Framework · Last verified
ISO/IEC 27018
ISO/IEC 27018 guides protection of PII in public clouds where the provider acts as PII processor; the current edition is 27018:2025 (third edition). ISO's own description: it "provides guidance for protecting personally identifiable information (PII) in public cloud services, specifically when the cloud service provider acts as a PII processor". Edition 3 published August 2025 replaced the 2019 text.
- Class
- Framework
- Owner
- ISO/IEC (Joint Technical Committee ISO/IEC JTC 1)
- Last verified
What it is
The official title is "Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors" (Edition 3, publication date 2025-08, status Published — ISO's page, read in a browser on 7 September 2026).
Its own title says "Guidelines": like 27002 and 27017 it is guidance built on ISO/IEC 27002, not a certifiable management system standard on its own in the pages read for this record.
The Estonian national catalogue (EVS) lists the 2025 edition as effective 26.08.2025, superseding 27018:2019; the national mirror gives 35 pages.
The scope is deliberately narrow — public cloud providers in the PII processor role; the controller role and non-cloud processing sit outside the title's own wording.
Who owns it
ISO and IEC jointly, through ISO/IEC JTC 1; national mirror editions exist (EVS entry cited above).
Who asks for it
Public cloud-assurance frameworks name it alongside 27017: Canada's CCCS SPIN 2017-01 lists ISO/IEC 27018 among the third-party assurance forms a department may leverage (quote carried on the linked cccs-cloud record).
Sources
- ISO — ISO/IEC 27018:2025 (standard page; opened via a real browser) ↗ — accessed
- EVS catalogue — ISO/IEC 27018:2025 (effective 26.08.2025) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.