Side-by-sideGlobalISO/IEC 27018

ISO/IEC 27018 ISO/IEC 27018 vs GDPR

Separate ISO/IEC 27018 control guidance from GDPR legal obligations, then reuse evidence only where the scoped controls match the processing.

ISO/IEC 27018:2025 is the current edition. The clause-level examples on this page come from the withdrawn 2019 edition, so check them against the edition named in a contract, report, or assessment. The standard does not determine GDPR applicability or prove legal compliance.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use GDPR to decide what the law requires and ISO/IEC 27018 to organize controls for a public-cloud provider acting on a customer's instructions. A role depends on the facts, not the contract label or an ISO claim. ISO/IEC 27018 can support processor evidence, but it does not establish a lawful basis, satisfy every term, authorize an international transfer, or prove GDPR compliance.

Side-by-side comparison

ISO/IEC 27018 vs GDPR: scope, duties, evidence, and decision rule

Use GDPR as the source of legal duties and ISO/IEC 27018 as supporting cloud-processor control guidance. Compare roles, triggers, records, deadlines, and assurance claims before reusing evidence.

Review all sources
First framework
ISO/IEC 27018

Voluntary public-cloud PII processor guidance whose controls can support evidence, while GDPR applicability, duties, deadlines, and enforcement come from the regulation.

Second framework
GDPR

Binding EU law that assigns controller and processor duties, individual rights, regulatory deadlines, transfer rules, and enforcement consequences according to its territorial and material scope.

Comparison row 1

Scope and covered activity

ISO/IEC 27018

Public-cloud providers protecting customer PII while acting on customer instructions. Provider-controlled processing for account management, billing, security, analytics, or product purposes needs a separate role analysis.

GDPR

Personal-data processing within GDPR's material and territorial scope, including qualifying processing by EU establishments and specified processing directed at people in the EU.

Operational implication

Test GDPR scope and role from the facts. A service can use ISO/IEC 27018 outside GDPR scope, and GDPR can apply even when the standard is not used.

Comparison row 2

Who must act

ISO/IEC 27018

The public-cloud provider operates processor controls; the customer retains authority over the instructed purposes. Shared-responsibility details vary across SaaS, PaaS, and IaaS and must be stated in the contract.

GDPR

Controllers and processors have distinct and sometimes overlapping duties. A contract label does not override who actually determines purposes and essential means.

Operational implication

Map each duty to the factual role and each control to the party that operates it. Record customer-operated controls and provider activities performed as controller.

Comparison row 3

Trigger or threshold

ISO/IEC 27018

Selected voluntarily or by contract for a public-cloud PII processor service. The standard has no statutory adoption threshold or GDPR deadline.

GDPR

Applies when processing falls within Articles 2 and 3. Separate facts trigger duties such as DPIAs, rights handling, breach notification, and transfer safeguards.

Operational implication

A contract request or audit date can trigger ISO work, but it cannot start, delay, or replace a GDPR duty.

Comparison row 4

Core obligations

ISO/IEC 27018

Guidance built on ISO/IEC 27002 for instructed processing, rights assistance, marketing restrictions, temporary files, disclosures, sub-contractors, incidents, contract measures, processing countries, and return or disposal.

GDPR

Legal rules for principles, lawful bases, transparency, rights, accountability, processor contracts, security, breaches, transfers, supervision, remedies, and penalties.

Operational implication

Map the relevant ISO control to the exact GDPR article and contract term. Do not turn a recommendation in the standard into a legal duty unless law or contract supplies that force.

Comparison row 5

Evidence and records

ISO/IEC 27018

Service and role scope, customer instructions, contracts, control operation, sub-contractor and country notices, disclosure logs, incident records, deletion or return results, findings, and corrections.

GDPR

Evidence depends on the duty and can include processing records, lawful-basis and notice decisions, terms, rights records, DPIAs, security measures, breach files, and transfer safeguards.

Operational implication

Keep a crosswalk with the GDPR article, contract term, ISO edition and clause, owner, evidence period, exceptions, and remaining legal evidence.

