FAQGlobalISO/IEC 27018

ISO/IEC 27018 FAQ Subprocessor Notice

Tell affected customers which subcontractor will process PII before use and communicate intended changes early enough for contractual objection or termination rights.

The current edition is ISO/IEC 27018:2025; the detailed control explanations here use the prior 2019 edition and should be checked against the edition named in a contract or assurance report. ISO/IEC 27018 is voluntary guidance, while applicable law and contracts can impose separate or stricter duties.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Under ISO/IEC 27018:2019, a public-cloud PII processor should disclose a before that subprocessor processes customer PII. The contract should explain whether consent is specific or general, and intended changes should be communicated early enough for the customer to object or terminate under the agreed terms. A public list helps, but it does not by itself prove timely notice or consent.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

What should a subprocessor notice contain?

First determine whether the vendor will process customer PII. If so, identify that subcontracting is used, the 's legal name, affected service and processing, countries where it can process PII, planned effective date, and how its contract meets or exceeds the primary processor's information-security and PII-protection obligations. A vendor with no access to or processing of customer PII is outside this notice decision.

ISO/IEC 27018 does not set a universal notice period. The processor should give notice in a timely manner, while the contract determines specific or general consent, timing, the objection route, and termination or alternative-service outcomes. If public disclosure creates unacceptable security risk, the 2019 guidance allows disclosure under a non-disclosure agreement or on customer request, provided customers know the information is available.

  • Complete supplier privacy and security review and sign the required flow-down terms before the begins processing PII; this includes providers storing backup copies.
  • Match the notice population to affected contracts and services; a website update does not prove that a contractually required notice reached the customer.
  • Do not expose business-specific security details that are unnecessary for the customer's decision.
Citations
ISO/IEC 27018:2025 standard page

ISO listing for the 2025 ISO/IEC 27018 public-cloud PII processor guidance that supports subprocessor notice evidence and customer disclosure controls.

ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

Question 3

Who owns the change and objection process?

Supplier management coordinates due diligence and the subcontract; privacy and security assess processing, locations, and controls; legal interprets consent and objection terms; the service owner controls customer communication and the go-live date.

An objection is not automatically a veto under ISO/IEC 27018. Follow the contract and applicable law: the outcome may be an alternative provider, a service limitation, remediation, or termination.

  • Name owners for vendor classification, privacy and security review, flow-down terms, customer notice, objections, release approval, and backups.
  • Keep supplier approval separate from customer authorization and release approval; each answers a different condition.
  • Store objections, responses, alternatives, termination decisions, and effective-date approval with the change record.
Citations
ISO/IEC 27018:2025 standard page

ISO listing for the 2025 ISO/IEC 27018 public-cloud PII processor guidance that supports subprocessor notice evidence and customer disclosure controls.

ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

Question 4

When is a new notice required?

Notify before first use and before an intended addition or replacement when the applicable contract or law requires it. Review whether a new notice is needed when the entity, affected service, processing purpose, countries, onward providers, or safeguards change.

Keep the effective date behind the required notice and objection window. If an urgent replacement is necessary, use only an emergency path supported by the contract and applicable law, then retain the decision and customer communication.

  • Review before first use and for a legal-entity replacement, new affected service, changed processing purpose, new country, onward provider, or changed safeguard.
  • Update the supplier register, data-flow map, public list, contract schedule, notice population, objection record, and release control.
  • Block the effective date until the required review, terms, notice, authorization, and objection process are complete, unless a contractually and legally valid emergency path applies.
Citations
ISO/IEC 27018:2025 standard page

ISO listing for the 2025 ISO/IEC 27018 public-cloud PII processor guidance that supports subprocessor notice evidence and customer disclosure controls.

ISO/IEC 27018:2019 standard page

ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.

Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding EU data protection regulation used for ISO/IEC 27018 comparison.
"protection of natural persons with regard to the processing of personal data"
iso.org
Referenced sections
  • ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
iso.org
Referenced sections
  • ISO listing for the 2025 ISO/IEC 27018 public-cloud PII processor guidance that supports subprocessor notice evidence and customer disclosure controls.
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"
Related guides

Explore more topics

ISO/IEC 27018 Audit Evidence FAQ
How to assess ISO/IEC 27018 audit evidence by edition, service scope, criteria, audit period, exceptions, and independent assurance.
ISO/IEC 27018 Breach Support FAQ
ISO/IEC 27018 breach support: when a cloud PII processor should notify a customer, what the contract should define, and what incident records to keep.
ISO/IEC 27018 Cloud Privacy FAQ
ISO/IEC 27018 FAQ on public-cloud PII processor scope, customer instructions, subprocessors, disclosures, breaches, deletion, audit evidence, and GDPR.
ISO/IEC 27018 Customer Instructions FAQ
What counts as a customer instruction under ISO/IEC 27018, how a cloud PII processor should validate it, and what evidence shows it was followed.
ISO/IEC 27018 DPA Clause Review Workflow
Review cloud data-processing terms for instructions, purpose limits, controls, subprocessors, disclosures, incidents, rights support, and deletion.
ISO/IEC 27018 GDPR Overlap FAQ
How ISO/IEC 27018 can support GDPR processor controls without replacing Article 28 terms, controller accountability, transfers, or breach duties.
ISO/IEC 27018 Government Access Evidence Guide
Build a controlled government-access case record showing request authentication, legal review, notice, approval, minimized disclosure, transfer, and closure.
ISO/IEC 27018 Government Access Evidence Workflow
Triage a government request for customer PII, validate authority, decide notice and challenge options, minimize disclosure, and preserve the decision record.
ISO/IEC 27018 Government Access FAQ
How ISO/IEC 27018 addresses legally binding law-enforcement requests: validation, customer consultation or notice, limited disclosure, and records.
ISO/IEC 27018 PII Return and Deletion FAQ
How to plan and prove PII return, transfer, deletion, anonymization, or archival across live systems, backups, temporary files, and subprocessors.
ISO/IEC 27018 Privacy Control Checklist
A practical ISO/IEC 27018:2025 checklist for public-cloud PII processors, with verifiable conditions, owners, evidence, exceptions, and edition controls.
ISO/IEC 27018 Processor Duties FAQ
What ISO/IEC 27018 expects from a public-cloud PII processor: customer instructions, purpose limits, security, transparency, incident support, and disposal.
ISO/IEC 27018 Public Cloud PII Processor Scope Guide
Decide whether a service fits ISO/IEC 27018's public-cloud PII processor scope, separate processor and controller activities, and document the boundary.
ISO/IEC 27018 Subprocessor Evidence Guide
Build subprocessor evidence that proves who processed customer PII, where, under which terms and controls, after which notice and approval, and with what exit result.
ISO/IEC 27018 Subprocessor Evidence Workflow
Assess and approve a cloud subprocessor, disclose its use and countries before processing, handle customer objections, and retain operating and exit evidence.
ISO/IEC 27018 Vendor Contract Requirements Guide
Contract guide for ISO/IEC 27018 public-cloud PII processing: scope, instructions, security, subprocessors, disclosures, incidents, rights support, audits, and exit.
ISO/IEC 27018 vs GDPR Comparison
Compare ISO/IEC 27018 cloud-processor guidance with GDPR legal duties, including scope, Article 28 contracts, breaches, transfers, evidence, and assurance limits.
ISO/IEC 27018 vs ISO/IEC 27701 Comparison
Compare ISO/IEC 27018:2025 cloud-processor guidance with the independent ISO/IEC 27701:2025 privacy management system, including scope, evidence, and assurance.
ISO/IEC 27018 vs SOC 2 Privacy Comparison
Compare ISO/IEC 27018 cloud-processor guidance with a SOC 2 examination that includes Privacy, including scope, Type 1 vs Type 2, evidence, and limits.
Using ISO/IEC 27018 for Public-Cloud PII Processing
Decide whether ISO/IEC 27018:2025 applies to a public-cloud PII processor, how it fits an ISMS, what evidence to keep, and which claims the evidence supports.