GuideGlobalISO/IEC 27018

ISO/IEC 27018 Public Cloud PII Processor Scope

Decide whether the service, provider activity, and customer relationship fit ISO/IEC 27018's public-cloud PII processor scope before assigning controls.

ISO/IEC 27018:2025 is the current edition. The role and control details below come from the withdrawn 2019 edition and must be checked against the edition named in a contract, certification scope, or assurance report. Applicable law and contracts can impose separate duties.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ISO/IEC 27018 applies when an organization provides public-cloud information processing under contract and acts as a by processing PII on behalf of and according to a customer's instructions. Scope the purpose and operation, not the company, because the same provider can determine separate purposes for customer-account or other processing.

Section 1

Is this a public-cloud PII processor activity?

Apply three tests. First, the offering must be a public-cloud service supplied under contract. Second, it must process PII, meaning information that can identify or be linked to a natural person; the provider may need customer context to recognize it. Third, the provider must process that PII on behalf of and according to the cloud customer's instructions. If any test fails, the activity is outside the standard's direct processor target, though other security, privacy, legal, or contractual requirements can still apply.

The customer retains authority over the processing and use of customer PII. The provider can choose technical methods needed to deliver the service, such as allocating storage or processing capacity, without changing role if those methods remain consistent with the customer's objectives and instructions.

Record the answer per service and processing purpose. A company-wide label such as "processor" is too broad when the provider determines separate purposes for account administration, security analytics, product improvement, or marketing.

  • In scope: public-cloud collection, storage, use, transmission, backup, restoration, and deletion performed for the customer's stated purposes.
  • Outside the direct scope: processing for the provider's independently chosen purposes and additional controller obligations that do not apply to processors.
  • Borderline case: a technical implementation choice needed to achieve the customer's objective can remain processor activity. A new provider-selected objective, reuse of customer PII for product improvement or marketing, or an instruction that does not cover the operation requires a separate role and legal assessment before processing.
  • Output: a dated scope record naming the service, customer type, PII categories, operations, purposes, locations, subprocessors, instruction source, control owner, exclusions, and approving role.
Section 2

Which customer, controller, provider, processor, and user roles apply?

The cloud service customer has the contract with the provider and authority over customer-PII processing. The customer can be an individual processing their own PII or an organization acting as PII controller, and it can authorize cloud users to use the service.

The provider is the public cloud only for instructed processing. Map each activity to the party that sets its purpose, the documented instruction, the operational owner, and the evidence that the service follows that instruction.

  • Customer evidence: contract, data-processing terms, service configuration, documented instructions, authorized-user model, and change approvals.
  • Provider evidence: service description, data-flow map, processing inventory, country list, subprocessor register, access-control records, logs, deletion design, and incident procedure.
  • Role split: identify provider-controlled purposes separately and do not present ISO/IEC 27018 coverage as proof that those controller activities comply with applicable law.
  • Approval: name the privacy or legal reviewer, service owner, decision date, unresolved assumptions, and the change that will force reassessment.
Section 3

What belongs inside the service and processing boundary?

Draw the boundary around the contracted service and every system that can store, transmit, access, restore, or delete customer PII. Include management interfaces, support tooling, telemetry containing PII, temporary files, backups, disaster-recovery copies, and sub-contracted processing.

For each component, state the PII categories, processing operation, customer purpose, responsible party, possible storage countries, retention or deletion rule, and evidence source. Mark customer-managed components and shared controls so neither party assumes the other operates them.

  • Include: production data, replicas, support access, diagnostic logs containing PII, temporary files, backups, and exports.
  • Trace: customer instruction -> service operation -> system or subprocessor -> country -> control -> retained evidence.
  • Exclude only with a reason, an owner, and evidence. A component is not outside scope merely because a different team or supplier operates it.
Section 4

What sits outside ISO/IEC 27018's direct scope?

Provider processing for an independently chosen purpose is not covered as processor activity. The 2019 edition specifically notes that a provider can act as PII controller for cloud-customer account data and does not cover the additional obligations that attach to that controller role.

ISO/IEC 27018 is guidance, not a universal data-processing agreement or a legal determination. Identify the governing law and contract separately. A certification or assurance report also has its own organization, service, location, system, control, and time-period boundaries.

  • Do not assume every cloud provider activity is processor activity.
  • Do not treat de-identified, anonymized, or telemetry data as outside scope without documenting the method, residual identifiability, and intended use.
  • Do not use an ISO/IEC 27018 claim to imply compliance with every privacy law or every clause in a customer's contract.
Section 5

Which changes require a new scope decision?

Reassess before a new purpose, PII category, service component, support route, subprocessor, processing country, retention rule, customer instruction, or contract term takes effect. Also reassess after a material incident or a finding that shows the recorded boundary was wrong.

