FAQGlobalISO/IEC 27018

ISO/IEC 27018 FAQ Processor Duties

Translate the public-cloud PII processor role into customer-instructed processing, purpose limitation, transparency, security, subprocessor, disclosure, incident, and disposal controls.

The current edition is ISO/IEC 27018:2025; the detailed control explanations here use the prior 2019 edition and should be checked against the edition named in a contract or assurance report. ISO/IEC 27018 is voluntary guidance, while applicable law and contracts can impose separate or stricter duties.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

A falls within ISO/IEC 27018's scope when it processes PII for a cloud customer and according to that customer's purposes and instructions. The provider should turn that role into contract terms, operating controls, customer-facing information, and records. ISO/IEC 27018 is voluntary guidance; applicable law and contracts determine binding duties.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

Which duties follow from the ISO/IEC 27018 processor role?

Under the 2019 edition, PII processed under a contract should not be used for a purpose independent of the customer's instructions. Marketing or advertising use requires express consent, and that consent should not be a condition of receiving the service. Where the customer depends on provider information or technical measures to handle access, correction, or erasure rights, the contract should specify that support.

The contract and responsibility map should cover minimum technical and organizational measures, customer and provider responsibilities, subprocessors and backup providers, processing countries, legally binding disclosure requests, breach notice and maximum delay, return or disposal, audit evidence, and a customer contact for PII questions. The exact allocation depends on the service model: application-layer controls can sit with the provider in SaaS but with the customer or another provider in PaaS or IaaS.

  • For each purpose, record whether the cloud customer is the and whether the provider follows instructions or determines an independent purpose; contract labels do not cure a conflicting operating model.
  • Confirm separately whether the provider acts as a controller for account, billing, security telemetry, or other own-purpose data; ISO/IEC 27018's processor scope does not cover that controller activity.
  • Map each applicable control to the service, responsible party, contract term, operating procedure, and evidence.
  • Document omitted controls and the reason for omission when ISO/IEC 27018 is used with an ISO/IEC 27001 information security management system.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the edition whose introduction, Clauses 5-18, and Annex A supply the detailed processor-role guidance summarized here.

Question 2

What evidence should show the duties operate?

Keep the purpose-by-purpose role decision, signed contract and instruction history, service and responsibility map, selected-control rationale, security procedures, access and event-log samples, subprocessor and country disclosures, breach and third-party disclosure records, and return or disposal results.

Evidence should show the control operated for the service and period under review. A policy or certificate title alone does not show whether a customer instruction was authorized, a notice reached affected customers, an incident was reported within the agreed period, or all relevant copies entered the disposal process.

  • Sample evidence from the actual service and review period, including authorized instructions, access changes, customer notices, incident records, and disposal jobs.
  • Document every omitted control and its justification when the standard is used to select controls for an ISO/IEC 27001 information security management system.
  • Link each exception to the affected service, contract, control, risk owner, corrective action, and review date.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

Recommended next step

Connect each processor duty to an owner and control

Record the instructed purpose, contract term, responsible party, operating procedure, current evidence, exception, and reassessment trigger for each duty.

Question 3

Who owns the processor responsibility map?

The organization should assign a customer contact for PII processing under the contract. Privacy and legal teams interpret roles and binding terms; security, cloud operations, incident response, and supplier teams operate their assigned controls; the service owner keeps the customer commitment and technical implementation aligned.

No single department can approve every processor duty. Route legal exceptions to authorized counsel, security exceptions to the risk owner, and customer-facing changes to the owner authorized to change the service commitment.

  • Name the service owner for the processor commitment, the privacy or legal owner for role and contract decisions, and operating owners for security, incidents, suppliers, rights support, and disposition.
  • Route a legal exception to authorized counsel, a security exception to the risk owner, and a customer-facing change to the owner authorized to change the service commitment.
  • Keep the responsibility map, exception decision, approval, and affected evidence together rather than in disconnected email threads.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

Question 4

When should processor duties be reassessed?

Reassess when the provider introduces an own purpose, changes the service or PII handled, adds a subprocessor or country, changes a contract or selected control, or finds a responsibility gap during an incident, audit, or customer request.

Also verify the edition named by the contract, certificate, or audit criteria. A 2019 control mapping should not be presented as evidence against the 2025 edition without an explicit transition or crosswalk.

