AuditXYZ

Compliance Framework

ISO/IEC 27018:2019 Code of Practice for Protection of Personally Identifiable Information (PII) in Public Clouds (ISO 27018)

ISO 27018 sets controls for protecting personally identifiable information in public cloud services. Learn how it helps cloud providers demonstrate PII protection compliance.

$15,000–$75,0002–6 monthsAudit Required2019
Issuing BodyInternational Organization for Standardization (ISO) / International Electrotechnical Commission (IEC)
First Published2014-07-29
Latest Version2019
Typical Cost$15,000–$75,000
Typical Timeline2–6 months
Audit RequiredYes
Audit FrequencyAudited as an extension to ISO 27001 surveillance and recertification cycles
Geographyglobal

ISO 27018: Protecting Personal Data in the Cloud

ISO/IEC 27018 establishes commonly accepted control objectives and guidelines for protecting personally identifiable information (PII) in public cloud computing environments. It is the first international standard focused specifically on privacy in cloud services.

What ISO 27018 Covers

The standard builds on ISO 27002 controls, adding PII-specific implementation guidance and introducing additional controls derived from privacy principles. Key areas include consent management, purpose limitation, data minimization, transparency, PII disclosure procedures, sub-processor oversight, and data portability.

ISO 27018 explicitly addresses the role of the cloud service provider as a PII processor, establishing expectations for how processors handle personal data on behalf of their customers (PII controllers).

Who Needs ISO 27018

Public cloud service providers that process PII on behalf of customers are the primary audience. This includes SaaS companies handling customer data, IaaS providers hosting applications with personal data, and any cloud service that touches PII.

The standard is particularly relevant for organizations subject to GDPR, as ISO 27018 maps well to GDPR processor requirements. Companies operating in healthcare, financial services, and education — where PII sensitivity is highest — find ISO 27018 especially valuable.

Key Privacy Controls

ISO 27018 introduces controls beyond standard ISO 27002, including:

  • Consent and choice — PII must not be used for marketing without explicit consent
  • Purpose limitation — Cloud providers must not process PII beyond the customer's instructions
  • Data minimization — Temporary files containing PII must be erased within a specified period
  • Transparency — Providers must disclose sub-processors and PII storage locations
  • Breach notification — Providers must notify customers of PII breaches promptly
  • Data return — PII must be returnable and erasable upon contract termination

Certification Path

Like ISO 27017, ISO 27018 is certified as an extension to ISO 27001. The incremental effort for organizations with existing ISO 27001 certification is manageable. Primary work involves documenting PII handling procedures, implementing privacy-specific controls, and ensuring sub-processor agreements meet the standard's requirements.

Organizations pursuing ISO 27018 alongside ISO 27017 create a comprehensive cloud security and privacy posture that resonates strongly with enterprise customers and regulators.

Key Privacy Controls in Detail

Consent and choice — Cloud providers may not use customer PII for their own purposes (such as advertising or service improvement) without obtaining explicit consent from the PII controller. This directly aligns with GDPR's purpose limitation principle.

Purpose limitation — Processing must be restricted to the customer's documented instructions. If a customer directs you to process data only for analytics, you cannot use it for model training or product development without explicit authorization.

Data minimization — Temporary files and caches containing PII must be erased within a specified period. This prevents uncontrolled accumulation of personal data in logs, backups, and intermediate processing artifacts.

Transparency — Providers must publicly disclose information about their PII handling practices: sub-processors used, geographic locations where data is stored, and applicable legal jurisdictions. Enterprise buyers now routinely request this as part of vendor due diligence.

Breach notification — ISO 27018 requires providers to notify customers of PII-involving security incidents promptly. The standard does not specify a timeframe as precisely as GDPR's 72-hour notification rule, but aligning with GDPR timelines is best practice.

Data return and deletion — Upon contract termination, providers must return PII to the customer and delete it from all systems, including backups, within a defined period. Providers must be able to certify deletion.

Sub-processor accountability — When a cloud provider engages sub-processors that handle customer PII, the provider remains accountable. ISO 27018 requires disclosure of sub-processors, customer notification of changes, and flow-down of privacy obligations to sub-processors via contract.

PII disclosure restrictions — Providers must not disclose customer PII to third parties (including law enforcement) without customer consent unless legally compelled. When legally compelled, the provider must notify the customer if permitted by law.

