Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
ISO 27018
ISO/IEC 27018 providing controls for protecting personally identifiable information in public cloud environments.
ISO/IEC 27018 is an international standard published jointly by ISO and IEC that sets out controls and guidance for protecting personally identifiable information (PII) in public cloud environments where the provider acts as a PII processor. Building on ISO/IEC 27002 and aligned with the privacy principles of ISO/IEC 29100, it addresses cloud-specific privacy concerns such as processing only on customer instructions, transparency about sub-processors and data locations, and support for the rights of the individuals whose data is processed.
The standard is a code of practice and is generally adopted alongside an ISO/IEC 27001 information security management system rather than certified in isolation. The current edition is ISO/IEC 27018:2025, which supersedes the 2014 and 2019 editions.
Ensure PII in the public cloud is processed only in line with the customer's documented instructions as the PII controller.
Provide clear information on sub-processors, data locations, and any disclosure of PII, including to law enforcement where permitted.
Enable the customer to meet obligations to individuals, such as access, correction and erasure of their data.
Provide for secure handling, return or deletion of PII at the end of the service relationship.
Read more
Anove scans your stack against ISO 27018 and 260+ other frameworks in minutes.