Cloud Shared Responsibility Mapper
Framework

ISO/IEC 27018:2019: the clauses behind the split

The code of practice for personal data processed by a public cloud provider. Tick it when any service holds personal data; a line with personal data and no 27018 raises a finding.

Shown when ticked. The framework on the compliance library.

Control areas it anchors

4
AreaClause
Data classification and handlingISO/IEC 27018 A.12.1
Incident responseISO/IEC 27018 A.10.1
Supplier and subserviceISO/IEC 27018 A.8.1
AI use and data retentionISO/IEC 27018 A.3.1 ยท ISO/IEC 27018 A.3.2

Every clause cited, quoted

6 of the 41 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

ISO/IEC 27018 A.3.1 Public cloud PII processor's purpose

PII to be processed under a contract should not be processed for any purpose independent of the instructions of the cloud service customer; the processor acts only on the customer's documented instructions and does not determine purposes of its own for customer PII.

What an assessor asks to see:
  • Contract clause restricting processing to customer instructions
  • Internal rule and controls preventing secondary use
  • Evidence of instruction-based processing
Where it usually falls short:
  • Analytics or product improvement run on customer PII without instruction
  • Instructions accepted informally with no record
Source: ISO/IEC 27018:2019
ISO/IEC 27018 A.3.2 Public cloud PII processor's commercial use

PII processed under a contract should not be used by the processor for the purposes of marketing and advertising without express consent, and such consent should not be a condition of receiving the service. This control is an addition to the general control in A.3.1 and is not intended to override it.

What an assessor asks to see:
  • Policy prohibiting marketing use of customer PII
  • Consent mechanism, if any, separate from the service terms
Where it usually falls short:
  • Marketing consent bundled into the service agreement
  • Usage data derived from customer PII used to target advertising
Source: ISO/IEC 27018:2019
ISO/IEC 27018 A.8.1 Disclosure of sub-contracted PII processing

If the public cloud PII processor uses sub-contractors to process PII, it should disclose this to the relevant cloud service customers before use, so that the customer can object or decline, and should keep the disclosure current as sub-contractors change.

What an assessor asks to see:
  • Published or contractual list of sub-contractors processing PII
  • Notification of changes before use
  • Customer objection mechanism
Where it usually falls short:
  • Sub-processors added without notice
  • List published once and never updated
Source: ISO/IEC 27018:2019
ISO/IEC 27018 A.10.1 Notification of a data breach involving PII

The public cloud PII processor should promptly notify the relevant cloud service customer in the event of any unauthorised access to PII or unauthorised access to processing equipment or facilities resulting in loss, disclosure or alteration of PII, within the period and with the content agreed in the contract, and should cooperate in the customer's response.

What an assessor asks to see:
  • Breach notification procedure with contractual timescales
  • Notification records
  • Evidence of cooperation with customer investigations
Where it usually falls short:
  • Breach determination left to the customer with no processor assessment
  • Notification sent after the customer's own regulatory deadline
Source: ISO/IEC 27018:2019
ISO/IEC 27018 A.11.12 Sub-contracted PII processing

Contracts between the public cloud PII processor and any sub-contractors that process PII should specify minimum technical and organisational measures that meet the information security and PII protection obligations of the processor, and such measures should not be subject to unilateral reduction by the sub-contractor.

What an assessor asks to see:
  • Sub-contractor agreements carrying the same minimum measures
  • Evidence the measures are verified
Where it usually falls short:
  • Sub-contractors engaged on their own standard terms
  • Flow-down clauses that omit PII obligations
Source: ISO/IEC 27018:2019
ISO/IEC 27018 A.12.1 Geographical location of PII

The public cloud PII processor should specify and document the countries in which PII can possibly be stored, so that the cloud service customer can assess whether the locations meet its legal and contractual obligations.

What an assessor asks to see:
  • Published or contractual list of countries where PII may be stored
  • Change notification when locations change
Where it usually falls short:
  • Locations stated for primary storage but not backups, support access or sub-contractors
  • Location list not updated when regions are added
Source: ISO/IEC 27018:2019