Privacy protection for personal data in the cloud

What it is

ISO 27018 provides additional guidance for protecting personally identifiable information (PII) in public cloud environments. It builds directly on your ISO 27001 foundation, specifically zeroing in on the security of the personal data that cloud service providers handle to answer a critical customer question: if I trust you with my data, how do I know you will treat it properly?

When to use it

Use this add-on when your organization provides cloud services, runs a SaaS platform, or processes personal data in a cloud environment, and customers or regulators expect clear, verifiable privacy controls. It turns rising data privacy regulations into a distinct competitive advantage.

What it adds

It extends your ISO 27001 ISMS with cloud-specific privacy controls without creating extra overhead. This add-on upgrades your Instant 27001 system by providing:

  • Tailored implementation guidelines for 14 existing ISO 27001 controls.
  • 25 new controls that follow the 11 international privacy principles defined in ISO 29100.
  • An updated Statement of Applicability (SoA) that seamlessly integrates these cloud-privacy requirements.
  • Clear migration instructions if you are upgrading your existing framework from ISO 27018:2019 to the ISO 27018:2025 version.

Add-ons can be used together with Instant 27001 for Confluence or Microsoft 365 (ISOPlanner). Instructions for installation and implementation are provided.

Relevant for

  • SaaS companies
  • Cloud service providers
  • Hosting providers
  • Managed service providers
  • Organizations processing customer data in cloud environments

Pricing

€ 1 495

All prices are excluding applicable taxes and subscription fees for Confluence, Microsoft 365 or ISOPlanner.

100% first time success! Start with confidence.

Order now   Book a demo