FAQGlobalISO/IEC 27018

ISO/IEC 27018 FAQ GDPR Overlap

Use ISO/IEC 27018 controls as supporting evidence for a GDPR processor program only after mapping the actual role, processing, contract, and legal requirement.

The current edition is ISO/IEC 27018:2025; the detailed control explanations here use the prior 2019 edition and should be checked against the edition named in a contract or assurance report. ISO/IEC 27018 is voluntary guidance, while applicable law and contracts can impose separate or stricter duties.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

can supply control evidence for parts of a program, but it does not certify GDPR compliance. First decide whether the GDPR applies to the processing; then classify the actual controller and GDPR processor for each purpose and map the contract, security risk, transfers, data-subject rights, and breach duties separately.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

How can ISO/IEC 27018 support GDPR work?

The standard's guidance on customer instructions, confidentiality, security, subprocessors, breach support, disclosures, customer-rights support, and return or disposal can support evidence for related duties when the same service, processing purpose, systems, countries, and review period are in scope.

Map the sources rather than treating them as interchangeable. The GDPR is binding law where its territorial and material scope tests are met. Article 28 then creates contract and processor requirements; supplies voluntary control guidance and may also become a contractual criterion.

  • Check GDPR territorial scope under Article 3 and material exclusions under Article 2 before using this mapping; the standard's global scope does not make the GDPR apply.
  • Confirm the GDPR role for each processing purpose; the same cloud provider can be a processor for customer content and a controller for separate account, billing, security, telemetry, or service-improvement data.
  • Map Article 28 duties to contract clauses, responsible teams, operating controls, and evidence.
  • Run separate checks for lawful basis, transparency, rights, data protection impact assessments, international transfers, and regulator or individual breach notification.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

GDPR consolidated text

Articles 5, 6, 12-22, 28, 32-39, and 44-49 establish GDPR duties that must be assessed separately from ISO/IEC 27018 controls.

Question 2

Which evidence can support both?

Reuse data flows, purpose-specific role decisions, Article 28 terms, control tests, subprocessor authorization and notices, processing-country and transfer records, incident support, rights-request assistance, and deletion evidence only when the covered entity, service, systems, countries, data, purpose, and period match.

Article 28 requires processing on documented instructions, confidentiality, Article 32 security, subprocessor conditions, assistance with rights and certain controller duties, return or deletion, information demonstrating compliance, and audits. An ISO control or audit report can support that record but cannot establish every element without the contract and operating facts.

  • Retain the purpose-by-purpose role decision, Article 28 contract, control mapping, evidence period, exceptions, and audit result.
  • Treat transfer mechanisms, lawful basis, controller transparency, DPIAs, and Articles 33 and 34 notifications as separate legal workstreams; an ISO control mapping does not decide them.
  • Record gaps as corrective action or legal risk with an owner and due date rather than treating an ISO certificate as closure.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

Question 4

When should the overlap mapping be reviewed?

Review for changed roles, purposes, services, personal data, establishment or targeting facts, contracts, subprocessors, processing countries, transfer mechanisms, incidents, law, regulator guidance, or standard editions.

A change from the 2019 to the 2025 edition needs a control crosswalk. It does not change the GDPR text or remove the need to assess current legal and regulatory requirements.

  • Set a recurring review and trigger a new assessment for changes to Article 2 or 3 scope facts, purposes, roles, data, services, countries, subprocessors, law, guidance, or standard editions.
  • Update the role record, Article 28 terms, transfer assessment, control crosswalk, evidence requests, and owner assignments when facts change.
  • Route unresolved legal gaps to authorized counsel and control gaps to corrective action with a named owner and due date.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Articles 38 and 39 establish the DPO's independence, advisory, and monitoring tasks.
"The controller and processor shall ensure that the data protection officer does not receive any instructions regarding the exercise of those tasks."
iso.org
Referenced sections
  • ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
iso.org
Referenced sections
  • Primary ISO listing for the 2025 edition of ISO/IEC 27018.
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"
Related guides

