloud due diligence evidence
  • Builds on ISO/IEC 27002 and ISO/IEC 29100, so it fits an existing ISMS without a parallel structure
  • Commonly audited as an extension to ISO/IEC 27001 certification, giving assessable assurance
  • Third edition aligned with ISO/IEC 27002:2022, keeping cloud privacy guidance current with the base control set
  • Complements ISO/IEC 27017 (cloud security) and ISO/IEC 27701 (privacy management system)

Key Requirements

  • Note: ISO/IEC 27018 is guidance — it is applied within an ISO/IEC 27001 ISMS rather than certified against on its own
  • Process PII only in accordance with the cloud service customer's documented instructions
  • Do not use PII received under the contract for advertising or marketing without express consent
  • Disclose the use of subcontractors that may process PII, and the countries where PII may be processed or stored
  • Support the customer in responding to data subject requests and in meeting its own obligations
  • Notify the customer of data breaches and of legally binding requests for disclosure of PII, where permitted
  • Maintain records of PII processing operations performed for customers
  • Ensure secure erasure, return and disposal of PII, including temporary files and decommissioned media
  • Encrypt PII transmitted over public networks and control the use of portable and physical media
  • Restrict, log and review administrator and privileged access to PII
  • Impose confidentiality obligations on personnel with access to PII
  • Restrict the creation of hardcopy material containing PII and control its handling
  • Provide the customer with information needed for its own compliance, including audit or assurance reports
  • Apply the underlying ISO/IEC 27002 controls with the PII-specific implementation guidance

Who Needs This Standard?

Public cloud service providers — SaaS, PaaS and IaaS — that process personal data on behalf of customers, and the controllers evaluating them: privacy officers, data protection officers, procurement and vendor risk teams in regulated and consumer-facing organizations.

Where to get ISO 27018

The full text of ISO 27018 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 27018 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.

Get our free implementation resources

Send me the implementation checklist for ISO 27018, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.

We'll only email you about this standard. Unsubscribe anytime.

Looking to get certified?

You cannot be certified to ISO 27018 — it is guidance, and no accredited scheme exists for it. The closest standards you can certify against are ISO 27001 (Information Security Management Systems) and ISO 27701 (Privacy Information Management Systems).

If that is the direction you are heading, tell us what stage you are at and we will put you in touch with people who work with them. Free and no obligation.

Get help with certification

In a hurry? You can also compare quotes from verified providers on CertBetter (affiliate link — we earn a commission, and it stays free for you).

Related Standards