FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
32of32items
Across 8 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
ISO/IEC 27018 Subprocessor Notice

Who owns the change and objection process?

Supplier management coordinates due diligence and the subcontract; privacy and security assess processing, locations, and controls; legal interprets consent and objection terms; the service owner controls customer communication and the go-live date.

An objection is not automatically a veto under ISO/IEC 27018. Follow the contract and applicable law: the outcome may be an alternative provider, a service limitation, remediation, or termination.

  • Name owners for vendor classification, privacy and security review, flow-down terms, customer notice, objections, release approval, and backups.
  • Keep supplier approval separate from customer authorization and release approval; each answers a different condition.
  • Store objections, responses, alternatives, termination decisions, and effective-date approval with the change record.
Citations
ISO/IEC 27018:2025 standard page

ISO listing for the 2025 ISO/IEC 27018 public-cloud PII processor guidance that supports subprocessor notice evidence and customer disclosure controls.

ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

ISO/IEC 27018 Subprocessor Notice

When is a new notice required?

Notify before first use and before an intended addition or replacement when the applicable contract or law requires it. Review whether a new notice is needed when the entity, affected service, processing purpose, countries, onward providers, or safeguards change.

Keep the effective date behind the required notice and objection window. If an urgent replacement is necessary, use only an emergency path supported by the contract and applicable law, then retain the decision and customer communication.

  • Review before first use and for a legal-entity replacement, new affected service, changed processing purpose, new country, onward provider, or changed safeguard.
  • Update the supplier register, data-flow map, public list, contract schedule, notice population, objection record, and release control.
  • Block the effective date until the required review, terms, notice, authorization, and objection process are complete, unless a contractually and legally valid emergency path applies.
Citations
ISO/IEC 27018:2025 standard page

ISO listing for the 2025 ISO/IEC 27018 public-cloud PII processor guidance that supports subprocessor notice evidence and customer disclosure controls.

ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

Page 3 of 3