The Certification Process

ISO 27018 follows the same extension model as ISO 27017. It cannot be certified independently.

Step 1 — Establish ISO 27001 ISMS. Complete or actively maintain ISO 27001 certification. The ISMS provides the management system foundation.

Step 2 — PII inventory and data flow mapping. Comprehensively map all PII you process as a cloud provider: what categories, from which customers, through which internal systems and sub-processors, stored in which locations.

Step 3 — Gap analysis against ISO 27018 controls. Compare current PII handling procedures against each ISO 27018 control. Sub-processor disclosure and deletion procedures are the most common gap areas.

Step 4 — Policy and contract updates. Update your privacy policy, data processing agreements, sub-processor agreements, and breach notification procedures to meet ISO 27018 requirements.

Step 5 — Internal audit. Conduct an internal audit covering both ISO 27001 and ISO 27018 controls.

Step 6 — Extended certification audit. Your certification body audits ISO 27018 controls as an extension to your ISO 27001 Stage 2 or surveillance audit.

Costs and Timeline

ComponentLow EstimateHigh Estimate
PII inventory and data mapping$5,000$20,000
Policy and contract updates$5,000$15,000
Extended audit scope$5,000$15,000
Sub-processor management tooling$2,000$10,000
Total incremental cost (from ISO 27001)$17,000$60,000

Timeline: 2 to 6 months for organizations with an active ISO 27001 ISMS. Longer if PII flows are complex or sub-processor contracts require extensive renegotiation.

ISO 27018 vs. ISO 27701 — ISO 27018 is cloud-specific and focuses on the provider role. ISO 27701 extends ISO 27001 into a full Privacy Information Management System covering both controllers and processors in all contexts, not just cloud. ISO 27701 is the more comprehensive privacy certification; ISO 27018 is the cloud-specific supplement.

ISO 27018 vs. GDPR — With roughly 55% overlap, ISO 27018 addresses many GDPR processor obligations but does not constitute a GDPR compliance certification. Organizations subject to GDPR should use ISO 27018 as a control framework supplement rather than a GDPR substitute.

ISO 27018 vs. ISO 27017ISO 27017 handles cloud security controls; ISO 27018 handles cloud PII privacy. The two are designed to work together and many organizations pursue both simultaneously.

How Automation Helps

Managing consent records, sub-processor inventories, and deletion workflows manually creates compliance risk as your customer base scales. Compliance automation platforms that integrate with your data infrastructure can automate evidence collection for many ISO 27018 controls.

LowerPlane supports ISO 27018 alongside ISO 27001 and ISO 27017 as part of its 50-plus framework library. At $4,000/year entry pricing with a free tier, it is a cost-effective way to manage the evidence requirements across all three ISO cloud standards simultaneously. AuditXYZ rates it 9.4/10. Full platform comparison at Best Compliance Automation Platforms.

Frequently Asked Questions

Is ISO 27018 the same as GDPR compliance? No. ISO 27018 certification demonstrates that your PII handling controls align with internationally recognized cloud privacy best practices, which overlaps with GDPR processor requirements. It is not a GDPR certification mechanism. For a more direct GDPR alignment path, consider ISO 27701, which maps explicitly to GDPR articles.

Do I need both ISO 27017 and ISO 27018? Not necessarily. If you process PII in cloud services, ISO 27018 is the more privacy-specific standard. ISO 27017 is broader cloud security. Many cloud providers pursue both because they address different buyer concerns — security teams care about ISO 27017 and privacy/legal teams care about ISO 27018.

How does ISO 27018 handle AI model training on customer data? The purpose limitation control directly applies. Using customer PII to train AI models requires explicit authorization from the PII controller. This has become a significant focus area in enterprise procurement as AI features proliferate in SaaS products.

What happens to my ISO 27018 certification if I add a new sub-processor? You must notify your customers of the new sub-processor (typically with a defined notice period in your DPA). The sub-processor must be bound by equivalent privacy obligations. Failure to disclose is a nonconformity under ISO 27018 and a potential GDPR violation. Maintaining an up-to-date, publicly accessible sub-processor list is the practical minimum.

Request a ISO 27018 consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

ISO 27001High80%
GDPRMedium55%

Get matched with a ISO 27018 auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.