ISO Certifications

ISO 27018:2025 — PII Protection in Public Clouds

Cloud privacy control implementation support — the controls for protecting personally identifiable information in public clouds, extending ISO 27001. ISO 27018 is guidance implemented alongside ISO 27001, not a standalone certification.

Book a consultation
ISO 27018 protection of PII in public clouds implementation
10-14 weeks Indicative timeline — varies with scope, size, sites and shifts
ISO Governing body / standard owner
Advisory Consulting, training & audit readiness
What this covers
ISO 27018Cloud PrivacyPIIISO 27001

What ISO 27018 covers

ISO 27018 is a code of practice for protecting personally identifiable information (PII) in public clouds. It extends ISO 27001 and ISO 27002 with controls aimed at public cloud service providers that process PII on behalf of their customers — setting expectations around how that personal data is handled, disclosed and protected.

It is most relevant to public cloud providers, and to the customers who entrust them with personal data and want assurance it is properly protected.

What implementation involves

ISO/IEC 27018 provides guidance for protecting personally identifiable information processed by public-cloud service providers. It is normally implemented as part of an ISO/IEC 27001-based information security and privacy framework and is not an independent management-system certification standard. We help you implement the PII-protection controls on top of an ISO 27001 information security management system, typically including:

  • Consent and choice over how PII is processed
  • Purpose limitation and restrictions on use of PII
  • Transparency about sub-processors and data locations
  • Controls over disclosure, return and deletion of PII

It sits within the IT-security part of the ISO Certifications portfolio and is frequently pursued alongside ISO 27017 for general cloud security.

Timeline & process

For an organisation that already holds ISO 27001, adding ISO 27018 typically takes around 10–14 weeks, depending on the scope and size of the services covered; implementing both together takes longer. Each engagement begins with a fixed-price scoping call and a proposal within 24 hours.

Common questions

Do we need ISO 27001 before ISO 27018?

Not to use it. ISO/IEC 27018 is a code of practice, so any public cloud provider processing personally identifiable information (PII) can apply its controls. If you want those controls independently assessed, yes: ISO 27018 is not certified on its own, so the controls are assessed within an ISO 27001 certification scope. That is why most organisations implement the two together.

How does ISO 27018 relate to ISO 27701?

ISO 27018 focuses specifically on PII handled by public cloud providers acting as processors. ISO/IEC 27701 is the broader privacy information management system standard, covering privacy across an organisation; since its 2025 edition it is a standalone standard that no longer requires ISO 27001. A cloud provider may apply ISO 27018 to its cloud services and certify its wider privacy programme to ISO 27701.

More services

Related services

ISO Certifications / 01 ISO 9001 quality management system documentation review

ISO 9001 — Quality Management

The world's most widely adopted standard for quality management systems.

ISO 9001QMSQuality Management
Get a quote
ISO Certifications / 02 ISO 27001 information security management implementation

ISO 27001 — Information Security Management

Globally recognised certification for information security management systems (ISMS).

ISO 27001ISMSInformation Security
Get a quote
ISO Certifications / 03 Industrial facility managing environmental impact under ISO 14001

ISO 14001 — Environmental Management

The international standard for environmental management systems and measurable sustainability.

ISO 14001EMSEnvironmental Management
Get a quote

Get started

Ready to get certified?

Get a free, fixed-price quote within one business day. No obligation, no sales pressure, no follow-up spam — just a clear path to certification.

Book a 30-min consultation
24-hour response time Fixed price, multi-currency Consulting & audit readiness Remote & on-site delivery
Call us