Back to Frameworks
Frameworks

ISO/IEC 27018

Framework Name

ISO/IEC 27018

Type

Voluntary

Region / Jurisdiction

Global

Enforcing Body / Certifying Party

International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). There is no standalone certification against ISO 27018, it is assessed as an extension to an existing ISO 27001 certification's scope, by the same accredited certification bodies

Penalty / Consequence of Non-Compliance

No legal penalty. The consequence is commercial: cloud providers that hold this, several major cloud platforms market it directly, gain a clear point of differentiation with enterprise customers who specifically ask how their personal data is handled in the cloud

What It Is & Why It Matters

ISO 27018 provides guidelines for protecting personally identifiable information (PII) specifically when a cloud provider is acting as a PII processor, meaning it handles personal data on behalf of a customer, under that customer's instructions, rather than deciding independently how the data gets used. It builds directly on ISO 27002's security controls, adding controls and guidance aimed specifically at privacy in a cloud context, and aligns with the privacy principles set out in a separate ISO standard, ISO 29100. The current third edition, published in 2025, updated the standard to align with the newer ISO 27002:2022 control set and added a new implementation annex with expanded practical guidance.

It matters because of a subtle but important shift in focus compared to most security standards on this list. Where something like ISO 27001 is largely about protecting an organization from threats, ISO 27018 is about protecting the people whose data that organization has been trusted with, its customers, and its customers' customers. For a cloud provider, being able to show specifically how it safeguards personal data, not just how it secures its infrastructure generally, is often what turns a security conversation into a trust conversation, which matters most to enterprise buyers handling sensitive customer data themselves.

Who Needs It

  • You are a cloud service provider processing personal data on behalf of your customers and want a recognized way to prove privacy-specific controls, not just general security
  • Enterprise customers are asking specifically how their end users' personal data is protected within your cloud environment
  • You already hold ISO 27001 and want to extend it with privacy controls tailored to a PII-processor relationship
  • You compete against larger cloud providers that already market this certification and want to close that credibility gap
Book A Demo