ISO/IEC 27018
Protect personal data in public clouds
The code of practice for protecting personally identifiable information (PII) in public clouds, for organisations acting as PII processors. Obligara instantiates the PII-processor controls grouped by the eleven ISO 29100 privacy principles, cross-mapped to ISO 27001 — so a privacy commitment becomes an evidenced control, not a policy statement.
~25
PII controls
11
privacy principles
Mapped
to ISO 27001
- PII-processor controls
- Grouped by privacy principle
- ISO 27001 cross-walk
- Evidence once

What’s in the module
Privacy for cloud PII processors
ISO 27018 sets the bar for handling personal data in a public cloud. Obligara instantiates its controls and maps them to your ISMS.
- 01
PII-processor controls
The Annex A controls a cloud PII processor must operate — consent, disclosure, and return and disposal of personal data.
- 02
Grouped by privacy principle
Organised around the eleven ISO 29100 privacy principles, so the story maps to how privacy teams think.
- 03
ISO 27001 cross-walk
Each control shows where an operating ISO 27001 control already covers it — extend your ISMS into privacy.
- 04
Evidence once
Shares the evidence store and audit trail with your security frameworks — no separate privacy silo.
How it runs
A privacy commitment, made evidenced
PII-processor controls
The Annex A controls a cloud PII processor must operate — consent, disclosure, and the return and disposal of personal data — instantiated and evidenced.
By privacy principle
Organised around the eleven ISO 29100 privacy principles, so the module maps to how a privacy team actually reasons about controls.
Extend your ISMS into privacy
Each control shows where an operating ISO 27001 control already covers it, so your security programme becomes a privacy programme without a separate silo.
See ISO 27018 on your controls
We’ll show the PII-processor controls, the privacy principles they map to, and how much your ISO 27001 already covers.