ISO and IEC have published ISO/IEC 27018:2025, the third edition of the code of practice for protecting personally identifiable information (PII) in public clouds acting as PII processors.
Key points
- Aligned with the control structure of ISO/IEC 27002:2022.
- Includes new extended implementation guidance in Annex B.
- Covers PII collection, storage, processing, transmission and deletion by cloud providers.
- Supports accountability between cloud providers and their customers.
- Complements ISO/IEC 27001 and ISO/IEC 27701.
Cloud providers certified against ISO/IEC 27001 with a 27018 extension should plan their transition. UK customers of cloud services can use it to check what privacy commitments their providers make.
Source: ISO/IEC 27018:2025 (ISO)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.