GuideGlobalISO/IEC 27018

ISO/IEC 27018 Using the Guidance

Use ISO/IEC 27018 when the service is a public cloud and the provider processes PII on a customer's behalf. Define that boundary, select controls through the supporting ISMS and risk process, and keep evidence for the exact service and claim.

ISO published edition 3 in August 2025. It aligns with ISO/IEC 27002:2022 and adds Annex B implementation guidance. Clause-level examples on this page are identified as 2019 guidance and must be checked against the 2025 edition and any edition named in a contract or assurance report.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ISO/IEC 27018:2025 applies to a public-cloud provider acting as a for a defined activity. It supplies privacy controls and implementation guidance, but it is not legislation and does not create a standalone certifiable management system. Start an assessment by recording the processing purpose, customer instruction, role, service boundary, edition, and assessment criteria.

Section 1

Who is ISO/IEC 27018 for, and what can it demonstrate?

The scope test has two parts. The provider must offer the processing through the public-cloud model, and it must process PII on behalf of and according to the instructions of a PII controller. A provider that decides its own purposes for a separate activity is acting as a controller for that activity, even if it is a processor for the hosted customer workload.

The standard can guide providers of any size and customers evaluating them. PII means information that can identify or be linked, directly or indirectly, to a natural person. The 2019 edition notes that a provider may not know whether data is PII without context from the customer, so the scope record should state known categories, assumptions, and who must notify whom when that context changes. The standard does not cover additional controller obligations created by a jurisdiction's privacy law.

A control mapping can show how a defined service addresses selected ISO/IEC 27018 criteria. It does not by itself show that the controls operated for a period, that every legal duty was met, or that services outside the stated boundary were assessed.

  • Record the provider entity, customer, service and deployment model, processing activities, PII categories known to the provider, countries, subprocessors, and responsibility split.
  • Separate processing performed on customer instructions from account administration, service analytics, fraud prevention, or other provider purposes that require their own role analysis.
  • Name the ISO/IEC 27018 edition and the assessment method: internal mapping, customer review, independent audit, or a certification whose scope expressly includes the relevant criteria.
  • Treat applicable law, contract terms, customer instructions, risk treatment, and corporate policy as separate requirement sources. They can require controls or implementation criteria beyond the standard, and a documented omission from the control set does not waive a binding duty.
Section 2

How does ISO/IEC 27018 fit with ISO/IEC 27001 and ISO/IEC 27002?

ISO/IEC 27001 contains requirements for an information security management system (ISMS). ISO/IEC 27002 supplies information-security control guidance. ISO/IEC 27018 adds controls and implementation guidance for public-cloud activities. ISO states that the 2025 edition is aligned with ISO/IEC 27002:2022.

The withdrawn 2019 edition was tied to ISO/IEC 27002:2013 and required its additional Annex A controls to be considered through an ISO/IEC 27001-based ISMS. Do not copy a 2019 clause map into a 2025 assessment without reconciling the changed structure, the 2022 control set, and the new Annex B.

An ISO/IEC 27001 certificate covers only its stated organization, locations, services, and ISMS scope. ISO/IEC 27018 can be included in assessment criteria or supporting control mappings, but the standard does not automatically extend the certificate or create a separate management-system certificate.

  • Map each selected ISO/IEC 27018 control to the applicable risk, ISO/IEC 27002 control, owner, implementation, and evidence.
  • Record controls that do not apply, the reason, the approving role, and any alternative risk treatment.
  • Reconcile older contracts, questionnaires, and reports that cite ISO/IEC 27018:2019 before reusing them for the 2025 edition.
  • Keep the Statement of Applicability, certification scope, ISO/IEC 27018 mapping, and customer-facing claims consistent.
Section 3

What operating evidence should a public-cloud PII processor keep?

Evidence must show both design and operation. A policy or contract can show what should happen; tickets, logs, notices, approvals, test results, and sampled records show whether the process ran for the service and period under review.

Use the 2019 controls below as detailed historical examples, then verify the corresponding 2025 control and implementation guidance. The 2019 edition addressed customer access administration, cryptography information, log availability, independent assurance, rights assistance, purpose limits, marketing consent, disclosure records, subprocessor transparency, incident notice, and return or disposal.

  • Scope and instructions: service inventory, role assessment, data-flow record, customer instructions, processing countries, and contract responsibility matrix.
  • Control design: approved policies, control mapping, access model, encryption and key-management information, logging design, incident procedure, and deletion policy.
  • Control operation: access reviews, event-log samples, subprocessor notices, disclosure register entries, incident records, customer-rights support tickets, and deletion or return records.
  • Assurance: auditor or certification-body identity, criteria, entity and service scope, locations, period, exceptions, report date, and any bridge letter or corrective-action status.
Recommended next step

Put the public-cloud privacy guidance into practice

Assign each selected ISO/IEC 27018 control to the scoped service, responsible owner, operating evidence, exception route, and review trigger.

Section 5

When should the ISO/IEC 27018 control set be reassessed?

Set a scheduled review and reopen the assessment when the provider's role, service architecture, processing purposes, customer instructions, known PII, subprocessors, processing countries, contract terms, applicable law, incident history, or assessment criteria change.

