Start a free trial
Menu

ISO/IEC 27018

ISO 27018 personal data in the cloud

Organisations processing personal data in the cloud, and the suppliers who serve them.

ISO 27018 extends ISO 27001 to the protection of personal data in public clouds. ComplyTrain gives you the framework to manage and evidence those controls.

What it is

What ISO 27018 is

ISO 27018 is a code of practice for protecting personally identifiable information (PII) in public cloud computing. It takes the general controls of ISO 27001 and ISO 27002 and adds a set specific to a cloud provider that processes personal data on behalf of its customers - covering consent, transparency, data handling, and the rights of the people whose data is held.

It is not a stand-alone management system. ISO 27018 is applied within an ISO 27001 ISMS: the management system provides the structure and the risk discipline, and ISO 27018 supplies the cloud-and-privacy-specific controls that sit inside it.

Why ISO 27018 exists

When an organisation moves personal data into a public cloud, it hands day-to-day control of that data to a provider - but not the accountability for it. ISO 27018 exists to give both sides a common, auditable baseline for how that data is handled: what the provider may and may not do with it, how it is returned or deleted, and how the provider demonstrates it. For a European organisation it maps closely onto GDPR expectations for processors, which is why it so often travels alongside a data-protection programme.

Who needs ISO 27018

Two audiences: cloud providers that process personal data and want to prove they handle it responsibly, and the organisations that buy from them and must satisfy their own regulators that their processor is trustworthy. If you process personal data in the cloud - as a provider or as a customer relying on one - ISO 27018 is the control set that makes “we protect it” demonstrable.

How it fits with ISO 27001

ISO 27001 is the frame; ISO 27018 is a set of additional, privacy-focused controls hung on it. You run the ISMS - scope, risk assessment, Annex A controls, Statement of Applicability - and extend it with the ISO 27018 controls wherever you process cloud PII. In practice, organisations certify to ISO 27001 with ISO 27018 controls incorporated, rather than certifying to ISO 27018 on its own.

ISO 27018 and the GDPR

ISO 27018 is not the GDPR and does not make you compliant with it on its own - the regulation carries legal obligations a code of practice cannot discharge. But the two are closely aligned: transparency to data subjects, restrictions on secondary use, support for data-subject rights and control over sub-processors are common to both. Implementing ISO 27018 within your ISMS is a practical way to evidence the security-and-handling side of your GDPR processor obligations.

Put ISO/IEC 27018 on a system that keeps the evidence

Documents, training, risks and evidence in one place, with the trail an auditor asks for.

How we help

How ComplyTrain helps you meet it

ComplyTrain gives you one place to manage and evidence the additional controls ISO 27018 asks for, within the same ISMS you run for ISO 27001:

  • The PII-handling policies and procedures under version control - Document Control
  • The ISO 27018 controls captured and traced to evidence - Requirements Management
  • Cloud and sub-processor risk assessed and recorded - Risk Management and Vendor Management
  • Records of training on data-handling obligations - Training Management

ComplyTrain is not itself ISO 27018 certified, and does not need to be: it is the system you build and run your own ISO 27018 program in. The certificate is yours to earn - ComplyTrain is where the evidence for it lives.

Request access to this standard

Tell us how you need to work with ISO/IEC 27018 and what you need from it. We will come back to you about what ComplyTrain can do.

Questions

Do we need ISO 27001 before ISO 27018?

In practice, yes. ISO 27018 is a set of cloud-and-PII-specific controls applied within an ISO 27001 information security management system. ComplyTrain lets you manage both in one place, tracing the additional ISO 27018 controls alongside your Annex A controls.

Can an organisation be certified to ISO 27018?

ISO 27018 is normally certified as part of an ISO 27001 certification rather than on its own - the ISO 27018 controls are incorporated into the ISMS and its Statement of Applicability, and the certification body audits them alongside the Annex A controls. Providers often state that their ISO 27001 certificate includes the ISO 27018 code of practice.

Is ISO 27018 the same as GDPR compliance?

No. The GDPR is law and carries obligations - lawful basis, data-subject rights, breach notification - that a code of practice cannot satisfy by itself. ISO 27018 addresses the security and handling of personal data in the cloud, which is a large part of a processor’s GDPR duties, so the two are complementary: ISO 27018 helps you evidence the security side, not replace the legal programme.

Implementation

How to adopt ISO 27018 - within your ISMS

ISO 27018 is adopted inside an ISO 27001 system, not alongside it. The additional work is focused.

  1. Map your cloud PII

    Identify where personal data is processed in the cloud, for whom, and under what agreements - the scope the ISO 27018 controls apply to.

  2. Extend the Statement of Applicability

    Add the ISO 27018 controls to your ISO 27001 Statement of Applicability - consent, transparency, data return and deletion, sub-processor control - and assign owners.

  3. Evidence and audit

    Operate the controls, keep the records that prove them, and include ISO 27018 in your internal audit and the certification body’s audit of the ISMS.

If you need to get there and have no quality function

A standard usually arrives as a contract condition rather than a project anyone planned for, and often at a company with no quality manager. Software is half the answer. Skylen's consultants are the other half, and because they build on ComplyTrain from day one you keep a live system your team owns rather than a binder and a departed consultant.

  • Gap assessment

    A clause-by-clause read of where you stand against the standard your contract cites, turned into a prioritised plan you could act on with us or alone.

    What an assessment covers
  • Guided implementation

    Our consultants build the system with your team - procedures, document control, the records you need to keep and the review cadence - and prepare you for the certification audit.

    How an engagement works
  • Full-service quality function

    We run and maintain the quality system for you, so a small team can reach and hold a standard without hiring a quality manager.

    What full-service means

Manage your ISO 27018 compliance in one system

See how ComplyTrain maps to your framework on a 30-minute demo, walked through on your own processes. Or start a trial and we will set up a workspace to match what you are working on.

What ComplyTrain does

One system for the whole compliance programme. Start with the module you need most.

  • Forms & Follow-up

    Collect information the same way every time, and decide in advance what happens next.

  • Controls & Assurance

    Know whether your controls are operating, not just whether a policy says they exist.

  • Project Planner

    Turn the compliance work you already know about into a plan with owners, dependencies and dates.

  • Product Compliance

    Know what you can offer, and hold the evidence behind every configuration you offer it in.

  • Reporting & Analytics

    Eight built-in reports across every module, scheduled, delivered, and filed where the evidence lives.

  • Media Monitoring

    The sector news that matters to your organisation - read and rated by AI, and delivered as a scheduled digest in your own language.

  • Grants & Tenders

    AI reads the tender pack and pulls out the requirements, deadlines and rules - then helps you draft the response from your own approved content, with you reviewing every step.

  • Stakeholder/Vendor Management

    One current register of the suppliers and partners you depend on - each risk-assessed, re-assessing itself on schedule, and wired straight into your risk register.

  • Requirements Management

    See every requirement you face - across every standard, plus your own contracts and policies - traced to the documents, evidence and processes that satisfy it.

  • Risk Management

    Identify, score, treat and review your risks in one place - with AI to help anyone run a proper assessment, and a defensible trail behind every decision.

  • Training Management

    Assign training, prove it was understood, and hold the competence records an auditor asks for.

  • Document Control

    Draft compliance documents with AI, keep every version under control, and export them beautifully branded - all in one place.

  • Quality Management

    Audits, corrective actions, processes and approvals in one quality system, organised around ISO 9001.

Latest from ComplyTrain

Other standards in Information security management (ISO/IEC 27000 family)

Compliance work does not have to live in documents and spreadsheets

See ComplyTrain on your own processes in a 30-minute demo, with your quality or compliance lead.