- Binding EU data protection regulation used for ISO/IEC 27018 comparison.
"protection of natural persons with regard to the processing of personal data"
Control subprocessor onboarding and changes with prior disclosure, timely customer notice, objection handling, responsibility flow-down, and evidence.
The detailed steps use withdrawn ISO/IEC 27018:2019. Check them against ISO/IEC 27018:2025, the customer contract, and applicable processor and transfer law; those sources can require different consent, notice, objection, or flow-down terms.
Structured answer sets in this page tree.
Cited legal and guidance references.
A should open this workflow before a proposed downstream provider receives production PII. Identify the provider and countries, assess controls and terms, complete any required customer authorization and notice, resolve objections, approve or reject the change, and retain operating and exit evidence.
Open the workflow before the proposed provider receives production PII. Record its legal entity, service, role, processing purpose and operations, PII categories, access type, affected customer services, possible storage and access countries, onward providers, and planned start date.
Confirm that the customer contract permits the appointment and states whether consent is specific or general. Identify the promised notice period, objection or termination route, transfer terms, security schedule, and the ISO/IEC 27018 edition used as a review criterion.
Treat a downstream provider as a for this workflow when it processes customer PII on the public-cloud provider's behalf while the provider performs the customer's instructions. Include backup, support, monitoring, content-delivery, and disaster-recovery providers when they meet that test. A vendor label or lack of routine human access does not decide the role; a provider with no PII access or one used only for a separate provider-controlled purpose needs its own documented classification.
Compare the supplier's controls and contract with the obligations the public-cloud provider owes its customers. Under the 2019 guidance, the contract should specify minimum technical and organizational measures that meet the provider's information-security and PII-protection obligations and should prevent unilateral reduction by the subprocessor.
Resolve gaps before approval or record a time-limited exception with the affected obligation, compensating measure, owner, approver, expiry, and customer impact. An assurance report supports due diligence only for the entities, services, locations, controls, and period it actually covers.
The 2019 guidance says relevant customers should be told about sub-contracted PII processing before use. It calls for the fact of subcontracting, relevant names, possible processing countries, and how the is bound to meet or exceed the provider's obligations.
Send notice through the contractually valid channel early enough for the promised objection or termination process. Preserve the notice version, recipient population, send and effective dates, delivery result, objections, responses, exceptions, withdrawals, and termination outcomes.
If public disclosure would create unacceptable security risk, the 2019 guidance permits controlled disclosure under a non-disclosure agreement or on request, while making customers aware that the information is available. Do not use that exception merely to avoid notice.
After the notice and objection window, an authorized approver checks the due-diligence report, signed terms, control mapping, country and transfer review, customer outcomes, unresolved conditions, and production safeguards. Record the approval and actual activation date.
Update the register, data-flow map, processing inventory, customer-facing list, country list, access groups, monitoring, incident contacts, retention schedule, backup map, and exit plan. Evidence must identify the supplier and service version actually approved.
Monitor material control changes, assurance coverage, incidents, complaints, country changes, acquisitions, onward providers, and contract renewals. Reopen due diligence and customer notice before a change takes effect when the contract or applicable rule requires it.
On exit, stop new transfers, revoke accounts and keys, remove integrations, reconcile stored PII and backups, obtain return or deletion evidence, update registers and notices, and record any legally required retention with access restrictions and a disposal date.
Connect due diligence, signed terms, customer notice, objections, approval, activation, monitoring, and exit in one supplier record.
Assign each onboarding gate, evidence request, exception, and reassessment trigger to an owner.
Review your current scope, evidence gaps, and next implementation steps.
"protection of natural persons with regard to the processing of personal data"
"Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors"
"Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors"