ISO 27018 succeeded by being narrow: one deployment model (public cloud), one role (processor), one problem (the temptation to treat customer PII as an asset). Its annex reads like a list of things cloud customers feared in 2014, advertising use, silent subcontracting, mystery jurisdictions, and turning those fears into auditable controls is why it colonized procurement templates so quickly. A decade on, 27701 offers the fuller management system, but 27018’s cloud-specific granularity and its entrenchment in contract language keep it load-bearing. For providers the play is composition, one ISMS carrying both references; for customers, the discipline is reading scope statements and DPAs instead of trust-page badges.
| Standard | ISO/IEC 27018:2019, code of practice (not standalone certifiable) |
|---|---|
| Role | Public cloud provider as PII processor |
| Core annex duties | Instructions-only, no ad use, subprocessor transparency, customer assistance, breach notice |
| Evidence form | 27018 within a 27001 certificate scope + DPA mirroring |
| GDPR fit | Maps closely to Article 28 processor duties |
| Source | ISO/IEC 27018 |
Making the claim real
Put the annex in the SoA. Guidance becomes auditable when the risk treatment selects it; the 27701 processor controls compose cleanly on top.
Mirror the annex in the DPA. Contract terms, not trust-page prose, make the commitments enforceable.
Publish the subprocessor machinery. Lists, countries, and change notifications are the transparency controls customers test first.
For buyers: assess systematically. The 27018 vendor assessment guide turns the five checks into a repeatable diligence step.
Cloud commitments start with knowing your own data flows: baseline what your site sends to cloud services with a free scan.