ISO/IEC 27018

acronym

cloudprivacygovernance & risk

Stands for: ISO/IEC 27018 (PII protection in the cloud)

The privacy extension of ISO 27001 - protecting personally identifiable information processed in the public cloud.

ISO/IEC 27018:2019 sets controls for cloud providers acting as processors of PII: consent, transparency about sub-processors, data return and deletion, and restrictions on using customer data for advertising. It maps closely to GDPR obligations, and rounds out the 27001/27017/27018 trio that cloud vendors present together.

Also known as: iso 27018, iso/iec 27018, iso27018

All glossary entries