ISO 27018: Protection of Personally Identifiable Information
What is 27018?ISO/IEC 27018:2019 is an information security code of practise for cloud service providers who process personally identifiable information for their customers. It’s an extension to ISO/IEC 27001:2013 and ISO/IEC 27002, and it provides additional security controls. It details privacy requirements and security control enhancements for privacy to be implemented by cloud service providers.
It is complementary to ISO 27017:2015, Security Control for Cloud Services, and to ISO 27701:2019, Privacy Information Management, both of which also extend ISO 27001:2013.
As an extension to ISO 27001, ISO 27018 provides guidance on 16 ISO 27002 controls, as well as providing 25 new privacy and security controls:
- The requirement to cooperate with PII controllers
- The maintenance of PII principals’ rights
- Compliance with fundamental privacy requirements, such as data minimisation and accuracy
- The principles of transparency and accountability
- Additional security controls
- Requirements for sub-contracted processing
Helps you with
- Customer trust
- Brand reputation
- Competitive advantage
- Data breaches
- Continued confidentiality
- Meet compliance
- Risk management
- Improved security
Other risk management standards:
- ISO 27001 - Information Security
- ISO 27701 - GDPR Compliance
- BS 10012 - Personal Information
- ISO 20000-1 - IT Service Management
- ISO 27017 - Security Controls for Cloud Services
- ISO 22301 - Business Continuity
- ISO 44001 - Collaborative Working
- ISO 55001 - Asset Management
- ISO 41001 - Facilities Management
ISO 27001 training
Benefits of ISO 27018 Certification
It helps reduce the risk of a privacy breach and fines from the ICO.
Provides external assurance to customers that personal information processed in the cloud by the cloud service provider is managed in a compliant manner.
Alternative to ISO 27701
It may be considered an appropriate alternative to ISO 27701 in the cloud services processor context.
Extends and enhances certification
It extends and enhances a clients ISO 27001 certification.
Provides a comprehensive privacy framework for cloud service providers who want increased assurance on the privacy compliance of their cloud services.
Steps to Certification
Complete a Quote Request Form so that we can understand your company and requirements. You can do this by completing either the online quick quote or the online formal quote request form. We will use this information to accurately define your scope of assessment and provide you with a proposal for certification.
Once you’ve agreed your proposal, we will contact you to book your assessment with an NQA Assessor. This assessment consists of two mandatory visits that form the Initial Certification Audit. Please note that you must be able to demonstrate that your management system has been fully operational for a minimum of three months and has been subject to a management review and full cycle of internal audits.
Following a successful two stage audit, a certification decision is made and if positive, then certification to the required standard is issued by NQA. You will receive both a hard and soft copy of the certificate. Certification is valid for three years and is maintained through a programme of annual surveillance audits and a three yearly recertification audit.
Information Security Toolkit
ISO 27001 FAQs
ISO 27001 Implementation Guide
ISO 27701 Implementation Guide
Risk Assurance Brochure
Integrated Quote Request Form
Information Security Management Training
Measuring Operational Resilience Method
ISO 27001 in relation to GDPR video
ISO 9001 to ISO 27001 Gap Guide
Annex SL Comparison Tool
CityFibre Case Study
Is Your Management System Integrated?
Need a Consultant?
Download Certification Logos