ISO/IEC 27018

ISO 27018 is a code of practice for protecting PII in the public cloud when the provider acts as a processor. It's the international counterpart to GDPR processor obligations and is often required for EU customers.

Who it applies to

Cloud service providers acting as processors of Personally Identifiable Information.

How ISO-STANDARD.app helps with ISO 27018

Pre-loaded ISO 27018 control mapping crosswalked to ISO 27001 Annex A so you don't duplicate work.

Evidence Vault stores signed, versioned artefacts (screenshots, logs, attestations) auditors and buyers accept.

Trust Center publishes your current ISO 27018 posture to prospects on demand — no PDF chase.

Internal Audit, CAPA and Management Review workflows built in, mapped to ISO 27018 clauses.

Policy templates with attestation, review cycles and change history that satisfy assessor sampling.

10 in-depth articles

What ISO 27018 actually covers

Not general cloud security — specifically PII protection when the cloud provider is a processor.

Processor focus

The controls address provider obligations. Customer-controlled PII protection lives elsewhere (27017, 27701).

Consent and purpose

Provider must not use customer PII for its own purposes without explicit consent. This includes marketing and profiling.

Sub-processor transparency

Sub-processors disclosed, changes notified, ability to object recognised in the contract.

Return and deletion

PII returned or deleted on contract end. Certified where possible.

How ISO-STANDARD.app helps with ISO 27018

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.

ISO 27018 and GDPR: how the mapping works

27018 predates GDPR but was heavily influenced by draft GDPR. The overlap is significant but not complete.

Common ground

Processor instructions, confidentiality, security, sub-processor management, breach cooperation, data return — all present in both.

Where GDPR goes further

Article 28 formal DPA requirements, DPA-mandated audit rights, cross-border transfer instruments. GDPR is more prescriptive.

Where 27018 goes further

Specific handling controls, incident notification content, staff confidentiality obligations.

Combined use

Cloud providers use 27018 as evidence of GDPR processor readiness plus their DPA. Not a substitute for a DPA — a supporting attestation.

How ISO-STANDARD.app helps with ISO 27018

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.

The 'no marketing without consent' rule

The one 27018 rule that surprises new cloud providers.

The rule

Customer PII cannot be used by the provider for advertising or marketing without explicit consent from the customer.

What counts

Product analytics that identify individuals, upsell campaigns targeting customer users, training AI on customer data — all restricted.

Consent mechanics

Consent must be explicit — buried opt-outs in ToS don't qualify. Separate opt-in is the safe path.

Practical implications

Product telemetry needs to be aggregated/anonymised. AI training on customer content needs explicit customer opt-in and often per-tenant.

How ISO-STANDARD.app helps with ISO 27018

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.

Sub-processor disclosure under ISO 27018

Buyers want to know who handles their PII downstream. 27018 pushes providers to tell them.

Named list

Sub-processors named with country, function and relationship. Public page or contractually shared list.

Change notification

Advance notice before adding or replacing a sub-processor. The window must give customers time to object or exit.

Objection right

Customer must be able to object to a new sub-processor. Contract sets out consequences (exit, transfer, alternative arrangement).

Contractual flow-down

The provider imposes 27018-equivalent obligations on its sub-processors. Not lip service — auditable.

How ISO-STANDARD.app helps with ISO 27018

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.

Breach notification obligations under ISO 27018

Provider tells customer without undue delay. Customer then meets its own regulatory obligations.

Timing

'Without undue delay' — often contractually tightened to 24 or 48 hours. Faster than most providers' default position.

Content

What happened, what data was affected, remediation actions, contact for the customer's investigation.

Cooperation

Provider supports the customer's regulator notifications. Especially important given GDPR's 72-hour clock.

Documentation

Every notification is logged, retained, and available to auditors.

How ISO-STANDARD.app helps with ISO 27018

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.

PII return and deletion at end of service

Same principle as 27017's general data control — but with PII-specific expectations.

Return format

Standard format on request. Structured PII delivered in a way the customer can import into a successor system.

Deletion timeline

Bounded window for deletion across all copies including backups. Disclosed in the contract.

Anonymisation as alternative

In some cases, anonymisation is accepted in place of deletion. The anonymisation must be genuine — irreversible.

Certificate

A signed deletion certificate is the norm. Some providers issue it automatically.

How ISO-STANDARD.app helps with ISO 27018

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.

Staff confidentiality and training under ISO 27018

Provider staff who touch PII need signed obligations and specific training.

Confidentiality obligations

Signed at hire, refreshed periodically. Cover PII specifically, not just generic 'information'.

Access limits

Access to customer PII limited to those who need it, logged, and reviewed.

Training content

PII handling, cross-border rules, incident recognition and reporting. Job-role tailored.

Evidence

Attendance records, materials, refresh cycles. Auditors sample.

How ISO-STANDARD.app helps with ISO 27018

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.

Audit and review rights: making them workable

Every customer wants audit rights. Nobody wants dozens of customers on-site. Third-party assurance closes the gap.

Contractual right

Customer typically has an audit right. Most contracts scope it to reasonable frequency and cost-bearing.

Third-party report

27018 audit reports and SOC 2 reports satisfy audit rights for the majority of customers.

On-site fallback

For regulated customers or after incidents, direct audit is the fallback. The mechanics are pre-agreed to avoid friction.

Publication

Publishing the current 27018 certificate and executive summary in a Trust Center reduces the number of on-site audit requests.

How ISO-STANDARD.app helps with ISO 27018

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.

Cross-border PII transfers and ISO 27018

The certificate is global. The transfers underneath are not. 27018 asks you to be explicit.

Data location

Provider discloses where PII is processed and stored. Customer decides whether the disclosure is acceptable.

Transfer mechanisms

Where transfers cross data protection borders, mechanisms must exist (SCCs, IDTA, adequacy decisions).

Change notification

Change of data location = change notification. Customer decides whether to accept.

Auditability

The provider can evidence where any given tenant's PII sits — not just the corporate footprint.

How ISO-STANDARD.app helps with ISO 27018

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.

Answering buyer questionnaires with ISO 27018

27018 answers a chunk of every enterprise PII questionnaire. Structure the response so buyers see it.

The certificate as anchor

Cite the certificate and scope up front. Attach the executive summary.

Map answers to controls

Answer each PII question by pointing to the 27018 control that supports it, plus supplementary evidence.

The Trust Center path

Point buyers to your Trust Center where the certificate, DPA, sub-processor list and privacy notice already live.

What 27018 doesn't cover

Special category data-specific handling, customer-side controls, some regulated-industry regimes. Answer those separately rather than stretch 27018 further than it goes.

How ISO-STANDARD.app helps with ISO 27018

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.

Ready to evidence ISO 27018?

Load the pre-mapped controls, capture evidence continuously, and publish your ISO 27018 posture to buyers on demand.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.