FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
32of32items
Across 8 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
ISO/IEC 27018 GDPR Overlap

When should the overlap mapping be reviewed?

Review for changed roles, purposes, services, personal data, establishment or targeting facts, contracts, subprocessors, processing countries, transfer mechanisms, incidents, law, regulator guidance, or standard editions.

A change from the 2019 to the 2025 ISO/IEC 27018 edition needs a control crosswalk. It does not change the GDPR text or remove the need to assess current legal and regulatory requirements.

  • Set a recurring review and trigger a new assessment for changes to Article 2 or 3 scope facts, purposes, roles, data, services, countries, subprocessors, law, guidance, or standard editions.
  • Update the role record, Article 28 terms, transfer assessment, control crosswalk, evidence requests, and owner assignments when facts change.
  • Route unresolved legal gaps to authorized counsel and control gaps to corrective action with a named owner and due date.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

ISO/IEC 27018 Government Access

How should a provider respond to a government request?

Route the request to authorized legal review before anyone searches for or discloses PII. Verify the issuer, service, customer, subject or account, requested data, time period, legal authority, jurisdiction, recipient obligations, binding effect, deadline, and any available challenge or narrowing procedure. Under the 2019 guidance, reject requests that are not legally binding, consult the customer before disclosure where legally permissible, and honor contractually agreed disclosures authorized by the customer.

The contract should require customer notice within its agreed process and time periods unless notice is prohibited. The standard gives criminal-law confidentiality as an example of a possible prohibition. It does not decide whether a particular request is valid, whether it must be challenged, or which law controls.

  • Validate the request and escalate to legal review before disclosure.
  • Limit disclosure to the customer, service, PII categories, subjects or accounts, and time period covered by the validated authority; data minimization or a challenge depends on the governing law and available procedure.
  • Notify the customer when law and the request allow it, and document any restriction on notice.
  • Record the request, the decision, the data disclosed, the approvals, and the reason for any exception.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 edition contains Annex A.6.1 on legally binding law-enforcement disclosure requests and A.6.2 on disclosure records.

ISO/IEC 27018 Government Access

What evidence should be kept?

Keep the original request, authentication steps, legal authority and analysis, customer and service match, preservation action, search criteria, any challenge or narrowing step, customer consultation or notice, legal prohibition on notice, approval, and secure transfer record.

The disclosure record should state what PII was disclosed, to whom, when, the source of the disclosure, and the source of authority. Preserve a content manifest or other verifiable description without duplicating the disclosed PII unnecessarily. Record a rejected request and its reason as well.

  • Retain the intake record, legal decision, scoped extraction approval, transfer receipt, customer communication, and disclosure log produced during the request.
  • Record the legal basis and end condition for a notice restriction; do not replace it with a generic confidentiality label.
  • Link any authentication, scoping, access-control, or logging failure to corrective action and a named owner.
Citations
ISO/IEC 27018:2019 standard page

Annex A.6.1 of the withdrawn 2019 edition addresses legally binding law-enforcement requests; A.6.2 specifies the core disclosure record.

ISO/IEC 27018 Government Access

Who should approve disclosure and notice decisions?

Authorized legal counsel determines validity, binding effect, available challenge, and notice restrictions for the specific jurisdiction. Privacy and security identify the covered PII and access path; the service owner coordinates permitted customer communication; only approved personnel extract and transfer data.

Separate legal authorization from technical execution. Use two-person review where appropriate, preserve chain-of-custody information, and prevent the requester from gaining broader system access than the validated process permits.

  • Name authorized legal reviewers, privacy and security scoping owners, extraction personnel, customer-communications owners, and backups.
  • Require legal approval of the authority and scope before technical extraction, and separate extraction from transfer approval.
  • Keep the request, legal decision, extraction approval, transfer receipt, and notice decision in the controlled request file.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

ISO/IEC 27018 Government Access

When should the process be reviewed?

Review the record after every request and test the process after changes to law, jurisdiction, processing location, subprocessor access, customer contract, request channel, personnel, or extraction controls.

A tabletop exercise should test request authentication, legal escalation, customer and service identification, notice restrictions, scoped extraction, approval, secure transfer, and the disclosure log.

  • Schedule tabletop exercises and retest after a request, legal change, new processing country, subprocessor change, or modification to search and export tooling.
  • Use findings to update request authentication, legal escalation, extraction controls, secure transfer, customer notice, and disclosure logging.
  • Assign unresolved over-collection, access, logging, or notice-control gaps to corrective action and a named risk owner.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

ISO/IEC 27018 PII Return and Deletion

What should the return and deletion outcome cover?