A change does not make every control ineffective, but it can invalidate the scope, control selection, responsibility split, or evidence sample. Record the change, affected controls, decision owner, required remediation, and the date the customer-facing claim was reviewed.

  • Before launch: approve the role, boundary, instructions, contract allocation, selected controls, and evidence plan.
  • During operation: monitor control evidence and review material supplier, location, architecture, and purpose changes.
  • After an incident or failed control: preserve the record, assess the affected claims, correct the control, and obtain the required approval.
  • At reassessment: verify the edition, close or disclose exceptions, and retire customer statements that no longer match the evidence.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding EU regulation included to show why legal compliance must be assessed separately from ISO/IEC 27018 controls.
"protection of natural persons with regard to the processing of personal data"
iso.org
Referenced sections
  • ISO's official listing identifies ISO/IEC 27001 as the requirements standard for an information security management system.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • ISO's official listing identifies ISO/IEC 27002 as guidance for information-security controls.
"Information security controls"
iso.org
Referenced sections
  • The prior edition is withdrawn, which limits claims based on an unreconciled 2019 assessment when the stated criterion is the 2025 edition.
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
iso.org
Referenced sections
  • The current edition and its relationship to ISO/IEC 27002:2022 support checking edition alignment whenever assessment criteria change.
"The 2025 edition has been aligned with the updated ISO/IEC 27002:2022"
Related guides

Explore more topics

ISO/IEC 27018 Audit Evidence FAQ
How to assess ISO/IEC 27018 audit evidence by edition, service scope, criteria, audit period, exceptions, and independent assurance.
ISO/IEC 27018 Breach Support FAQ
ISO/IEC 27018 breach support: when a cloud PII processor should notify a customer, what the contract should define, and what incident records to keep.
ISO/IEC 27018 Cloud Privacy FAQ
ISO/IEC 27018 FAQ on public-cloud PII processor scope, customer instructions, subprocessors, disclosures, breaches, deletion, audit evidence, and GDPR.
ISO/IEC 27018 Customer Instructions FAQ
What counts as a customer instruction under ISO/IEC 27018, how a cloud PII processor should validate it, and what evidence shows it was followed.
ISO/IEC 27018 DPA Clause Review Workflow
Review cloud data-processing terms for instructions, purpose limits, controls, subprocessors, disclosures, incidents, rights support, and deletion.
ISO/IEC 27018 GDPR Overlap FAQ
How ISO/IEC 27018 can support GDPR processor controls without replacing Article 28 terms, controller accountability, transfers, or breach duties.
ISO/IEC 27018 Government Access Evidence Guide
Build a controlled government-access case record showing request authentication, legal review, notice, approval, minimized disclosure, transfer, and closure.
ISO/IEC 27018 Government Access Evidence Workflow
Triage a government request for customer PII, validate authority, decide notice and challenge options, minimize disclosure, and preserve the decision record.
ISO/IEC 27018 Government Access FAQ
How ISO/IEC 27018 addresses legally binding law-enforcement requests: validation, customer consultation or notice, limited disclosure, and records.
ISO/IEC 27018 PII Return and Deletion FAQ
How to plan and prove PII return, transfer, deletion, anonymization, or archival across live systems, backups, temporary files, and subprocessors.
ISO/IEC 27018 Privacy Control Checklist
A practical ISO/IEC 27018:2025 checklist for public-cloud PII processors, with verifiable conditions, owners, evidence, exceptions, and edition controls.
ISO/IEC 27018 Processor Duties FAQ
What ISO/IEC 27018 expects from a public-cloud PII processor: customer instructions, purpose limits, security, transparency, incident support, and disposal.
ISO/IEC 27018 Public Cloud PII Processor Scope Guide
Decide whether a service fits ISO/IEC 27018's public-cloud PII processor scope, separate processor and controller activities, and document the boundary.
ISO/IEC 27018 Subprocessor Evidence Guide
Build subprocessor evidence that proves who processed customer PII, where, under which terms and controls, after which notice and approval, and with what exit result.
ISO/IEC 27018 Subprocessor Evidence Workflow
Assess and approve a cloud subprocessor, disclose its use and countries before processing, handle customer objections, and retain operating and exit evidence.
ISO/IEC 27018 Subprocessor Notice FAQ
What an ISO/IEC 27018 subprocessor notice should disclose, when customers should receive it, and what evidence should support consent and objections.
ISO/IEC 27018 Vendor Contract Requirements Guide
Contract guide for ISO/IEC 27018 public-cloud PII processing: scope, instructions, security, subprocessors, disclosures, incidents, rights support, audits, and exit.
ISO/IEC 27018 vs GDPR Comparison
Compare ISO/IEC 27018 cloud-processor guidance with GDPR legal duties, including scope, Article 28 contracts, breaches, transfers, evidence, and assurance limits.
ISO/IEC 27018 vs ISO/IEC 27701 Comparison
Compare ISO/IEC 27018:2025 cloud-processor guidance with the independent ISO/IEC 27701:2025 privacy management system, including scope, evidence, and assurance.
ISO/IEC 27018 vs SOC 2 Privacy Comparison
Compare ISO/IEC 27018 cloud-processor guidance with a SOC 2 examination that includes Privacy, including scope, Type 1 vs Type 2, evidence, and limits.