ISO 27018
Definition
ISO 27018
ISO 27018 is the standard covering personal data held in public clouds by providers acting as processors. It obliges a provider to say where data sits and who else touches it, which is precisely what buyers of offshore processing need to establish.
Those two disclosures are the whole reason to care about it.
Most security standards tell you a provider has controls. This one tells you specific facts about your own data — which country it rests in, and which other companies the provider has brought in behind it.
It applies to providers processing personal data on someone else’s behalf, which describes most outsourced arrangements involving customer records.
Key takeaways
- ISO 27018 addresses cloud providers acting as processors of personally identifiable information.
- Certified providers must tell customers which countries or regions their data may be stored in.
- Customer data cannot be used for marketing or advertising without explicit, non-conditional consent.
- Providers must disclose the subprocessors that can reach customer data.
How it works
ISO 27018 gives guidance to cloud providers acting as processors of personally identifiable information (PII) on assessing risk and implementing controls. It is built on the general security controls rather than standing alone.
The controller and processor split is the structural idea. Microsoft describes controllers as those who control the collection, holding, processing, or use of personal information, while processors act on their behalf and do not decide the purposes.
That mirrors European data protection law, where Article 28 requires a controller to use only processors providing sufficient guarantees to implement appropriate technical and organisational measures. The vocabulary is deliberately compatible.
Four obligations do the practical work. Microsoft records that the standard requires certified providers to inform customers of the countries or regions where data might be stored, and bars using customer data for advertising without explicit consent.
It adds that consent can’t be a condition for use of the cloud service — a detail that stops the obligation being satisfied by a tick-box at sign-up.
It also requires a policy for return, transfer and secure disposal of personal data, and proactive disclosure of the subprocessors involved.
| Obligation | What a buyer gets from it |
|---|---|
| Data location disclosure | Knowing which jurisdictions can reach your records |
| No advertising use | Your customer data stays out of the provider’s own products |
| Consent not conditional | The permission cannot be bundled into the service terms |
| Return and secure disposal | A defined exit path for personal data |
| Subprocessor disclosure | Visibility of the fourth parties behind your provider |
The last row is the one that surprises buyers. Your provider’s suppliers are handling your customers’ data, and most contracts never name them.
Examples
Cloud privacy commitments matter most at the points where data crosses an organisational or national boundary. The cases here are the sort that surface only after the certificate is issued.
A European insurer needs to know whether its records leave the region. The data location obligation answers that in writing, which no general security certificate does.
A bank asks its provider to name every subprocessor and receives a list of eleven. Four were analytics firms nobody in procurement had heard of, which is a routine finding in cybersecurity outsourcing reviews.
A retailer exits a contract and invokes the return and disposal policy. Without it, “delete our data” is a request rather than an obligation, and data center outsourcing exits drag for months.
A health client checks whether its provider trains models on customer records. The advertising and consent provisions do not settle that question, which is why newer AI-specific standards exist.
Related terms
Cloud privacy sits between general security standards and actual data protection law, and the three get blurred constantly. Every definition here stops early, which is the only way this set stays usable.
- ISO 27001: the certifiable security management system this code of practice is audited alongside.
- GDPR (General Data Protection Regulation): binding European law, where ISO 27018 is a voluntary standard.
- Data Privacy Act Philippines: the national law governing personal data in a major delivery market.
- Cybersecurity outsourcing: buying security operations, rather than certifying privacy handling.
- Data center outsourcing: the infrastructure layer where residency questions are physically settled.
- Compliance outsourcing: delegating regulatory work itself, not adopting a privacy standard.
- ISO certification: the general audit mechanism behind ISO management standards.
FAQ
Is ISO 27018 a law?
No. It is a voluntary standard. Data protection law such as the GDPR is binding, and certification does not substitute for compliance with it.
Who does it apply to?
Cloud providers that process personal data under contract for other organisations. It is written for processors rather than for the organisations that decide the purposes.
What does it say about data location?
Certified providers must inform customers of the countries or regions in which their data might be stored, which is the residency answer most buyers actually need.
Does it stop a provider using my data?
For marketing and advertising, yes, without explicit consent — and that consent cannot be made a condition of using the service.
How does it relate to ISO 27017?
ISO 27017 covers cloud security controls generally. ISO 27018 narrows to personal data held by a provider acting as a processor.
Which edition is current?
A 2025 edition has replaced the earlier code of practice, aligning it with the 2022 revision of the underlying security controls.
Review source partners in the Outsource Accelerator hubs directory and ask where the data sits and who else can reach it.







Independent




