---
title: "ISO/IEC 27018 Cloud Privacy FAQ"
canonical_url: "https://www.sorena.io/artifacts/global/iso-27018/faq"
source_url: "https://www.sorena.io/artifacts/global/iso-27018/faq/items/page/3"
author: "Sorena AI"
description: "ISO/IEC 27018 FAQ on public-cloud PII processor scope, customer instructions, subprocessors, disclosures, breaches, deletion, audit evidence, and GDPR."
published_at: "2026-05-09"
updated_at: "2026-07-25"
keywords:
  - "ISO/IEC 27018 FAQ"
  - "ISO/IEC 27018"
  - "ISO/IEC 27018 Public Cloud PII Processor Privacy Controls"
  - "ISO/IEC 27018 FAQ checklist"
  - "ISO/IEC 27018 FAQ evidence"
  - "ISO/IEC 27018 FAQ implementation"
  - "FAQ"
  - "cloud privacy guidance"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# ISO/IEC 27018 Cloud Privacy FAQ

ISO/IEC 27018 FAQ on public-cloud PII processor scope, customer instructions, subprocessors, disclosures, breaches, deletion, audit evidence, and GDPR.

*FAQ* *Global* *ISO/IEC 27018*

## ISO/IEC 27018 FAQ

Answer the main ISO/IEC 27018 questions by separating processor scope, voluntary guidance, contract and control evidence, and applicable privacy law.

The current edition is ISO/IEC 27018:2025; the detailed control explanations here use the prior 2019 edition and should be checked against the edition named in a contract or assurance report. ISO/IEC 27018 is voluntary guidance, while applicable law and contracts can impose separate or stricter duties.

ISO/IEC 27018 gives public-cloud providers guidance for protecting PII when they process it on behalf of customers and according to customer instructions. Start by confirming that processor role, each processing purpose, the service and data in scope, the edition used by the contract or assurance report, and any binding law. The current edition is 2025; the detailed clause examples on these pages come from the withdrawn 2019 edition and should not be treated as a substitute for the current text.

## Definitions

### Personally identifiable information

**Term:** PII

PII is information that can identify a natural person or can be linked directly or indirectly to that person. Examples can include a name, account identifier, contact detail, location, device or network identifier, or a combination of less obvious attributes when the holder or another party can reasonably make the link.

**Why it matters here:** ISO/IEC 27018 covers PII handled by a public-cloud provider on a customer's behalf. The provider may need the customer's context to know that a field or combination is identifiable, so scope records should capture known categories, assumptions, and changes rather than relying only on field names.

Sources:

- [ISO/IEC 27018:2025 standard page](https://www.iso.org/standard/27018?ref=sorena.io)
- [ISO/IEC 27018:2019 standard page](https://www.iso.org/standard/76559.html?ref=sorena.io)
- [GDPR Article 4 personal-data definition](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02016R0679-20160504&ref=sorena.io)

## Browse sub-FAQ modules

### [ISO/IEC 27018 Audit Evidence FAQ](/artifacts/global/iso-27018/faq/audit-evidence.md)

How to assess ISO/IEC 27018 audit evidence by edition, service scope, criteria, audit period, exceptions, and independent assurance.

- 4 items

### [ISO/IEC 27018 Breach Support FAQ](/artifacts/global/iso-27018/faq/breach-support.md)

ISO/IEC 27018 breach support: when a cloud PII processor should notify a customer, what the contract should define, and what incident records to keep.

- 4 items

### [ISO/IEC 27018 Customer Instructions FAQ](/artifacts/global/iso-27018/faq/customer-instructions.md)

What counts as a customer instruction under ISO/IEC 27018, how a cloud PII processor should validate it, and what evidence shows it was followed.

- 4 items

### [ISO/IEC 27018 GDPR Overlap FAQ](/artifacts/global/iso-27018/faq/gdpr-overlap.md)

How ISO/IEC 27018 can support GDPR processor controls without replacing Article 28 terms, controller accountability, transfers, or breach duties.

- 4 items

### [ISO/IEC 27018 Government Access FAQ](/artifacts/global/iso-27018/faq/government-access.md)

How ISO/IEC 27018 addresses legally binding law-enforcement requests: validation, customer consultation or notice, limited disclosure, and records.

