All resources
Guide 8 min read

ISO 27018 explained: proof you protect PII in the cloud

C1The Compliance One team30 August 2026

Most SaaS companies are, in privacy terms, a processor. Your customer decides what personal data to collect and why; you hold and process it on their behalf, in a public cloud, doing what they instruct. That role comes with specific obligations, and until recently there was no clean way to prove you meet them. ISO 27018 is that way.

It is the code of practice for protecting personally identifiable information (PII) in public clouds acting as PII processors. The 2025 third edition was realigned to ISO 27002:2022, so it layers PII-processor guidance on the control set you may already know, and adds 25 extended controls grouped by the privacy principles of ISO 29100.

ISO 27001 proves your security. ISO 27018 proves that when the data in question is somebody's personal information, you handle it the way a careful processor should. Buyers' privacy teams ask for the second one by name.

What the 25 extra controls actually cover

The Annex A controls are refreshingly concrete, and they map to the questions customers actually ask:

  • Breach notification: tell the customer promptly when PII is exposed, with what they need to notify regulators.
  • Sub-processing transparency: disclose who else touches the data, before you use them.
  • Return and deletion: give the data back and delete it, including from backups, when the contract ends.
  • Where the data lives: document the countries PII can be stored in, and the transfer safeguards.
  • No surprise uses: never use customer PII for your own marketing without express consent.

Why it is easier than it looks

Because the base controls are the ISO 27002:2022 set, ISO 27018 is certified as an extension to ISO 27001, not as a separate scheme. If you already hold 27001, you have done the structural work; you mainly add the 25 PII controls and a handful of processor documents. In Compliance One the whole control set ships enabled with a Statement of Applicability, the processor documents come pre-filled, and your continuous cloud-posture evidence flows into the matching controls automatically. The privacy question stops being a nervous email and becomes an attachment.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map this to your environment.