Side-by-sideGlobalISO/IEC 27018

ISO/IEC 27018 ISO/IEC 27018 vs ISO/IEC 27701

Use ISO/IEC 27018 for focused public-cloud processor controls and ISO/IEC 27701 for an organization-wide privacy information management system; combine them when both scopes matter.

Both standards have current 2025 editions. ISO/IEC 27701:2025 is an independent management-system standard, while the withdrawn 2019 edition was an extension to ISO/IEC 27001 and ISO/IEC 27002. Check every clause, certificate, and transition claim against the named edition.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Choose ISO/IEC 27018:2025 when the decision centers on controls for a public-cloud provider acting as a PII processor. Choose ISO/IEC 27701:2025 when the organization needs an independent for PII controller and processor activities. Use both when the broader PIMS includes public-cloud processor services, but keep each standard's scope, controls, evidence, and assurance claim separate.

Side-by-side comparison

ISO/IEC 27018 vs ISO/IEC 27701: scope, duties, evidence, and decision rule

Compare the focused cloud-processor controls in ISO/IEC 27018:2025 with the independent PIMS requirements in ISO/IEC 27701:2025. Use the withdrawn 2019 editions only when a historical contract, certificate, or assessment names them.

Review all sources
First framework
ISO/IEC 27018

Focused guidance for protecting customer PII in public-cloud processor services; it does not itself create a management system, legal duty, or universal certification claim.

Second framework
ISO/IEC 27701

An independent for controller and processor activities. The 2025 edition can be used alone; the withdrawn 2019 edition depended on an ISMS extension model.

Comparison row 1

Scope and covered activity

ISO/IEC 27018

Public-cloud providers processing customer PII under instruction; separate provider-controller activity and additional controller duties remain outside the direct scope.

ISO/IEC 27701

ISO/IEC 27701:2025 establishes an independent PIMS for organizations acting as PII controllers, processors, or both. It can span products, services, functions, and processing beyond public cloud.

Operational implication

Use the service role and management-system boundary to choose focused cloud guidance, a broader PIMS, or both. Do not apply the withdrawn 2019 dependency model to the 2025 edition.

Comparison row 2

Who must act

ISO/IEC 27018

Provider privacy, security, legal, cloud operations, supplier, incident-response, and service owners operate the controls; customers retain authority over instructed processing.

ISO/IEC 27701

Top management and assigned privacy, risk, legal, security, procurement, operations, internal-audit, and control owners run the PIMS across its controller and processor scope.

Operational implication

Keep the cloud provider/customer responsibility split and provider-controlled processing visible inside the wider PIMS role model.

Comparison row 3

Trigger or threshold

ISO/IEC 27018

Adopt when a public-cloud processor and customer need a recognized privacy-control baseline, or when a contract or assurance request names the standard.

ISO/IEC 27701

Selected when an organization wants a governed PIMS across roles, processing, risks, objectives, operations, evaluation, and improvement. It is not limited to public cloud.

Operational implication

A request for cloud-processor controls does not automatically require a PIMS, and a PIMS claim does not show that a public-cloud service was assessed against ISO/IEC 27018.

Comparison row 4

Core obligations

ISO/IEC 27018

Guidance supplements ISO/IEC 27002 controls with public-cloud processor responsibilities for instructions, purpose, customers, security, subcontracting, disclosure, incidents, and disposal.

ISO/IEC 27701

The 2025 edition sets PIMS requirements and guidance for establishment, implementation, maintenance, and continual improvement. The 2019 edition's ISMS-extension structure is historical.

Operational implication

Cross-reference controls but preserve each edition's clause structure, applicability decision, management-system boundary, and assurance scope.

Comparison row 5

Evidence and records

ISO/IEC 27018

Scope and role records, control applicability, contracts, operating samples, subprocessor and country notices, disclosure and incident records, deletion evidence, findings, and corrections.

ISO/IEC 27701

PIMS boundary, PII roles and processing, interested parties, applicable requirements, privacy risks, objectives, policies, responsibilities, operating records, monitoring, internal audits, findings, corrective actions, and management review.