Start with the trigger and authorized outcome: a customer instruction, purpose expiry, retention-schedule event, contract termination, or valid legal requirement. Then define the export format and verification, timing, contract-end recovery buffer, erasure method, live systems, temporary files, logs, backups and continuity copies, subprocessor copies, archives, legal holds, and completion notice.

ISO/IEC 27018 recognizes return, transfer to another processor or controller, secure deletion or destruction, anonymization, and archival as possible dispositions. Return or transfer requires a usable export and confirmed recipient; deletion or destruction requires a defined mechanism; anonymization requires evidence that the result is no longer identifiable by reasonably likely means; archival requires a valid purpose, restricted access, and a retention end. None should be used to avoid a required return or deletion.

  • State the retention period after contract termination that protects against accidental lapse without turning the buffer into indefinite retention.
  • Specify the disposition mechanism in the contract, such as de-linking, overwriting, demagnetization, physical destruction, or another applicable commercial standard.
  • Apply a documented age limit and periodic cleanup to unused temporary files.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

ISO/IEC 27018 PII Return and Deletion

Which evidence should prove disposition?

Keep the authorized instruction, purpose and retention trigger, inventory and system scope, export manifest and receipt, deletion jobs and logs, temporary-file cleanup result, backup expiry schedule, subprocessor confirmations, legal-hold record, verification sample, exceptions, and completion notice.

For backups that cannot be selectively erased without harming integrity, document the technical constraint, access restriction, fixed expiry, restoration procedure, and rule that returns restored data to the deletion queue before normal use. ISO/IEC 27018 does not set one universal deletion period; the policy and contract should state the applicable period.

  • Reconcile the disposition inventory to actual storage, backup, logging, continuity, and subprocessor architecture rather than relying on a policy statement alone.
  • Record each completed, pending, failed, or excepted copy with its system owner, expected completion date, and verification result.
  • Retain customer authorization, export receipt, deletion evidence, subprocessor confirmations, and the final completion or exception notice.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

ISO/IEC 27018 PII Return and Deletion

Who approves retention exceptions?

Cloud operations performs disposition; privacy and records owners validate the inventory and retention schedule; legal confirms a legal hold or statutory retention basis; supplier management obtains subprocessor results; the service owner confirms the customer outcome and unresolved copies.

A retention exception should identify the specific data, authority, owner, access restriction, end condition, and review date. Keep excepted data isolated from ordinary processing and delete it when the exception ends.

  • Name owners for the customer instruction, export, active-store deletion, backup expiry, subprocessor completion, legal holds, and customer confirmation.
  • Require legal or records approval for a retention exception and technical verification for the affected copy; neither substitutes for the other.
  • Keep the authority, scope, end condition, review, and final deletion evidence with the disposition record.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

ISO/IEC 27018 PII Return and Deletion

When should disposal controls be retested?

Retest for platform, backup, storage, logging, subprocessor, contract, retention, legal-hold, or termination-workflow changes and after a failed or partial deletion.

Test the complete path: customer authorization, export if requested, deletion from active stores and temporary files, backup expiry, subprocessor completion, exception handling, verification, and customer confirmation.

  • Set a recurring end-to-end test and retest after storage, backup, logging, subprocessor, contract, retention, or legal-hold changes.
  • Use results to update the system inventory, deletion jobs, restoration controls, supplier terms, customer instructions, and evidence checklist.
  • Assign every missing, failed, or delayed disposition step to corrective action, a documented exception, or management review.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

ISO/IEC 27018 Processor Duties

Which duties follow from the ISO/IEC 27018 processor role?

Under the 2019 edition, PII processed under a contract should not be used for a purpose independent of the customer's instructions. Marketing or advertising use requires express consent, and that consent should not be a condition of receiving the service. Where the customer depends on provider information or technical measures to handle access, correction, or erasure rights, the contract should specify that support.

The contract and responsibility map should cover minimum technical and organizational measures, customer and provider responsibilities, subprocessors and backup providers, processing countries, legally binding disclosure requests, breach notice and maximum delay, return or disposal, audit evidence, and a customer contact for PII questions. The exact allocation depends on the service model: application-layer controls can sit with the provider in SaaS but with the customer or another provider in PaaS or IaaS.

  • For each purpose, record whether the cloud customer is the PII controller and whether the provider follows instructions or determines an independent purpose; contract labels do not cure a conflicting operating model.
  • Confirm separately whether the provider acts as a controller for account, billing, security telemetry, or other own-purpose data; ISO/IEC 27018's processor scope does not cover that controller activity.
  • Map each applicable control to the service, responsible party, contract term, operating procedure, and evidence.
  • Document omitted controls and the reason for omission when ISO/IEC 27018 is used with an ISO/IEC 27001 information security management system.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the edition whose introduction, Clauses 5-18, and Annex A supply the detailed processor-role guidance summarized here.

