What counts as a customer instruction?
Under ISO/IEC 27018:2019, instructions to a can be contained in the contract and can include the service objective and time frame. An order, customer-controlled configuration, authenticated support request, or approved change can implement that contract when the authorized channel, requester, service, PII, operation, purpose, and duration are clear.
A processor may choose technical methods needed to deliver the customer's purpose without an express instruction for every implementation detail. For example, the provider may allocate processing resources to use network capacity efficiently. The method must remain consistent with the customer's general instructions, follow the relevant privacy principles when it collects or uses PII, and never introduce an independent processing purpose.
- Define which customer roles and channels can issue instructions and how the provider authenticates them.
- Reject or clarify a request that conflicts with the contract, exceeds the requester's authority, lacks a defined service or purpose, or introduces unsupported processing.
- Escalate an instruction that appears to conflict with applicable law; for GDPR-covered processing, Article 28 requires the processor to inform the controller immediately if, in its opinion, an instruction infringes the GDPR or other Union or Member State data-protection law.
Primary ISO listing for the 2025 edition of ISO/IEC 27018.
ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.