Operational implication

Use one evidence inventory only if every item retains its standard, edition, clause, scope, owner, period, sampling limits, and result.

Comparison row 6

Timing and cadence

ISO/IEC 27018

No statutory implementation deadline: cadence follows service changes, risk, contract, evidence expiry, incidents, audits, and the edition used.

ISO/IEC 27701

No statutory adoption deadline. Review follows the PIMS lifecycle, material changes, risk, monitoring, internal audit, management review, corrective action, and the applicable assurance cycle.

Operational implication

Track the 2019-to-2025 transition and assurance dates separately. Neither standard changes a deadline imposed by law or contract.

Comparison row 7

Enforcement or assurance route

ISO/IEC 27018

Voluntary guidance can support internal audit, customer assurance, or a defined independent audit or certification arrangement; claims must name the service and criteria.

ISO/IEC 27701

As an independent MSS, ISO/IEC 27701:2025 can be the stated criterion for a defined assessment or certification scheme. Any claim remains limited to its certificate, scope, edition, and scheme.

Operational implication

Verify the certificate or report, entity, boundary, sites, edition, dates, exclusions, certification body, accreditation context, and transition status.

Comparison row 8

Overlap and reuse

ISO/IEC 27018

Service inventories, contracts, controls, tickets, logs, supplier records, incidents, deletion results, and audit evidence can be reused where scope and criteria match.

ISO/IEC 27701

Governance, inventories, role maps, risk, contracts, suppliers, incidents, audits, corrective actions, and management review can support the wider PIMS.

Operational implication

Reuse evidence only where the organizational boundary, role, service, processing, control, period, and test criteria overlap.

Comparison row 9

Practical decision rule

ISO/IEC 27018

Choose it when the primary problem is protecting customer PII in a public-cloud processor service and making that control operation understandable to customers.

ISO/IEC 27701

Choose it when the primary need is a privacy management system spanning controller and processor activities, governance, risk, operation, evaluation, and improvement.

Operational implication

Use both when the PIMS includes public-cloud processor services. Preserve separate editions, applicability decisions, control references, evidence, and assurance claims.

Practical decision rule

How should teams decide between ISO/IEC 27018 and ISO/IEC 27701?

  • Choose ISO/IEC 27018:2025 for public-cloud PII processor controls involving customer instructions, sub-contractors, disclosures, incidents, locations, deletion, and processor evidence.
  • Choose ISO/IEC 27701:2025 for an independent PIMS spanning controller and processor governance, risk, operation, evaluation, and continual improvement.
  • Use both when the PIMS boundary includes public-cloud processor services; map shared evidence but retain each standard's edition, clause, scope, result, and assurance boundary.
Section 1

Which standard fits the primary objective?

ISO/IEC 27018:2025 provides guidance for protecting PII in public-cloud services when the provider acts as a processor. It builds on ISO/IEC 27002 and focuses on the provider-customer relationship, cloud-specific responsibilities, transparency, and PII controls.

ISO/IEC 27701:2025 sets requirements and guidance for establishing, implementing, maintaining, and continually improving a . It applies to PII controllers and processors and can be used alone as an independent management-system standard.

Do not carry the 2019 dependency model into a 2025 decision. ISO/IEC 27701:2019 was an extension to ISO/IEC 27001 and ISO/IEC 27002 for organizations processing PII within an ISMS; ISO marks that edition withdrawn and replaced.

  • Choose ISO/IEC 27018 for cloud-service controls involving customer instructions, rights assistance, disclosures, sub-contractors, incidents, processing locations, and disposal.
  • Choose ISO/IEC 27701 for a governed PIMS with organizational scope, privacy risks, objectives, roles, operation, evaluation, corrective action, and continual improvement.
  • Use both when the PIMS boundary includes public-cloud processor services; map overlaps but retain separate applicability decisions and evidence references.
Section 2

When is ISO/IEC 27018 the direct control guide?

