ISO/IEC 27018
ISO 27018 is a code of practice for protecting PII in the public cloud when the provider acts as a processor. It's the international counterpart to GDPR processor obligations and is often required for EU customers.
Who it applies to
Cloud service providers acting as processors of Personally Identifiable Information.
How ISO-STANDARD.app helps with ISO 27018
10 in-depth articles
What ISO 27018 actually covers
Not general cloud security — specifically PII protection when the cloud provider is a processor.
Processor focus
The controls address provider obligations. Customer-controlled PII protection lives elsewhere (27017, 27701).
Consent and purpose
Provider must not use customer PII for its own purposes without explicit consent. This includes marketing and profiling.
Sub-processor transparency
Sub-processors disclosed, changes notified, ability to object recognised in the contract.
Return and deletion
PII returned or deleted on contract end. Certified where possible.
How ISO-STANDARD.app helps with ISO 27018
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.
ISO 27018 and GDPR: how the mapping works
27018 predates GDPR but was heavily influenced by draft GDPR. The overlap is significant but not complete.
Common ground
Processor instructions, confidentiality, security, sub-processor management, breach cooperation, data return — all present in both.
Where GDPR goes further
Article 28 formal DPA requirements, DPA-mandated audit rights, cross-border transfer instruments. GDPR is more prescriptive.
Where 27018 goes further
Specific handling controls, incident notification content, staff confidentiality obligations.
Combined use
Cloud providers use 27018 as evidence of GDPR processor readiness plus their DPA. Not a substitute for a DPA — a supporting attestation.
How ISO-STANDARD.app helps with ISO 27018
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.
The 'no marketing without consent' rule
The one 27018 rule that surprises new cloud providers.
The rule
Customer PII cannot be used by the provider for advertising or marketing without explicit consent from the customer.
What counts
Product analytics that identify individuals, upsell campaigns targeting customer users, training AI on customer data — all restricted.
Consent mechanics
Consent must be explicit — buried opt-outs in ToS don't qualify. Separate opt-in is the safe path.
Practical implications
Product telemetry needs to be aggregated/anonymised. AI training on customer content needs explicit customer opt-in and often per-tenant.
How ISO-STANDARD.app helps with ISO 27018
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.
Sub-processor disclosure under ISO 27018
Buyers want to know who handles their PII downstream. 27018 pushes providers to tell them.
Named list
Sub-processors named with country, function and relationship. Public page or contractually shared list.
Change notification
Advance notice before adding or replacing a sub-processor. The window must give customers time to object or exit.
Objection right
Customer must be able to object to a new sub-processor. Contract sets out consequences (exit, transfer, alternative arrangement).
Contractual flow-down
The provider imposes 27018-equivalent obligations on its sub-processors. Not lip service — auditable.
How ISO-STANDARD.app helps with ISO 27018
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.
Breach notification obligations under ISO 27018
Provider tells customer without undue delay. Customer then meets its own regulatory obligations.
Timing
'Without undue delay' — often contractually tightened to 24 or 48 hours. Faster than most providers' default position.
Content
What happened, what data was affected, remediation actions, contact for the customer's investigation.
Cooperation
Provider supports the customer's regulator notifications. Especially important given GDPR's 72-hour clock.
Documentation
Every notification is logged, retained, and available to auditors.
How ISO-STANDARD.app helps with ISO 27018
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.
PII return and deletion at end of service
Same principle as 27017's general data control — but with PII-specific expectations.
Return format
Standard format on request. Structured PII delivered in a way the customer can import into a successor system.
Deletion timeline
Bounded window for deletion across all copies including backups. Disclosed in the contract.
Anonymisation as alternative
In some cases, anonymisation is accepted in place of deletion. The anonymisation must be genuine — irreversible.
Certificate
A signed deletion certificate is the norm. Some providers issue it automatically.
How ISO-STANDARD.app helps with ISO 27018
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.
Staff confidentiality and training under ISO 27018
Provider staff who touch PII need signed obligations and specific training.
Confidentiality obligations
Signed at hire, refreshed periodically. Cover PII specifically, not just generic 'information'.
Access limits
Access to customer PII limited to those who need it, logged, and reviewed.
Training content
PII handling, cross-border rules, incident recognition and reporting. Job-role tailored.
Evidence
Attendance records, materials, refresh cycles. Auditors sample.
How ISO-STANDARD.app helps with ISO 27018
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.
Audit and review rights: making them workable
Every customer wants audit rights. Nobody wants dozens of customers on-site. Third-party assurance closes the gap.
Contractual right
Customer typically has an audit right. Most contracts scope it to reasonable frequency and cost-bearing.
Third-party report
27018 audit reports and SOC 2 reports satisfy audit rights for the majority of customers.
On-site fallback
For regulated customers or after incidents, direct audit is the fallback. The mechanics are pre-agreed to avoid friction.
Publication
Publishing the current 27018 certificate and executive summary in a Trust Center reduces the number of on-site audit requests.
How ISO-STANDARD.app helps with ISO 27018
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.
Cross-border PII transfers and ISO 27018
The certificate is global. The transfers underneath are not. 27018 asks you to be explicit.
Data location
Provider discloses where PII is processed and stored. Customer decides whether the disclosure is acceptable.
Transfer mechanisms
Where transfers cross data protection borders, mechanisms must exist (SCCs, IDTA, adequacy decisions).
Change notification
Change of data location = change notification. Customer decides whether to accept.
Auditability
The provider can evidence where any given tenant's PII sits — not just the corporate footprint.
How ISO-STANDARD.app helps with ISO 27018
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.
Answering buyer questionnaires with ISO 27018
27018 answers a chunk of every enterprise PII questionnaire. Structure the response so buyers see it.
The certificate as anchor
Cite the certificate and scope up front. Attach the executive summary.
Map answers to controls
Answer each PII question by pointing to the 27018 control that supports it, plus supplementary evidence.
The Trust Center path
Point buyers to your Trust Center where the certificate, DPA, sub-processor list and privacy notice already live.
What 27018 doesn't cover
Special category data-specific handling, customer-side controls, some regulated-industry regimes. Answer those separately rather than stretch 27018 further than it goes.
How ISO-STANDARD.app helps with ISO 27018
Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 27018 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 27018 shape.
Ready to evidence ISO 27018?
Load the pre-mapped controls, capture evidence continuously, and publish your ISO 27018 posture to buyers on demand.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.