ISO/IEC 27018 Protection of PII in Public Clouds

Sets out what a processor must do when handling personal data belonging to others in a public cloud. Applied on top of ISO/IEC 27001.

ITS own scheme

This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →

Who this is for

  • Companies processing client personal data in the cloud
  • SaaS providers handling end-user information
  • Companies with sub-processors or cross-border transfers

What certification gives you

  • Locks processing to the documented instructions of the customer

  • Requires sub-processors and processing locations to be disclosed in advance

  • Puts a defined notification deadline in place when a breach occurs