Privacy

ISO/IEC 27018

Protection of PII in Public Clouds

Formal standard Global ISO/IEC JTC 1/SC 27 Since 2014

A code of practice for public cloud providers acting as processors of personally identifiable information: consent and choice, purpose limitation, disclosure to third parties, return and deletion, and transparency about sub-processors.

Every major cloud provider certifies against it, so it is more often something you inherit from a vendor than something you implement, but it is the right question to ask of any processor in the chain.

At a glance

Category
Privacy
Jurisdiction
Global
Governance
ISO/IEC JTC 1/SC 27
Status
ISO/IEC 27018:2019
First released
2014

Links

Related frameworks

Other entries under Privacy.

See ISO/IEC 27018 in context

Open the interactive Data Landscape for Regulation to compare ISO/IEC 27018 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.