ISO/IEC 27018
Data PrivacyIssued by ISO/IEC
ISO/IEC 27018:2019 (second edition) sets out controls for protecting personally identifiable information (PII) handled by public cloud providers acting as PII processors — meaning the provider processes personal data on behalf of another company, not for its own purposes. It covers obligations like restricting how PII is used for the provider's own purposes, requiring transparency about subcontractors, and supporting the customer's ability to fulfill data-subject and breach-notification duties. It's implemented as an extension to a company's ISO/IEC 27001 ISMS and typically pursued by cloud providers processing customer or end-user personal data, such as SaaS vendors handling EU personal data under GDPR.
Get notified the moment ISO/IEC 27018 actually changes — reviewed by a human before it ever reaches you.
Get started freeMost recent update
No published updates yet
This framework hasn't had a confirmed update yet — check back after the next monitoring run.