- Binding EU data protection regulation used for ISO/IEC 27018 comparison.
"protection of natural persons with regard to the processing of personal data"
Answer the main ISO/IEC 27018 questions by separating processor scope, voluntary guidance, contract and control evidence, and applicable privacy law.
The current edition is ISO/IEC 27018:2025; the detailed control explanations here use the prior 2019 edition and should be checked against the edition named in a contract or assurance report. ISO/IEC 27018 is voluntary guidance, while applicable law and contracts can impose separate or stricter duties.
Structured answer sets in this page tree.
Cited legal and guidance references.
ISO/IEC 27018 gives public-cloud providers guidance for protecting when they process it on behalf of customers and according to customer instructions. Start by confirming that processor role, each processing purpose, the service and data in scope, the edition used by the contract or assurance report, and any binding law. The current edition is 2025; the detailed clause examples on these pages come from the withdrawn 2019 edition and should not be treated as a substitute for the current text.
These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.
How to assess ISO/IEC 27018 audit evidence by edition, service scope, criteria, audit period, exceptions, and independent assurance.
ISO/IEC 27018 breach support: when a cloud PII processor should notify a customer, what the contract should define, and what incident records to keep.
What counts as a customer instruction under ISO/IEC 27018, how a cloud PII processor should validate it, and what evidence shows it was followed.
How ISO/IEC 27018 can support GDPR processor controls without replacing Article 28 terms, controller accountability, transfers, or breach duties.
How ISO/IEC 27018 addresses legally binding law-enforcement requests: validation, customer consultation or notice, limited disclosure, and records.
How to plan and prove PII return, transfer, deletion, anonymization, or archival across live systems, backups, temporary files, and subprocessors.
What ISO/IEC 27018 expects from a public-cloud PII processor: customer instructions, purpose limits, security, transparency, incident support, and disposal.
What an ISO/IEC 27018 subprocessor notice should disclose, when customers should receive it, and what evidence should support consent and objections.
It directly targets organizations of any type or size that provide information-processing services as processors through public cloud computing under contract. A provider is acting as a PII processor when it processes PII on behalf of and according to the instructions of a PII controller.
The same provider may act as a controller for account, billing, fraud-prevention, or other data it processes for its own purposes. That controller activity falls outside ISO/IEC 27018's processor scope and needs its own legal and control analysis.
Confirm the service model and responsibility split. Application-layer access, backup, logging, and deletion responsibilities can differ across software, platform, and infrastructure services, so the contract should assign each responsibility.
The 2019 edition covers instructions and independent-purpose limits, express consent for marketing use, customer support for rights, security and confidentiality, access and logs, subprocessors and processing countries, legally binding disclosures, breach notice, return and disposal, and independent assurance.
Control selection depends on risk, the contract, applicable law, and the provider's actual role. When the standard is used with ISO/IEC 27001, omitted controls need a documented justification; additional controls may also be required.
It is voluntary guidance, not privacy law. ISO lists ISO/IEC 27018:2025 as the current third edition and ISO/IEC 27018:2019 as withdrawn. Verify the edition, audit criteria, legal entity, public-cloud service, processor scope, period, exclusions, and assurance scheme before describing what a certificate or report covers.
ISO/IEC 27018 can support an ISO/IEC 27001 control environment, but an ISO/IEC 27018 reference does not by itself prove GDPR compliance, create a lawful basis, or satisfy a contract.
Ask for the provider's role and service scope, relevant contract terms, responsibility and control mappings, current independent evidence, operating samples, subprocessor and country records, breach and disclosure handling, deletion outcomes, open findings, and customer responsibilities.
Match each item to the customer's service and review period. A certificate outside the service boundary, an expired report, or a generic policy cannot answer a service-specific control question. Keep ISO guidance separate from binding legal and contractual duties.
Record the provider role, service boundary, cited edition, contract term, control owner, current evidence, exception, and next review date.
Convert the relevant answer into scoped control tasks, evidence requests, exceptions, and review dates.
Review your current scope, evidence gaps, and next implementation steps.
Open the focused answers for processor duties, customer instructions, subprocessor notice, government access, breach support, return and deletion, audit evidence, and GDPR overlap. Each page identifies the decision, evidence, exceptions, and review triggers for that topic.
Reuse evidence across customer assurance, internal audit, supplier governance, incident review, and legal mapping only when its service, period, criteria, and limitations still match the new use.
"protection of natural persons with regard to the processing of personal data"
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"