What it is
What ISO 27018 is
ISO 27018 is a code of practice for protecting personally identifiable information (PII) in public cloud computing. It takes the general controls of ISO 27001 and ISO 27002 and adds a set specific to a cloud provider that processes personal data on behalf of its customers - covering consent, transparency, data handling, and the rights of the people whose data is held.
It is not a stand-alone management system. ISO 27018 is applied within an ISO 27001 ISMS: the management system provides the structure and the risk discipline, and ISO 27018 supplies the cloud-and-privacy-specific controls that sit inside it.
Why ISO 27018 exists
When an organisation moves personal data into a public cloud, it hands day-to-day control of that data to a provider - but not the accountability for it. ISO 27018 exists to give both sides a common, auditable baseline for how that data is handled: what the provider may and may not do with it, how it is returned or deleted, and how the provider demonstrates it. For a European organisation it maps closely onto GDPR expectations for processors, which is why it so often travels alongside a data-protection programme.
Who needs ISO 27018
Two audiences: cloud providers that process personal data and want to prove they handle it responsibly, and the organisations that buy from them and must satisfy their own regulators that their processor is trustworthy. If you process personal data in the cloud - as a provider or as a customer relying on one - ISO 27018 is the control set that makes “we protect it” demonstrable.
How it fits with ISO 27001
ISO 27001 is the frame; ISO 27018 is a set of additional, privacy-focused controls hung on it. You run the ISMS - scope, risk assessment, Annex A controls, Statement of Applicability - and extend it with the ISO 27018 controls wherever you process cloud PII. In practice, organisations certify to ISO 27001 with ISO 27018 controls incorporated, rather than certifying to ISO 27018 on its own.
ISO 27018 and the GDPR
ISO 27018 is not the GDPR and does not make you compliant with it on its own - the regulation carries legal obligations a code of practice cannot discharge. But the two are closely aligned: transparency to data subjects, restrictions on secondary use, support for data-subject rights and control over sub-processors are common to both. Implementing ISO 27018 within your ISMS is a practical way to evidence the security-and-handling side of your GDPR processor obligations.