ISO/IEC 27018 Processor Duties

What evidence should show the duties operate?

Keep the purpose-by-purpose role decision, signed contract and instruction history, service and responsibility map, selected-control rationale, security procedures, access and event-log samples, subprocessor and country disclosures, breach and third-party disclosure records, and return or disposal results.

Evidence should show the control operated for the service and period under review. A policy or certificate title alone does not show whether a customer instruction was authorized, a notice reached affected customers, an incident was reported within the agreed period, or all relevant copies entered the disposal process.

  • Sample evidence from the actual service and review period, including authorized instructions, access changes, customer notices, incident records, and disposal jobs.
  • Document every omitted control and its justification when the standard is used to select controls for an ISO/IEC 27001 information security management system.
  • Link each exception to the affected service, contract, control, risk owner, corrective action, and review date.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

ISO/IEC 27018 Processor Duties

Who owns the processor responsibility map?

The organization should assign a customer contact for PII processing under the contract. Privacy and legal teams interpret roles and binding terms; security, cloud operations, incident response, and supplier teams operate their assigned controls; the service owner keeps the customer commitment and technical implementation aligned.

No single department can approve every processor duty. Route legal exceptions to authorized counsel, security exceptions to the risk owner, and customer-facing changes to the owner authorized to change the service commitment.

  • Name the service owner for the processor commitment, the privacy or legal owner for role and contract decisions, and operating owners for security, incidents, suppliers, rights support, and disposition.
  • Route a legal exception to authorized counsel, a security exception to the risk owner, and a customer-facing change to the owner authorized to change the service commitment.
  • Keep the responsibility map, exception decision, approval, and affected evidence together rather than in disconnected email threads.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

ISO/IEC 27018 Processor Duties

When should processor duties be reassessed?

Reassess when the provider introduces an own purpose, changes the service or PII handled, adds a subprocessor or country, changes a contract or selected control, or finds a responsibility gap during an incident, audit, or customer request.

Also verify the edition named by the contract, certificate, or audit criteria. A 2019 control mapping should not be presented as evidence against the 2025 edition without an explicit transition or crosswalk.

  • Set a recurring role-and-control review and reassess after a new purpose, service, PII category, country, subprocessor, contract, incident, audit finding, or standard edition.
  • Update the role decision, responsibility map, selected-control rationale, contract, procedures, customer disclosures, and evidence requests.
  • Route unresolved role conflicts to authorized privacy or legal owners and control gaps to corrective action, management review, or documented risk acceptance.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

ISO/IEC 27018 Subprocessor Notice

What should a subprocessor notice contain?

First determine whether the vendor will process customer PII. If so, identify that subcontracting is used, the subprocessor's legal name, affected service and processing, countries where it can process PII, planned effective date, and how its contract meets or exceeds the primary processor's information-security and PII-protection obligations. A vendor with no access to or processing of customer PII is outside this notice decision.

ISO/IEC 27018 does not set a universal notice period. The processor should give notice in a timely manner, while the contract determines specific or general consent, timing, the objection route, and termination or alternative-service outcomes. If public disclosure creates unacceptable security risk, the 2019 guidance allows disclosure under a non-disclosure agreement or on customer request, provided customers know the information is available.

  • Complete supplier privacy and security review and sign the required flow-down terms before the subprocessor begins processing PII; this includes providers storing backup copies.
  • Match the notice population to affected contracts and services; a website update does not prove that a contractually required notice reached the customer.
  • Do not expose business-specific security details that are unnecessary for the customer's decision.
Citations
ISO/IEC 27018:2025 standard page

ISO listing for the 2025 ISO/IEC 27018 public-cloud PII processor guidance that supports subprocessor notice evidence and customer disclosure controls.

ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

ISO/IEC 27018 Subprocessor Notice

What evidence should prove notice and consent?

Keep the prior and new subprocessor records, approved due diligence, signed flow-down terms, affected services, processing and countries, notice text, recipient population, send and effective dates, delivery evidence, consent basis, objections, responses, withdrawals, alternative-service or termination outcomes, and the release approval that prevented processing before the required step.

For GDPR-covered processing, Article 28 requires prior specific authorization for the named subprocessor or general written authorization. Under general authorization, the processor must inform the controller of intended additions or replacements so the controller can object; the processor must also impose the same data-protection obligations on the other processor and remains fully liable to the controller for that processor's obligations.

  • Retain the vendor classification, due diligence approval, signed terms, customer authorization basis, notice population, delivery evidence, objection record, and release approval.
  • Reconcile the public list, contract schedule, supplier register, data-flow map, processing countries, and deployed service before the effective date.
  • Record unresolved objections and exceptions with the contractual outcome, decision owner, and effective-date control.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

Page 2 of 3