NewThe AI Consultant plans and drafts your whole ISO 27001 cycle.Read more
Skip to content

ISO/IEC 27018

Protect personal data in public clouds

The code of practice for protecting personally identifiable information (PII) in public clouds, for organisations acting as PII processors. Obligara instantiates the PII-processor controls grouped by the eleven ISO 29100 privacy principles, cross-mapped to ISO 27001 — so a privacy commitment becomes an evidenced control, not a policy statement.

ISO 27018 · moduleISO 27018

~25

PII controls

11

privacy principles

Mapped

to ISO 27001

  • PII-processor controls
  • Grouped by privacy principle
  • ISO 27001 cross-walk
  • Evidence once
A team handling personal data on their computers

What’s in the module

Privacy for cloud PII processors

ISO 27018 sets the bar for handling personal data in a public cloud. Obligara instantiates its controls and maps them to your ISMS.

  • 01

    PII-processor controls

    The Annex A controls a cloud PII processor must operate — consent, disclosure, and return and disposal of personal data.

  • 02

    Grouped by privacy principle

    Organised around the eleven ISO 29100 privacy principles, so the story maps to how privacy teams think.

  • 03

    ISO 27001 cross-walk

    Each control shows where an operating ISO 27001 control already covers it — extend your ISMS into privacy.

  • 04

    Evidence once

    Shares the evidence store and audit trail with your security frameworks — no separate privacy silo.

How it runs

A privacy commitment, made evidenced

PII-processor controls

The Annex A controls a cloud PII processor must operate — consent, disclosure, and the return and disposal of personal data — instantiated and evidenced.

By privacy principle

Organised around the eleven ISO 29100 privacy principles, so the module maps to how a privacy team actually reasons about controls.

Extend your ISMS into privacy

Each control shows where an operating ISO 27001 control already covers it, so your security programme becomes a privacy programme without a separate silo.

See ISO 27018 on your controls

We’ll show the PII-processor controls, the privacy principles they map to, and how much your ISO 27001 already covers.