FAQGlobalISO/IEC 27018

ISO/IEC 27018 FAQ Government Access

Validate the request, reject demands that are not legally binding, consult or notify the customer where permitted, minimize any authorized disclosure, and record its source and authority.

The current edition is ISO/IEC 27018:2025; the detailed control explanations here use the prior 2019 edition and should be checked against the edition named in a contract or assurance report. ISO/IEC 27018 is voluntary guidance, while applicable law and contracts can impose separate or stricter duties.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ISO/IEC 27018:2019 describes how a processor should handle a from law enforcement: validate the request, reject a non-binding demand, consult the customer where legally permissible, follow the contractual notice procedure unless notice is prohibited, and record any disclosure. The standard does not decide the governing law or remove legal prohibitions on notice.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

How should a provider respond to a government request?

Route the request to authorized legal review before anyone searches for or discloses PII. Verify the issuer, service, customer, subject or account, requested data, time period, legal authority, jurisdiction, recipient obligations, binding effect, deadline, and any available challenge or narrowing procedure. Under the 2019 guidance, reject requests that are not legally binding, consult the customer before disclosure where legally permissible, and honor contractually agreed disclosures authorized by the customer.

The contract should require customer notice within its agreed process and time periods unless notice is prohibited. The standard gives criminal-law confidentiality as an example of a possible prohibition. It does not decide whether a particular request is valid, whether it must be challenged, or which law controls.

  • Validate the request and escalate to legal review before disclosure.
  • Limit disclosure to the customer, service, PII categories, subjects or accounts, and time period covered by the validated authority; data minimization or a challenge depends on the governing law and available procedure.
  • Notify the customer when law and the request allow it, and document any restriction on notice.
  • Record the request, the decision, the data disclosed, the approvals, and the reason for any exception.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 edition contains Annex A.6.1 on legally binding law-enforcement disclosure requests and A.6.2 on disclosure records.

Question 2

What evidence should be kept?

Keep the original request, authentication steps, legal authority and analysis, customer and service match, preservation action, search criteria, any challenge or narrowing step, customer consultation or notice, legal prohibition on notice, approval, and secure transfer record.

The should state what PII was disclosed, to whom, when, the source of the disclosure, and the source of authority. Preserve a content manifest or other verifiable description without duplicating the disclosed PII unnecessarily. Record a rejected request and its reason as well.

  • Retain the intake record, legal decision, scoped extraction approval, transfer receipt, customer communication, and disclosure log produced during the request.
  • Record the legal basis and end condition for a notice restriction; do not replace it with a generic confidentiality label.
  • Link any authentication, scoping, access-control, or logging failure to corrective action and a named owner.
Citations
ISO/IEC 27018:2019 standard page

Annex A.6.1 of the withdrawn 2019 edition addresses legally binding law-enforcement requests; A.6.2 specifies the core disclosure record.

Question 3

Who should approve disclosure and notice decisions?

Authorized legal counsel determines validity, binding effect, available challenge, and notice restrictions for the specific jurisdiction. Privacy and security identify the covered PII and access path; the service owner coordinates permitted customer communication; only approved personnel extract and transfer data.

Separate legal authorization from technical execution. Use two-person review where appropriate, preserve chain-of-custody information, and prevent the requester from gaining broader system access than the validated process permits.

  • Name authorized legal reviewers, privacy and security scoping owners, extraction personnel, customer-communications owners, and backups.
  • Require legal approval of the authority and scope before technical extraction, and separate extraction from transfer approval.
  • Keep the request, legal decision, extraction approval, transfer receipt, and notice decision in the controlled request file.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

Question 4

When should the process be reviewed?

Review the record after every request and test the process after changes to law, jurisdiction, processing location, subprocessor access, customer contract, request channel, personnel, or extraction controls.

A tabletop exercise should test request authentication, legal escalation, customer and service identification, notice restrictions, scoped extraction, approval, secure transfer, and the disclosure log.

