All frameworks
ISOCertification · cloud privacy

ISO 27018 compliance

Prove you protect customers' personal data in the cloud.

ISO/IEC 27018 is the code of practice for protecting personally identifiable information (PII) when you process it on behalf of your customers in a public cloud. The 2025 third edition is realigned to ISO/IEC 27002:2022: it layers PII-processor guidance on the whole control set and adds 25 extended controls organised by the ISO/IEC 29100 privacy principles. It is the recognised, auditable way for a SaaS or public-cloud provider to show it handles the personal data entrusted to it properly.

Start from the basics

The standard

ISO/IEC 27018:2025 — Protection of PII in public clouds acting as PII processors

Who needs it

Any SaaS or public-cloud provider that stores or processes its customers' personal data and gets asked 'how do you protect PII in your cloud?' — especially those selling to privacy-regulated buyers, and anyone already holding ISO 27001 or 27017 who wants a PII-specific credential to match.

29100

privacy principles, mapped

The basics

What is ISO 27018?

An extension of ISO 27002:2022 for public-cloud PII processors: PII-specific guidance on the existing controls, plus a 25-control Annex A grouped by privacy principle (consent, purpose, minimization, disclosure limitation, transparency, accountability, information security, privacy compliance).

Squarely for the PII processor: you process personal data for, and on the instructions of, your cloud service customer (the controller). If you also decide the purposes of processing, additional obligations apply (see ISO 27701).

Certified alongside ISO 27001 by an accredited body, and aligned with the GDPR, so it is credible evidence to privacy-conscious customers and regulators.

Why it matters

What ISO 27018 does for your business

It answers the PII question

'How do you protect our users' personal data?' has no certificate of its own until 27018. It is the recognised, auditable answer for a processor.

It rides on your ISO 27001

The base controls are the ISO 27002:2022 set, so 27018 maps one-to-one to 27001 and your existing evidence carries across.

It aligns with GDPR

The Annex A controls map to GDPR processor obligations and to ISO 27701, turning 'we're GDPR-friendly' into audited proof.

What it covers

Process only on instructions

No use of customer PII for your own purposes, including marketing, without express consent.

Be transparent

Disclose sub-processing, the countries where PII is stored, and your security measures before contracting.

Be accountable

Prompt PII breach notification, recorded disclosures, and a clear return/transfer/disposal path at exit.

Secure the data

Encryption in transit, unique user IDs, confidentiality obligations, and secure erasure of temporary files.

The hard way

Processor privacy obligations are a maze: breach notification timelines, sub-processor disclosure, law-enforcement request handling, data-residency transparency, secure return and deletion at exit. Standing all of that up by hand, and evidencing it to every customer's security team, is where cloud privacy programmes stall.

The easier way, with Compliance One

  • Ships the full ISO 27018:2025 control set — every ISO 27002:2022 control with PII-processor guidance plus the 25 Annex A privacy-principle controls — enabled by default with a Statement of Applicability.
  • Auto-populates evidence: because the base controls are ISO 27002:2022, your continuous AWS/Azure/GCP posture scans flow straight into the matching controls.
  • Pre-fills the processor documents: PII protection policy, processor DPA addendum, sub-processor register, PII breach-notification and disclosure procedures, return/disposal policy, geographical-location-of-PII register and more.
  • Cross-maps to ISO 27001, ISO 27701 and GDPR, so your security and privacy programmes share one source of truth.

Do it once, reuse it everywhere. Evidence you collect for ISO 27018is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

Is ISO 27018 a standalone certification?
It is certified as an extension to ISO 27001 rather than on its own — your 27018 controls sit on top of your ISMS. The 2025 third edition realigns it to ISO 27002:2022.
What's the difference between 27017, 27018 and 27701?
27017 is cloud security controls (for customers and providers). 27018 is protecting PII specifically when you are a public-cloud PII processor. 27701 is a full privacy management system for controllers and processors. They overlap and Compliance One cross-maps them so evidence is shared.
We already have ISO 27001 — how much extra work?
Much less than a new framework. The base controls are the same ISO 27002:2022 set, so we map them one-to-one and carry your evidence across; you mainly add the 25 Annex A PII controls and a few processor documents.
Does it help with GDPR?
Yes — the Annex A controls align with GDPR processor obligations (Art. 28, 30, 32, 33). It is strong, independent evidence of a compliant processing programme, though GDPR compliance ultimately rests with you and your counsel.

Ready to tackle ISO 27018?

See exactly how Compliance One maps ISO 27018 to your environment in a 30-minute walkthrough — and how much of it we handle for you.