Home  /  Certifications  /  ISO/IEC 27018
Cybersecurity & IT

ISO/IEC 27018 — Cloud Privacy

A code of practice for protecting personally identifiable information (PII) processed in public cloud services, extending ISO 27001.

What It Is

Protecting personal data in the cloud

ISO/IEC 27018 provides guidance for cloud service providers acting as PII processors, covering consent, transparency, data minimization, and breach notification for personal data handled in the cloud.

It gives customers assurance that their data is handled with appropriate privacy safeguards when hosted with a certified provider.

Quick Facts
Category
Cloud Privacy
Based on
ISO/IEC 27001
Certificate validity
3 years
Surveillance visits
Annual
Who Needs It

Is ISO/IEC 27018 right for you?

Typical Fit

Cloud service providers processing personal data on behalf of customers, particularly in regulated or privacy-sensitive sectors.

Key Benefits

What this gives you

Strengthens your security posture

Structured controls reduce exposure to common attack paths.

Builds customer & partner trust

A credential that speeds up vendor security reviews.

Supports regulatory compliance

Maps cleanly onto requirements in multiple jurisdictions.

Reduces incident risk

Proactive controls lower the likelihood and impact of incidents.

Clear incident response readiness

Documented processes for when something does go wrong.

A differentiator in tenders

Increasingly a baseline requirement in enterprise procurement.

Getting Started

How the process works

The same straightforward path applies across every standard and service we support.

1

Gap review & scoping

2

Build required documentation

3

Assessment / submission

4

Certificate / clearance issued

See the Full Certification Process

Ready to start your ISO/IEC 27018 journey?

Tell us a bit about your organization and we'll put together a straightforward, competitive quote.