> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ISO 27018:2019

> Protect personally identifiable information (PII) in public cloud environments.

> Protect personally identifiable information (PII) in public cloud environments.

ISO/IEC 27018 is a code of practice for protecting personally identifiable information (PII) in public clouds acting as PII processors. It builds on ISO 27002 with privacy-specific controls for cloud service providers handling personal data on behalf of their customers.

<Note>
  ISO 27018 is implemented alongside ISO 27001 and is especially relevant for cloud providers that process personal data for their customers.
</Note>

## Who needs ISO 27018:2019?

<CardGroup cols={2}>
  <Card title="Public cloud providers" icon="cloud">
    Cloud processors handling PII on behalf of customers who want to demonstrate privacy protection.
  </Card>

  <Card title="Privacy-conscious buyers" icon="user-shield">
    Customers selecting cloud vendors that can prove strong PII handling practices.
  </Card>
</CardGroup>

## Key components

<CardGroup cols={3}>
  <Card title="PII processor controls" icon="server">
    Controls specific to organizations processing PII in the cloud on behalf of others.
  </Card>

  <Card title="Consent and choice" icon="square-check">
    Ensures PII is processed according to customer instructions and consent.
  </Card>

  <Card title="Transparency" icon="eye">
    Disclosure of sub-processors and data handling practices to customers.
  </Card>

  <Card title="Data return and deletion" icon="trash">
    Controls for returning and securely deleting PII at the end of a contract.
  </Card>
</CardGroup>

## How DSALTA helps with ISO 27018:2019

<Steps>
  <Step title="Activate ISO 27018">
    Select ISO 27018 alongside your ISO 27001 ISMS. DSALTA maps PII protection controls.
  </Step>

  <Step title="Review PII controls">
    Review cloud PII processor controls and assign owners.
  </Step>

  <Step title="Collect evidence automatically">
    Connect integrations to gather privacy and security evidence.
  </Step>

  <Step title="Approve policies">
    Review and approve PII handling and sub-processor policies.
  </Step>

  <Step title="Prepare for audit">
    Share evidence with your certification body.
  </Step>
</Steps>

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Is ISO 27018 certifiable on its own?" icon="certificate">
    No. Like 27017, it extends ISO 27001 and is assessed as part of that certification scope.
  </Accordion>

  <Accordion title="Does 27018 satisfy GDPR?" icon="globe">
    It supports GDPR compliance for cloud processors but does not replace GDPR obligations.
  </Accordion>
</AccordionGroup>

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Available Frameworks](/guides/compliance/frameworks-available)
* [Controls](/guides/compliance/controls)
* [Audits](/guides/compliance/audits)
