Back to Standards
Security & Access ControlGlobal

ISO/IEC 27018: PII Protection in Cloud

ISO 27018

Code of practice for protecting personally identifiable information (PII) in public clouds.

Purpose

Establishes controls and guidelines for protecting PII processed by cloud service providers.

Requirements Overview

PII protection controls; Consent management; Transparency of PII processing; Communication of security incidents

Overview

ISO/IEC 27018 emerged in 2014 as a critical response to the growing complexity of cloud computing and personal data protection. Developed by the International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC), the standard addressed significant gaps in existing information security frameworks regarding personally identifiable information (PII) in public cloud environments. Prior to ISO 27018, cloud service providers lacked a comprehensive, standardized approach to protecting customer data across distributed infrastructure. The standard specifically extended ISO/IEC 27002 controls to create a targeted code of practice for cloud-based PII management. Its development reflected the increasing global concerns about data privacy, cross-border data transfers, and the unique security challenges presented by multi-tenant cloud architectures. For data centers, ISO 27018 represents a pivotal framework that mandates explicit responsibilities between cloud service providers and customers. The standard requires providers to implement 37 specific controls addressing PII processing accountability, consent management, and incident communication protocols. Unlike previous generic security standards, ISO 27018 uniquely defines a clear responsibility matrix for shared cloud infrastructure, compelling providers to communicate exactly which security controls they guarantee versus those requiring customer implementation. The standard's significance extends beyond technical compliance. It provides a structured approach for cloud service providers to demonstrate robust data protection practices, build customer trust, and navigate increasingly complex global privacy regulations such as GDPR and CCPA. By establishing clear guidelines for PII handling, ISO 27018 has become an essential benchmark for organizations offering public cloud services.

Key Requirements

PII Processing Transparency and Notification

CSPs must provide customers with explicit documentation detailing all PII processing activities, including purposes, categories of data processed, recipients of data, and retention periods.

Data centers must maintain and publish privacy impact assessments and processing notices that clearly delineate customer responsibilities from provider obligations.

This requirement mandates real-time visibility into where PII resides, how it flows through infrastructure, and what transformations occur—fundamentally requiring CSPs to map PII through their data center network topology and document every processing operation.

Consent Management and Purpose Limitation

Cloud providers must ensure PII is processed only for explicitly consented purposes and implement technical controls preventing secondary use or reuse beyond original collection intent.

Data centers must architect systems where PII tagged for specific purposes (e.g., billing, service delivery) cannot be accessed by systems serving different functions (e.g., analytics, marketing).

This requires implementing purpose-aware access controls, data classification schemas, and enforcement mechanisms that prevent unauthorized purpose expansion or data linkage across unrelated processing contexts.

Accountability and Responsibility Mapping

ISO 27018 requires CSPs to establish explicit responsibility matrices documenting whether specific controls are implemented by the provider, the customer, or jointly.

Data center operators must maintain documented evidence of control ownership for each of the 37 PII protection controls, including which party is responsible for encryption, access management, audit logging, and breach notification.

This documentation must be provided to customers pre-engagement and updated whenever responsibility allocations change, creating ongoing operational documentation requirements within data center management systems.

PII Deletion and Return on Contract Termination

Upon customer request or contract termination, CSPs must delete or return all customer PII within a defined timeframe and provide written certification of deletion completion.

Data centers must implement secure deletion procedures meeting NIST 800-88 guidelines that ensure cryptographic erasure or physical destruction of media containing PII.

This requirement mandates maintaining deletion logs, implementing deletion verification processes, and coordinating deletion across geographically distributed data center facilities where customer data may be replicated or backed up.

Security Incident Notification and Communication

CSPs must establish incident response procedures ensuring customers are notified of any suspected or confirmed PII security incidents without undue delay, typically within 72 hours or per applicable jurisdiction requirements.

Data centers must implement automated incident detection systems, maintain incident logs with tamper-proof timestamps, and establish escalation procedures that trigger immediate customer notification upon discovery of unauthorized PII access or suspected breaches.

This requires integration between security operations centers and customer communication channels with documented evidence of notification timing.

Audit Rights and Customer Verification

ISO 27018 grants cloud customers explicit audit rights allowing them to verify CSP compliance with PII protection controls through on-site audits, independent third-party audits, or remote assessment mechanisms.

Data centers must maintain audit-ready infrastructure with comprehensive logs, access controls documentation, and the ability to demonstrate control implementation to customer auditors within defined timeframes.

This includes maintaining evidence of segregation of duties, encryption key management, staff training records, and vendor management procedures related to PII processing.

Encryption and Cryptographic Key Management

Cloud providers must implement encryption for PII both in transit (TLS 1.2+) and at rest, with encryption key management procedures ensuring customers maintain control or escrow of encryption keys.

Data centers must architect systems where customer PII encryption keys are never accessible to provider staff, implementing hardware security modules (HSMs), key escrow services, or customer-managed key infrastructures.

This requirement impacts data center design, requiring separate cryptographic key infrastructure, customer key management interfaces, and procedures preventing commingling of keys across customer tenants.

Subcontractor and Third-Party Management

CSPs must contractually bind all subcontractors, backup providers, disaster recovery vendors, and other third parties processing customer PII to equivalent PII protection obligations.

Data centers must maintain approved vendor lists, documented contracts containing PII protection clauses, and periodic verification that subcontractors maintain compliance.

This extends PII protection responsibility across the entire data center supply chain, including disaster recovery providers, managed service providers, and infrastructure suppliers, requiring ongoing vendor audit procedures.

Who Uses & Why

ISO 27018 compliance becomes mandatory for data centers in several critical scenarios. Organizations processing PII for customers in regulated industries (financial services, healthcare, government) must implement the standard, particularly when serving European, North American, or Asia-Pacific markets. Mandatory compliance is triggered when data centers meet specific conditions: offering public cloud infrastructure, platform, or software services; processing customer data in GDPR jurisdictions; serving CCPA-regulated organizations; or supporting regulated entities with specific vendor requirements (HIPAA, PCI-DSS). Optional but highly recommended scenarios include multi-tenant cloud services, disaster recovery platforms, backup services processing customer PII, and providers targeting enterprise customers with rigorous vendor due diligence processes. Geographic considerations play a crucial role, with European operations requiring more stringent GDPR-aligned controls compared to other regions. Complexity and cost considerations vary. Large hyperscale cloud providers and managed hosting platforms will find implementation more straightforward, while mid-market data centers might face more significant investment in technical and procedural modifications. Organizations should conduct a comprehensive cost-benefit analysis, considering potential competitive advantages, customer trust, and reduced legal risks against implementation expenses.