- 4 items

### [ISO/IEC 27018 PII Return and Deletion FAQ](/artifacts/global/iso-27018/faq/pii-return-and-deletion.md)

How to plan and prove PII return, transfer, deletion, anonymization, or archival across live systems, backups, temporary files, and subprocessors.

- 4 items

### [ISO/IEC 27018 Processor Duties FAQ](/artifacts/global/iso-27018/faq/processor-duties.md)

What ISO/IEC 27018 expects from a public-cloud PII processor: customer instructions, purpose limits, security, transparency, incident support, and disposal.

- 4 items

### [ISO/IEC 27018 Subprocessor Notice FAQ](/artifacts/global/iso-27018/faq/subprocessor-notice.md)

What an ISO/IEC 27018 subprocessor notice should disclose, when customers should receive it, and what evidence should support consent and objections.

- 4 items

Browse all indexed questions: [/artifacts/global/iso-27018/faq/items](/artifacts/global/iso-27018/faq/items.md)

## All FAQ items

*Page 3 of 3. Showing 2 of 32 items.*

### [Who owns the change and objection process?](/artifacts/global/iso-27018/faq/subprocessor-notice.md#who-owns-the-change-and-objection-process)

*Module: [ISO/IEC 27018 Subprocessor Notice](/artifacts/global/iso-27018/faq/subprocessor-notice.md)*

Supplier management coordinates due diligence and the subcontract; privacy and security assess processing, locations, and controls; legal interprets consent and objection terms; the service owner controls customer communication and the go-live date.

- Name owners for vendor classification, privacy and security review, flow-down terms, customer notice, objections, release approval, and backups.
- Keep supplier approval separate from customer authorization and release approval; each answers a different condition.
- Store objections, responses, alternatives, termination decisions, and effective-date approval with the change record.

Sources for this answer:

- [ISO/IEC 27018:2025 standard page](https://www.iso.org/standard/27018?ref=sorena.io) - ISO listing for the 2025 ISO/IEC 27018 public-cloud PII processor guidance that supports subprocessor notice evidence and customer disclosure controls.
- [ISO/IEC 27018:2019 standard page](https://www.iso.org/standard/76559.html?ref=sorena.io) - ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

### [When is a new notice required?](/artifacts/global/iso-27018/faq/subprocessor-notice.md#when-is-a-new-notice-required)

*Module: [ISO/IEC 27018 Subprocessor Notice](/artifacts/global/iso-27018/faq/subprocessor-notice.md)*

Notify before first use and before an intended addition or replacement when the applicable contract or law requires it. Review whether a new notice is needed when the entity, affected service, processing purpose, countries, onward providers, or safeguards change.

- Review before first use and for a legal-entity replacement, new affected service, changed processing purpose, new country, onward provider, or changed safeguard.
- Update the supplier register, data-flow map, public list, contract schedule, notice population, objection record, and release control.
- Block the effective date until the required review, terms, notice, authorization, and objection process are complete, unless a contractually and legally valid emergency path applies.

Sources for this answer:

- [ISO/IEC 27018:2025 standard page](https://www.iso.org/standard/27018?ref=sorena.io) - ISO listing for the 2025 ISO/IEC 27018 public-cloud PII processor guidance that supports subprocessor notice evidence and customer disclosure controls.
- [ISO/IEC 27018:2019 standard page](https://www.iso.org/standard/76559.html?ref=sorena.io) - ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

## FAQ Pagination

- Canonical index (page 1): [/artifacts/global/iso-27018/faq/items](/artifacts/global/iso-27018/faq/items.md)
- Page 1 rule: `/page/1` is intentionally not generated; use the canonical index markdown URL.
- Current page: 3 of 3

Pages: [1](/artifacts/global/iso-27018/faq/items.md) | [2](/artifacts/global/iso-27018/faq/items/page/2.md) | [3](/artifacts/global/iso-27018/faq/items/page/3.md)

[Previous page](/artifacts/global/iso-27018/faq/items/page/2.md)

*Recommended next step*

*Placement: after implementation guidance*

## Apply the answer to the scoped cloud service

Record the provider role, service boundary, cited edition, contract term, control owner, current evidence, exception, and next review date.

- [Open Assessment Autopilot for ISO/IEC 27018](/solutions/assessment.md): Convert the relevant answer into scoped control tasks, evidence requests, exceptions, and review dates.
- [Talk through implementation](/contact.md): Review your current scope, evidence gaps, and next implementation steps.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/global/iso-27018/faq/items/page/3.md