Explore more topics

ISO/IEC 27018 Audit Evidence FAQ
How to assess ISO/IEC 27018 audit evidence by edition, service scope, criteria, audit period, exceptions, and independent assurance.
ISO/IEC 27018 Breach Support FAQ
ISO/IEC 27018 breach support: when a cloud PII processor should notify a customer, what the contract should define, and what incident records to keep.
ISO/IEC 27018 Cloud Privacy FAQ
ISO/IEC 27018 FAQ on public-cloud PII processor scope, customer instructions, subprocessors, disclosures, breaches, deletion, audit evidence, and GDPR.
ISO/IEC 27018 Customer Instructions FAQ
What counts as a customer instruction under ISO/IEC 27018, how a cloud PII processor should validate it, and what evidence shows it was followed.
ISO/IEC 27018 DPA Clause Review Workflow
Review cloud data-processing terms for instructions, purpose limits, controls, subprocessors, disclosures, incidents, rights support, and deletion.
ISO/IEC 27018 Government Access Evidence Guide
Build a controlled government-access case record showing request authentication, legal review, notice, approval, minimized disclosure, transfer, and closure.
ISO/IEC 27018 Government Access Evidence Workflow
Triage a government request for customer PII, validate authority, decide notice and challenge options, minimize disclosure, and preserve the decision record.
ISO/IEC 27018 Government Access FAQ
How ISO/IEC 27018 addresses legally binding law-enforcement requests: validation, customer consultation or notice, limited disclosure, and records.
ISO/IEC 27018 PII Return and Deletion FAQ
How to plan and prove PII return, transfer, deletion, anonymization, or archival across live systems, backups, temporary files, and subprocessors.
ISO/IEC 27018 Privacy Control Checklist
A practical ISO/IEC 27018:2025 checklist for public-cloud PII processors, with verifiable conditions, owners, evidence, exceptions, and edition controls.
ISO/IEC 27018 Processor Duties FAQ
What ISO/IEC 27018 expects from a public-cloud PII processor: customer instructions, purpose limits, security, transparency, incident support, and disposal.
ISO/IEC 27018 Public Cloud PII Processor Scope Guide
Decide whether a service fits ISO/IEC 27018's public-cloud PII processor scope, separate processor and controller activities, and document the boundary.
ISO/IEC 27018 Subprocessor Evidence Guide
Build subprocessor evidence that proves who processed customer PII, where, under which terms and controls, after which notice and approval, and with what exit result.
ISO/IEC 27018 Subprocessor Evidence Workflow
Assess and approve a cloud subprocessor, disclose its use and countries before processing, handle customer objections, and retain operating and exit evidence.
ISO/IEC 27018 Subprocessor Notice FAQ
What an ISO/IEC 27018 subprocessor notice should disclose, when customers should receive it, and what evidence should support consent and objections.
ISO/IEC 27018 Vendor Contract Requirements Guide
Contract guide for ISO/IEC 27018 public-cloud PII processing: scope, instructions, security, subprocessors, disclosures, incidents, rights support, audits, and exit.
ISO/IEC 27018 vs GDPR Comparison
Compare ISO/IEC 27018 cloud-processor guidance with GDPR legal duties, including scope, Article 28 contracts, breaches, transfers, evidence, and assurance limits.
ISO/IEC 27018 vs ISO/IEC 27701 Comparison
Compare ISO/IEC 27018:2025 cloud-processor guidance with the independent ISO/IEC 27701:2025 privacy management system, including scope, evidence, and assurance.
ISO/IEC 27018 vs SOC 2 Privacy Comparison
Compare ISO/IEC 27018 cloud-processor guidance with a SOC 2 examination that includes Privacy, including scope, Type 1 vs Type 2, evidence, and limits.
Using ISO/IEC 27018 for Public-Cloud PII Processing
Decide whether ISO/IEC 27018:2025 applies to a public-cloud PII processor, how it fits an ISMS, what evidence to keep, and which claims the evidence supports.