Comparison row 6

Timing and cadence

ISO/IEC 27018

No statutory implementation deadline: cadence follows service changes, risk, contract, evidence expiry, incidents, audits, and the edition used.

GDPR

Applies while processing remains in scope. Specific duties have their own timing: for example, a processor notifies the controller of a personal-data breach without undue delay, while the controller's supervisory-authority deadline can be 72 hours after awareness.

Operational implication

Do not convert an ISO review date into a GDPR deadline or apply the controller's 72-hour authority-notification rule as the processor-to-controller contract deadline.

Comparison row 7

Enforcement or assurance route

ISO/IEC 27018

Voluntary guidance can be assessed through internal audit, customer assurance, or a defined independent scheme. Any claim must name the entity, service, edition, scope, exclusions, and assessment basis.

GDPR

Supervisory authorities and courts apply the regulation. Article 42(4) states that certification does not reduce the controller's or processor's responsibility for compliance.

Operational implication

Describe an ISO assessment as evidence about scoped controls, not regulator approval, a legal opinion, or proof of GDPR compliance.

Comparison row 8

Overlap and reuse

ISO/IEC 27018

Service inventories, contracts, controls, tickets, logs, supplier records, incidents, deletion results, and audit evidence can be reused where scope and criteria match.

GDPR

contracts, security, subprocessor records, incident response, rights assistance, disclosures, processing locations, and deletion evidence can overlap. GDPR still needs role, lawful-basis, transparency, transfer, DPIA, and other legal evidence.

Operational implication

Reuse an artifact only after matching the actor, purpose, data, system, country, date, population, and acceptance criteria.

Comparison row 9

Practical decision rule

ISO/IEC 27018

Use it to design and explain controls for a public-cloud service that processes customer PII under instruction.

GDPR

Use GDPR analysis whenever the question concerns applicability, roles, lawfulness, rights, statutory duties, transfers, notification, enforcement, or remedies.

Operational implication

Where both apply, cite GDPR for the legal duty and ISO/IEC 27018 for the supporting control. Record gaps instead of declaring equivalence.

Practical decision rule

How should teams use ISO/IEC 27018 alongside GDPR?

  • Determine GDPR scope and the controller or processor role for each processing purpose, including provider-controlled uses outside customer instructions.
  • Map terms and other applicable duties to the current ISO/IEC 27018 controls, naming both the legal source and standard edition.
  • Reuse evidence only where actor, purpose, system, data, country, supplier, time period, population, and acceptance criteria match; record every gap and owner.
Section 1

Which source decides the requirement?

GDPR is binding EU law when its material and territorial scope applies. It assigns duties according to the facts: a controller determines purposes and means, while a processor handles personal data on the controller's behalf. A cloud provider can be a processor for hosted customer data and a controller for separate account, billing, security, or product-improvement processing.

GDPR can apply to processing in the context of an EU establishment and to specified processing by an organization outside the EU that offers goods or services to, or monitors the behavior of, people in the EU. Article 2 also excludes activities outside Union-law scope, Member State criminal-law activities governed by the law-enforcement regime, and a natural person's purely personal or household activity. ISO/IEC 27018 adoption changes none of those tests.

ISO/IEC 27018:2025 gives guidance for protecting PII in public clouds when the provider acts as a PII processor. It is built on ISO/IEC 27002. The detailed examples here - customer instructions, rights assistance, disclosure records, sub-contractor notices, breach support, and disposal - are grounded in ISO/IEC 27018:2019 and must be checked against the 2025 text before use as current clause criteria.

Start with the GDPR role and scope analysis. Then record which ISO control supports which legal or contractual duty. A standard control can be useful evidence, but the legal conclusion still depends on the processing, jurisdiction, contract, and applicable GDPR article.

  • Record each processing purpose, data category, data-subject group, system, location, recipient, and controller or processor role.
  • Name the GDPR article or contract term that creates the duty; cite ISO/IEC 27018 separately as control guidance.
  • Treat provider-controlled uses of customer data as a separate role analysis rather than forcing them into the processor scope.
Section 2

Where can the controls support GDPR processor duties?

requires a processor contract to cover documented instructions, confidentiality, Article 32 security, subprocessor conditions, assistance with data-subject rights and specified controller duties, deletion or return at the controller's choice, information needed to demonstrate compliance, and audits. ISO/IEC 27018 control evidence can support several of these terms, but the contract must still satisfy Article 28.

