---
title: "Using ISO/IEC 27018 for Public-Cloud PII Processing"
canonical_url: "https://www.sorena.io/artifacts/global/iso-27018/compliance"
source_url: "https://www.sorena.io/artifacts/global/iso-27018/compliance"
author: "Sorena AI"
description: "Decide whether ISO/IEC 27018:2025 applies to a public-cloud PII processor, how it fits an ISMS, what evidence to keep, and which claims the evidence supports."
published_at: "2026-05-09"
updated_at: "2026-07-25"
keywords:
  - "ISO/IEC 27018"
  - "public cloud PII processor"
  - "ISO/IEC 27001 ISMS"
  - "ISO/IEC 27002 controls"
  - "cloud privacy guidance"
  - "assurance evidence"
  - "ISO/IEC 27018 Public Cloud PII Processor Privacy Controls"
  - "ISO/IEC 27018 implementation guidance"
  - "Guide"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# Using ISO/IEC 27018 for Public-Cloud PII Processing

Decide whether ISO/IEC 27018:2025 applies to a public-cloud PII processor, how it fits an ISMS, what evidence to keep, and which claims the evidence supports.

*Guide* *Global* *ISO/IEC 27018*

## ISO/IEC 27018 Using the Guidance

Use ISO/IEC 27018 when the service is a public cloud and the provider processes PII on a customer's behalf. Define that boundary, select controls through the supporting ISMS and risk process, and keep evidence for the exact service and claim.

ISO published edition 3 in August 2025. It aligns with ISO/IEC 27002:2022 and adds Annex B implementation guidance. Clause-level examples on this page are identified as 2019 guidance and must be checked against the 2025 edition and any edition named in a contract or assurance report.

ISO/IEC 27018:2025 applies to a public-cloud provider acting as a PII processor for a defined activity. It supplies privacy controls and implementation guidance, but it is not legislation and does not create a standalone certifiable management system. Start an assessment by recording the processing purpose, customer instruction, role, service boundary, edition, and assessment criteria.

## Definitions

### Personally identifiable information processor

**Term:** PII processor

A PII processor processes personally identifiable information on behalf of and according to the instructions of a PII controller. The role attaches to a processing activity, not automatically to the whole provider: the same organization can be a processor for hosted customer data and a controller for account or other data used for its own purposes.

**Why it matters here:** ISO/IEC 27018 directly targets a public-cloud provider only for activities in which it acts as a PII processor. Record the customer instruction, purpose, operations, service boundary, and any separately controlled provider purpose before selecting controls or making an assurance claim.

Sources:

- [ISO/IEC 27018:2025 standard page](https://www.iso.org/standard/27018?ref=sorena.io)
- [ISO/IEC 27018:2019 standard page](https://www.iso.org/standard/76559.html?ref=sorena.io)

## Who is ISO/IEC 27018 for, and what can it demonstrate?

The scope test has two parts. The provider must offer the processing through the public-cloud model, and it must process PII on behalf of and according to the instructions of a PII controller. A provider that decides its own purposes for a separate activity is acting as a controller for that activity, even if it is a processor for the hosted customer workload.

The standard can guide providers of any size and customers evaluating them. PII means information that can identify or be linked, directly or indirectly, to a natural person. The 2019 edition notes that a provider may not know whether data is PII without context from the customer, so the scope record should state known categories, assumptions, and who must notify whom when that context changes. The standard does not cover additional controller obligations created by a jurisdiction's privacy law.

A control mapping can show how a defined service addresses selected ISO/IEC 27018 criteria. It does not by itself show that the controls operated for a period, that every legal duty was met, or that services outside the stated boundary were assessed.

- Record the provider entity, customer, service and deployment model, processing activities, PII categories known to the provider, countries, subprocessors, and responsibility split.
- Separate processing performed on customer instructions from account administration, service analytics, fraud prevention, or other provider purposes that require their own role analysis.
- Name the ISO/IEC 27018 edition and the assessment method: internal mapping, customer review, independent audit, or a certification whose scope expressly includes the relevant criteria.
- Treat applicable law, contract terms, customer instructions, risk treatment, and corporate policy as separate requirement sources. They can require controls or implementation criteria beyond the standard, and a documented omission from the control set does not waive a binding duty.

