← ISO and SOC Certifications

ISO/IEC 27018

Protection of personally identifiable information in public clouds acting as PII processors. Updated: September 29, 2026.

ISO/IEC 27018 is a code of practice for organisations that process other people's personal data in a public cloud. Its perspective is specifically that of the processor — you hold the data, but it is not yours and the decisions about it are not yours either.

What It Requires in Practice

Its Relationship With Data Protection Law

27018 predates and is broadly aligned with modern data protection regimes, and it is frequently used as evidence of processor diligence. It is worth being precise, though: it is not a certification of legal compliance. Conforming to it does not establish that you meet the GDPR or any other regime, and no auditor issues that opinion. It demonstrates a recognised standard of processor practice, which is a genuine but narrower claim. Where a certifiable privacy management system is what you need, ISO/IEC 27701 is the closer fit.

How It Is Certified

Like 27017, it is a code of practice, assessed as an extension to an ISO/IEC 27001 certification and reflected in the Statement of Applicability. Certification bodies commonly audit 27017 and 27018 together.

Who Needs It

Anyone hosting, processing or storing personal data on behalf of customers: SaaS providers, managed hosting, payroll and HR platforms, analytics processors, and backup providers. If your customers are asking you to sign a data processing agreement, 27018 is the standard that says you have thought about what you are signing.

Written from an infrastructure perspective. We are not a certification body, an audit firm or a legal adviser, and this is not legal advice. Standards are revised on a cycle — confirm the current edition before you commit.