What should a subprocessor notice contain?
First determine whether the vendor will process customer PII. If so, identify that subcontracting is used, the 's legal name, affected service and processing, countries where it can process PII, planned effective date, and how its contract meets or exceeds the primary processor's information-security and PII-protection obligations. A vendor with no access to or processing of customer PII is outside this notice decision.
ISO/IEC 27018 does not set a universal notice period. The processor should give notice in a timely manner, while the contract determines specific or general consent, timing, the objection route, and termination or alternative-service outcomes. If public disclosure creates unacceptable security risk, the 2019 guidance allows disclosure under a non-disclosure agreement or on customer request, provided customers know the information is available.
- Complete supplier privacy and security review and sign the required flow-down terms before the begins processing PII; this includes providers storing backup copies.
- Match the notice population to affected contracts and services; a website update does not prove that a contractually required notice reached the customer.
- Do not expose business-specific security details that are unnecessary for the customer's decision.
ISO listing for the 2025 ISO/IEC 27018 public-cloud PII processor guidance that supports subprocessor notice evidence and customer disclosure controls.
ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.