  • Schedule tabletop exercises and retest after a request, legal change, new processing country, subprocessor change, or modification to search and export tooling.
  • Use findings to update request authentication, legal escalation, extraction controls, secure transfer, customer notice, and disclosure logging.
  • Assign unresolved over-collection, access, logging, or notice-control gaps to corrective action and a named risk owner.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding EU data protection regulation used for ISO/IEC 27018 comparison.
"protection of natural persons with regard to the processing of personal data"
iso.org
Referenced sections
  • ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
iso.org
Referenced sections
  • Primary ISO listing for the 2025 edition of ISO/IEC 27018.
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"
Related guides

Explore more topics

ISO/IEC 27018 Audit Evidence FAQ
How to assess ISO/IEC 27018 audit evidence by edition, service scope, criteria, audit period, exceptions, and independent assurance.
ISO/IEC 27018 Breach Support FAQ
ISO/IEC 27018 breach support: when a cloud PII processor should notify a customer, what the contract should define, and what incident records to keep.
ISO/IEC 27018 Cloud Privacy FAQ
ISO/IEC 27018 FAQ on public-cloud PII processor scope, customer instructions, subprocessors, disclosures, breaches, deletion, audit evidence, and GDPR.
ISO/IEC 27018 Customer Instructions FAQ
What counts as a customer instruction under ISO/IEC 27018, how a cloud PII processor should validate it, and what evidence shows it was followed.
ISO/IEC 27018 DPA Clause Review Workflow
Review cloud data-processing terms for instructions, purpose limits, controls, subprocessors, disclosures, incidents, rights support, and deletion.
ISO/IEC 27018 GDPR Overlap FAQ
How ISO/IEC 27018 can support GDPR processor controls without replacing Article 28 terms, controller accountability, transfers, or breach duties.
ISO/IEC 27018 Government Access Evidence Guide
Build a controlled government-access case record showing request authentication, legal review, notice, approval, minimized disclosure, transfer, and closure.
ISO/IEC 27018 Government Access Evidence Workflow
Triage a government request for customer PII, validate authority, decide notice and challenge options, minimize disclosure, and preserve the decision record.
ISO/IEC 27018 PII Return and Deletion FAQ
How to plan and prove PII return, transfer, deletion, anonymization, or archival across live systems, backups, temporary files, and subprocessors.
ISO/IEC 27018 Privacy Control Checklist
A practical ISO/IEC 27018:2025 checklist for public-cloud PII processors, with verifiable conditions, owners, evidence, exceptions, and edition controls.
ISO/IEC 27018 Processor Duties FAQ
What ISO/IEC 27018 expects from a public-cloud PII processor: customer instructions, purpose limits, security, transparency, incident support, and disposal.
ISO/IEC 27018 Public Cloud PII Processor Scope Guide
Decide whether a service fits ISO/IEC 27018's public-cloud PII processor scope, separate processor and controller activities, and document the boundary.
ISO/IEC 27018 Subprocessor Evidence Guide
Build subprocessor evidence that proves who processed customer PII, where, under which terms and controls, after which notice and approval, and with what exit result.
ISO/IEC 27018 Subprocessor Evidence Workflow
Assess and approve a cloud subprocessor, disclose its use and countries before processing, handle customer objections, and retain operating and exit evidence.
ISO/IEC 27018 Subprocessor Notice FAQ
What an ISO/IEC 27018 subprocessor notice should disclose, when customers should receive it, and what evidence should support consent and objections.
ISO/IEC 27018 Vendor Contract Requirements Guide
Contract guide for ISO/IEC 27018 public-cloud PII processing: scope, instructions, security, subprocessors, disclosures, incidents, rights support, audits, and exit.
ISO/IEC 27018 vs GDPR Comparison
Compare ISO/IEC 27018 cloud-processor guidance with GDPR legal duties, including scope, Article 28 contracts, breaches, transfers, evidence, and assurance limits.
ISO/IEC 27018 vs ISO/IEC 27701 Comparison
Compare ISO/IEC 27018:2025 cloud-processor guidance with the independent ISO/IEC 27701:2025 privacy management system, including scope, evidence, and assurance.
ISO/IEC 27018 vs SOC 2 Privacy Comparison
Compare ISO/IEC 27018 cloud-processor guidance with a SOC 2 examination that includes Privacy, including scope, Type 1 vs Type 2, evidence, and limits.
Using ISO/IEC 27018 for Public-Cloud PII Processing
Decide whether ISO/IEC 27018:2025 applies to a public-cloud PII processor, how it fits an ISMS, what evidence to keep, and which claims the evidence supports.