Skip to content
ISO 27018 Certification

Cloud privacy,independently certified.

When an organisation puts personal data into the cloud, it is trusting a provider it does not control with information it remains responsible for. ISO 27018 is the international standard that governs exactly this situation. It sets out how cloud service providers should protect the personally identifiable information they handle on behalf of their customers, adding privacy-specific safeguards on top of general cloud security.

Glowing cloud icon linked by arrows to three laptops, each displaying a padlock, over a circuit board
What it proves

The privacy commitments buyers ask about, independently assessed.

Cloud PII protection

ISO/IEC 27018 is the code of practice for protecting personally identifiable information, known as PII, in public cloud environments where the provider acts as a PII processor. It extends an organisation's core information security controls with privacy-specific safeguards for personal data held in the cloud, and its current edition is aligned to the modern ISO 27002 control set.

Certification against it proves that a cloud provider handles personal data with the specific care that customers, and their legal teams, increasingly demand. It addresses the commitments enterprise buyers ask about during due diligence: how consent is respected, how transparency over sub-processors is maintained, how customers are notified of relevant events, and how personal data is returned or deleted when a contract ends. For a customer deciding whether to trust a provider with their users' personal data, an ISO 27018 certificate is independent evidence that those commitments are real and assessed.

Cloud service providersFingertip touching a glowing cloud icon containing a padlock, ringed by a blue network mesh and security symbols
Who it is for

Cloud providers processing personal data for their customers.

ISO 27018 is aimed primarily at cloud service providers that process personal data on behalf of their customers. If your organisation runs a cloud platform, a SaaS product, or any service that stores or processes other organisations' personal data, ISO 27018 is the standard that demonstrates you protect that data responsibly.

It is especially relevant where the personal data involved is sensitive or the customers are demanding. IT and software companies providing platforms to enterprise clients use it to answer the privacy questions that now appear in every serious procurement process. Banking and financial services organisations and healthcare providers, whether operating cloud services or holding others to account, treat cloud PII protection as essential rather than optional.

As data protection expectations rise across the Indian market and internationally, ISO 27018 gives cloud providers a recognised way to prove their privacy commitments to the customers who ask.

How it fits

Security asks if the service is safe. Privacy asks about the data inside it.

ISO 27018 is not a standalone certificate. Like its sibling cloud standard ISO 27017, it builds on the foundation of an ISO 27001 information security management system and is certified as an extension of it, assessed as part of the same audit rather than in isolation.

The relationship between the three standards is worth understanding. ISO 27001 provides the information security foundation. ISO 27017 adds cloud security in general. ISO 27018 adds the privacy-specific layer for personal data in the cloud. A mature cloud provider handling personal data often pursues all three, layered together, because they answer different questions: is your information security sound, is your cloud service secure, and specifically how do you protect the personal data within it. Certiva Global can assess these together in a coordinated audit, so cloud security and cloud privacy are covered coherently.

One coordinated audit
ISO 27017

Cloud Security

Cloud-specific security controls, and a clear split of responsibility between cloud provider and cloud customer.

ISO 27018

Cloud Privacy

Privacy-specific safeguards for the personally identifiable information a provider handles on behalf of its customers.

Both are extensions of an ISO 27001 information security management system, so they can be assessed together in one coordinated audit.

The certification process

Assessed as part of your information security certification.

Certiva Global certifies ISO 27018 as part of an ISO 27001 information security certification, assessing the cloud privacy controls alongside your core information security controls.

Compliant with ISO/IEC 17021-1
01

Design review

Our auditor confirms first that the ISO 27018 privacy controls for cloud PII are properly designed, alongside the core information security controls they extend.

02

Evidence in practice

Our auditor then gathers evidence that those controls operate in practice, from how personal data is protected and access is controlled to how it is returned or deleted at the end of a contract. If the evidence supports certification, the cloud privacy scope is certified as part of your information security certification.

03

Surveillance & recertification

Certification is maintained through annual surveillance audits across the three-year cycle, so your privacy commitments are shown to be sustained, not just met once.

Why Certiva Global

Auditors who understand cloud privacy, not just cloud.

Certiva Global is an independent international certification body based in Hyderabad, serving organisations worldwide and operating in compliance with ISO/IEC 17021-1.

Security and privacy expertise

Our auditors understand both information security and the specific demands of protecting personal data in the cloud, so the assessment reflects how cloud privacy actually works in practice.

We assess and certify only

We do not build or run your controls, and that independence is what gives your certificate its weight with the enterprise customers who scrutinise how their data is handled.

Cloud security and privacy together

Because ISO 27018 pairs naturally with ISO 27017, we can assess cloud privacy and cloud security in one coordinated audit rather than two disconnected exercises.

To begin, request a no-obligation scoping discussion with our technical team.

Questions

Frequently asked questions

ISO 27018 certification demonstrates that a cloud service provider protects the personally identifiable information (PII) it handles on behalf of its customers. ISO/IEC 27018 is the code of practice for protecting personal data in public clouds, certified as an extension of an ISO 27001 information security management system.

No. ISO 27018 is not a standalone certificate. Like ISO 27017, it builds on an ISO 27001 information security management system and is certified as an extension of it, assessed as part of the same audit.

ISO 27017 addresses cloud security in general, for both providers and customers. ISO 27018 focuses specifically on protecting personal data (PII) that a cloud provider handles on behalf of its customers. They are complementary and are often certified together, both as extensions of ISO 27001.

Primarily cloud service providers that process personal data on behalf of their customers, such as SaaS and platform providers, especially those serving enterprise clients in IT and software, banking and financial services, and healthcare, where cloud PII protection is scrutinised during procurement.

Yes, in practice. Because ISO 27018 extends an information security management system and is certified as part of an ISO 27001 audit, an organisation needs an ISO 27001 management system in place to certify its cloud privacy controls under ISO 27018.

As part of an ISO 27001 certification, it is valid for three years, maintained through annual surveillance audits, with a recertification audit at the end of the cycle.

Ready to begin your certification journey?

Get a transparent, no-obligation scoping discussion with our technical team.