ISO/IEC 27018:2019: the clauses behind the split
The code of practice for personal data processed by a public cloud provider. Tick it when any service holds personal data; a line with personal data and no 27018 raises a finding.
Shown when ticked. The framework on the compliance library.
Control areas it anchors
4Every clause cited, quoted
6 of the 41 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
ISO/IEC 27018 A.3.1 Public cloud PII processor's purposePII to be processed under a contract should not be processed for any purpose independent of the instructions of the cloud service customer; the processor acts only on the customer's documented instructions and does not determine purposes of its own for customer PII.
- Contract clause restricting processing to customer instructions
- Internal rule and controls preventing secondary use
- Evidence of instruction-based processing
- Analytics or product improvement run on customer PII without instruction
- Instructions accepted informally with no record
ISO/IEC 27018 A.3.2 Public cloud PII processor's commercial usePII processed under a contract should not be used by the processor for the purposes of marketing and advertising without express consent, and such consent should not be a condition of receiving the service. This control is an addition to the general control in A.3.1 and is not intended to override it.
- Policy prohibiting marketing use of customer PII
- Consent mechanism, if any, separate from the service terms
- Marketing consent bundled into the service agreement
- Usage data derived from customer PII used to target advertising
ISO/IEC 27018 A.8.1 Disclosure of sub-contracted PII processingIf the public cloud PII processor uses sub-contractors to process PII, it should disclose this to the relevant cloud service customers before use, so that the customer can object or decline, and should keep the disclosure current as sub-contractors change.
- Published or contractual list of sub-contractors processing PII
- Notification of changes before use
- Customer objection mechanism
- Sub-processors added without notice
- List published once and never updated
ISO/IEC 27018 A.10.1 Notification of a data breach involving PIIThe public cloud PII processor should promptly notify the relevant cloud service customer in the event of any unauthorised access to PII or unauthorised access to processing equipment or facilities resulting in loss, disclosure or alteration of PII, within the period and with the content agreed in the contract, and should cooperate in the customer's response.
- Breach notification procedure with contractual timescales
- Notification records
- Evidence of cooperation with customer investigations
- Breach determination left to the customer with no processor assessment
- Notification sent after the customer's own regulatory deadline
ISO/IEC 27018 A.11.12 Sub-contracted PII processingContracts between the public cloud PII processor and any sub-contractors that process PII should specify minimum technical and organisational measures that meet the information security and PII protection obligations of the processor, and such measures should not be subject to unilateral reduction by the sub-contractor.
- Sub-contractor agreements carrying the same minimum measures
- Evidence the measures are verified
- Sub-contractors engaged on their own standard terms
- Flow-down clauses that omit PII obligations
ISO/IEC 27018 A.12.1 Geographical location of PIIThe public cloud PII processor should specify and document the countries in which PII can possibly be stored, so that the cloud service customer can assess whether the locations meet its legal and contractual obligations.
- Published or contractual list of countries where PII may be stored
- Change notification when locations change
- Locations stated for primary storage but not backups, support access or sub-contractors
- Location list not updated when regions are added