FAQGlobalISO/IEC 27018

ISO/IEC 27018 FAQ

Answer the main ISO/IEC 27018 questions by separating processor scope, voluntary guidance, contract and control evidence, and applicable privacy law.

The current edition is ISO/IEC 27018:2025; the detailed control explanations here use the prior 2019 edition and should be checked against the edition named in a contract or assurance report. ISO/IEC 27018 is voluntary guidance, while applicable law and contracts can impose separate or stricter duties.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
FAQ modules
8

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ISO/IEC 27018 gives public-cloud providers guidance for protecting when they process it on behalf of customers and according to customer instructions. Start by confirming that processor role, each processing purpose, the service and data in scope, the edition used by the contract or assurance report, and any binding law. The current edition is 2025; the detailed clause examples on these pages come from the withdrawn 2019 edition and should not be treated as a substitute for the current text.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items32
Focused FAQ modules
8
Showing 8 of 8
FAQ module

ISO/IEC 27018 Audit Evidence FAQ

How to assess ISO/IEC 27018 audit evidence by edition, service scope, criteria, audit period, exceptions, and independent assurance.

4 items
FAQ module

ISO/IEC 27018 Breach Support FAQ

ISO/IEC 27018 breach support: when a cloud PII processor should notify a customer, what the contract should define, and what incident records to keep.

4 items
FAQ module

ISO/IEC 27018 Customer Instructions FAQ

What counts as a customer instruction under ISO/IEC 27018, how a cloud PII processor should validate it, and what evidence shows it was followed.

4 items
FAQ module

ISO/IEC 27018 GDPR Overlap FAQ

How ISO/IEC 27018 can support GDPR processor controls without replacing Article 28 terms, controller accountability, transfers, or breach duties.

4 items
FAQ module

ISO/IEC 27018 Government Access FAQ

How ISO/IEC 27018 addresses legally binding law-enforcement requests: validation, customer consultation or notice, limited disclosure, and records.

4 items
FAQ module

ISO/IEC 27018 PII Return and Deletion FAQ

How to plan and prove PII return, transfer, deletion, anonymization, or archival across live systems, backups, temporary files, and subprocessors.

4 items
FAQ module

ISO/IEC 27018 Processor Duties FAQ

What ISO/IEC 27018 expects from a public-cloud PII processor: customer instructions, purpose limits, security, transparency, incident support, and disposal.

4 items
FAQ module

ISO/IEC 27018 Subprocessor Notice FAQ

What an ISO/IEC 27018 subprocessor notice should disclose, when customers should receive it, and what evidence should support consent and objections.

4 items
Question 1

Who is ISO/IEC 27018 for?

It directly targets organizations of any type or size that provide information-processing services as processors through public cloud computing under contract. A provider is acting as a PII processor when it processes PII on behalf of and according to the instructions of a PII controller.

The same provider may act as a controller for account, billing, fraud-prevention, or other data it processes for its own purposes. That controller activity falls outside ISO/IEC 27018's processor scope and needs its own legal and control analysis.

Confirm the service model and responsibility split. Application-layer access, backup, logging, and deletion responsibilities can differ across software, platform, and infrastructure services, so the contract should assign each responsibility.

  • Answer the practical question first: what decision is required, who owns it, and what evidence proves it is current?
  • Keep the answer tied to the ISO/IEC 27018 scope instead of turning it into a generic policy statement.
  • Escalate when the record changes risk acceptance, customer commitments, regulatory duties, or certification evidence.
Question 2

Which processor controls and contract topics does it cover?

The 2019 edition covers instructions and independent-purpose limits, express consent for marketing use, customer support for rights, security and confidentiality, access and logs, subprocessors and processing countries, legally binding disclosures, breach notice, return and disposal, and independent assurance.

Control selection depends on risk, the contract, applicable law, and the provider's actual role. When the standard is used with ISO/IEC 27001, omitted controls need a documented justification; additional controls may also be required.

  • Relevant evidence: customer instructions, DPA clauses, subprocessor notices, deletion and return records, disclosure records, access logs, and incident support evidence.
  • Decision record: scope, assumption, risk or obligation, owner, approval, and date.
  • Operation record: ticket, log, review, test, contract clause, register entry, or control sample showing the process ran.
  • Review record: result, exception, corrective action, next owner, and next review date.
Question 3

Is ISO/IEC 27018 a law or a standalone certification?

It is voluntary guidance, not privacy law. ISO lists ISO/IEC 27018:2025 as the current third edition and ISO/IEC 27018:2019 as withdrawn. Verify the edition, audit criteria, legal entity, public-cloud service, processor scope, period, exclusions, and assurance scheme before describing what a certificate or report covers.