For breaches, Article 33(2) requires the processor to notify the controller without undue delay after becoming aware of a personal-data breach. The GDPR's 72-hour rule applies to a controller notifying the supervisory authority under Article 33(1), not automatically to the processor's notice to the controller. The 2019 standard instead recommends that the contract define the maximum processor-to-customer delay.

Useful evidence includes approved customer instructions, confidentiality commitments, security-control results, subprocessor authorizations and change notices, rights-assistance tickets, breach timelines, disclosure records, deletion or return results, and audit information.

  • Legal and privacy: approve the role analysis, terms, instructions, subprocessor mechanism, transfer position, and escalation path.
  • Security and cloud operations: retain control designs, access reviews, logging, restoration records, incident evidence, and deletion tests for the scoped service.
  • Supplier management: keep the authorized subprocessor list, processing countries, flowed-down obligations, notices of intended changes, and customer responses.
  • Service owner: reconcile the contract, product behavior, public documentation, and evidence whenever the service changes.
Section 3

What remains outside an ISO/IEC 27018 claim?

ISO/IEC 27018 does not determine whether GDPR applies, who is controller or processor, which lawful basis supports processing, what notice individuals receive, whether a DPIA is required, how rights requests are decided, or which Chapter V transfer mechanism is valid. It also does not set supervisory powers or administrative fines.

Certification or adherence to a standard may support accountability, but Article 42(4) states that certification does not reduce a controller's or processor's responsibility for GDPR compliance. A certificate or control mapping therefore cannot replace a legal assessment.

  • Controller-only questions: lawful basis, notices, purpose compatibility, rights decisions, DPIAs, and many accountability judgments.
  • Shared but separate duties: security, records, breach response, regulatory cooperation, and transfer controls depend on role and facts.
  • Processor-specific questions: documented instructions, confidentiality, subprocessors, assistance, deletion or return, audit information, and direct statutory duties.
Section 4

How should evidence be mapped without claiming equivalence?

Reuse evidence only when its actor, service, processing purpose, data, location, control period, and acceptance criteria match the GDPR duty being assessed. Keep a crosswalk with separate columns for the GDPR article, contract term, ISO edition and clause, control owner, evidence, exception, and review date.

For example, a deletion test can support an ISO disposal control and (3)(g), but it does not prove that the controller chose deletion rather than return, that every subprocessor and backup copy was covered, or that a separate retention law did not require preservation.

  • Reject evidence that predates a material service, supplier, processing, or control change.
  • Record sampling limits, excluded environments, failed tests, open corrective actions, and customer-operated controls.
  • Do not describe a mapping, audit report, or certificate as regulator approval or proof of GDPR compliance.
Section 5

When must the mapping be reviewed?

Review the mapping when a processing purpose, role, service feature, data category, customer instruction, subprocessor, country, transfer mechanism, contract, incident, law, regulatory interpretation, or standard edition changes. Also review before relying on evidence outside its tested period.

ISO/IEC 27018:2025 replaced the 2019 edition and aligns with ISO/IEC 27002:2022. A team still using 2019 clause references should document the transition decision and reconcile its crosswalk with the current edition rather than silently relabeling old evidence.

  • Assign an owner and review date to every unresolved scope, role, transfer, subprocessor, or evidence issue.
  • Escalate processing outside documented instructions, unapproved subprocessors, missed breach notices, failed deletion tests, and unsupported transfer claims.
  • Keep superseded mappings with their effective dates so an auditor or incident reviewer can reconstruct which criteria applied at the time.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding EU data protection regulation used for ISO/IEC 27018 comparison.
"protection of natural persons with regard to the processing of personal data"
iso.org
Referenced sections
  • The withdrawn 2019 controls support the listed evidence examples for instructions, sub-contractors, countries, disclosures, incidents, and disposal.
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
iso.org
Referenced sections
  • Primary ISO listing for the 2025 edition of ISO/IEC 27018.
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"
Related guides

