Skip to main content
Category: Data Protection & Privacy

ISO/IEC 27018

Also known as: ISO 27018, Code of Practice for Protection of Personally Identifiable Information (PII) in Public Clouds
Simply put

ISO/IEC 27018 is an international standard that offers guidance for protecting personal information stored or processed in public cloud services. It focuses specifically on situations where a cloud service provider handles personally identifiable information (PII) on behalf of its customers. The standard sets out control objectives, controls, and guidelines intended to help providers safeguard that information.

Formal definition

ISO/IEC 27018 is a code of practice that establishes commonly accepted control objectives, controls, and implementation guidelines for protecting personally identifiable information (PII) in public cloud computing environments, applied to cloud service providers acting as PII processors. It functions as a sector-specific supplement building on the broader ISO/IEC 27000-series information security framework rather than as a standalone certification of an organization's entire security program. Among its provisions, it addresses requirements such as policies enabling the return, transfer, and secure disposal of personal information within a reasonable period. Practitioners should note that alignment with ISO/IEC 27018 supports readiness and can demonstrate PII-protection practices, but the extent of applicability depends on the cloud provider's role, scope of engagement, and the specific controls implemented; the standard has been issued in multiple editions (including 2014, 2019, and 2025), which may differ in detail.

Why it matters

Organizations increasingly rely on public cloud services to store and process personal information, but doing so introduces a shared-responsibility challenge: the customer remains accountable for its data even though a cloud service provider handles it. ISO/IEC 27018 matters because it gives buyers and providers a common reference point for what protecting personally identifiable information (PII) in a public cloud should look like, translating the broad principles of the ISO/IEC 27000-series into cloud-specific control objectives and guidelines. For a security leader evaluating vendors, alignment with the standard can be a useful signal that a provider has considered PII-specific concerns rather than only general information security.

The practical value of ISO/IEC 27018 lies in its focus on the provider acting as a PII processor. It addresses concerns that matter to customers who entrust personal data to a third party, such as having policies that enable the return, transfer, and secure disposal of personal information within a reasonable period. These provisions help customers reason about what happens to their data during and after an engagement, which is often a gap in less structured vendor relationships. It is important to note, however, that the standard is a code of practice and supports readiness and demonstration of PII-protection practices; it is not a guarantee that any given deployment is compliant with a specific privacy law or free from risk.

A common expert correction is to avoid treating ISO/IEC 27018 as a standalone certification of an organization's entire security program. It is a sector-specific supplement that builds on the wider ISO/IEC 27000-series framework, and its applicability depends on the provider's role, the scope of the engagement, and which controls are actually implemented. The standard has also been issued in multiple editions, including 2014, 2019, and 2025, which may differ in detail, so referencing a specific edition matters when assessing what a provider claims to follow.

Who it's relevant to

Cloud Service Providers Acting as PII Processors
Providers that store or process personal information on behalf of their customers are the primary audience for ISO/IEC 27018. The standard gives them a structured set of control objectives and guidelines for demonstrating PII-protection practices to prospective and existing clients. Providers should be clear about which edition they align with and which controls they have actually implemented, since alignment is not the same as certifying their entire security program.
Organizations Buying Public Cloud Services
Customers who entrust personal data to a public cloud provider can use ISO/IEC 27018 as a reference when evaluating and comparing vendors. It helps buyers ask targeted questions about data return, transfer, and secure disposal, and about how PII is protected during processing. Buyers should remember that accountability for their data typically remains with them, so provider alignment supports due diligence rather than transferring responsibility.
Virtual and Fractional CISOs Advising on Vendor Risk
A virtual or fractional CISO may reference ISO/IEC 27018 when guiding a client through cloud vendor selection, third-party risk assessment, or governance around personal data. In such engagements the vCISO typically advises and directs on how to interpret provider claims and set requirements; the standard supports readiness discussions but does not by itself confirm compliance with any specific privacy regulation, and hands-on implementation usually sits with the provider or the client's internal teams.
Compliance and Privacy Teams
Teams responsible for privacy and regulatory alignment can use ISO/IEC 27018 as one input when assessing how personal data is handled in public cloud environments. Because it is a code of practice that supplements the broader ISO/IEC 27000-series rather than a substitute for legal compliance, these teams should map its guidance to their applicable regulatory obligations rather than assuming the standard alone satisfies them.

Inside ISO/IEC 27018

Code of Practice for PII Protection in Public Clouds
ISO/IEC 27018 is a code of practice that provides guidance on protecting personally identifiable information (PII) processed by public cloud service providers acting as PII processors. It supplements the broader ISO/IEC 27002 control guidance rather than functioning as a standalone certifiable management system.
Alignment with the ISO/IEC 27001 Family
The standard is designed to be used alongside ISO/IEC 27001 and ISO/IEC 27002, extending their controls with cloud-specific considerations for PII. Organizations typically implement it within the context of an existing information security management system rather than in isolation.
Processor-Focused Controls
It addresses obligations relevant to cloud providers in a PII processor role, such as processing PII according to customer instructions, transparency about subcontractors and data handling, and support for the cloud customer's own compliance responsibilities. The specific control set and how it maps to a given engagement may vary by provider and interpretation.
Privacy-Oriented Augmentation of Security Controls
Where general security controls exist, ISO/IEC 27018 adds privacy-specific expectations, addressing areas such as consent, purpose limitation, data return or deletion, and disclosure practices. It focuses on the handling of PII rather than on general operational security tooling.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27018.

