Office hours · 09:00–18:00 IST info@abscerts.com
+91 96257 76771 +91 97925 86202 EN · 40+ countries

ISO Certifications

ISO 27018:2019 — PII Protection in Public Clouds

Certification against the controls for protecting personally identifiable information in public clouds — extending ISO 27001 for cloud providers that process PII.

Book a consultation
ISO 27018 protection of PII in public clouds certification
10-14 weeks Typical timeline to certificate
ISO Governing body / standard owner
IAS/IAF Accredited & globally recognised
What this covers
ISO 27018Cloud PrivacyPIIISO 27001

What ISO 27018 covers

ISO 27018 is a code of practice for protecting personally identifiable information (PII) in public clouds. It extends ISO 27001 and ISO 27002 with controls aimed at public cloud service providers that process PII on behalf of their customers — setting expectations around how that personal data is handled, disclosed and protected.

It is most relevant to public cloud providers, and to the customers who entrust them with personal data and want assurance it is properly protected.

What certification involves

Because ISO 27018 builds on ISO 27001, certification assesses the PII-protection controls on top of an information security management system, typically including:

  • Consent and choice over how PII is processed
  • Purpose limitation and restrictions on use of PII
  • Transparency about sub-processors and data locations
  • Controls over disclosure, return and deletion of PII

It sits within the IT-security part of the ISO Certifications portfolio and is frequently pursued alongside ISO 27017 for general cloud security.

Timeline & process

For an organisation that already holds ISO 27001, adding ISO 27018 typically takes around 10–14 weeks; implementing both together takes longer. Each engagement begins with a fixed-price scoping call and a proposal within 24 hours.

Common questions

Do we need ISO 27001 before ISO 27018?

Yes. ISO 27018 extends an ISO 27001 information security management system with controls specific to protecting PII in public clouds. ISO 27001 is the foundation; ISO 27018 adds the cloud-PII controls, and the two are often certified together.

How does ISO 27018 relate to ISO 27701?

ISO 27018 focuses specifically on PII handled by public cloud providers. ISO 27701 is the broader Privacy Information Management System extending ISO 27001 to privacy across an organisation. A cloud provider may hold both.

More services

Related certifications

agile-transformation / 01 Agile coaching with a delivery team

Agile Coaching

Experienced coaches working alongside your teams and leaders to adopt agile ways of working — and to sustain them across the organisation.

Agile CoachingAgile TransformationScrumKanban
Get a quote
cmmi / 02 CMMi for Development process maturity improvement

CMMi for Development (CMMi-DEV)

Process maturity improvement for organisations that design and build products, software and systems — benchmarked against the CMMI Development view.

CMMiCMMi-DEVProcess ImprovementSoftware Development
Get a quote
industry-food-certifications / 03 HACCP food safety hazard analysis certification

HACCP Certification

Certification of a HACCP food safety system — the internationally recognised approach to identifying and controlling hazards across the food chain.

HACCPFood SafetyHazard AnalysisIndustry & Food
Get a quote

Get started

Ready to get certified?

Get a free, fixed-price quote within one business day. No obligation, no sales pressure, no follow-up spam — just a clear path to certification.

Book a 30-min consultation
24-hour response time Fixed price, multi-currency IAS / IAF accredited 40+ countries served

Before you go — let us help

Drop your details and we'll send a free certification roadmap tailored to your business. No spam, ever.

By submitting, you agree to ABS's privacy policy. We never share your details.