Sources for this answer:

- [ISO/IEC 27018:2025 standard page](https://www.iso.org/standard/27018?ref=sorena.io) - ISO identifies the current edition, its public-cloud PII processor scope, its alignment with ISO/IEC 27002:2022, and the addition of Annex B implementation guidance.
- [ISO/IEC 27018:2019 standard page](https://www.iso.org/standard/76559.html?ref=sorena.io) - The withdrawn 2019 scope applies to organizations providing cloud processing as PII processors under contract and says controller obligations can extend beyond the document.

## How does ISO/IEC 27018 fit with ISO/IEC 27001 and ISO/IEC 27002?

ISO/IEC 27001 contains requirements for an information security management system (ISMS). ISO/IEC 27002 supplies information-security control guidance. ISO/IEC 27018 adds controls and implementation guidance for public-cloud PII processor activities. ISO states that the 2025 edition is aligned with ISO/IEC 27002:2022.

The withdrawn 2019 edition was tied to ISO/IEC 27002:2013 and required its additional Annex A controls to be considered through an ISO/IEC 27001-based ISMS. Do not copy a 2019 clause map into a 2025 assessment without reconciling the changed structure, the 2022 control set, and the new Annex B.

An ISO/IEC 27001 certificate covers only its stated organization, locations, services, and ISMS scope. ISO/IEC 27018 can be included in assessment criteria or supporting control mappings, but the standard does not automatically extend the certificate or create a separate management-system certificate.

- Map each selected ISO/IEC 27018 control to the applicable risk, ISO/IEC 27002 control, owner, implementation, and evidence.
- Record controls that do not apply, the reason, the approving role, and any alternative risk treatment.
- Reconcile older contracts, questionnaires, and reports that cite ISO/IEC 27018:2019 before reusing them for the 2025 edition.
- Keep the Statement of Applicability, certification scope, ISO/IEC 27018 mapping, and customer-facing claims consistent.

Sources for this answer:

- [ISO/IEC 27018:2019 standard page](https://www.iso.org/standard/76559.html?ref=sorena.io) - The 2019 edition was based on ISO/IEC 27002:2013 and is now withdrawn; it is useful for interpreting historical criteria, not as the current edition.
- [ISO/IEC 27001:2022 standard page](https://www.iso.org/standard/27001?ref=sorena.io) - ISO's official listing identifies ISO/IEC 27001 as the requirements standard for an information security management system.
- [ISO/IEC 27002:2022 standard page](https://www.iso.org/standard/75652.html?ref=sorena.io) - ISO's official listing identifies ISO/IEC 27002 as guidance for information-security controls.

## What operating evidence should a public-cloud PII processor keep?

Evidence must show both design and operation. A policy or contract can show what should happen; tickets, logs, notices, approvals, test results, and sampled records show whether the process ran for the service and period under review.

Use the 2019 controls below as detailed historical examples, then verify the corresponding 2025 control and implementation guidance. The 2019 edition addressed customer access administration, cryptography information, log availability, independent assurance, rights assistance, purpose limits, marketing consent, disclosure records, subprocessor transparency, incident notice, and return or disposal.

- Scope and instructions: service inventory, role assessment, data-flow record, customer instructions, processing countries, and contract responsibility matrix.
- Control design: approved policies, control mapping, access model, encryption and key-management information, logging design, incident procedure, and deletion policy.
- Control operation: access reviews, event-log samples, subprocessor notices, disclosure register entries, incident records, customer-rights support tickets, and deletion or return records.
- Assurance: auditor or certification-body identity, criteria, entity and service scope, locations, period, exceptions, report date, and any bridge letter or corrective-action status.

Sources for this answer:

- [ISO/IEC 27018:2019 standard page](https://www.iso.org/standard/76559.html?ref=sorena.io) - Detailed 2019 guidance supports the listed historical evidence examples, including customer access, cryptography information, logs, independent audit evidence, Annex A privacy controls, and contract allocation.

*Recommended next step*

*Placement: after implementation guidance*

## Put the public-cloud privacy guidance into practice

Assign each selected ISO/IEC 27018 control to the scoped service, responsible owner, operating evidence, exception route, and review trigger.

- [Open Assessment Autopilot for ISO/IEC 27018](/solutions/assessment.md): Convert the scoped ISO/IEC 27018 guidance into accountable tasks, evidence requests, and review checkpoints.
- [Talk through implementation](/contact.md): Review your current scope, evidence gaps, and next implementation steps.

