ISO/IEC 27018
ISO/IEC 27018 is an international standard that offers guidance for protecting personal information stored or processed in public cloud services. It focuses specifically on situations where a cloud service provider handles personally identifiable information (PII) on behalf of its customers. The standard sets out control objectives, controls, and guidelines intended to help providers safeguard that information.
ISO/IEC 27018 is a code of practice that establishes commonly accepted control objectives, controls, and implementation guidelines for protecting personally identifiable information (PII) in public cloud computing environments, applied to cloud service providers acting as PII processors. It functions as a sector-specific supplement building on the broader ISO/IEC 27000-series information security framework rather than as a standalone certification of an organization's entire security program. Among its provisions, it addresses requirements such as policies enabling the return, transfer, and secure disposal of personal information within a reasonable period. Practitioners should note that alignment with ISO/IEC 27018 supports readiness and can demonstrate PII-protection practices, but the extent of applicability depends on the cloud provider's role, scope of engagement, and the specific controls implemented; the standard has been issued in multiple editions (including 2014, 2019, and 2025), which may differ in detail.
Why it matters
Organizations increasingly rely on public cloud services to store and process personal information, but doing so introduces a shared-responsibility challenge: the customer remains accountable for its data even though a cloud service provider handles it. ISO/IEC 27018 matters because it gives buyers and providers a common reference point for what protecting personally identifiable information (PII) in a public cloud should look like, translating the broad principles of the ISO/IEC 27000-series into cloud-specific control objectives and guidelines. For a security leader evaluating vendors, alignment with the standard can be a useful signal that a provider has considered PII-specific concerns rather than only general information security.
The practical value of ISO/IEC 27018 lies in its focus on the provider acting as a PII processor. It addresses concerns that matter to customers who entrust personal data to a third party, such as having policies that enable the return, transfer, and secure disposal of personal information within a reasonable period. These provisions help customers reason about what happens to their data during and after an engagement, which is often a gap in less structured vendor relationships. It is important to note, however, that the standard is a code of practice and supports readiness and demonstration of PII-protection practices; it is not a guarantee that any given deployment is compliant with a specific privacy law or free from risk.
A common expert correction is to avoid treating ISO/IEC 27018 as a standalone certification of an organization's entire security program. It is a sector-specific supplement that builds on the wider ISO/IEC 27000-series framework, and its applicability depends on the provider's role, the scope of the engagement, and which controls are actually implemented. The standard has also been issued in multiple editions, including 2014, 2019, and 2025, which may differ in detail, so referencing a specific edition matters when assessing what a provider claims to follow.
Who it's relevant to
Inside ISO/IEC 27018
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27018.