FAQGlobalISO/IEC 27018

ISO/IEC 27018 FAQ

Answer the main ISO/IEC 27018 questions by separating processor scope, voluntary guidance, contract and control evidence, and applicable privacy law.

The current edition is ISO/IEC 27018:2025; the detailed control explanations here use the prior 2019 edition and should be checked against the edition named in a contract or assurance report. ISO/IEC 27018 is voluntary guidance, while applicable law and contracts can impose separate or stricter duties.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 16, 2026
FAQ modules
8

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 16, 2026
Overview

Use these answers to determine the provider's public-cloud PII processor role, the relevant ISO/IEC 27018 guidance, and the evidence or legal analysis needed next.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items32
Focused FAQ modules
8
Showing 8 of 8
FAQ module

ISO/IEC 27018 Audit Evidence FAQ

How should teams handle Audit Evidence under ISO/IEC 27018? Practical answer with owners, evidence, review triggers, and external source references.

4 items
FAQ module

ISO/IEC 27018 Breach Support FAQ

How should teams handle Breach Support under ISO/IEC 27018? Practical answer with owners, evidence, review triggers, and external source references.

4 items
FAQ module

ISO/IEC 27018 Customer Instructions FAQ

How should teams handle Customer Instructions under ISO/IEC 27018? Practical answer with owners, evidence, review triggers, and external source references.

4 items
FAQ module

ISO/IEC 27018 GDPR Overlap FAQ

How should teams handle GDPR Overlap under ISO/IEC 27018? Practical answer with owners, evidence, review triggers, and external source references.

4 items
FAQ module

ISO/IEC 27018 Government Access FAQ

How should cloud providers handle Government Access requests under ISO/IEC 27018? Practical answer with owners, evidence, review triggers, and external source references.

4 items
FAQ module

ISO/IEC 27018 PII Return and Deletion FAQ

How should cloud providers prove PII Return and Deletion under ISO/IEC 27018? Practical answer with owners, evidence, review triggers, and external source references.

4 items
FAQ module

ISO/IEC 27018 Processor Duties FAQ

How should teams handle Processor Duties under ISO/IEC 27018? Practical answer with owners, evidence, review triggers, and external source references.

4 items
FAQ module

ISO/IEC 27018 Subprocessor Notice FAQ

How should teams handle Subprocessor Notice under ISO/IEC 27018? Practical answer with owners, evidence, review triggers, and external source references.

4 items
Question 1

Who is ISO/IEC 27018 for?

It directly targets organizations providing public-cloud information-processing services as PII processors under contract; controller activity can be relevant but carries additional obligations outside this scope.

Use the page's decision and evidence steps only after confirming the public-cloud PII processor scope, the applicable customer instructions and contract, and the edition of ISO/IEC 27018 being used.

ISO/IEC 27018 is useful when it turns broad intent into repeatable work: prove how a public cloud provider protects personal data when acting as a PII processor. The page therefore ends in ownership, evidence, and review cadence, not only a definition.

  • Answer the practical question first: what decision is required, who owns it, and what evidence proves it is current?
  • Keep the answer tied to the ISO/IEC 27018 scope instead of turning it into a generic policy statement.
  • Escalate when the record changes risk acceptance, customer commitments, regulatory duties, or certification evidence.
Question 2

Which processor controls and contract topics does it cover?

Core topics include instructions and purpose limits, customer enablement, security controls, logs, subprocessors, countries, disclosures, incidents, return and deletion, and independent assurance.

A strong evidence set tells a visitor, auditor, customer, or decision owner what was decided, why it was reasonable, who approved it, and when it must be reviewed again.

  • Relevant evidence: customer instructions, DPA clauses, subprocessor notices, deletion and return records, disclosure records, access logs, and incident support evidence.
  • Decision record: scope, assumption, risk or obligation, owner, approval, and date.
  • Operation record: ticket, log, review, test, contract clause, register entry, or control sample showing the process ran.
  • Review record: result, exception, corrective action, next owner, and next review date.
Question 3

Is ISO/IEC 27018 a law or a standalone certification?

It is voluntary guidance, not privacy law. Verify the exact edition, audit or certificate scope, and assurance scheme before describing any organization or service as certified.

Avoid overfitting the workflow to one audit cycle. The same record should help during normal operations, change review, incident response, supplier review, or management review depending on the topic.

  • Intake: describe the public cloud service, PII processing activity, customer instruction, subprocessor, control, disclosure request, or incident affected.
  • Classification: decide whether this is processor scope, customer instructions, purpose limits, contract, subprocessor, disclosure, incident, deletion, or privacy-control evidence.
  • Escalation: route exceptions to the person or forum that can accept risk or fund remediation.
Question 4

What evidence should customers ask a provider for?

