Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
ISO 27018

ISO 27018: personal data in your cloud, protected on the record

Add the ISO/IEC 27018 controls for protecting personally identifiable information in public clouds to your ISO 27001 ISMS, with the processor commitments documented and the technical controls checked in your cloud accounts.

What is ISO 27018?

ISO/IEC 27018 is the international code of practice for protecting personally identifiable information in public cloud computing services, written for cloud providers that act as PII processors for their customers. It builds on ISO/IEC 27002: for each relevant control it adds guidance specific to personal data in the cloud, and it adds controls of its own drawn from the privacy principles of ISO/IEC 29100. Those cover processing only on the customer's documented instructions, not using customer data for marketing or advertising without explicit consent, giving customers the means to honor their users' rights, transparency about where data is stored, which sub-processors handle it and when it is disclosed to authorities, notifying customers of breaches, and returning or securely deleting data when the service ends. Like ISO 27017 it is not a management system standard and is not certified on its own: it is audited as an extension of an ISO 27001 certificate, with its controls added to the Statement of Applicability. Buyers in Europe and Asia-Pacific read it as the cloud-privacy counterpart to ISO 27701.

In one paragraph

ISO/IEC 27018 is the international code of practice for protecting personally identifiable information in public clouds, written for cloud providers acting as PII processors. It takes the ISO/IEC 27002 controls, adds cloud-privacy guidance for each, and adds its own controls on consent and purpose, customer control of their data, transparency about sub-processors and data location, breach notification and secure deletion. It is certified as an extension of an ISO 27001 certificate, usually alongside ISO 27017.

Who it's for

SaaS and cloud providers that process personal data for their customers and are asked, by European and Asia-Pacific buyers in particular, how that data is protected and governed in the cloud.

With Viglyn

How Viglyn runs ISO 27018

  • The 27018 controls added to your ISO 27001 Statement of Applicability, with the processor commitments (instructions, purpose, sub-processors, location, deletion) written down as controlled documents
  • Technical controls checked automatically in your cloud accounts: encryption, access to personal data stores, logging, data location and retention
  • The sub-processor list and the customer notification procedures kept current in the vendor module and the evidence base
  • Evidence shared with ISO 27701 and GDPR, so the privacy work is done once
  • The extension audited alongside your ISO 27001 Stage 1 and Stage 2 inside Viglyn, with scoped auditor access
Straight answers

The ISO 27018 questions that decide it

ISO 27018 or ISO 27701?

ISO 27018 is a code of practice for processors in public clouds, certified as an extension of ISO 27001; ISO 27701 is a full privacy management system with controller and processor controls. Cloud providers often hold 27018 first and grow into 27701; Viglyn runs both on the same evidence.

How long does ISO 27018 take?

Weeks on top of an existing ISO 27001 system, because most of the controls are technical and can be checked in your cloud accounts, and the rest are commitments you write down once. Without ISO 27001 the ISMS comes first, and Viglyn runs both together.

How much does ISO 27018 cost with Viglyn?

ISO 27018 counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. The certification body's fee for the extended audit is separate and paid by you directly; we take no commission.

FAQ

More ISO 27018 questions

Does ISO 27018 cover GDPR?
It covers the processor's side of it well: instructions, sub-processors, transparency, breach support and deletion map closely to GDPR Article 28 and Article 32. It is not a GDPR certification, and controller obligations sit outside it; Viglyn tracks those as evidence alongside.
Can we certify ISO 27018 without ISO 27001?
No. It is a code of practice, so it is certified as an extension of an ISO 27001 certificate. If you do not hold ISO 27001 yet, Viglyn runs the ISMS and the extension from one evidence base and the cloud-privacy controls join the Statement of Applicability from the start.
What is the difference from ISO 27017?
ISO 27017 covers cloud security controls for providers and customers; ISO 27018 covers the protection of personal data in public clouds, for providers acting as processors. Most cloud providers hold both as extensions of ISO 27001, and Viglyn maps both on the same evidence.

See ISO 27018 run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.