  • Set a recurring role-and-control review and reassess after a new purpose, service, PII category, country, subprocessor, contract, incident, audit finding, or standard edition.
  • Update the role decision, responsibility map, selected-control rationale, contract, procedures, customer disclosures, and evidence requests.
  • Route unresolved role conflicts to authorized privacy or legal owners and control gaps to corrective action, management review, or documented risk acceptance.
Citations
ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding EU data protection regulation used for ISO/IEC 27018 comparison.
"protection of natural persons with regard to the processing of personal data"
iso.org
Referenced sections
  • ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
iso.org
Referenced sections
  • Primary ISO listing for the 2025 edition of ISO/IEC 27018.
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"
Related guides

Explore more topics

ISO/IEC 27018 Audit Evidence FAQ
How to assess ISO/IEC 27018 audit evidence by edition, service scope, criteria, audit period, exceptions, and independent assurance.
ISO/IEC 27018 Breach Support FAQ
ISO/IEC 27018 breach support: when a cloud PII processor should notify a customer, what the contract should define, and what incident records to keep.
ISO/IEC 27018 Cloud Privacy FAQ
ISO/IEC 27018 FAQ on public-cloud PII processor scope, customer instructions, subprocessors, disclosures, breaches, deletion, audit evidence, and GDPR.
ISO/IEC 27018 Customer Instructions FAQ
What counts as a customer instruction under ISO/IEC 27018, how a cloud PII processor should validate it, and what evidence shows it was followed.
ISO/IEC 27018 DPA Clause Review Workflow
Review cloud data-processing terms for instructions, purpose limits, controls, subprocessors, disclosures, incidents, rights support, and deletion.
ISO/IEC 27018 GDPR Overlap FAQ
How ISO/IEC 27018 can support GDPR processor controls without replacing Article 28 terms, controller accountability, transfers, or breach duties.
ISO/IEC 27018 Government Access Evidence Guide
Build a controlled government-access case record showing request authentication, legal review, notice, approval, minimized disclosure, transfer, and closure.
ISO/IEC 27018 Government Access Evidence Workflow
Triage a government request for customer PII, validate authority, decide notice and challenge options, minimize disclosure, and preserve the decision record.
ISO/IEC 27018 Government Access FAQ
How ISO/IEC 27018 addresses legally binding law-enforcement requests: validation, customer consultation or notice, limited disclosure, and records.
ISO/IEC 27018 PII Return and Deletion FAQ
How to plan and prove PII return, transfer, deletion, anonymization, or archival across live systems, backups, temporary files, and subprocessors.
ISO/IEC 27018 Privacy Control Checklist
A practical ISO/IEC 27018:2025 checklist for public-cloud PII processors, with verifiable conditions, owners, evidence, exceptions, and edition controls.
ISO/IEC 27018 Public Cloud PII Processor Scope Guide
Decide whether a service fits ISO/IEC 27018's public-cloud PII processor scope, separate processor and controller activities, and document the boundary.
ISO/IEC 27018 Subprocessor Evidence Guide
Build subprocessor evidence that proves who processed customer PII, where, under which terms and controls, after which notice and approval, and with what exit result.
ISO/IEC 27018 Subprocessor Evidence Workflow
Assess and approve a cloud subprocessor, disclose its use and countries before processing, handle customer objections, and retain operating and exit evidence.
ISO/IEC 27018 Subprocessor Notice FAQ
What an ISO/IEC 27018 subprocessor notice should disclose, when customers should receive it, and what evidence should support consent and objections.
ISO/IEC 27018 Vendor Contract Requirements Guide
Contract guide for ISO/IEC 27018 public-cloud PII processing: scope, instructions, security, subprocessors, disclosures, incidents, rights support, audits, and exit.
ISO/IEC 27018 vs GDPR Comparison
Compare ISO/IEC 27018 cloud-processor guidance with GDPR legal duties, including scope, Article 28 contracts, breaches, transfers, evidence, and assurance limits.
ISO/IEC 27018 vs ISO/IEC 27701 Comparison
Compare ISO/IEC 27018:2025 cloud-processor guidance with the independent ISO/IEC 27701:2025 privacy management system, including scope, evidence, and assurance.
ISO/IEC 27018 vs SOC 2 Privacy Comparison
Compare ISO/IEC 27018 cloud-processor guidance with a SOC 2 examination that includes Privacy, including scope, Type 1 vs Type 2, evidence, and limits.
Using ISO/IEC 27018 for Public-Cloud PII Processing
Decide whether ISO/IEC 27018:2025 applies to a public-cloud PII processor, how it fits an ISMS, what evidence to keep, and which claims the evidence supports.