What is ISO/IEC 27018:2019 — the Cloud PII Privacy Standard?
Code of Practice for PII in Public Cloud
ISO/IEC 27018:2019 is the international standard providing a code of practice for protecting Personally Identifiable Information (PII) in public cloud computing environments — specifically targeting cloud service providers acting as PII processors for their customers' personal data.
Extension to ISO 27001 ISMS
ISO 27018 is not a standalone standard — it is an extension to ISO 27001, adding cloud-specific PII protection controls (Annex A) to the ISMS framework. Certified through a combined ISO 27001 + ISO 27018 audit by a NABCB-accredited certification body — one audit, two certifications.
DPDPA 2023 & GDPR Enabler
For Indian cloud companies, ISO 27018:2019 simultaneously provides DPDPA 2023 compliance evidence (Section 8(5) security safeguards, Section 12 right to erasure, data processor obligations) and GDPR Article 28 "sufficient guarantees" for EU/UK clients — one certification, multiple compliance outcomes.
| Parameter | ISO/IEC 27018:2019 Facts |
|---|---|
| Full title | ISO/IEC 27018:2019 — Information technology — Security techniques — Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors |
| Published by | ISO/IEC — Joint Technical Committee JTC 1, Subcommittee SC 27 |
| First edition | ISO/IEC 27018:2014 — updated to ISO/IEC 27018:2019 |
| Scope | Public cloud computing environments — cloud service providers acting as PII processors |
| Primary applicability | SaaS companies, cloud hosting providers, BPOs, managed service providers processing customer PII in public cloud |
| Relationship to ISO 27001 | Extension to ISO 27001 ISMS — adds Annex A cloud PII-specific controls. Not a standalone certification. |
| Annex A controls | ~25 additional controls covering consent, purpose limitation, transparency, data subject rights, sub-processors, deletion, security, and cross-border transfers |
| Key privacy principles | Consent, Purpose Limitation, Data Minimisation, Accuracy, Transparency, Data Subject Rights, Retention & Deletion, Sub-processor Management, Cross-border Transfer Controls |
| Certification validity | 3 years — annual surveillance audits (combined with ISO 27001 surveillance) |
| Indian regulatory alignment | DPDPA 2023 (Sections 7, 8, 12, 16), IT Act Section 43A, CERT-In cloud security requirements, RBI/IRDAI data localisation |
| International alignment | GDPR Article 28 (data processor requirements), GDPR Article 32 (security), APEC CBPR, OECD Privacy Principles |
| Related standards | ISO 27001:2022 (ISMS), ISO 27701:2019 (PIMS extension), ISO 27017:2015 (cloud security controls), ISO 27002:2022 (implementation guidance) |