Privacy
ISO/IEC 27018
Protection of PII in Public Clouds
A code of practice for public cloud providers acting as processors of personally identifiable information: consent and choice, purpose limitation, disclosure to third parties, return and deletion, and transparency about sub-processors.
Every major cloud provider certifies against it, so it is more often something you inherit from a vendor than something you implement, but it is the right question to ask of any processor in the chain.
At a glance
- Category
- Privacy
- Jurisdiction
- Global
- Governance
- ISO/IEC JTC 1/SC 27
- Status
- ISO/IEC 27018:2019
- First released
- 2014
Links
Related frameworks
Other entries under Privacy.
- ISO/IEC 27701: Privacy Information Management System
- NIST Privacy Framework
- ISO/IEC 29100: Privacy Framework
See ISO/IEC 27018 in context
Open the interactive Data Landscape for Regulation to compare ISO/IEC 27018 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.