- Binding EU regulation included to show why legal compliance must be assessed separately from ISO/IEC 27018 controls.
"protection of natural persons with regard to the processing of personal data"
Use ISO/IEC 27018 when the service is a public cloud and the provider processes PII on a customer's behalf. Define that boundary, select controls through the supporting ISMS and risk process, and keep evidence for the exact service and claim.
ISO published edition 3 in August 2025. It aligns with ISO/IEC 27002:2022 and adds Annex B implementation guidance. Clause-level examples on this page are identified as 2019 guidance and must be checked against the 2025 edition and any edition named in a contract or assurance report.
Structured answer sets in this page tree.
Cited legal and guidance references.
ISO/IEC 27018:2025 applies to a public-cloud provider acting as a for a defined activity. It supplies privacy controls and implementation guidance, but it is not legislation and does not create a standalone certifiable management system. Start an assessment by recording the processing purpose, customer instruction, role, service boundary, edition, and assessment criteria.
The scope test has two parts. The provider must offer the processing through the public-cloud model, and it must process PII on behalf of and according to the instructions of a PII controller. A provider that decides its own purposes for a separate activity is acting as a controller for that activity, even if it is a processor for the hosted customer workload.
The standard can guide providers of any size and customers evaluating them. PII means information that can identify or be linked, directly or indirectly, to a natural person. The 2019 edition notes that a provider may not know whether data is PII without context from the customer, so the scope record should state known categories, assumptions, and who must notify whom when that context changes. The standard does not cover additional controller obligations created by a jurisdiction's privacy law.
A control mapping can show how a defined service addresses selected ISO/IEC 27018 criteria. It does not by itself show that the controls operated for a period, that every legal duty was met, or that services outside the stated boundary were assessed.
ISO/IEC 27001 contains requirements for an information security management system (ISMS). ISO/IEC 27002 supplies information-security control guidance. ISO/IEC 27018 adds controls and implementation guidance for public-cloud activities. ISO states that the 2025 edition is aligned with ISO/IEC 27002:2022.
The withdrawn 2019 edition was tied to ISO/IEC 27002:2013 and required its additional Annex A controls to be considered through an ISO/IEC 27001-based ISMS. Do not copy a 2019 clause map into a 2025 assessment without reconciling the changed structure, the 2022 control set, and the new Annex B.
An ISO/IEC 27001 certificate covers only its stated organization, locations, services, and ISMS scope. ISO/IEC 27018 can be included in assessment criteria or supporting control mappings, but the standard does not automatically extend the certificate or create a separate management-system certificate.
Evidence must show both design and operation. A policy or contract can show what should happen; tickets, logs, notices, approvals, test results, and sampled records show whether the process ran for the service and period under review.
Use the 2019 controls below as detailed historical examples, then verify the corresponding 2025 control and implementation guidance. The 2019 edition addressed customer access administration, cryptography information, log availability, independent assurance, rights assistance, purpose limits, marketing consent, disclosure records, subprocessor transparency, incident notice, and return or disposal.
Assign each selected ISO/IEC 27018 control to the scoped service, responsible owner, operating evidence, exception route, and review trigger.
Convert the scoped ISO/IEC 27018 guidance into accountable tasks, evidence requests, and review checkpoints.
Review your current scope, evidence gaps, and next implementation steps.
Do not say that ISO/IEC 27018 is law, that using it automatically satisfies a privacy regime, or that an ISO/IEC 27001 certificate covers ISO/IEC 27018 unless the certificate and supporting report identify the relevant scope and criteria. A control mapping, internal assessment, independent audit, and accredited certification are different forms of evidence.
State what was assessed and by whom. Name the edition, provider entity, service, locations if relevant, assessment criteria, period or date, assurance method, and material exceptions. Distinguish the provider's processor controls from the customer's controller duties.
Set a scheduled review and reopen the assessment when the provider's role, service architecture, processing purposes, customer instructions, known PII, subprocessors, processing countries, contract terms, applicable law, incident history, or assessment criteria change.
A change does not make every control ineffective, but it can invalidate the scope, control selection, responsibility split, or evidence sample. Record the change, affected controls, decision owner, required remediation, and the date the customer-facing claim was reviewed.
"protection of natural persons with regard to the processing of personal data"
"Information security management systems — Requirements"
"Information security controls"
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
"The 2025 edition has been aligned with the updated ISO/IEC 27002:2022"