## What should teams avoid claiming about certification or legal compliance?

Do not say that ISO/IEC 27018 is law, that using it automatically satisfies a privacy regime, or that an ISO/IEC 27001 certificate covers ISO/IEC 27018 unless the certificate and supporting report identify the relevant scope and criteria. A control mapping, internal assessment, independent audit, and accredited certification are different forms of evidence.

State what was assessed and by whom. Name the edition, provider entity, service, locations if relevant, assessment criteria, period or date, assurance method, and material exceptions. Distinguish the provider's processor controls from the customer's controller duties.

- Avoid 'ISO/IEC 27018 certified' unless the issuing body and document use that wording and the scope supports it.
- Avoid 'GDPR compliant' or equivalent legal conclusions based only on an ISO assessment.
- Do not imply that a customer inherits the provider's assurance or transfers its own controller responsibilities.
- Do not reuse a 2019 control map as evidence of 2025 alignment without a documented reconciliation.

Sources for this answer:

- [ISO/IEC 27018:2025 standard page](https://www.iso.org/standard/27018?ref=sorena.io) - ISO describes ISO/IEC 27018:2025 as guidance that complements an ISO/IEC 27001-based ISMS and aligns with ISO/IEC 27002:2022.
- [ISO/IEC 27018:2019 standard page](https://www.iso.org/standard/76559.html?ref=sorena.io) - The prior edition is withdrawn, which limits claims based on an unreconciled 2019 assessment when the stated criterion is the 2025 edition.

## When should the ISO/IEC 27018 control set be reassessed?

Set a scheduled review and reopen the assessment when the provider's role, service architecture, processing purposes, customer instructions, known PII, subprocessors, processing countries, contract terms, applicable law, incident history, or assessment criteria change.

A change does not make every control ineffective, but it can invalidate the scope, control selection, responsibility split, or evidence sample. Record the change, affected controls, decision owner, required remediation, and the date the customer-facing claim was reviewed.

- Before launch: approve the role, boundary, instructions, contract allocation, selected controls, and evidence plan.
- During operation: monitor control evidence and review material supplier, location, architecture, and purpose changes.
- After an incident or failed control: preserve the record, assess the affected claims, correct the control, and obtain the required approval.
- At reassessment: verify the edition, close or disclose exceptions, and retire customer statements that no longer match the evidence.

Sources for this answer:

- [ISO/IEC 27018:2025 standard page](https://www.iso.org/standard/27018?ref=sorena.io) - The current edition and its relationship to ISO/IEC 27002:2022 support checking edition alignment whenever assessment criteria change.

## Primary sources

- [ISO/IEC 27018:2025 standard page](https://www.iso.org/standard/27018?ref=sorena.io) - Current ISO listing for edition 3, published in August 2025, aligned with ISO/IEC 27002:2022, with a new Annex B.
  - Quote: "Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"
- [ISO/IEC 27018:2019 standard page](https://www.iso.org/standard/76559.html?ref=sorena.io) - Withdrawn edition used only for the detailed historical control examples on this page and for interpreting criteria that expressly cite 2019.
  - Quote: "Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
- [GDPR consolidated text](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02016R0679-20160504&ref=sorena.io) - Binding EU regulation included to show why legal compliance must be assessed separately from ISO/IEC 27018 controls.
  - Quote: "protection of natural persons with regard to the processing of personal data"

