ISO 27018
ISO 27018 compliance software
Organisations processing personal data in the cloud, and the suppliers who serve them.
ISO 27018 extends ISO 27001 to the protection of personal data in public clouds. ComplyTrain gives you the framework to manage and evidence those controls.
ComplyTrain fully supports this standard
What ISO 27018 is
ISO 27018 is a code of practice for protecting personally identifiable information (PII) in public cloud computing. It takes the general controls of ISO 27001 and ISO 27002 and adds a set specific to a cloud provider that processes personal data on behalf of its customers - covering consent, transparency, data handling, and the rights of the people whose data is held.
It is not a stand-alone management system. ISO 27018 is applied within an ISO 27001 ISMS: the management system provides the structure and the risk discipline, and ISO 27018 supplies the cloud-and-privacy-specific controls that sit inside it.
Why ISO 27018 exists
When an organisation moves personal data into a public cloud, it hands day-to-day control of that data to a provider - but not the accountability for it. ISO 27018 exists to give both sides a common, auditable baseline for how that data is handled: what the provider may and may not do with it, how it is returned or deleted, and how the provider demonstrates it. For a European organisation it maps closely onto GDPR expectations for processors, which is why it so often travels alongside a data-protection programme.
Who needs ISO 27018
Two audiences: cloud providers that process personal data and want to prove they handle it responsibly, and the organisations that buy from them and must satisfy their own regulators that their processor is trustworthy. If you process personal data in the cloud - as a provider or as a customer relying on one - ISO 27018 is the control set that makes “we protect it” demonstrable.
How it fits with ISO 27001
ISO 27001 is the frame; ISO 27018 is a set of additional, privacy-focused controls hung on it. You run the ISMS - scope, risk assessment, Annex A controls, Statement of Applicability - and extend it with the ISO 27018 controls wherever you process cloud PII. In practice, organisations certify to ISO 27001 with ISO 27018 controls incorporated, rather than certifying to ISO 27018 on its own.
ISO 27018 and the GDPR
ISO 27018 is not the GDPR and does not make you compliant with it on its own - the regulation carries legal obligations a code of practice cannot discharge. But the two are closely aligned: transparency to data subjects, restrictions on secondary use, support for data-subject rights and control over sub-processors are common to both. Implementing ISO 27018 within your ISMS is a practical way to evidence the security-and-handling side of your GDPR processor obligations.
How ComplyTrain helps you meet it
ComplyTrain gives you one place to manage and evidence the additional controls ISO 27018 asks for, within the same ISMS you run for ISO 27001:
- The PII-handling policies and procedures under version control - Document Control
- The ISO 27018 controls captured and traced to evidence - Requirements Management
- Cloud and sub-processor risk assessed and recorded - Risk Management and Vendor Management
- Records of training on data-handling obligations - Training Management
ComplyTrain is not itself ISO 27018 certified, and does not need to be: it is the system you build and run your own ISO 27018 program in. The certificate is yours to earn - ComplyTrain is where the evidence for it lives.
Questions
Do we need ISO 27001 before ISO 27018?
In practice, yes. ISO 27018 is a set of cloud-and-PII-specific controls applied within an ISO 27001 information security management system. ComplyTrain lets you manage both in one place, tracing the additional ISO 27018 controls alongside your Annex A controls.
Can an organisation be certified to ISO 27018?
ISO 27018 is normally certified as part of an ISO 27001 certification rather than on its own - the ISO 27018 controls are incorporated into the ISMS and its Statement of Applicability, and the certification body audits them alongside the Annex A controls. Providers often state that their ISO 27001 certificate includes the ISO 27018 code of practice.
Is ISO 27018 the same as GDPR compliance?
No. The GDPR is law and carries obligations - lawful basis, data-subject rights, breach notification - that a code of practice cannot satisfy by itself. ISO 27018 addresses the security and handling of personal data in the cloud, which is a large part of a processor’s GDPR duties, so the two are complementary: ISO 27018 helps you evidence the security side, not replace the legal programme.
Implementation
How to adopt ISO 27018 - within your ISMS
ISO 27018 is adopted inside an ISO 27001 system, not alongside it. The additional work is focused.
Map your cloud PII
Identify where personal data is processed in the cloud, for whom, and under what agreements - the scope the ISO 27018 controls apply to.
Extend the Statement of Applicability
Add the ISO 27018 controls to your ISO 27001 Statement of Applicability - consent, transparency, data return and deletion, sub-processor control - and assign owners.
Evidence and audit
Operate the controls, keep the records that prove them, and include ISO 27018 in your internal audit and the certification body’s audit of the ISMS.
