What it covers
ISO 27018 sets out how a cloud provider should handle the personal data its customers entrust to it: process it only on the customer's instructions, not use it for marketing or advertising without consent, disclose sub processors and the countries where data may be stored, help customers respond to data subject requests, notify customers of breaches, and return or delete data at the end of the contract.
Who uses it
Cloud and SaaS providers that process personal data for business customers. It gives those customers assurance that the provider's commitments match what a data processing agreement under the GDPR requires.
How it is certified
Like ISO 27017, it is a code of practice rather than a management system standard. Its controls are usually assessed as an extension of an ISO 27001 certification.
ISO 27018 or ISO 27701
ISO 27701 is a full privacy management system for any organisation, whether controller or processor, and since 2025 it can be certified on its own. ISO 27018 is narrower and focused on public cloud processors. Many large cloud providers hold both.