Explore more topics

ISO/IEC 27018 Audit Evidence FAQ
How to assess ISO/IEC 27018 audit evidence by edition, service scope, criteria, audit period, exceptions, and independent assurance.
ISO/IEC 27018 Breach Support FAQ
ISO/IEC 27018 breach support: when a cloud PII processor should notify a customer, what the contract should define, and what incident records to keep.
ISO/IEC 27018 Cloud Privacy FAQ
ISO/IEC 27018 FAQ on public-cloud PII processor scope, customer instructions, subprocessors, disclosures, breaches, deletion, audit evidence, and GDPR.
ISO/IEC 27018 Customer Instructions FAQ
What counts as a customer instruction under ISO/IEC 27018, how a cloud PII processor should validate it, and what evidence shows it was followed.
ISO/IEC 27018 DPA Clause Review Workflow
Review cloud data-processing terms for instructions, purpose limits, controls, subprocessors, disclosures, incidents, rights support, and deletion.
ISO/IEC 27018 GDPR Overlap FAQ
How ISO/IEC 27018 can support GDPR processor controls without replacing Article 28 terms, controller accountability, transfers, or breach duties.
ISO/IEC 27018 Government Access Evidence Guide
Build a controlled government-access case record showing request authentication, legal review, notice, approval, minimized disclosure, transfer, and closure.
ISO/IEC 27018 Government Access Evidence Workflow
Triage a government request for customer PII, validate authority, decide notice and challenge options, minimize disclosure, and preserve the decision record.
ISO/IEC 27018 Government Access FAQ
How ISO/IEC 27018 addresses legally binding law-enforcement requests: validation, customer consultation or notice, limited disclosure, and records.
ISO/IEC 27018 PII Return and Deletion FAQ
How to plan and prove PII return, transfer, deletion, anonymization, or archival across live systems, backups, temporary files, and subprocessors.
ISO/IEC 27018 Privacy Control Checklist
A practical ISO/IEC 27018:2025 checklist for public-cloud PII processors, with verifiable conditions, owners, evidence, exceptions, and edition controls.
ISO/IEC 27018 Processor Duties FAQ
What ISO/IEC 27018 expects from a public-cloud PII processor: customer instructions, purpose limits, security, transparency, incident support, and disposal.
ISO/IEC 27018 Public Cloud PII Processor Scope Guide
Decide whether a service fits ISO/IEC 27018's public-cloud PII processor scope, separate processor and controller activities, and document the boundary.
ISO/IEC 27018 Subprocessor Evidence Guide
Build subprocessor evidence that proves who processed customer PII, where, under which terms and controls, after which notice and approval, and with what exit result.
ISO/IEC 27018 Subprocessor Evidence Workflow
Assess and approve a cloud subprocessor, disclose its use and countries before processing, handle customer objections, and retain operating and exit evidence.
ISO/IEC 27018 Subprocessor Notice FAQ
What an ISO/IEC 27018 subprocessor notice should disclose, when customers should receive it, and what evidence should support consent and objections.
ISO/IEC 27018 Vendor Contract Requirements Guide
Contract guide for ISO/IEC 27018 public-cloud PII processing: scope, instructions, security, subprocessors, disclosures, incidents, rights support, audits, and exit.
ISO/IEC 27018 vs ISO/IEC 27701 Comparison
Compare ISO/IEC 27018:2025 cloud-processor guidance with the independent ISO/IEC 27701:2025 privacy management system, including scope, evidence, and assurance.
ISO/IEC 27018 vs SOC 2 Privacy Comparison
Compare ISO/IEC 27018 cloud-processor guidance with a SOC 2 examination that includes Privacy, including scope, Type 1 vs Type 2, evidence, and limits.
Using ISO/IEC 27018 for Public-Cloud PII Processing
Decide whether ISO/IEC 27018:2025 applies to a public-cloud PII processor, how it fits an ISMS, what evidence to keep, and which claims the evidence supports.