## Related Topic Guides

- [ISO/IEC 27018 Audit Evidence FAQ](/artifacts/global/iso-27018/faq/audit-evidence.md): How to assess ISO/IEC 27018 audit evidence by edition, service scope, criteria, audit period, exceptions, and independent assurance.
- [ISO/IEC 27018 Breach Support FAQ](/artifacts/global/iso-27018/faq/breach-support.md): ISO/IEC 27018 breach support: when a cloud PII processor should notify a customer, what the contract should define, and what incident records to keep.
- [ISO/IEC 27018 Cloud Privacy FAQ](/artifacts/global/iso-27018/faq.md): ISO/IEC 27018 FAQ on public-cloud PII processor scope, customer instructions, subprocessors, disclosures, breaches, deletion, audit evidence, and GDPR.
- [ISO/IEC 27018 Customer Instructions FAQ](/artifacts/global/iso-27018/faq/customer-instructions.md): What counts as a customer instruction under ISO/IEC 27018, how a cloud PII processor should validate it, and what evidence shows it was followed.
- [ISO/IEC 27018 DPA Clause Review Workflow](/artifacts/global/iso-27018/dpa-clause-workflow.md): Review cloud data-processing terms for instructions, purpose limits, controls, subprocessors, disclosures, incidents, rights support, and deletion.
- [ISO/IEC 27018 GDPR Overlap FAQ](/artifacts/global/iso-27018/faq/gdpr-overlap.md): How ISO/IEC 27018 can support GDPR processor controls without replacing Article 28 terms, controller accountability, transfers, or breach duties.
- [ISO/IEC 27018 Government Access Evidence Guide](/artifacts/global/iso-27018/government-access-evidence.md): Build a controlled government-access case record showing request authentication, legal review, notice, approval, minimized disclosure, transfer, and closure.
- [ISO/IEC 27018 Government Access Evidence Workflow](/artifacts/global/iso-27018/government-access-evidence-workflow.md): Triage a government request for customer PII, validate authority, decide notice and challenge options, minimize disclosure, and preserve the decision record.
- [ISO/IEC 27018 Government Access FAQ](/artifacts/global/iso-27018/faq/government-access.md): How ISO/IEC 27018 addresses legally binding law-enforcement requests: validation, customer consultation or notice, limited disclosure, and records.
- [ISO/IEC 27018 PII Return and Deletion FAQ](/artifacts/global/iso-27018/faq/pii-return-and-deletion.md): How to plan and prove PII return, transfer, deletion, anonymization, or archival across live systems, backups, temporary files, and subprocessors.
- [ISO/IEC 27018 Privacy Control Checklist](/artifacts/global/iso-27018/privacy-control-checklist.md): A practical ISO/IEC 27018:2025 checklist for public-cloud PII processors, with verifiable conditions, owners, evidence, exceptions, and edition controls.
- [ISO/IEC 27018 Processor Duties FAQ](/artifacts/global/iso-27018/faq/processor-duties.md): What ISO/IEC 27018 expects from a public-cloud PII processor: customer instructions, purpose limits, security, transparency, incident support, and disposal.
- [ISO/IEC 27018 Public Cloud PII Processor Scope Guide](/artifacts/global/iso-27018/public-cloud-pii-processor-scope.md): Decide whether a service fits ISO/IEC 27018's public-cloud PII processor scope, separate processor and controller activities, and document the boundary.
- [ISO/IEC 27018 Subprocessor Evidence Guide](/artifacts/global/iso-27018/subprocessor-evidence.md): Build subprocessor evidence that proves who processed customer PII, where, under which terms and controls, after which notice and approval, and with what exit result.
- [ISO/IEC 27018 Subprocessor Evidence Workflow](/artifacts/global/iso-27018/subprocessor-evidence-workflow.md): Assess and approve a cloud subprocessor, disclose its use and countries before processing, handle customer objections, and retain operating and exit evidence.
- [ISO/IEC 27018 Subprocessor Notice FAQ](/artifacts/global/iso-27018/faq/subprocessor-notice.md): What an ISO/IEC 27018 subprocessor notice should disclose, when customers should receive it, and what evidence should support consent and objections.
- [ISO/IEC 27018 Vendor Contract Requirements Guide](/artifacts/global/iso-27018/vendor-contract-requirements.md): Contract guide for ISO/IEC 27018 public-cloud PII processing: scope, instructions, security, subprocessors, disclosures, incidents, rights support, audits, and exit.
- [ISO/IEC 27018 vs GDPR Comparison](/artifacts/global/iso-27018/iso-27018-vs-gdpr.md): Compare ISO/IEC 27018 cloud-processor guidance with GDPR legal duties, including scope, Article 28 contracts, breaches, transfers, evidence, and assurance limits.
- [ISO/IEC 27018 vs ISO/IEC 27701 Comparison](/artifacts/global/iso-27018/iso-27018-vs-iso-27701.md): Compare ISO/IEC 27018:2025 cloud-processor guidance with the independent ISO/IEC 27701:2025 privacy management system, including scope, evidence, and assurance.
- [ISO/IEC 27018 vs SOC 2 Privacy Comparison](/artifacts/global/iso-27018/iso-27018-vs-soc-2-privacy.md): Compare ISO/IEC 27018 cloud-processor guidance with a SOC 2 examination that includes Privacy, including scope, Type 1 vs Type 2, evidence, and limits.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/global/iso-27018/compliance.md
