ISO/IEC 27018 Protection of PII in Public Clouds

Sets out what an organisation must do when it processes other people's personal information in a public cloud. Certified as an extension of ISO/IEC 27001.

ITS own scheme

This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →

What this certification proves

ISO/IEC 27018 is not about your own personal data. It is about personal data entrusted to you by someone else. Cloud and SaaS operators hold their clients' member records. That data does not belong to the operator — it belongs to the client, and ultimately to the individuals concerned.

So the standard compresses down to a single principle: use it only within the instructions you were given. Using entrusted personal data for your own advertising, or analysing it under the banner of «service improvement», or feeding it to marketing, requires the explicit consent of the client organisation. That is what separates this standard decisively from other security standards.

Around that sit three more duties: tell the client before sub-contracting, disclose which countries the data is processed in, and notify within a defined period when a breach occurs.

⚠️ This standard is not certified on its own. It is audited as an extension of ISO/IEC 27001.

Who this is for

  • Organisations processing client personal data in the cloud
  • SaaS providers handling end-user information
  • Organisations with sub-processing or cross-border transfers

🌱 How this relates to ESG

S Social

Maps onto the S (Social) pillar. Personal data is a matter of individual rights, which every major ESG framework classifies as social.

  • GRI 418 (Customer Privacy) — privacy breach complaints reported under Social
  • Korea's K-ESG guideline, S domain «information protection» — privacy framework and incident count
  • Processor obligations under Korea's Personal Information Protection Act — no use beyond purpose, restrictions on sub-processing, security measures. The content overlaps directly
  • GDPR processor obligations — the same duties European customers ask about during due diligence
  • The strongest answer when a client audits you — it is third-party confirmation that entrusted data is not used improperly

What certification gives you

How the requirements are structured

This is the overall shape of what the standard asks for. Working through it in this order is a sensible way to prepare.

ISO/IEC 27018Protection of PII in Public CloudsP · 조항 27001 4 – 6PlanScope the entrustedpersonal data and…D · 조항 27002 + Annex ADoOperate purposelimitation,…C · 조항 27001 9CheckReview accessrecords and…A · 조항 27001 10ActRemove causes ofbreaches and revise…
계획 → 실행 → 점검 → 개선이 한 번으로 끝나지 않고 계속 돕니다. 심사에서 보는 것도 «이 바퀴가 실제로 도는가» 입니다.
ClauseTitleIn plain terms
BasisISO/IEC 27001 + 27002An information security management system and the general control set underpin this. 27018 is not certified separately.
Annex A-1Consent and choiceUsing entrusted personal data for advertising or analysis requires the client's consent.
Annex A-2Purpose limitationNever use the data beyond the purpose the client instructed. The heart of the standard.
Annex A-3TransparencyDisclose sub-processors and processing countries in advance, and notify when they change.
Annex A-4Supporting individual rightsProvide the functions and cooperation the client needs to answer access and erasure requests.
Annex A-5Access and recordsRecord and retain who accessed personal data and when.
Annex A-6Storage and transmissionEncrypt at rest and in transit, and restrict removable media.
Annex A-7Breach notification and returnNotify the client within the defined period after a breach, and return or delete data at contract end.

※ This is a summary written to help you, not the text of the standard. Please refer to the published standard for the exact requirements.

Before you apply, please check

Having these in place makes the audit considerably smoother. If you are not ready yet, you are still welcome to get in touch — we will set out what to do first, with a timeline.

  • 🔴 Do you hold ISO/IEC 27001, or are you preparing it in parallel? 27018 cannot be certified alone
  • Is there an inventory of personal data entrusted by clients and the purposes for which it is processed?
  • 🔴 Are you using entrusted data for service improvement, analytics or marketing? That requires client consent
  • Is there a sub-processor list, and has the client been informed? (including overseas providers)
  • Have you disclosed which country's servers hold the personal data?
  • Are access logs kept for personal data — who viewed what, and when?
  • Is encryption applied at rest and in transit?
  • Is there a breach notification procedure stating within how many days the client will be told?
  • Is there a return and deletion procedure at contract end, with evidence of deletion retained?
  • Have you carried out at least one internal audit yourselves? (required before the audit)
See the 8-step certification process →

You can apply for ISO/IEC 27018 certification here

Tell us your organisation’s size and the standards you need, and we will send you the audit duration and a fee proposal. You are free to decide after seeing it.

Tel 02-786-9242Email info@itscert.or.krFax 02-6940-9317

※ ITS Certification Body does not provide management system consultancy. Auditing and consultancy must remain separate. What we can do is explain the certification process and what you need to have in place.

Which audit division handles this

Audits against this standard are carried out by our 정보보안심사본부. See the organisation chart →