Is ISO/IEC 27018 a standalone certification that proves my organization protects personal data in the cloud?
Not exactly. ISO/IEC 27018 is a code of practice that extends ISO/IEC 27001 and ISO/IEC 27002 controls with guidance for protecting personally identifiable information (PII) in public cloud environments. It is typically implemented in conjunction with an ISO/IEC 27001 information security management system rather than as an independent standard. Organizations often demonstrate conformance through an ISO/IEC 27001 certification whose scope references ISO/IEC 27018 controls, so treating it as a wholly separate certificate can misrepresent how it is applied. A virtual CISO can help clarify how the standard fits within your broader management system, but conformance depends on your implementation and the scope you define.
Does adopting ISO/IEC 27018 make my organization compliant with privacy regulations like GDPR or HIPAA?
No. ISO/IEC 27018 provides controls and guidance aligned to privacy principles for cloud PII processing, and it may support readiness toward regulatory obligations, but it is not itself a legal compliance mechanism. Regulations such as GDPR or HIPAA impose their own requirements that a single standard does not automatically satisfy. Implementing ISO/IEC 27018 can help structure controls in a way that eases certain compliance efforts, but conformance and legal compliance are distinct. Accountability for meeting regulatory obligations remains with your organization and its officers, not with a standard or with a vCISO advising on it.
Where should ISO/IEC 27018 sit relative to an existing ISO/IEC 27001 program?
ISO/IEC 27018 is generally implemented as an extension layered on top of an existing or planned ISO/IEC 27001 management system, adding cloud- and PII-specific guidance to the baseline controls. In many engagements, a virtual CISO would recommend establishing or maturing the ISO/IEC 27001 framework first, then mapping the additional 27018 controls into the same governance, risk, and control structure. This avoids duplicating processes and keeps the standard integrated rather than treated as a parallel program. The practical sequencing may vary based on your organizational maturity and current certification status.
How does a virtual CISO typically support an ISO/IEC 27018 initiative, and what falls outside that role?
A virtual CISO commonly provides strategy, governance oversight, gap assessment against the standard, control mapping, and executive-level guidance to prepare your organization for conformance. Hands-on operational work, such as configuring cloud tooling, administering controls day to day, or executing internal audits, is often outside the typical vCISO scope unless it is explicitly contracted. The vCISO advises and directs, but implementation ownership and the underlying decisions usually remain with your internal teams and cloud providers. Clarifying scope boundaries at the outset helps set realistic expectations.
What organizational factors influence how effectively ISO/IEC 27018 can be implemented?
Effectiveness often depends on organizational maturity, the state of any existing ISO/IEC 27001 management system, access to relevant stakeholders, and the cooperation of cloud service providers whose environments process the PII. Because ISO/IEC 27018 addresses public cloud PII processing, clear contractual and technical visibility into provider responsibilities is typically important. In many engagements, gaps arise where roles between the organization and its cloud providers are not clearly delineated. A virtual CISO can help identify these dependencies, but outcomes vary with client cooperation and defined scope.
Can implementing ISO/IEC 27018 guarantee that our cloud-stored personal data will not be breached?
No standard can guarantee breach prevention, and ISO/IEC 27018 should not be presented that way. It offers a structured set of controls and guidance intended to reduce risk and improve the handling of PII in cloud environments, but residual risk remains regardless of conformance. A virtual CISO can help you use the standard to strengthen governance and control coverage, yet accountability for security decisions and outcomes stays with your organization. Framing the standard as risk reduction rather than a guarantee reflects how experienced practitioners describe its value.

Common misconceptions

ISO/IEC 27018 certification proves an organization is fully compliant with privacy regulations such as GDPR or HIPAA.
ISO/IEC 27018 is a code of practice that can support privacy readiness and demonstrate certain processor safeguards, but conformance is not equivalent to legal compliance with any specific regulation. Accountability for regulatory compliance typically remains with the client organization and its officers, and mapping the standard to a particular law requires separate legal and compliance analysis.
A virtual CISO engagement that references ISO/IEC 27018 guarantees the client will achieve or maintain certification.
A vCISO typically supports readiness, governance, and program development related to the standard but does not guarantee certification outcomes. Certification depends on an independent assessment, organizational maturity, client cooperation, and the scope agreed in the engagement, and results may vary by provider and auditor.
ISO/IEC 27018 applies to any organization handling personal data.
The standard is specifically oriented toward public cloud service providers acting as PII processors and is used in conjunction with the ISO/IEC 27001 and 27002 framework. Its applicability and relevance depend on an organization's role in the data processing chain and its cloud service model.

Best practices

Confirm whether the organization is acting as a PII processor in a public cloud context before treating ISO/IEC 27018 as the relevant reference, since its focus is on that specific role.
Implement ISO/IEC 27018 in conjunction with an ISO/IEC 27001 and 27002 program rather than as a standalone effort, so the privacy-specific guidance sits within an established security management structure.
Distinguish clearly between supporting readiness for the standard and asserting certification or regulatory compliance, and document what each engagement scope does and does not cover.
Define engagement scope explicitly, clarifying that a virtual CISO advises on governance, program development, and privacy control alignment while operational tasks and independent assessments are typically handled separately unless contracted.
Keep accountability with the client organization and its officers, using the vCISO role to advise and direct on PII protection controls rather than to assume legal or regulatory liability.
Assess organizational maturity, stakeholder access, and client cooperation early, since the value of applying ISO/IEC 27018 guidance often depends on these factors and on a well-defined scope.