• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » ISO 27018

ISO 27018

Definition

ISO 27018

ISO 27018 is the standard covering personal data held in public clouds by providers acting as processors. It obliges a provider to say where data sits and who else touches it, which is precisely what buyers of offshore processing need to establish.

Those two disclosures are the whole reason to care about it.

Most security standards tell you a provider has controls. This one tells you specific facts about your own data — which country it rests in, and which other companies the provider has brought in behind it.

It applies to providers processing personal data on someone else’s behalf, which describes most outsourced arrangements involving customer records.

Key takeaways

  • ISO 27018 addresses cloud providers acting as processors of personally identifiable information.
  • Certified providers must tell customers which countries or regions their data may be stored in.
  • Customer data cannot be used for marketing or advertising without explicit, non-conditional consent.
  • Providers must disclose the subprocessors that can reach customer data.

How it works

ISO 27018 gives guidance to cloud providers acting as processors of personally identifiable information (PII) on assessing risk and implementing controls. It is built on the general security controls rather than standing alone.

The controller and processor split is the structural idea. Microsoft describes controllers as those who control the collection, holding, processing, or use of personal information, while processors act on their behalf and do not decide the purposes.

That mirrors European data protection law, where Article 28 requires a controller to use only processors providing sufficient guarantees to implement appropriate technical and organisational measures. The vocabulary is deliberately compatible.

Four obligations do the practical work. Microsoft records that the standard requires certified providers to inform customers of the countries or regions where data might be stored, and bars using customer data for advertising without explicit consent.

It adds that consent can’t be a condition for use of the cloud service — a detail that stops the obligation being satisfied by a tick-box at sign-up.

It also requires a policy for return, transfer and secure disposal of personal data, and proactive disclosure of the subprocessors involved.

ObligationWhat a buyer gets from it
Data location disclosureKnowing which jurisdictions can reach your records
No advertising useYour customer data stays out of the provider’s own products
Consent not conditionalThe permission cannot be bundled into the service terms
Return and secure disposalA defined exit path for personal data
Subprocessor disclosureVisibility of the fourth parties behind your provider

The last row is the one that surprises buyers. Your provider’s suppliers are handling your customers’ data, and most contracts never name them.

Examples

Cloud privacy commitments matter most at the points where data crosses an organisational or national boundary. The cases here are the sort that surface only after the certificate is issued.

A European insurer needs to know whether its records leave the region. The data location obligation answers that in writing, which no general security certificate does.

A bank asks its provider to name every subprocessor and receives a list of eleven. Four were analytics firms nobody in procurement had heard of, which is a routine finding in cybersecurity outsourcing reviews.

A retailer exits a contract and invokes the return and disposal policy. Without it, “delete our data” is a request rather than an obligation, and data center outsourcing exits drag for months.

A health client checks whether its provider trains models on customer records. The advertising and consent provisions do not settle that question, which is why newer AI-specific standards exist.

Related terms

Cloud privacy sits between general security standards and actual data protection law, and the three get blurred constantly. Every definition here stops early, which is the only way this set stays usable.

FAQ

Is ISO 27018 a law?

No. It is a voluntary standard. Data protection law such as the GDPR is binding, and certification does not substitute for compliance with it.

Who does it apply to?

Cloud providers that process personal data under contract for other organisations. It is written for processors rather than for the organisations that decide the purposes.

What does it say about data location?

Certified providers must inform customers of the countries or regions in which their data might be stored, which is the residency answer most buyers actually need.

Does it stop a provider using my data?

For marketing and advertising, yes, without explicit consent — and that consent cannot be made a condition of using the service.

How does it relate to ISO 27017?

ISO 27017 covers cloud security controls generally. ISO 27018 narrows to personal data held by a provider acting as a processor.

Which edition is current?

A 2025 edition has replaced the earlier code of practice, aligning it with the 2022 revision of the underlying security controls.

Review source partners in the Outsource Accelerator hubs directory and ask where the data sits and who else can reach it.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image