Separate ISO/IEC 27018 control guidance from GDPR legal obligations, then reuse evidence only where the scoped controls match the processing.
ISO/IEC 27018:2025 is the current edition. The clause-level examples on this page come from the withdrawn 2019 edition, so check them against the edition named in a contract, report, or assessment. The standard does not determine GDPR applicability or prove legal compliance.
Use GDPR to decide what the law requires and ISO/IEC 27018 to organize controls for a public-cloud provider acting on a customer's instructions. A role depends on the facts, not the contract label or an ISO claim. ISO/IEC 27018 can support processor evidence, but it does not establish a lawful basis, satisfy every term, authorize an international transfer, or prove GDPR compliance.
Side-by-side comparison
ISO/IEC 27018 vs GDPR: scope, duties, evidence, and decision rule
Use GDPR as the source of legal duties and ISO/IEC 27018 as supporting cloud-processor control guidance. Compare roles, triggers, records, deadlines, and assurance claims before reusing evidence.
Voluntary public-cloud PII processor guidance whose controls can support evidence, while GDPR applicability, duties, deadlines, and enforcement come from the regulation.
Second framework
GDPR
Binding EU law that assigns controller and processor duties, individual rights, regulatory deadlines, transfer rules, and enforcement consequences according to its territorial and material scope.
ISO/IEC 27018 vs GDPR: scope, duties, evidence, and decision rule
Public-cloud providers protecting customer PII while acting on customer instructions. Provider-controlled processing for account management, billing, security, analytics, or product purposes needs a separate role analysis.
Personal-data processing within GDPR's material and territorial scope, including qualifying processing by EU establishments and specified processing directed at people in the EU.
The public-cloud provider operates processor controls; the customer retains authority over the instructed purposes. Shared-responsibility details vary across SaaS, PaaS, and IaaS and must be stated in the contract.
Controllers and processors have distinct and sometimes overlapping duties. A contract label does not override who actually determines purposes and essential means.
Map each duty to the factual role and each control to the party that operates it. Record customer-operated controls and provider activities performed as controller.
Applies when processing falls within Articles 2 and 3. Separate facts trigger duties such as DPIAs, rights handling, breach notification, and transfer safeguards.
Guidance built on ISO/IEC 27002 for instructed processing, rights assistance, marketing restrictions, temporary files, disclosures, sub-contractors, incidents, contract measures, processing countries, and return or disposal.
Map the relevant ISO control to the exact GDPR article and contract term. Do not turn a recommendation in the standard into a legal duty unless law or contract supplies that force.
Service and role scope, customer instructions, contracts, control operation, sub-contractor and country notices, disclosure logs, incident records, deletion or return results, findings, and corrections.
Evidence depends on the duty and can include processing records, lawful-basis and notice decisions, terms, rights records, DPIAs, security measures, breach files, and transfer safeguards.
Applies while processing remains in scope. Specific duties have their own timing: for example, a processor notifies the controller of a personal-data breach without undue delay, while the controller's supervisory-authority deadline can be 72 hours after awareness.
Do not convert an ISO review date into a GDPR deadline or apply the controller's 72-hour authority-notification rule as the processor-to-controller contract deadline.
Voluntary guidance can be assessed through internal audit, customer assurance, or a defined independent scheme. Any claim must name the entity, service, edition, scope, exclusions, and assessment basis.
Supervisory authorities and courts apply the regulation. Article 42(4) states that certification does not reduce the controller's or processor's responsibility for compliance.
Service inventories, contracts, controls, tickets, logs, supplier records, incidents, deletion results, and audit evidence can be reused where scope and criteria match.
contracts, security, subprocessor records, incident response, rights assistance, disclosures, processing locations, and deletion evidence can overlap. GDPR still needs role, lawful-basis, transparency, transfer, DPIA, and other legal evidence.
Public-cloud providers protecting customer PII while acting on customer instructions. Provider-controlled processing for account management, billing, security, analytics, or product purposes needs a separate role analysis.
