GlossaryISO 27001

ISO 27018

Short answer

ISO 27018 is the international code of practice for protecting personal data in public cloud services when the provider acts as a data processor. It adds privacy controls to the ISO 27002 guidance, covering consent, purpose limitation, transparency about sub processors and data location, and breach notification.

What it covers

ISO 27018 sets out how a cloud provider should handle the personal data its customers entrust to it: process it only on the customer's instructions, not use it for marketing or advertising without consent, disclose sub processors and the countries where data may be stored, help customers respond to data subject requests, notify customers of breaches, and return or delete data at the end of the contract.

Who uses it

Cloud and SaaS providers that process personal data for business customers. It gives those customers assurance that the provider's commitments match what a data processing agreement under the GDPR requires.

How it is certified

Like ISO 27017, it is a code of practice rather than a management system standard. Its controls are usually assessed as an extension of an ISO 27001 certification.

ISO 27018 or ISO 27701

ISO 27701 is a full privacy management system for any organisation, whether controller or processor, and since 2025 it can be certified on its own. ISO 27018 is narrower and focused on public cloud processors. Many large cloud providers hold both.

Related terms

Keep reading on this topic

ISO 27001 information security management: scope, risk treatment, Annex A controls, internal audit and the certification audit process, explained.

Go to the topic hub