Write the contract around the real public-cloud service: processing roles, customer instructions, allocated controls, subprocessors, processing countries, disclosures, incidents, evidence, and end-of-service data handling.
ISO/IEC 27018:2025 is the current edition. The detailed clause examples here come from the withdrawn 2019 edition and must be reconciled to the 2025 text. GDPR Article 28 is included only as an EU-law comparison; other jurisdictions and contracts can require different terms.
A cloud processing contract should identify each activity in which the provider acts as a , state what it may do with , allocate every shared control, govern changes and incidents, specify the evidence the customer receives, and account for every copy at exit. PII is information that can identify a person or be linked, directly or indirectly, to that person. ISO/IEC 27018 supplies control guidance; applicable law determines which clauses are legally required.
1
Section 1
Which scope, roles, and instructions must the contract define?
Start with the service boundary and role for each processing purpose. ISO/IEC 27018 covers a public-cloud provider when it processes on behalf of and according to a customer's instructions. A sets the purposes and means of processing; a acts on the controller's behalf and instructions. Processing for the provider's own purposes needs a separate role, purpose, notice, legal, and contract analysis.
For an EU controller-processor relationship, requires a binding written contract or other legal act that states the subject matter and duration, nature and purpose, personal-data types, data-subject categories, and controller rights and obligations. It also requires documented instructions and specified processor duties. Those legal requirements come from the GDPR, not from ISO/IEC 27018.
For any jurisdiction, define instructions precisely enough to govern normal operation and change. Cover enabled features, support access, diagnostic data, locations, transfers, retention, deletion, and what the provider must do if an instruction conflicts with applicable law. Define whether silence, use of a feature, an administrator action, a support ticket, or an API call counts as an instruction, and how the provider authenticates the person issuing it.
Identify the contracting entities, covered services and accounts, term, processing operations, purposes, or personal-data types, affected people, and processing countries.
Attach or incorporate documented customer instructions and define who may change them, how changes are authenticated, and when they take effect.
Allocate customer and provider responsibilities for access, configuration, keys, logging, backups, requests from individuals, incidents, and deletion for the actual SaaS, PaaS, or IaaS model.
Separate processor activity from any provider-controlled analytics, security, billing, or account activity instead of assigning one role to the whole relationship.
Name the ISO/IEC 27018 edition if the standard is a contract criterion, and define how a change of edition will be assessed rather than incorporated automatically.
Which privacy and security commitments should be explicit?
Describe minimum technical and organizational measures in a security schedule or other controlled attachment. The 2019 edition said these measures should keep contracted security arrangements in place, prevent independent processing purposes, and not be subject to unilateral reduction by the provider. It also called for equivalent minimum measures in subprocessor contracts.
Avoid a generic promise to use 'appropriate security' without an allocation or verification method. State the control outcome, responsible party, service dependency, evidence available to the customer, notification process for material changes, and remedy when a committed control is not operating.
Purpose and confidentiality - Limit processing to customer instructions and bind authorized personnel to confidentiality that survives their access or engagement.
Access and identity - Allocate user provisioning, deprovisioning, privileged access, unique IDs, access review, and compromised-credential response.
Encryption and transfer - State how is protected on public networks, what encryption and key options the provider supplies, and which settings the customer controls.
Logging and restoration - Define event and restoration logs, access to customer-relevant records, retention, review, time synchronization, and protection from alteration or cross-customer access.
Backups and resilience - Describe backup and restoration capability, recovery timing, customer responsibilities, locations, , and how retention and deletion apply to backup copies.
Control changes - Require notice of a material reduction or replacement, a documented assessment, and the agreed correction, objection, or termination path.
How should subprocessors, locations, and disclosures be handled?
The 2019 edition called for disclosure of relevant before use, transparency about processing countries, timely notice of intended changes, and a route for the customer to object or terminate. It allowed restricted disclosure under a non-disclosure agreement or on request when public detail would create an unacceptable security risk, provided the customer knew the information was available.
Keep compelled disclosures separate from ordinary subprocessor processing. The 2019 edition called for the provider to reject requests that are not legally binding, consult the customer before disclosure where legally permitted, and record what was disclosed, to whom, when, under what authority, and from which source.
Maintain a subprocessor schedule with legal name, service, processing function, countries, effective date, and the means used to impose the provider's -protection obligations.
Define specific or general customer authorization, the notice period for additions or replacements, the information supplied, and the process and consequence of an objection.
Require to meet the allocated technical and organizational measures and prevent unilateral reduction of those measures.
List countries where may be stored or processed and define notice and objection or termination rights for material location changes.
For binding disclosure requests, define validation, legal escalation, customer consultation or notice where permitted, production approval, minimization, and a disclosure record.
State the exception when law prohibits notice; do not promise customer notice in every case.
What assistance, evidence, and exit outcomes should be agreed?
Set measurable assistance duties for requests from individuals, privacy assessments, security reviews, incidents, regulatory enquiries, and customer audits. The 2019 edition said the contract should define the maximum delay for notifying the customer of a qualifying breach; it did not prescribe one universal number. Choose the period from applicable law, customer duties, risk, and operational capability.
Define exit by data location and copy type. Address export format and timing, return or transfer, live deletion, temporary files, replicas, logs, backups, business-continuity copies, support systems, subprocessor copies, anonymization or archival, legal retention exceptions, and the evidence the provider will supply.
Rights assistance - State the channels, information, technical functions, response targets, and cost allocation for access, correction, erasure, export, or restriction support.
Incident support - Define the trigger, maximum notification delay, contact route, initial facts, update cadence, evidence preservation, root-cause information, corrective action, and regulatory support.
Assurance - Define the independent evidence provided, criteria, scope, period, frequency, exceptions, remediation updates, and a secure alternative when individual audits are impractical.
Audit - Preserve applicable statutory audit rights; specify notice, confidentiality, frequency, assessor qualifications, security safeguards, access limits, and allocation of cost without making the right unusable.
Exit - Give the customer a usable export window and state the selected return, transfer, deletion, anonymization, or archival outcome for each copy type and subprocessor.
Retention exception - Identify any law that requires storage, restrict processing during retention, set the owner and final deletion trigger, and notify the customer where permitted.
Do not let a policy URL or online security schedule change a negotiated protection without control. Define which documents are incorporated, the version or change mechanism, which changes require notice or consent, and the order of precedence when terms conflict.
For an exception, record the affected clause and service, reason, duration, residual risk, compensating control, evidence, approving roles, customer notice or consent if required, and the event that ends or reopens the exception.
Reopen the terms when purposes, instructions, features, architecture, , countries, control ownership, applicable law, or assurance criteria change.
Require prompt notice of a committed control failure and define correction, temporary protection, evidence, and claim updates.
Track exceptions to expiry or closure; do not treat silence, a stale questionnaire, or an old audit report as approval.
Before renewal, reconcile the contract to the current service, current evidence, and the ISO/IEC 27018 edition named in the agreement.
GDPR Article 28 requires a written binding arrangement and makes several duties conditional on instructions, authorization, available information, or applicable Union or Member State law.
"The contract or the other legal act referred to in paragraphs 3 and 4 shall be in writing"
The 2019 edition supports clear responsibility allocation and timely notice of intended subprocessor and country changes, with objection or termination paths.
"Contractual agreements need to clearly specify the PII protection responsibilities of all organizations involved"