Personal-data processing within GDPR's material and territorial scope, including qualifying processing by EU establishments and specified processing directed at people in the EU.
The public-cloud provider operates processor controls; the customer retains authority over the instructed purposes. Shared-responsibility details vary across SaaS, PaaS, and IaaS and must be stated in the contract.
Controllers and processors have distinct and sometimes overlapping duties. A contract label does not override who actually determines purposes and essential means.
Map each duty to the factual role and each control to the party that operates it. Record customer-operated controls and provider activities performed as controller.
Applies when processing falls within Articles 2 and 3. Separate facts trigger duties such as DPIAs, rights handling, breach notification, and transfer safeguards.
Guidance built on ISO/IEC 27002 for instructed processing, rights assistance, marketing restrictions, temporary files, disclosures, sub-contractors, incidents, contract measures, processing countries, and return or disposal.
Map the relevant ISO control to the exact GDPR article and contract term. Do not turn a recommendation in the standard into a legal duty unless law or contract supplies that force.
Service and role scope, customer instructions, contracts, control operation, sub-contractor and country notices, disclosure logs, incident records, deletion or return results, findings, and corrections.
Evidence depends on the duty and can include processing records, lawful-basis and notice decisions, terms, rights records, DPIAs, security measures, breach files, and transfer safeguards.
Applies while processing remains in scope. Specific duties have their own timing: for example, a processor notifies the controller of a personal-data breach without undue delay, while the controller's supervisory-authority deadline can be 72 hours after awareness.
Do not convert an ISO review date into a GDPR deadline or apply the controller's 72-hour authority-notification rule as the processor-to-controller contract deadline.
Voluntary guidance can be assessed through internal audit, customer assurance, or a defined independent scheme. Any claim must name the entity, service, edition, scope, exclusions, and assessment basis.
Supervisory authorities and courts apply the regulation. Article 42(4) states that certification does not reduce the controller's or processor's responsibility for compliance.
Service inventories, contracts, controls, tickets, logs, supplier records, incidents, deletion results, and audit evidence can be reused where scope and criteria match.
contracts, security, subprocessor records, incident response, rights assistance, disclosures, processing locations, and deletion evidence can overlap. GDPR still needs role, lawful-basis, transparency, transfer, DPIA, and other legal evidence.
How should teams use ISO/IEC 27018 alongside GDPR?
Determine GDPR scope and the controller or processor role for each processing purpose, including provider-controlled uses outside customer instructions.
Map terms and other applicable duties to the current ISO/IEC 27018 controls, naming both the legal source and standard edition.
Reuse evidence only where actor, purpose, system, data, country, supplier, time period, population, and acceptance criteria match; record every gap and owner.
GDPR is binding EU law when its material and territorial scope applies. It assigns duties according to the facts: a controller determines purposes and means, while a processor handles personal data on the controller's behalf. A cloud provider can be a processor for hosted customer data and a controller for separate account, billing, security, or product-improvement processing.
GDPR can apply to processing in the context of an EU establishment and to specified processing by an organization outside the EU that offers goods or services to, or monitors the behavior of, people in the EU. Article 2 also excludes activities outside Union-law scope, Member State criminal-law activities governed by the law-enforcement regime, and a natural person's purely personal or household activity. ISO/IEC 27018 adoption changes none of those tests.
ISO/IEC 27018:2025 gives guidance for protecting PII in public clouds when the provider acts as a PII processor. It is built on ISO/IEC 27002. The detailed examples here - customer instructions, rights assistance, disclosure records, sub-contractor notices, breach support, and disposal - are grounded in ISO/IEC 27018:2019 and must be checked against the 2025 text before use as current clause criteria.
Start with the GDPR role and scope analysis. Then record which ISO control supports which legal or contractual duty. A standard control can be useful evidence, but the legal conclusion still depends on the processing, jurisdiction, contract, and applicable GDPR article.
Record each processing purpose, data category, data-subject group, system, location, recipient, and controller or processor role.
Name the GDPR article or contract term that creates the duty; cite ISO/IEC 27018 separately as control guidance.
Treat provider-controlled uses of customer data as a separate role analysis rather than forcing them into the processor scope.
Where can the controls support GDPR processor duties?
requires a processor contract to cover documented instructions, confidentiality, Article 32 security, subprocessor conditions, assistance with data-subject rights and specified controller duties, deletion or return at the controller's choice, information needed to demonstrate compliance, and audits. ISO/IEC 27018 control evidence can support several of these terms, but the contract must still satisfy Article 28.
For breaches, Article 33(2) requires the processor to notify the controller without undue delay after becoming aware of a personal-data breach. The GDPR's 72-hour rule applies to a controller notifying the supervisory authority under Article 33(1), not automatically to the processor's notice to the controller. The 2019 standard instead recommends that the contract define the maximum processor-to-customer delay.
Useful evidence includes approved customer instructions, confidentiality commitments, security-control results, subprocessor authorizations and change notices, rights-assistance tickets, breach timelines, disclosure records, deletion or return results, and audit information.
Legal and privacy: approve the role analysis, terms, instructions, subprocessor mechanism, transfer position, and escalation path.
Security and cloud operations: retain control designs, access reviews, logging, restoration records, incident evidence, and deletion tests for the scoped service.
Supplier management: keep the authorized subprocessor list, processing countries, flowed-down obligations, notices of intended changes, and customer responses.
Service owner: reconcile the contract, product behavior, public documentation, and evidence whenever the service changes.
ISO/IEC 27018 does not determine whether GDPR applies, who is controller or processor, which lawful basis supports processing, what notice individuals receive, whether a DPIA is required, how rights requests are decided, or which Chapter V transfer mechanism is valid. It also does not set supervisory powers or administrative fines.
Certification or adherence to a standard may support accountability, but Article 42(4) states that certification does not reduce a controller's or processor's responsibility for GDPR compliance. A certificate or control mapping therefore cannot replace a legal assessment.
Controller-only questions: lawful basis, notices, purpose compatibility, rights decisions, DPIAs, and many accountability judgments.
Shared but separate duties: security, records, breach response, regulatory cooperation, and transfer controls depend on role and facts.
Processor-specific questions: documented instructions, confidentiality, subprocessors, assistance, deletion or return, audit information, and direct statutory duties.
How should evidence be mapped without claiming equivalence?
Reuse evidence only when its actor, service, processing purpose, data, location, control period, and acceptance criteria match the GDPR duty being assessed. Keep a crosswalk with separate columns for the GDPR article, contract term, ISO edition and clause, control owner, evidence, exception, and review date.
For example, a deletion test can support an ISO disposal control and (3)(g), but it does not prove that the controller chose deletion rather than return, that every subprocessor and backup copy was covered, or that a separate retention law did not require preservation.
Reject evidence that predates a material service, supplier, processing, or control change.
Record sampling limits, excluded environments, failed tests, open corrective actions, and customer-operated controls.
Do not describe a mapping, audit report, or certificate as regulator approval or proof of GDPR compliance.
Review the mapping when a processing purpose, role, service feature, data category, customer instruction, subprocessor, country, transfer mechanism, contract, incident, law, regulatory interpretation, or standard edition changes. Also review before relying on evidence outside its tested period.
ISO/IEC 27018:2025 replaced the 2019 edition and aligns with ISO/IEC 27002:2022. A team still using 2019 clause references should document the transition decision and reconcile its crosswalk with the current edition rather than silently relabeling old evidence.
Assign an owner and review date to every unresolved scope, role, transfer, subprocessor, or evidence issue.
Escalate processing outside documented instructions, unapproved subprocessors, missed breach notices, failed deletion tests, and unsupported transfer claims.
Keep superseded mappings with their effective dates so an auditor or incident reviewer can reconstruct which criteria applied at the time.