| Scope and covered activity | Public-cloud providers processing customer PII under instruction; separate provider-controller activity and additional controller duties remain outside the direct scope. | ISO/IEC 27701:2025 establishes an independent PIMS for organizations acting as PII controllers, processors, or both. It can span products, services, functions, and processing beyond public cloud. | Use the service role and management-system boundary to choose focused cloud guidance, a broader PIMS, or both. Do not apply the withdrawn 2019 dependency model to the 2025 edition. |
|---|
| Who must act | Provider privacy, security, legal, cloud operations, supplier, incident-response, and service owners operate the controls; customers retain authority over instructed processing. | Top management and assigned privacy, risk, legal, security, procurement, operations, internal-audit, and control owners run the PIMS across its controller and processor scope. | Keep the cloud provider/customer responsibility split and provider-controlled processing visible inside the wider PIMS role model. |
|---|
| Trigger or threshold | Adopt when a public-cloud processor and customer need a recognized privacy-control baseline, or when a contract or assurance request names the standard. | Selected when an organization wants a governed PIMS across roles, processing, risks, objectives, operations, evaluation, and improvement. It is not limited to public cloud. | A request for cloud-processor controls does not automatically require a PIMS, and a PIMS claim does not show that a public-cloud service was assessed against ISO/IEC 27018. |
|---|
| Core obligations | Guidance supplements ISO/IEC 27002 controls with public-cloud processor responsibilities for instructions, purpose, customers, security, subcontracting, disclosure, incidents, and disposal. | The 2025 edition sets PIMS requirements and guidance for establishment, implementation, maintenance, and continual improvement. The 2019 edition's ISMS-extension structure is historical. | Cross-reference controls but preserve each edition's clause structure, applicability decision, management-system boundary, and assurance scope. |
|---|
| Evidence and records | Scope and role records, control applicability, contracts, operating samples, subprocessor and country notices, disclosure and incident records, deletion evidence, findings, and corrections. | PIMS boundary, PII roles and processing, interested parties, applicable requirements, privacy risks, objectives, policies, responsibilities, operating records, monitoring, internal audits, findings, corrective actions, and management review. | Use one evidence inventory only if every item retains its standard, edition, clause, scope, owner, period, sampling limits, and result. |
|---|
| Timing and cadence | No statutory implementation deadline: cadence follows service changes, risk, contract, evidence expiry, incidents, audits, and the edition used. | No statutory adoption deadline. Review follows the PIMS lifecycle, material changes, risk, monitoring, internal audit, management review, corrective action, and the applicable assurance cycle. | Track the 2019-to-2025 transition and assurance dates separately. Neither standard changes a deadline imposed by law or contract. |
|---|
| Enforcement or assurance route | Voluntary guidance can support internal audit, customer assurance, or a defined independent audit or certification arrangement; claims must name the service and criteria. | As an independent MSS, ISO/IEC 27701:2025 can be the stated criterion for a defined assessment or certification scheme. Any claim remains limited to its certificate, scope, edition, and scheme. | Verify the certificate or report, entity, boundary, sites, edition, dates, exclusions, certification body, accreditation context, and transition status. |
|---|
| Overlap and reuse | Service inventories, contracts, controls, tickets, logs, supplier records, incidents, deletion results, and audit evidence can be reused where scope and criteria match. | Governance, inventories, role maps, risk, contracts, suppliers, incidents, audits, corrective actions, and management review can support the wider PIMS. | Reuse evidence only where the organizational boundary, role, service, processing, control, period, and test criteria overlap. |
|---|
| Practical decision rule | Choose it when the primary problem is protecting customer PII in a public-cloud processor service and making that control operation understandable to customers. | Choose it when the primary need is a privacy management system spanning controller and processor activities, governance, risk, operation, evaluation, and improvement. | Use both when the PIMS includes public-cloud processor services. Preserve separate editions, applicability decisions, control references, evidence, and assurance claims. |
|---|