ISO/IEC 27018 Scope, controls, contracts, evidence, and comparisons
ISO/IEC 27018:2025 gives privacy guidance to public-cloud providers that process personally identifiable information (), meaning information that can identify or be linked to a natural person, for customers. It is a standard, not a privacy law or a standalone management-system certification, and it does not replace duties created by applicable law or contract.
ISO published edition 3 on 26 August 2025 and withdrew the 2019 edition. The standard sets no universal implementation, breach-notification, deletion, audit, or reassessment deadline; law, contract, risk, and the selected controls determine those timings. Check the edition, criteria, entity, service scope, period, exclusions, and assessment method before relying on any conformance or assurance claim.
First confirm the offering uses the public-cloud model and the provider processes on behalf of and according to the customer's instructions. Apply that test to each purpose: provider-controlled account, billing, fraud-prevention, analytics, or marketing activity needs a separate controller analysis. Then map responsibilities, purpose limits, subprocessors, countries, disclosures, incident support, security, return or deletion, and evidence to the actual service and contract.
Choose the next ISO/IEC 27018 decision
New to the standard? Confirm the public-cloud processor role first. If scope is already documented, jump to the control, contract, evidence, assurance, or comparison you need.
Start here: scope and responsibilities
Establish the service boundary, distinguish controller and processor activities, and understand what the standard and a scoped assurance report can and cannot demonstrate.
Customer instructions and contract controls
Turn the role split into processing instructions, purpose limits, allocated technical and organizational measures, rights and incident assistance, and end-of-service outcomes.
Subprocessors and compelled disclosures
Build evidence for subprocessor transparency and change notice, processing countries, legally binding disclosure requests, legally permitted customer notice, and disclosure records.
Compare frameworks or answer a specific question
Keep ISO/IEC 27018 distinct from binding privacy law, a broader privacy information management system, and SOC 2 examination criteria, or open the focused FAQ.
Turn ISO/IEC 27018 guidance into owned work
Assign ISO/IEC 27018 controls, evidence requests, exceptions, and review checkpoints to the teams responsible for them.
- Start with the overview to confirm whether the standard fits your cloud processing model.
- Use the topic pages to identify the controls, evidence, and owners that matter most.
- Keep records in one place so privacy, security, legal, and compliance teams can review the same source of truth.