ISO/IEC 27018 can support an ISO/IEC 27001 control environment, but an ISO/IEC 27018 reference does not by itself prove GDPR compliance, create a lawful basis, or satisfy a contract.

  • Intake: describe the public cloud service, processing activity, customer instruction, subprocessor, control, disclosure request, or incident affected.
  • Classification: decide whether this is processor scope, customer instructions, purpose limits, contract, subprocessor, disclosure, incident, deletion, or privacy-control evidence.
  • Escalation: route exceptions to the person or forum that can accept risk or fund remediation.
Question 4

What evidence should customers ask a provider for?

Ask for the provider's role and service scope, relevant contract terms, responsibility and control mappings, current independent evidence, operating samples, subprocessor and country records, breach and disclosure handling, deletion outcomes, open findings, and customer responsibilities.

Match each item to the customer's service and review period. A certificate outside the service boundary, an expired report, or a generic policy cannot answer a service-specific control question. Keep ISO guidance separate from binding legal and contractual duties.

  • Do not cite a standard title as evidence that a process is operating.
  • Do not reuse an old audit artifact after the scope, service, supplier, or risk has changed.
  • Do not hide exceptions; record them as risk acceptance, corrective action, or management-review inputs.
Question 5

Which focused ISO/IEC 27018 question should I open next?

Open the focused answers for processor duties, customer instructions, subprocessor notice, government access, breach support, return and deletion, audit evidence, and GDPR overlap. Each page identifies the decision, evidence, exceptions, and review triggers for that topic.

Reuse evidence across customer assurance, internal audit, supplier governance, incident review, and legal mapping only when its service, period, criteria, and limitations still match the new use.

  • Set a review date and a change-trigger rule.
  • Track findings until closure and connect them to corrective actions or risk acceptance.
  • Use management review to decide resourcing, risk appetite, scope changes, and evidence quality.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding EU data protection regulation used for ISO/IEC 27018 comparison.
"protection of natural persons with regard to the processing of personal data"
iso.org
Referenced sections
  • ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
iso.org
Referenced sections
  • Primary ISO listing for the 2025 edition of ISO/IEC 27018.
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"
Related guides

Explore more topics

ISO/IEC 27018 DPA Clause Review Workflow
Review cloud data-processing terms for instructions, purpose limits, controls, subprocessors, disclosures, incidents, rights support, and deletion.
ISO/IEC 27018 Government Access Evidence Guide
Build a controlled government-access case record showing request authentication, legal review, notice, approval, minimized disclosure, transfer, and closure.
ISO/IEC 27018 Government Access Evidence Workflow
Triage a government request for customer PII, validate authority, decide notice and challenge options, minimize disclosure, and preserve the decision record.
ISO/IEC 27018 Privacy Control Checklist
A practical ISO/IEC 27018:2025 checklist for public-cloud PII processors, with verifiable conditions, owners, evidence, exceptions, and edition controls.
ISO/IEC 27018 Public Cloud PII Processor Scope Guide
Decide whether a service fits ISO/IEC 27018's public-cloud PII processor scope, separate processor and controller activities, and document the boundary.
ISO/IEC 27018 Subprocessor Evidence Guide
Build subprocessor evidence that proves who processed customer PII, where, under which terms and controls, after which notice and approval, and with what exit result.
ISO/IEC 27018 Subprocessor Evidence Workflow
Assess and approve a cloud subprocessor, disclose its use and countries before processing, handle customer objections, and retain operating and exit evidence.
ISO/IEC 27018 Vendor Contract Requirements Guide
Contract guide for ISO/IEC 27018 public-cloud PII processing: scope, instructions, security, subprocessors, disclosures, incidents, rights support, audits, and exit.
ISO/IEC 27018 vs GDPR Comparison
Compare ISO/IEC 27018 cloud-processor guidance with GDPR legal duties, including scope, Article 28 contracts, breaches, transfers, evidence, and assurance limits.
ISO/IEC 27018 vs ISO/IEC 27701 Comparison
Compare ISO/IEC 27018:2025 cloud-processor guidance with the independent ISO/IEC 27701:2025 privacy management system, including scope, evidence, and assurance.
ISO/IEC 27018 vs SOC 2 Privacy Comparison
Compare ISO/IEC 27018 cloud-processor guidance with a SOC 2 examination that includes Privacy, including scope, Type 1 vs Type 2, evidence, and limits.
Using ISO/IEC 27018 for Public-Cloud PII Processing
Decide whether ISO/IEC 27018:2025 applies to a public-cloud PII processor, how it fits an ISMS, what evidence to keep, and which claims the evidence supports.