Which duties follow from the ISO/IEC 27018 processor role?
Under the 2019 edition, PII processed under a contract should not be used for a purpose independent of the customer's instructions. Marketing or advertising use requires express consent, and that consent should not be a condition of receiving the service. Where the customer depends on provider information or technical measures to handle access, correction, or erasure rights, the contract should specify that support.
The contract and responsibility map should cover minimum technical and organizational measures, customer and provider responsibilities, subprocessors and backup providers, processing countries, legally binding disclosure requests, breach notice and maximum delay, return or disposal, audit evidence, and a customer contact for PII questions. The exact allocation depends on the service model: application-layer controls can sit with the provider in SaaS but with the customer or another provider in PaaS or IaaS.
- For each purpose, record whether the cloud customer is the and whether the provider follows instructions or determines an independent purpose; contract labels do not cure a conflicting operating model.
- Confirm separately whether the provider acts as a controller for account, billing, security telemetry, or other own-purpose data; ISO/IEC 27018's processor scope does not cover that controller activity.
- Map each applicable control to the service, responsible party, contract term, operating procedure, and evidence.
- Document omitted controls and the reason for omission when ISO/IEC 27018 is used with an ISO/IEC 27001 information security management system.
Primary ISO listing for the 2025 edition of ISO/IEC 27018.
ISO's withdrawn 2019 listing identifies the edition whose introduction, Clauses 5-18, and Annex A supply the detailed processor-role guidance summarized here.