- The GDPR source supports processor and subprocessor governance context when ISO/IEC 27018 evidence is mapped to binding EU privacy duties.
"protection of natural persons with regard to the processing of personal data"
Build a time-aware evidence pack showing who processes customer PII, where, under which controls and terms, and how customers were informed.
The evidence fields below map to withdrawn ISO/IEC 27018:2019. Check the current 2025 edition, the applicable customer contract, and processor and transfer law before treating the pack as sufficient.
Structured answer sets in this page tree.
Cited legal and guidance references.
A needs more than a current list. The evidence pack should show what each downstream provider does, which customer services and PII it affects, where processing can occur, how obligations flow down, when customers were told, how objections were resolved, what controls operated, and what happened at exit.
Give each relationship a stable record. Identify the legal entity, contracted service, role, processing purpose and operations, PII categories, affected customer services, access type, possible storage and access countries, onward providers, responsible owner, approval, start date, review date, and exit status.
Link the record to the customer instruction and processing terms that authorize the activity. Record whether customer consent is specific or general, the applicable notice period and channel, the objection or termination route, and any customer-specific restriction.
A downstream provider belongs in this pack when it processes customer PII on the public-cloud provider's behalf while the provider performs the customer's instructions. Include backup, disaster-recovery, support, observability, and other providers when they meet that test. Distinguish a supplier with no PII processing, or one used only for a separate provider-controlled purpose, by documenting the actual data flow, purpose, and permissions rather than relying on its title.
Keep the risk assessment and the facts behind it: service architecture, access paths, countries, PII sensitivity and volume, tenant isolation, privileged access, encryption, logging, resilience, restoration, vulnerability management, incident history, disposal, and unresolved findings.
Map the signed terms to the provider's customer obligations. The 2019 guidance says the contract should specify minimum technical and organizational measures that meet the provider's security and PII-protection obligations and should prevent unilateral reduction by the subprocessor.
Link each provider's scope, authority, controls, notice history, operating samples, findings, and exit result.
Track the register, due diligence, contract evidence, customer notices, exceptions, and review dates together.
Review your current scope, evidence gaps, and next implementation steps.
Preserve the exact notice sent, the change it described, recipient population, contractual channel, send date, delivery result, promised notice period, effective date, objections, responses, customer-specific blocks, withdrawals, and termination outcomes. A current web list cannot prove that notice preceded use.
Under the 2019 guidance, relevant customers should be told before a is used. Disclosed information should include relevant names, possible processing countries, and how the subprocessor is obliged to meet or exceed the provider's obligations. Timely change notice should allow objection or termination.
For the review period, sample actual user and privileged access, region configuration, data transfers, restoration events, incident communications, government-request handling, control changes, assurance exceptions, remediation, and retention or deletion jobs. Match samples to the approved entity, service, account, country, and period.
At exit, retain evidence that new transfers stopped, accounts and keys were revoked, integrations were removed, customer PII and working copies were returned or deleted, backups entered the documented expiry process, and registers and customer-facing lists were updated.
Refresh before onboarding and when the service, legal entity, ownership, processing purpose, PII, access, country, onward provider, control set, assurance scope, contract, customer commitment, incident history, or exit status changes.
Set both a scheduled review and event triggers. A review can reuse evidence only when its entity, service, location, control, and period still match the decision being supported.
"protection of natural persons with regard to the processing of personal data"
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"