Use ISO/IEC 27018 when a public-cloud provider needs specific control guidance for PII processed on a customer's instructions. Confirm the service category, shared-responsibility boundary, customer authority, provider-controlled processing outside that authority, sub-contractors, and countries where PII can be stored.

The withdrawn 2019 edition provides detailed examples for rights assistance, marketing restrictions, disclosure requests and records, sub-contractor notices, breach support, contract measures, return or disposal, and processing locations. Use those examples only as historical grounding until they are checked against ISO/IEC 27018:2025.

  • Scope evidence: service boundary, PII flows, processor role, customer instructions, locations, sub-contractors, and responsibility matrix.
  • Control evidence: access reviews, logs, disclosure records, incident files, restoration controls, deletion tests, and rights-assistance tickets.
  • Contract evidence: minimum measures, confidentiality, sub-contractor flow-down, change notices, breach terms, disposal method, and audit information.
  • Assurance evidence: named edition, assessed service, exclusions, dates, findings, corrective actions, and the basis of any public claim.
Section 3

When is ISO/IEC 27701 the broader system choice?

Use ISO/IEC 27701:2025 when the organization needs a PIMS spanning governance and operational privacy work across controller and processor roles. The management-system boundary can cover more than cloud services and should identify the organizational units, products, processing, interested parties, legal and contractual requirements, risks, and interfaces within scope.

ISO states that the 2025 edition can be used alone. It also aligns with existing ISO/IEC 27001 systems, so an organization can coordinate them without treating ISO/IEC 27001 as a prerequisite for the current PIMS.

  • Define the PIMS boundary, controller and processor roles, PII processing, internal and external interfaces, and applicable requirements.
  • Assign privacy risks, objectives, controls, owners, resources, monitoring, internal audits, management review, and corrective actions.
  • Keep the public-cloud processor responsibility matrix inside the wider PIMS when ISO/IEC 27018 also applies.
Section 4

Which evidence can be coordinated?

Coordinate PII inventories, role maps, risk assessments, policies, legal and contractual requirements, supplier records, incidents, internal audits, findings, corrective actions, and management review. Add the cloud-specific instructions, locations, sub-contractor notices, disclosures, deletion tests, and shared-responsibility evidence needed for ISO/IEC 27018.

Keep one evidence inventory if that reduces duplicate collection, but label the standard, edition, clause or criterion, organizational and service scope, control owner, evidence period, sampling limits, and result for every use.

  • Do not infer that a PIMS-wide record covers a cloud service that is outside the PIMS boundary.
  • Do not infer that a cloud control proves organization-wide governance, performance evaluation, or continual improvement.
  • Record exclusions, failed tests, open corrective actions, accepted risks, and evidence that predates a material change.
Section 5

How should edition and assurance claims be checked?

Verify the exact standard and edition, legal entity, sites, services, PIMS or control boundary, exclusions, assessment dates, certification body or assurance provider, accreditation context, transition status, and scheme rules. An ISO/IEC 27701:2025 claim does not automatically include ISO/IEC 27018:2025, and the reverse is also false.

A certificate or report supports only its stated scope and criteria. It does not establish compliance with every privacy law, contract, customer requirement, or processing activity.

  • Reject an edition-free badge or statement when the underlying certificate or report is unavailable.
  • Document the move from ISO/IEC 27701:2019 to 2025 because the current edition changed from an ISMS extension to an independent MSS.
  • Recheck mappings after changes to roles, services, processing, suppliers, countries, management-system boundaries, standards, or assurance schemes.
Primary sources

References and citations

iso.org
Referenced sections
  • The withdrawn edition contains the detailed cloud-processor controls cited here; ISO's lifecycle record shows it has been replaced by the 2025 edition.
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
iso.org
Referenced sections
  • Primary ISO listing for the 2025 edition of ISO/IEC 27018.
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"
iso.org
Referenced sections
  • ISO's withdrawn 2019 listing documents the former extension to ISO/IEC 27001 and ISO/IEC 27002 and identifies the 2025 replacement.
"Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management"
iso.org
Referenced sections
  • ISO describes the current edition as an independent PIMS standard for controllers and processors.
"Privacy information management systems — Requirements and guidance"
Related guides

