Compliance · Cloud privacy

ISO/IEC 27018 — protecting personal data in public clouds

Proof you handle other people's personal data properly.

ISO/IEC 27018 is the code of practice for protecting personally identifiable information when you process it as a cloud provider. It puts real constraints on what you may do with customer PII — including not using it for your own advertising without explicit consent.

PII

In public cloud

Processor

Primary role

27002+

Extends

What ISO 27018 requires

It's aimed squarely at processors — organizations handling personal data on behalf of someone else.

Customer control of PII

The customer stays in charge of their data. You process it on instruction, return or delete it on request, and don't repurpose it because it happens to be sitting on your servers.

No advertising use

27018 explicitly restricts using customer PII for marketing or advertising without express consent — a commitment that resonates in enterprise procurement.

Transparency & disclosure

Sub-processors must be disclosed, data locations known, and lawful-access requests handled and communicated according to defined rules.

Who needs ISO 27018

Cloud providers and SaaS platforms processing personal data for their customers.

  • SaaS platforms storing customer end-user data
  • Cloud and hosting providers acting as processors
  • Vendors supporting GDPR-regulated customers
  • Providers competing on privacy in enterprise deals

How intSignal gets you there

We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.

PII inventory

We map what personal data you hold, where it lives, who touches it, and how long you keep it.

Processor controls

We implement the consent, purpose-limitation, and instruction-only processing controls the standard requires.

Sub-processor governance

We build the disclosure, due diligence, and flow-down obligations for everyone downstream of you.

Return & deletion

We prove you can hand data back or destroy it on request, with evidence.

Disclosure handling

We define how lawful-access requests are handled, logged, and communicated.

Audit alignment

We align 27018 with your ISO 27001 scope and your customers' GDPR obligations.

How the engagement runs

1

Inventory PII

Find the personal data and map its flows.

2

Assess

Measure current controls against 27018.

3

Implement

Close consent, retention, and transparency gaps.

4

Govern sub-processors

Disclose and contractually bind the chain.

5

Assess & maintain

Fold into 27001 audit scope and keep it current.

Frequently asked questions

How does ISO 27018 relate to GDPR?

27018 isn't GDPR certification, but it maps closely to processor obligations — purpose limitation, sub-processor transparency, deletion, and breach handling. Certified 27018 controls make it materially easier to satisfy customers' GDPR due diligence and Article 28 requirements.

Is ISO 27018 separately certifiable?

Like 27017, it's a code of practice assessed within an ISO 27001 certification scope rather than a standalone certificate. Most organizations show it as an extension of their 27001 certification.

We're a controller, not a processor — does it apply?

27018 is written for processors handling PII in public clouds. If you're a controller, ISO 27701 is usually the better fit because it addresses both roles and builds a full privacy management system.

Other frameworks we support

Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.

ISO 27018 for your environment

Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.