27018
ISO/IEC 27018:2019 · Protection of PII in public clouds

ISO/IEC 27018Cloud privacy

Code of practice for protecting personally identifiable information processed by public cloud providers — evidence for privacy-conscious customers.

SCHEME CARD · INFORMATION SECURITY
ISO/IEC 27018Protection of PII in public clouds · 2019
Who it's for
Cloud providers, saas companies and more
Audit model
Stage 1 + Stage 2 + surveillance
Certificate validity
3 years
Typical timeline
4–6 weeks (with 27001)
Listed in public registerCombines with ISO/IEC 27001, ISO/IEC 27017
3 yrscertificate validity, with annual surveillance audits
2audit stages — documentation review, then on-site assessment
4–6weeks from application to certificate, typical timeline
1business day to a fixed offer after your application
Why companies certify

Who needs ISO/IEC 27018— and when

ISO/IEC 27018 extends ISO/IEC 27001 with PII-specific controls: purpose limitation, customer consent for use of data, disclosure notifications, return and deletion, and staff confidentiality agreements.

INDUSTRIES WE CERTIFY TO ISO/IEC 27018

Cloud providersSaaS companiesOutsourcing & BPOHealthcare ITFintech
Not sure whether ISO/IEC 27018 fits? Our auditors run a short diagnostic review and suggest the scheme — or a combination of two or three — that answers your customers' requirements.
Inside the standard

What the audit examines

01Purpose limitation

PII processed only per customer instructions.

02Disclosure control

Notification of law-enforcement requests where permitted.

03Data return & deletion

Secure erasure at contract end.

04Sub-processors

Transparency of processors in the chain.

05Confidentiality

Staff agreements and training.

What the audit covers

Requirements,clause by clause

ISO/IEC 27018 is audited against these requirement areas. Open each one to see what auditors look for in your company.

Clause 4Context of the organisation+
Interested parties, internal and external issues, and how the scope of the system is defined.
Clause 5Leadership+
Top management commitment, a policy that fits the business, roles and responsibilities.
Clause 6Planning+
Risks and opportunities identified and addressed; measurable objectives with plans to reach them.
Clause 7Support+
Resources, competence and awareness, communication, control of documented information.
Clause 8Operation+
How processes are planned, controlled and delivered day to day.
Clauses 9–10Evaluation & improvement+
Monitoring, internal audits, management review — and how nonconformities become corrective actions.
Benefits

What ISO/IEC 27018certification gives you

  • Privacy assurance for cloud customers
  • Support for GDPR processor obligations
  • Documented PII handling practices
  • Certified together with ISO/IEC 27001
  • Competitive advantage in public-sector and healthcare deals
Integrated audit

Hold more than one standard? One audit.

ISO/IEC 27018 shares its structure with ISO/IEC 27001, ISO/IEC 27017. We audit them together — one team, one visit, one report.

−25%audit days on average
1lead auditor for all standards
The path to certificate

Five steps from application to ISO/IEC 27018

Scroll the steps — the bar shows where you are in the process. Every step has a named coordinator and a fixed timeline.

STEP 1 / 5 · Application & offer
STEP 11 business day
Application & offer

You send a short application; a coordinator sizes the audit and sends a fixed offer.

→ Offer with audit plan
STEP 21–2 days
Stage 1 audit

Documentation review and readiness check — remote or on site. Gaps are listed, not penalised.

→ Readiness report
STEP 3By calculation
Stage 2 audit

On-site assessment of implementation and effectiveness with a team that knows your sector.

→ Audit report
STEP 45–10 days
Decision & certificate

Independent certification decision; the certificate is issued and entered into the public register.

→ ISO/IEC 27018 certificate
STEP 5Annual
Surveillance & renewal

Annual surveillance keeps the certificate in force; re-certification in year three.

→ Certificate maintained
Readiness check

Are you readyfor Stage 1?

Tick what you already have. You do not need a perfect system to apply — you need a working one.

Your readiness
0%

Based on the items ticked on the left. Indicative — the Stage 1 audit gives the formal picture.

Apply for ISO/IEC 27018 →
FAQ · ISO/IEC 27018

Questions companiesask before certifying

Did not find yours? Call us — a coordinator answers within the same business day.

+38 (044) 332-30-76
How long is the certificate valid?+
Three years, maintained through annual surveillance audits and renewed by a re-certification audit in year three.
Can we combine it with other standards?+
Yes — integrated audits reduce total audit days and cost. Tell us which standards you hold and we size one combined audit.
How is the audit priced?+
Audit duration is calculated by international rules from headcount, sites and complexity, so quotations are comparable between certification bodies.
Related schemes

Often certifiedtogether

Get certifiedto ISO/IEC 27018

Send an application — we define scope and audit duration, and issue a fixed offer within one business day.

  • Auditors with experience in your industry
  • Fixed price — no surprises after Stage 1
  • Certificate listed in the public register
By sending the form you agree to the processing of the data for preparing a quotation.