It answers the PII question
'How do you protect our users' personal data?' has no certificate of its own until 27018. It is the recognised, auditable answer for a processor.
Prove you protect customers' personal data in the cloud.
ISO/IEC 27018 is the code of practice for protecting personally identifiable information (PII) when you process it on behalf of your customers in a public cloud. The 2025 third edition is realigned to ISO/IEC 27002:2022: it layers PII-processor guidance on the whole control set and adds 25 extended controls organised by the ISO/IEC 29100 privacy principles. It is the recognised, auditable way for a SaaS or public-cloud provider to show it handles the personal data entrusted to it properly.
The standard
ISO/IEC 27018:2025 — Protection of PII in public clouds acting as PII processors
Who needs it
Any SaaS or public-cloud provider that stores or processes its customers' personal data and gets asked 'how do you protect PII in your cloud?' — especially those selling to privacy-regulated buyers, and anyone already holding ISO 27001 or 27017 who wants a PII-specific credential to match.
29100
privacy principles, mapped
The basics
An extension of ISO 27002:2022 for public-cloud PII processors: PII-specific guidance on the existing controls, plus a 25-control Annex A grouped by privacy principle (consent, purpose, minimization, disclosure limitation, transparency, accountability, information security, privacy compliance).
Squarely for the PII processor: you process personal data for, and on the instructions of, your cloud service customer (the controller). If you also decide the purposes of processing, additional obligations apply (see ISO 27701).
Certified alongside ISO 27001 by an accredited body, and aligned with the GDPR, so it is credible evidence to privacy-conscious customers and regulators.
Why it matters
'How do you protect our users' personal data?' has no certificate of its own until 27018. It is the recognised, auditable answer for a processor.
The base controls are the ISO 27002:2022 set, so 27018 maps one-to-one to 27001 and your existing evidence carries across.
The Annex A controls map to GDPR processor obligations and to ISO 27701, turning 'we're GDPR-friendly' into audited proof.
No use of customer PII for your own purposes, including marketing, without express consent.
Disclose sub-processing, the countries where PII is stored, and your security measures before contracting.
Prompt PII breach notification, recorded disclosures, and a clear return/transfer/disposal path at exit.
Encryption in transit, unique user IDs, confidentiality obligations, and secure erasure of temporary files.
Processor privacy obligations are a maze: breach notification timelines, sub-processor disclosure, law-enforcement request handling, data-residency transparency, secure return and deletion at exit. Standing all of that up by hand, and evidencing it to every customer's security team, is where cloud privacy programmes stall.
Do it once, reuse it everywhere. Evidence you collect for ISO 27018is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.
See exactly how Compliance One maps ISO 27018 to your environment in a 30-minute walkthrough — and how much of it we handle for you.