When the cited standard edition changes, compare the new criteria with the existing control map rather than silently relabeling old evidence. ISO states that the 2025 edition aligns with ISO/IEC 27002:2022 and adds Annex B implementation guidance.

  • Keep the prior decision, the changed fact, the reviewer, the new conclusion, and the effective date.
  • Update the data flow, processing inventory, customer notice, contract schedule, country list, subprocessor register, and control evidence affected by the change.
  • Escalate a proposed independent purpose or unresolved role conflict for a separate legal and privacy assessment before processing begins.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding EU data protection regulation used for ISO/IEC 27018 comparison.
"protection of natural persons with regard to the processing of personal data"
iso.org
Referenced sections
  • ISO's withdrawn 2019 listing identifies the prior edition; its detailed clauses remain relevant only when that edition is the stated criterion.
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
iso.org
Referenced sections
  • Primary ISO listing for the 2025 edition of ISO/IEC 27018.
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"
Related guides

Explore more topics

ISO/IEC 27018 Audit Evidence FAQ
How to assess ISO/IEC 27018 audit evidence by edition, service scope, criteria, audit period, exceptions, and independent assurance.
ISO/IEC 27018 Breach Support FAQ
ISO/IEC 27018 breach support: when a cloud PII processor should notify a customer, what the contract should define, and what incident records to keep.
ISO/IEC 27018 Cloud Privacy FAQ
ISO/IEC 27018 FAQ on public-cloud PII processor scope, customer instructions, subprocessors, disclosures, breaches, deletion, audit evidence, and GDPR.
ISO/IEC 27018 Customer Instructions FAQ
What counts as a customer instruction under ISO/IEC 27018, how a cloud PII processor should validate it, and what evidence shows it was followed.
ISO/IEC 27018 DPA Clause Review Workflow
Review cloud data-processing terms for instructions, purpose limits, controls, subprocessors, disclosures, incidents, rights support, and deletion.
ISO/IEC 27018 GDPR Overlap FAQ
How ISO/IEC 27018 can support GDPR processor controls without replacing Article 28 terms, controller accountability, transfers, or breach duties.
ISO/IEC 27018 Government Access Evidence Guide
Build a controlled government-access case record showing request authentication, legal review, notice, approval, minimized disclosure, transfer, and closure.
ISO/IEC 27018 Government Access Evidence Workflow
Triage a government request for customer PII, validate authority, decide notice and challenge options, minimize disclosure, and preserve the decision record.
ISO/IEC 27018 Government Access FAQ
How ISO/IEC 27018 addresses legally binding law-enforcement requests: validation, customer consultation or notice, limited disclosure, and records.
ISO/IEC 27018 PII Return and Deletion FAQ
How to plan and prove PII return, transfer, deletion, anonymization, or archival across live systems, backups, temporary files, and subprocessors.
ISO/IEC 27018 Privacy Control Checklist
A practical ISO/IEC 27018:2025 checklist for public-cloud PII processors, with verifiable conditions, owners, evidence, exceptions, and edition controls.
ISO/IEC 27018 Processor Duties FAQ
What ISO/IEC 27018 expects from a public-cloud PII processor: customer instructions, purpose limits, security, transparency, incident support, and disposal.
ISO/IEC 27018 Subprocessor Evidence Guide
Build subprocessor evidence that proves who processed customer PII, where, under which terms and controls, after which notice and approval, and with what exit result.
ISO/IEC 27018 Subprocessor Evidence Workflow
Assess and approve a cloud subprocessor, disclose its use and countries before processing, handle customer objections, and retain operating and exit evidence.
ISO/IEC 27018 Subprocessor Notice FAQ
What an ISO/IEC 27018 subprocessor notice should disclose, when customers should receive it, and what evidence should support consent and objections.
ISO/IEC 27018 Vendor Contract Requirements Guide
Contract guide for ISO/IEC 27018 public-cloud PII processing: scope, instructions, security, subprocessors, disclosures, incidents, rights support, audits, and exit.
ISO/IEC 27018 vs GDPR Comparison
Compare ISO/IEC 27018 cloud-processor guidance with GDPR legal duties, including scope, Article 28 contracts, breaches, transfers, evidence, and assurance limits.
ISO/IEC 27018 vs ISO/IEC 27701 Comparison
Compare ISO/IEC 27018:2025 cloud-processor guidance with the independent ISO/IEC 27701:2025 privacy management system, including scope, evidence, and assurance.
ISO/IEC 27018 vs SOC 2 Privacy Comparison
Compare ISO/IEC 27018 cloud-processor guidance with a SOC 2 examination that includes Privacy, including scope, Type 1 vs Type 2, evidence, and limits.
Using ISO/IEC 27018 for Public-Cloud PII Processing
Decide whether ISO/IEC 27018:2025 applies to a public-cloud PII processor, how it fits an ISMS, what evidence to keep, and which claims the evidence supports.