home / frameworks / iso-27018

// International standards

ISO/IEC 27018:2025

ISO/IEC 27018 sets out controls and guidance for public cloud providers that process personal information for their customers. The third edition, published in August 2025, aligns with ISO/IEC 27002:2022 and adds a new Annex B.

InternationalISO/IEC 27018:2025 (Edition 3, August 2025)

Overview

ISO/IEC 27018 is a code of practice for protecting personally identifiable information (PII) in public cloud services where the provider acts as a PII processor. It builds on ISO/IEC 27002, adapting the security controls to cloud processing and adding privacy-specific controls. The third edition was published in August 2025 and replaced the 2019 edition. It runs to 35 pages.

According to ISO, the 2025 edition was aligned with ISO/IEC 27002:2022 and includes a new Annex B with extended implementation guidance. It covers PII through its whole life in the service, from collection and storage to transmission and deletion. The controls deal with processing only on customer instructions, transparency about subcontractors and data location, notification of breaches, limits on disclosure to authorities, and the return or deletion of PII when a contract ends. The customer stays in control.

It has no management system. Providers usually add its controls to the scope and Statement of Applicability of an ISO/IEC 27001 certification, and the certification body reviews them during the same audit. In Canada, guidance from the Office of the Privacy Commissioner says organizations remain responsible for personal information sent to a third party for processing and should use contracts to obtain a comparable level of protection, a role this standard can support. It complements, but doesn't replace, ISO/IEC 27701 or legal advice under PIPEDA and Quebec's Law 25.

Who it applies to in Canada

Public cloud service providers that process personally identifiable information (PII) on behalf of customers, acting as PII processors. Customers also use it to set expectations when they choose and contract with such providers.

Under PIPEDA, a Canadian organization stays accountable for personal information it transfers to a cloud provider and must use contracts or other means to protect it. ISO/IEC 27018 gives Canadian buyers and cloud providers a shared, auditable set of processor controls to point to in those contracts.

Controls at a glance

The standard pairs cloud-specific guidance on ISO/IEC 27002 security controls with extra controls for PII processors, grouped here by the privacy obligation they address.

Customer instructions and purpose

  • Process PII only on the customer's documented instructions
  • Don't use customer PII for marketing or advertising without consent
  • Help customers respond to individuals' access and correction requests

Transparency and subcontractors

  • Disclose the use of subcontractors before they process PII
  • Tell customers about changes to subcontractors
  • Disclose the countries where PII may be stored or processed

Disclosure to authorities

  • Reject requests for disclosure that aren't legally binding
  • Notify the customer of binding requests unless legally prohibited
  • Record disclosures of PII to third parties

Breach notification

  • Notify customers promptly of breaches involving their PII
  • Agree notification terms in the contract
  • Keep records of incidents and responses

Retention, return, and deletion

  • Set and follow a policy for returning or deleting PII
  • Securely erase temporary files and backups on schedule
  • Handle storage media reuse and disposal safely

Security of PII in the cloud

  • Confidentiality commitments for staff with access to PII
  • Restrict and log access to customer PII
  • Encrypt PII in transit over public networks
  • Use unique user IDs and manage access rights

Accountability and review

  • Assign responsibility for PII protection
  • Review privacy and security controls independently
  • Provide customers with evidence of compliance

Certification and assessment

ISO/IEC 27018 isn't certified on its own. A cloud provider adds its controls to the ISO/IEC 27001 Statement of Applicability, and the certification body checks them during the ISMS audit. The result appears on the ISO/IEC 27001 certificate or in a separate statement of conformity.

Dates to know

2025-08
ISO/IEC 27018:2025 (Edition 3) published, replacing the 2019 edition

Resources

Official texts and free tools for ISO 27018. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. ISO/IEC 27018:2025 Protection of PII in public clouds acting as PII processors, ISO
  2. Guidelines for processing personal data across borders, Office of the Privacy Commissioner of Canada