ISO/IEC 27018
acronymcloudprivacygovernance & risk
Stands for: ISO/IEC 27018 (PII protection in the cloud)
The privacy extension of ISO 27001 - protecting personally identifiable information processed in the public cloud.
ISO/IEC 27018:2019 sets controls for cloud providers acting as processors of PII: consent, transparency about sub-processors, data return and deletion, and restrictions on using customer data for advertising. It maps closely to GDPR obligations, and rounds out the 27001/27017/27018 trio that cloud vendors present together.
Also known as: iso 27018, iso/iec 27018, iso27018