Ask for role and service scope, contracts, control mappings, independent evidence, samples, subprocessor and country records, disclosure and incident handling, deletion outcomes, exceptions, and current reviews.

Another failure is mixing standards and regulations without stating which source creates the requirement. Use ISO standards to structure management-system practice, and use legal sources separately when a binding obligation applies.

  • Do not cite a standard title as evidence that a process is operating.
  • Do not reuse an old audit artifact after the scope, service, supplier, or risk has changed.
  • Do not hide exceptions; record them as risk acceptance, corrective action, or management-review inputs.
Question 5

Which focused ISO/IEC 27018 question should I open next?

Open the focused answers below for processor duties, instructions, subprocessor notice, government access, breach support, deletion, audit evidence, and GDPR overlap.

Reuse evidence across customer assurance, internal audit, supplier governance, incident review, legal mapping, and management review only when each use keeps its own scope and criteria visible.

  • Set a review date and a change-trigger rule.
  • Track findings until closure and connect them to corrective actions or risk acceptance.
  • Use management review to decide resourcing, risk appetite, scope changes, and evidence quality.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding EU data protection regulation used for ISO/IEC 27018 comparison.
"protection of natural persons with regard to the processing of personal data"
eur-lex.europa.eu
Referenced sections
  • Binding EU data protection regulation used for ISO/IEC 27018 comparison.
"protection of natural persons with regard to the processing of personal data"
iso.org
Referenced sections
  • ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
iso.org
Referenced sections
  • Primary ISO listing for the 2025 edition of ISO/IEC 27018.
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"
Related guides

Explore more topics

ISO/IEC 27018 DPA Clause Workflow Template and Workflow
ISO/IEC 27018 DPA Clause Workflow for ISO/IEC 27018 Public Cloud PII Processor Privacy Controls: practical decisions, evidence, owners, review cadence, and cited implementation guidance.
ISO/IEC 27018 Government Access Evidence Guide
ISO/IEC 27018 Government Access Evidence for ISO/IEC 27018 Public Cloud PII Processor Privacy Controls: practical decisions, evidence, owners, review cadence, and cited implementation guidance.
ISO/IEC 27018 Government Access Evidence Workflow
ISO/IEC 27018 Government Access Evidence Workflow for ISO/IEC 27018 Public Cloud PII Processor Privacy Controls: practical decisions, evidence, owners, review cadence, and cited implementation guidance.
ISO/IEC 27018 Privacy Control Checklist
ISO/IEC 27018 Privacy Control Checklist for ISO/IEC 27018 Public Cloud PII Processor Privacy Controls: practical decisions, evidence, owners, review cadence, and cited implementation guidance.
ISO/IEC 27018 Public Cloud PII Processor Scope Guide
Define when ISO/IEC 27018 applies to a public cloud provider acting as a PII processor, with owner, evidence, and review guidance.
ISO/IEC 27018 Subprocessor Evidence Guide
ISO/IEC 27018 Subprocessor Evidence for ISO/IEC 27018 Public Cloud PII Processor Privacy Controls: practical decisions, evidence, owners, review cadence, and cited implementation guidance.
ISO/IEC 27018 Subprocessor Evidence Workflow
ISO/IEC 27018 Subprocessor Evidence Workflow for ISO/IEC 27018 Public Cloud PII Processor Privacy Controls: practical decisions, evidence, owners, review cadence, and cited implementation guidance.
ISO/IEC 27018 Vendor Contract Requirements Guide
ISO/IEC 27018 Vendor Contract Requirements for ISO/IEC 27018 Public Cloud PII Processor Privacy Controls: practical decisions, evidence, owners, review cadence, and cited implementation guidance.
ISO/IEC 27018 vs GDPR Comparison
ISO/IEC 27018 vs GDPR for ISO/IEC 27018 Public Cloud PII Processor Privacy Controls: practical decisions, evidence, owners, review cadence, and cited implementation guidance.
ISO/IEC 27018 vs ISO/IEC 27701 Comparison
ISO/IEC 27018 vs ISO/IEC 27701 for ISO/IEC 27018 Public Cloud PII Processor Privacy Controls: practical decisions, evidence, owners, review cadence, and cited implementation guidance.
ISO/IEC 27018 vs SOC 2 Privacy Comparison
ISO/IEC 27018 vs SOC 2 Privacy for ISO/IEC 27018 Public Cloud PII Processor Privacy Controls: practical decisions, evidence, owners, review cadence, and cited implementation guidance.
Using ISO/IEC 27018 for Public-Cloud PII Processing
Use ISO/IEC 27018 guidance for a public-cloud PII processor without confusing the standard, an ISMS certification scope, contracts, or binding privacy law.