ISO/IEC 27018Free Resource

ISO/IEC 27018 Scope, controls, contracts, evidence, and comparisons

ISO/IEC 27018:2025 gives privacy guidance to public-cloud providers that process personally identifiable information (), meaning information that can identify or be linked to a natural person, for customers. It is a standard, not a privacy law or a standalone management-system certification, and it does not replace duties created by applicable law or contract.

By Sorena AICurrent edition: 2025No signup required
Quick scan
ISO/IEC 27018
What it covers
Privacy controls and implementation guidance for public-cloud providers acting as . It does not cover the provider's separate controller purposes or replace jurisdiction-specific controller duties. The 2025 edition is aligned with ISO/IEC 27002:2022 and adds extended implementation guidance in Annex B.
How to use it
Decide the role, purpose, data, and service boundary first. Then select controls through the applicable risk and information security management system process, assign contract responsibilities, test operation with service-specific records, justify omissions, and set scheduled and event-driven review triggers.
Who should read it first
Cloud providers, customers evaluating those providers, and privacy, security, legal, procurement, and compliance teams that need a shared scope and evidence model.

ISO published edition 3 on 26 August 2025 and withdrew the 2019 edition. The standard sets no universal implementation, breach-notification, deletion, audit, or reassessment deadline; law, contract, risk, and the selected controls determine those timings. Check the edition, criteria, entity, service scope, period, exclusions, and assessment method before relying on any conformance or assurance claim.

Key dates
Guides
Deep pages
FAQ
Standalone answers
Compare
Side-by-side
Evidence
Reusable
What this ISO/IEC 27018 hub helps you do
Understand the standard
Confirm that the service uses the public-cloud model, handles information that can identify or be linked to a person, and processes that on behalf of and according to a customer's instructions. The same provider may be a controller for separate processing that it determines, so classify each purpose and operation rather than the company as a whole.
Organize the work
Translate the processor role into allocated responsibilities, customer instructions, purpose limits, access and logging, subprocessor notice and objection routes, country transparency, legally binding disclosure handling, incident support, and return or deletion controls. Assign shared controls for the actual software, platform, or infrastructure service model.
Prepare for questions
Keep the contract, control mapping, operating samples, subprocessor and country notices, disclosure and incident records, deletion evidence, exceptions, and assurance material tied to the named entity, service boundary, period, edition, and assessment method. Reassess when roles, purposes, systems, suppliers, countries, terms, law, incidents, or criteria change.
Scope
Evidence
Review
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 16, 2026

First confirm the offering uses the public-cloud model and the provider processes on behalf of and according to the customer's instructions. Apply that test to each purpose: provider-controlled account, billing, fraud-prevention, analytics, or marketing activity needs a separate controller analysis. Then map responsibilities, purpose limits, subprocessors, countries, disclosures, incident support, security, return or deletion, and evidence to the actual service and contract.

Recommended reading path

Choose the next ISO/IEC 27018 decision

New to the standard? Confirm the public-cloud processor role first. If scope is already documented, jump to the control, contract, evidence, assurance, or comparison you need.

1

Start here: scope and responsibilities

Establish the service boundary, distinguish controller and processor activities, and understand what the standard and a scoped assurance report can and cannot demonstrate.

3

Subprocessors and compelled disclosures

Build evidence for subprocessor transparency and change notice, processing countries, legally binding disclosure requests, legally permitted customer notice, and disclosure records.

4

Compare frameworks or answer a specific question

Keep ISO/IEC 27018 distinct from binding privacy law, a broader privacy information management system, and SOC 2 examination criteria, or open the focused FAQ.

Next step

Turn ISO/IEC 27018 guidance into owned work

Assign ISO/IEC 27018 controls, evidence requests, exceptions, and review checkpoints to the teams responsible for them.

What this unlocks
  • Start with the overview to confirm whether the standard fits your cloud processing model.
  • Use the topic pages to identify the controls, evidence, and owners that matter most.
  • Keep records in one place so privacy, security, legal, and compliance teams can review the same source of truth.