Quick answer
ISO 27018 extends ISO 27001 with privacy controls for protecting personal data (PII) in public cloud environments, written from the perspective of the cloud provider acting as a PII processor. It codifies the commitments enterprise customers want from a cloud vendor: process only on instruction, no advertising use of customer data, transparency about subprocessors and locations, breach notification, and support for the customer's own data-subject obligations. For SaaS companies processing personal data, it's the cloud-privacy certificate that complements ISO 27017's cloud-security one.
The commitments it standardizes
- Instruction-bound processing: customer data is processed only per the agreement, with commercial reuse (profiling, advertising) explicitly off the table unless separately consented.
- Transparency: disclosed subprocessors, disclosed processing locations, and notification of changes, the same expectations GDPR Article 28 makes contractual.
- Customer enablement: supporting your customers' data-subject requests (access, deletion) and giving them what they need for their own compliance.
- Return and deletion: defined handling at contract end.
- PII-specific security: encryption, access restriction, and personnel confidentiality for PII in the cloud service.
If this reads like a standardized DPA, that's the value: an accredited auditor has verified you actually operate these commitments, which converts DPA negotiation claims into certificate lines.
Who certifies and why
SaaS vendors selling to privacy-sensitive enterprises and the public sector get the clearest return: the certificate answers privacy questionnaires' cloud sections, differentiates in procurements that score certifications, and reduces bespoke audit demands from large customers. It rides the ISO 27001 certification cycle as an extension, and it pairs with ISO 27701: 27701 certifies your privacy management system broadly; 27018 certifies the public-cloud processor commitments specifically. Many vendors hold both; see how the work overlaps.

Get a personalized walkthrough of automated compliance for your team. No commitment required.