ISO 27018
Conditional standard · ISO/IEC 27018, Protection of PII in public clouds acting as PII processors
ISO/IEC
International
First published 2014; current edition 2019
Assessed within an ISO 27001 certification scope
You process personal data in a public cloud, or rely on one that does
Curated, versioned & cross-mapped
The obligation, plainly.
ISO 27018 applies the privacy lens to public-cloud processing: consent and instruction discipline, transparency about sub-processors and locations, return and deletion of data, disclosure handling, and the operational controls a PII processor in the cloud must run.
For regulated organisations it works as the due-diligence baseline for cloud providers: a provider holding 27018 has documented answers for the questions the NDPA, GDPR and POPIA make you ask about your processors.
Where programmes are tested.
Instruction and consent discipline
PII processed only on instruction, with no independent use, and consent handled per the controller's terms.
Transparency
Sub-processors, processing locations and disclosure requests visible to the customer.
Return and deletion
Data returned or destroyed on exit, with the mechanics evidenced.
Curated once, evidenced continuously.
- 27018's processor duties are curated and cross-mapped to the same privacy and vendor controls the data-protection acts demand, so cloud due diligence and legal compliance run off one set.
- Requirements resolve to shared controls: implement a control once and it counts toward every framework it maps to.
- Status is evidence-gated: a requirement can't be marked implemented without valid, in-date evidence behind it.
- Every attestation carries maker/checker, and every action lands in an append-only audit trail.
ISO 27018, asked plainly.
The questions compliance teams actually ask before an adoption decision or an audit.
Who should hold ISO 27018, us or our cloud provider?
Primarily the provider, it codifies the PII-processor role in public cloud. Your side is to verify it, map your controller duties over it, and keep the evidence in your processor due-diligence file, which is exactly where the catalog's vendor controls put it.
Does 27018 satisfy the NDPA or GDPR processor requirements?
It covers much of the operational substance, instructions, sub-processors, deletion, disclosure, but the legal instruments still require their own contracts and clauses. Treat the certificate as strong evidence inside a compliant contract, not a substitute for one.
How does it relate to ISO 27701?
27018 is narrow and operational: PII in public cloud, processor role. 27701 is the full privacy management system across roles and environments. Providers often hold both; the catalog cross-maps them so the overlap is implemented once.
Where it connects.
The full catalogCompliance you can prove.
Walk into your next audit ready.
Book a working demo. We'll map your obligations to the standards you're audited against and the regulators you actually answer to.
The platform, modules, catalog, audit trail and security architecture are live today; the continuous live-evidence engine is in active development, shown in a working demo. Reach us at hello@cardinalgrc.com.