- Binding EU data protection regulation used for ISO/IEC 27018 comparison.
"protection of natural persons with regard to the processing of personal data"
Decide whether the service, provider activity, and customer relationship fit ISO/IEC 27018's public-cloud PII processor scope before assigning controls.
ISO/IEC 27018:2025 is the current edition. The role and control details below come from the withdrawn 2019 edition and must be checked against the edition named in a contract, certification scope, or assurance report. Applicable law and contracts can impose separate duties.
Structured answer sets in this page tree.
Cited legal and guidance references.
ISO/IEC 27018 applies when an organization provides public-cloud information processing under contract and acts as a by processing PII on behalf of and according to a customer's instructions. Scope the purpose and operation, not the company, because the same provider can determine separate purposes for customer-account or other processing.
Apply three tests. First, the offering must be a public-cloud service supplied under contract. Second, it must process PII, meaning information that can identify or be linked to a natural person; the provider may need customer context to recognize it. Third, the provider must process that PII on behalf of and according to the cloud customer's instructions. If any test fails, the activity is outside the standard's direct processor target, though other security, privacy, legal, or contractual requirements can still apply.
The customer retains authority over the processing and use of customer PII. The provider can choose technical methods needed to deliver the service, such as allocating storage or processing capacity, without changing role if those methods remain consistent with the customer's objectives and instructions.
Record the answer per service and processing purpose. A company-wide label such as "processor" is too broad when the provider determines separate purposes for account administration, security analytics, product improvement, or marketing.
The cloud service customer has the contract with the provider and authority over customer-PII processing. The customer can be an individual processing their own PII or an organization acting as PII controller, and it can authorize cloud users to use the service.
The provider is the public cloud only for instructed processing. Map each activity to the party that sets its purpose, the documented instruction, the operational owner, and the evidence that the service follows that instruction.
Draw the boundary around the contracted service and every system that can store, transmit, access, restore, or delete customer PII. Include management interfaces, support tooling, telemetry containing PII, temporary files, backups, disaster-recovery copies, and sub-contracted processing.
For each component, state the PII categories, processing operation, customer purpose, responsible party, possible storage countries, retention or deletion rule, and evidence source. Mark customer-managed components and shared controls so neither party assumes the other operates them.
Provider processing for an independently chosen purpose is not covered as processor activity. The 2019 edition specifically notes that a provider can act as PII controller for cloud-customer account data and does not cover the additional obligations that attach to that controller role.
ISO/IEC 27018 is guidance, not a universal data-processing agreement or a legal determination. Identify the governing law and contract separately. A certification or assurance report also has its own organization, service, location, system, control, and time-period boundaries.
Reassess before a new purpose, PII category, service component, support route, subprocessor, processing country, retention rule, customer instruction, or contract term takes effect. Also reassess after a material incident or a finding that shows the recorded boundary was wrong.
When the cited standard edition changes, compare the new criteria with the existing control map rather than silently relabeling old evidence. ISO states that the 2025 edition aligns with ISO/IEC 27002:2022 and adds Annex B implementation guidance.
Assign accountable owners, collect current evidence, and set review checkpoints for this privacy decision.
Convert ISO/IEC 27018 Public Cloud PII Processor Scope into accountable tasks, evidence requests, and review checkpoints.
Review your current scope, evidence gaps, and next implementation steps.
"protection of natural persons with regard to the processing of personal data"
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"