ISO/IEC 27018
Protection of personally identifiable information in public clouds acting as PII processors. Updated: September 29, 2026.
ISO/IEC 27018 is a code of practice for organisations that process other people's personal data in a public cloud. Its perspective is specifically that of the processor — you hold the data, but it is not yours and the decisions about it are not yours either.
What It Requires in Practice
- Process only on instructions. The data is used for the customer's purposes and nothing else — notably, not for your own marketing or analytics without explicit consent.
- Be transparent about sub-processors and about where processing happens, so the customer can meet their own obligations.
- Tell the customer about disclosure requests. Where a law-enforcement or government request arrives, notify the customer unless prohibited — and record it.
- Return or delete on termination, including from backups, on a defined timescale.
- Support the customer's obligations — being able to correct, delete or export a specific individual's data, because the customer will be asked to and cannot do it alone.
- Notify breaches promptly, because the customer's own notification clock depends on yours.
Its Relationship With Data Protection Law
27018 predates and is broadly aligned with modern data protection regimes, and it is frequently used as evidence of processor diligence. It is worth being precise, though: it is not a certification of legal compliance. Conforming to it does not establish that you meet the GDPR or any other regime, and no auditor issues that opinion. It demonstrates a recognised standard of processor practice, which is a genuine but narrower claim. Where a certifiable privacy management system is what you need, ISO/IEC 27701 is the closer fit.
How It Is Certified
Like 27017, it is a code of practice, assessed as an extension to an ISO/IEC 27001 certification and reflected in the Statement of Applicability. Certification bodies commonly audit 27017 and 27018 together.
Who Needs It
Anyone hosting, processing or storing personal data on behalf of customers: SaaS providers, managed hosting, payroll and HR platforms, analytics processors, and backup providers. If your customers are asking you to sign a data processing agreement, 27018 is the standard that says you have thought about what you are signing.
Written from an infrastructure perspective. We are not a certification body, an audit firm or a legal adviser, and this is not legal advice. Standards are revised on a cycle — confirm the current edition before you commit.