ISO/IEC 27018 Protection of PII in Public Clouds
Sets out what an organisation must do when it processes other people's personal information in a public cloud. Certified as an extension of ISO/IEC 27001.
This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →
What this certification proves
ISO/IEC 27018 is not about your own personal data. It is about personal data entrusted to you by someone else. Cloud and SaaS operators hold their clients' member records. That data does not belong to the operator — it belongs to the client, and ultimately to the individuals concerned.
So the standard compresses down to a single principle: use it only within the instructions you were given. Using entrusted personal data for your own advertising, or analysing it under the banner of «service improvement», or feeding it to marketing, requires the explicit consent of the client organisation. That is what separates this standard decisively from other security standards.
Around that sit three more duties: tell the client before sub-contracting, disclose which countries the data is processed in, and notify within a defined period when a breach occurs.
⚠️ This standard is not certified on its own. It is audited as an extension of ISO/IEC 27001.
Who this is for
- Organisations processing client personal data in the cloud
- SaaS providers handling end-user information
- Organisations with sub-processing or cross-border transfers
🌱 How this relates to ESG
S SocialMaps onto the S (Social) pillar. Personal data is a matter of individual rights, which every major ESG framework classifies as social.
- GRI 418 (Customer Privacy) — privacy breach complaints reported under Social
- Korea's K-ESG guideline, S domain «information protection» — privacy framework and incident count
- Processor obligations under Korea's Personal Information Protection Act — no use beyond purpose, restrictions on sub-processing, security measures. The content overlaps directly
- GDPR processor obligations — the same duties European customers ask about during due diligence
- The strongest answer when a client audits you — it is third-party confirmation that entrusted data is not used improperly
What certification gives you
- Commits you in writing to using entrusted data only within instructions — the core of the standardSee the 8-step process →
- Establishes notice of sub-processors and processing countries, and notification when they changeRequest audit duration and fees →
- Builds the framework for notifying clients within a defined period after a breachCheck a certified organisation →
- Cuts the time spent responding to client security questionnairesSee ISO/IEC 27001 →
- For personal data across the whole organisation, look at ISO/IEC 27701See ISO/IEC 27701 →
How the requirements are structured
This is the overall shape of what the standard asks for. Working through it in this order is a sensible way to prepare.
| Clause | Title | In plain terms |
|---|---|---|
| Basis | ISO/IEC 27001 + 27002 | An information security management system and the general control set underpin this. 27018 is not certified separately. |
| Annex A-1 | Consent and choice | Using entrusted personal data for advertising or analysis requires the client's consent. |
| Annex A-2 | Purpose limitation | Never use the data beyond the purpose the client instructed. The heart of the standard. |
| Annex A-3 | Transparency | Disclose sub-processors and processing countries in advance, and notify when they change. |
| Annex A-4 | Supporting individual rights | Provide the functions and cooperation the client needs to answer access and erasure requests. |
| Annex A-5 | Access and records | Record and retain who accessed personal data and when. |
| Annex A-6 | Storage and transmission | Encrypt at rest and in transit, and restrict removable media. |
| Annex A-7 | Breach notification and return | Notify the client within the defined period after a breach, and return or delete data at contract end. |
※ This is a summary written to help you, not the text of the standard. Please refer to the published standard for the exact requirements.
Before you apply, please check
Having these in place makes the audit considerably smoother. If you are not ready yet, you are still welcome to get in touch — we will set out what to do first, with a timeline.
- 🔴 Do you hold ISO/IEC 27001, or are you preparing it in parallel? 27018 cannot be certified alone
- Is there an inventory of personal data entrusted by clients and the purposes for which it is processed?
- 🔴 Are you using entrusted data for service improvement, analytics or marketing? That requires client consent
- Is there a sub-processor list, and has the client been informed? (including overseas providers)
- Have you disclosed which country's servers hold the personal data?
- Are access logs kept for personal data — who viewed what, and when?
- Is encryption applied at rest and in transit?
- Is there a breach notification procedure stating within how many days the client will be told?
- Is there a return and deletion procedure at contract end, with evidence of deletion retained?
- Have you carried out at least one internal audit yourselves? (required before the audit)
You can apply for ISO/IEC 27018 certification here
Tell us your organisation’s size and the standards you need, and we will send you the audit duration and a fee proposal. You are free to decide after seeing it.
Tel 02-786-9242Email info@itscert.or.krFax 02-6940-9317
※ ITS Certification Body does not provide management system consultancy. Auditing and consultancy must remain separate. What we can do is explain the certification process and what you need to have in place.
Which audit division handles this
Audits against this standard are carried out by our 정보보안심사본부. See the organisation chart →
