Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27018 cloud privacy explained

ISO 27018: A Clear Guide to the 2025 Cloud Privacy Rules

ISO 27018 is the standard for the position most cloud providers are actually in: holding personal data that belongs to somebody else, under their instructions, with no right to decide what happens to it. The third edition, ISO/IEC 27018:2025, is current — and the standard is more useful to sales teams than most people realise, because it answers the questions customer privacy reviews ask.

This guide covers what the standard requires, the six obligations that carry commercial weight, why there is no certificate, and how it fits with ISO 27001 and ISO 27701.

ISO 27018: where it applies and what it adds to ISO 27001
One narrow case — public cloud, PII, acting as processor — and a specific set of duties.

When ISO 27018 applies

Three conditions together. You operate a public cloud service; the service handles personally identifiable information; and you act as a PII processor — processing on behalf of and under the instructions of the customer, who is the controller.

Change any one and the standard stops fitting. A private cloud for your own group, a service that touches no personal data, or a business where you decide the purposes yourself all fall outside its scope. That precision is the point: it is written for a role, not for an industry.

What it adds to ISO 27001

  What it is Certifiable on its own?
ISO/IEC 27001 The information security management system Yes
ISO/IEC 27002 Guidance on the information security controls No
ISO/IEC 27017 Cloud security controls for providers and customers No — audited as an ISO 27001 extension
ISO/IEC 27018 PII protection for public cloud processors No — audited as an ISO 27001 extension
ISO/IEC 27701 Privacy information management, controllers and processors Yes, alongside ISO 27001

There is no standalone ISO 27018 certificate, and any vendor claiming one is describing something else — usually an ISO 27001 certificate whose scope statement mentions the extension. That is legitimate and worth asking to see in full.

The six obligations that carry commercial weight

  1. Process only on documented instructions. No use of customer PII for your own purposes — advertising, marketing or product development — without consent. This is the clause customers check first, and the one that constrains an analytics roadmap.
  2. Disclose sub-processors before you use them. Named, with the processing they perform, and with notice before changes so the customer can object.
  3. Handle law enforcement requests properly. Reject requests without a legal basis, notify the customer unless prohibited, and record every request and response.
  4. Be transparent about location. Where PII may be stored and processed, including sub-processor locations — which is what makes a customer’s transfer assessment possible.
  5. Notify breaches, and record them. A defined route, defined timing and a log the customer can be shown.
  6. Return, transfer and dispose of PII on termination. With confirmation, and with retention and secure deletion policies stated rather than implied.

Read that list as a sales asset rather than a compliance burden. Every item is something a customer’s privacy review asks about, and a provider that can answer with a documented control and an audited scope shortens its own sales cycle.

What the 2025 edition changed

The third edition aligned the text with ISO/IEC 27002:2022 — the restructured control set — and added a new annex. If your documentation still maps to the older control numbering, the mapping is what needs updating rather than the controls themselves. Our guide to ISO 27017 and the 2026 edition covers the cloud security half of the same pair.

ISO 27018 and the privacy law you actually have to comply with

Conformity is not compliance. GDPR Article 28, the UK regime, and comparable processor obligations elsewhere impose legal duties that a standard cannot discharge — a data processing agreement is still a contract, and a transfer mechanism is still a legal instrument.

What the standard does is give you a recognised control set for exactly those duties, and an audited scope statement that a customer can rely on instead of a questionnaire. Where you need certifiable privacy management across controller and processor roles together, ISO 27701 is the larger instrument — see our guide to the ISO 27701 controls. Where you are specifically a public cloud processor and want the narrow, well-understood answer, this is it.

Where implementations fall short

The sub-processor list is out of date. A new tool is adopted, PII flows through it, and the published list still shows last year’s set. This is the failure customers discover, and it damages trust disproportionately.

Marketing use creeps back in. Product analytics on customer data, added by a team that never saw the commitment. Write the restriction into the engineering standard, not only into the policy.

No law enforcement register. The requirement is to record requests and responses. Organizations handle them competently and record nothing, which leaves nothing to show.

Deletion promised, not evidenced. Confirmation of return or deletion on termination has to be producible, including from backups within a stated period.

Frequently asked questions

Can we be certified to ISO 27018?
Not on its own. It is implemented as an extension to an ISO 27001 management system and covered in that certificate’s scope, which is what an accredited auditor assesses.

What is the current edition?
ISO/IEC 27018:2025, the third edition, aligned with ISO/IEC 27002:2022.

Does it apply if we are a controller?
No. It is written for PII processors in public clouds. Controllers should look to ISO 27701 and to their legal obligations directly.

Does it satisfy GDPR?
No standard does. It provides a control set that maps well onto processor obligations and gives customers audited evidence, which is a substantial part of demonstrating compliance but not a substitute for it.

How does it differ from ISO 27017?
ISO 27017 covers cloud security generally, for providers and customers. ISO 27018 covers privacy specifically, and only for processors handling PII in a public cloud.

Where this leaves you

If you process personal data in a public cloud for customers, implement ISO 27018 as an extension to your ISO 27001 scope and make the six obligations real: no secondary use, a sub-processor list that is genuinely current, a law enforcement register, published locations, a breach route with timing, and evidence of deletion on termination. Then put the scope statement in front of customers — the commercial value of the standard is that it answers their privacy review before they send it.

References

  • ISO/IEC 27018:2025 — protection of PII in public clouds acting as PII processors.
  • ISO/IEC 27001 — the management system the extension is audited within.

More on cloud security

Processor obligation records, sub-processor registers and the control mapping are in the ISO 27017 & ISO 27018 Cloud Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.