How can ISO/IEC 27018 support GDPR work?
The standard's guidance on customer instructions, confidentiality, security, subprocessors, breach support, disclosures, customer-rights support, and return or disposal can support evidence for related duties when the same service, processing purpose, systems, countries, and review period are in scope.
Map the sources rather than treating them as interchangeable. The GDPR is binding law where its territorial and material scope tests are met. Article 28 then creates contract and processor requirements; supplies voluntary control guidance and may also become a contractual criterion.
- Check GDPR territorial scope under Article 3 and material exclusions under Article 2 before using this mapping; the standard's global scope does not make the GDPR apply.
- Confirm the GDPR role for each processing purpose; the same cloud provider can be a processor for customer content and a controller for separate account, billing, security, telemetry, or service-improvement data.
- Map Article 28 duties to contract clauses, responsible teams, operating controls, and evidence.
- Run separate checks for lawful basis, transparency, rights, data protection impact assessments, international transfers, and regulator or individual breach notification.
Primary ISO listing for the 2025 edition of ISO/IEC 27018.
ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.
Articles 5, 6, 12-22, 28, 32-39, and 44-49 establish GDPR duties that must be assessed separately from ISO/IEC 27018 controls.