AuditXYZ

Compliance Framework

ISO/IEC 27018:2019 Code of Practice for Protection of Personally Identifiable Information (PII) in Public Clouds

ISO 27018 sets controls for protecting personally identifiable information in public cloud services. Learn how it helps cloud providers demonstrate PII protection compliance.

$15,000–$75,0002–6 monthsAudit Required2019
Issuing BodyInternational Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)
First Published2014-07-29
Latest Version2019
Typical Cost$15,000–$75,000
Typical Timeline2–6 months
Audit RequiredYes
Audit FrequencyAudited as an extension to ISO 27001 surveillance and recertification cycles
Geographyglobal

ISO 27018: Protecting Personal Data in the Cloud

ISO/IEC 27018 establishes commonly accepted control objectives and guidelines for protecting personally identifiable information (PII) in public cloud computing environments. It is the first international standard focused specifically on privacy in cloud services.

What ISO 27018 Covers

The standard builds on ISO 27002 controls, adding PII-specific implementation guidance and introducing additional controls derived from privacy principles. Key areas include consent management, purpose limitation, data minimization, transparency, PII disclosure procedures, sub-processor oversight, and data portability.

ISO 27018 explicitly addresses the role of the cloud service provider as a PII processor, establishing expectations for how processors handle personal data on behalf of their customers (PII controllers).

Who Needs ISO 27018

Public cloud service providers that process PII on behalf of customers are the primary audience. This includes SaaS companies handling customer data, IaaS providers hosting applications with personal data, and any cloud service that touches PII.

The standard is particularly relevant for organizations subject to GDPR, as ISO 27018 maps well to GDPR processor requirements. Companies operating in healthcare, financial services, and education — where PII sensitivity is highest — find ISO 27018 especially valuable.

Key Privacy Controls

ISO 27018 introduces controls beyond standard ISO 27002, including:

  • Consent and choice — PII must not be used for marketing without explicit consent
  • Purpose limitation — Cloud providers must not process PII beyond the customer's instructions
  • Data minimization — Temporary files containing PII must be erased within a specified period
  • Transparency — Providers must disclose sub-processors and PII storage locations
  • Breach notification — Providers must notify customers of PII breaches promptly
  • Data return — PII must be returnable and erasable upon contract termination

Certification Path

Like ISO 27017, ISO 27018 is certified as an extension to ISO 27001. The incremental effort for organizations with existing ISO 27001 certification is manageable. Primary work involves documenting PII handling procedures, implementing privacy-specific controls, and ensuring sub-processor agreements meet the standard's requirements.

Organizations pursuing ISO 27018 alongside ISO 27017 create a comprehensive cloud security and privacy posture that resonates strongly with enterprise customers and regulators.

Get the ISO 27018 starter pack

By submitting, you agree to our privacy policy.

Framework Mappings

Get matched with a ISO 27018 auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.

Recommended Tools