← ALL FRAMEWORKS

ISO/IEC 27018

Data Privacy

Issued by ISO/IEC

ISO/IEC 27018:2019 (second edition) sets out controls for protecting personally identifiable information (PII) handled by public cloud providers acting as PII processors — meaning the provider processes personal data on behalf of another company, not for its own purposes. It covers obligations like restricting how PII is used for the provider's own purposes, requiring transparency about subcontractors, and supporting the customer's ability to fulfill data-subject and breach-notification duties. It's implemented as an extension to a company's ISO/IEC 27001 ISMS and typically pursued by cloud providers processing customer or end-user personal data, such as SaaS vendors handling EU personal data under GDPR.

Get notified the moment ISO/IEC 27018 actually changes — reviewed by a human before it ever reaches you.

Get started free

Most recent update

No published updates yet

This framework hasn't had a confirmed update yet — check back after the next monitoring run.