Back to Standards

    ISO 27018

    Cloud Privacy Protection

    Guidance standard

    Code of practice for protection of personally identifiable information in public clouds.

    Can you get certified to ISO 27018?

    ISO 27018 is a guidance standard. It offers recommendations rather than auditable requirements, so no accredited body can certify an organisation to ISO 27018. Any claim of "ISO 27018 certification" should be treated with caution.

    What is ISO 27018?

    ISO 27018 establishes commonly accepted control objectives for protecting Personally Identifiable Information (PII) in public cloud computing environments.

    Applying ISO 27018 in your organisation

    There is no certification to pursue, but an experienced consultant can help you apply ISO 27018 alongside the management system standards you are certified to. Reading the published document is the best starting point.

    Authoritative source

    This page summarises ISO 27018 (current published edition). Always confirm the detail against the published document.