Explore more topics

ISO/IEC 27018 Audit Evidence FAQ
How to assess ISO/IEC 27018 audit evidence by edition, service scope, criteria, audit period, exceptions, and independent assurance.
ISO/IEC 27018 Breach Support FAQ
ISO/IEC 27018 breach support: when a cloud PII processor should notify a customer, what the contract should define, and what incident records to keep.
ISO/IEC 27018 Cloud Privacy FAQ
ISO/IEC 27018 FAQ on public-cloud PII processor scope, customer instructions, subprocessors, disclosures, breaches, deletion, audit evidence, and GDPR.
ISO/IEC 27018 Customer Instructions FAQ
What counts as a customer instruction under ISO/IEC 27018, how a cloud PII processor should validate it, and what evidence shows it was followed.
ISO/IEC 27018 DPA Clause Review Workflow
Review cloud data-processing terms for instructions, purpose limits, controls, subprocessors, disclosures, incidents, rights support, and deletion.
ISO/IEC 27018 GDPR Overlap FAQ
How ISO/IEC 27018 can support GDPR processor controls without replacing Article 28 terms, controller accountability, transfers, or breach duties.
ISO/IEC 27018 Government Access Evidence Guide
Build a controlled government-access case record showing request authentication, legal review, notice, approval, minimized disclosure, transfer, and closure.
ISO/IEC 27018 Government Access Evidence Workflow
Triage a government request for customer PII, validate authority, decide notice and challenge options, minimize disclosure, and preserve the decision record.
ISO/IEC 27018 Government Access FAQ
How ISO/IEC 27018 addresses legally binding law-enforcement requests: validation, customer consultation or notice, limited disclosure, and records.
ISO/IEC 27018 PII Return and Deletion FAQ
How to plan and prove PII return, transfer, deletion, anonymization, or archival across live systems, backups, temporary files, and subprocessors.
ISO/IEC 27018 Privacy Control Checklist
A practical ISO/IEC 27018:2025 checklist for public-cloud PII processors, with verifiable conditions, owners, evidence, exceptions, and edition controls.
ISO/IEC 27018 Processor Duties FAQ
What ISO/IEC 27018 expects from a public-cloud PII processor: customer instructions, purpose limits, security, transparency, incident support, and disposal.
ISO/IEC 27018 Public Cloud PII Processor Scope Guide
Decide whether a service fits ISO/IEC 27018's public-cloud PII processor scope, separate processor and controller activities, and document the boundary.
ISO/IEC 27018 Subprocessor Evidence Guide
Build subprocessor evidence that proves who processed customer PII, where, under which terms and controls, after which notice and approval, and with what exit result.
ISO/IEC 27018 Subprocessor Evidence Workflow
Assess and approve a cloud subprocessor, disclose its use and countries before processing, handle customer objections, and retain operating and exit evidence.
ISO/IEC 27018 Subprocessor Notice FAQ
What an ISO/IEC 27018 subprocessor notice should disclose, when customers should receive it, and what evidence should support consent and objections.
ISO/IEC 27018 Vendor Contract Requirements Guide
Contract guide for ISO/IEC 27018 public-cloud PII processing: scope, instructions, security, subprocessors, disclosures, incidents, rights support, audits, and exit.
ISO/IEC 27018 vs GDPR Comparison
Compare ISO/IEC 27018 cloud-processor guidance with GDPR legal duties, including scope, Article 28 contracts, breaches, transfers, evidence, and assurance limits.
ISO/IEC 27018 vs SOC 2 Privacy Comparison
Compare ISO/IEC 27018 cloud-processor guidance with a SOC 2 examination that includes Privacy, including scope, Type 1 vs Type 2, evidence, and limits.
Using ISO/IEC 27018 for Public-Cloud PII Processing
Decide whether ISO/IEC 27018:2025 applies to a public-cloud PII processor, how it fits an ISMS, what evidence to keep, and which claims the evidence supports.