xmodoxmodo

Frameworks · Global standards

ISO/IEC 27018:2019

ISO/IEC 27018:2019 is a code of practice for protecting personally identifiable information (PII) in public clouds that act as PII processors. It gives implementation guidance on the ISO/IEC 27002 controls that apply to public-cloud PII. It also adds controls for requirements that the existing control set does not address.

Who it applies to

It applies to public cloud service providers that process personal data for customers. It also applies to providers whose customers require evidence of PII protection alongside ISO/IEC 27001.

Main requirements

Consent & purpose

The provider processes data only on the customer's instructions and for the agreed purpose.

Transparency

The provider discloses its sub-processors, data locations and any disclosures to authorities.

Data subject support

The provider gives customers tools and processes to meet access, correction and erasure requests.

Security & breach

The provider encrypts and securely deletes data, and notifies the customer of breaches.

How xmodo supports it

  • 1

    xmodo adds it as an extension to ISO/IEC 27001. Sub-processors and locations come from the third-party module and the trust center.

  • 2

    Requirements map to GDPR, the UAE PDPL and ISO/IEC 27701, so processor obligations are evidenced once.

Related frameworks

ISO/IEC 27018:2019 shares requirements with the frameworks below. Controls you already run for any of them count towards ISO/IEC 27018:2019 as well.

Frequently asked questions

How does 27018 differ from 27701?

27018 is a code of practice for public-cloud PII processors, certified as an extension of 27001. 27701 is a privacy information management system extension that covers controllers and processors. Many providers hold both, and xmodo maps each to the other.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo