Don’t do SECURITY. Do business SECURELY.

ISO/IEC 27018:2025 published for PII in public clouds

ISO and IEC publish the third edition of ISO/IEC 27018, aligned to ISO/IEC 27002:2022, for protecting PII in public clouds.

ISO and IEC have published ISO/IEC 27018:2025, the third edition of the code of practice for protecting personally identifiable information (PII) in public clouds acting as PII processors.

Key points

  • Aligned with the control structure of ISO/IEC 27002:2022.
  • Includes new extended implementation guidance in Annex B.
  • Covers PII collection, storage, processing, transmission and deletion by cloud providers.
  • Supports accountability between cloud providers and their customers.
  • Complements ISO/IEC 27001 and ISO/IEC 27701.

Cloud providers certified against ISO/IEC 27001 with a 27018 extension should plan their transition. UK customers of cloud services can use it to check what privacy commitments their providers make.

Source: ISO/IEC 27018:2025 (ISO)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights