Compliance · Cloud privacy
Proof you handle other people's personal data properly.
ISO/IEC 27018 is the code of practice for protecting personally identifiable information when you process it as a cloud provider. It puts real constraints on what you may do with customer PII — including not using it for your own advertising without explicit consent.
PII
In public cloud
Processor
Primary role
27002+
Extends
It's aimed squarely at processors — organizations handling personal data on behalf of someone else.
The customer stays in charge of their data. You process it on instruction, return or delete it on request, and don't repurpose it because it happens to be sitting on your servers.
27018 explicitly restricts using customer PII for marketing or advertising without express consent — a commitment that resonates in enterprise procurement.
Sub-processors must be disclosed, data locations known, and lawful-access requests handled and communicated according to defined rules.
Cloud providers and SaaS platforms processing personal data for their customers.
We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.
We map what personal data you hold, where it lives, who touches it, and how long you keep it.
We implement the consent, purpose-limitation, and instruction-only processing controls the standard requires.
We build the disclosure, due diligence, and flow-down obligations for everyone downstream of you.
We prove you can hand data back or destroy it on request, with evidence.
We define how lawful-access requests are handled, logged, and communicated.
We align 27018 with your ISO 27001 scope and your customers' GDPR obligations.
Find the personal data and map its flows.
Measure current controls against 27018.
Close consent, retention, and transparency gaps.
Disclose and contractually bind the chain.
Fold into 27001 audit scope and keep it current.
27018 isn't GDPR certification, but it maps closely to processor obligations — purpose limitation, sub-processor transparency, deletion, and breach handling. Certified 27018 controls make it materially easier to satisfy customers' GDPR due diligence and Article 28 requirements.
Like 27017, it's a code of practice assessed within an ISO 27001 certification scope rather than a standalone certificate. Most organizations show it as an extension of their 27001 certification.
27018 is written for processors handling PII in public clouds. If you're a controller, ISO 27701 is usually the better fit because it addresses both roles and builds a full privacy management system.
Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.
Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.