ISO 27018: What It Is & Why It Matters
ISO/IEC 27018 is a code of practice for protecting personally identifiable information in public cloud services, giving cloud providers guidance on handling personal data as processors.
In this explainer
- Understand what ISO/IEC 27018 covers and who it is aimed at
- Learn the privacy-focused themes it adds for the cloud
- Understand its relationship to broader privacy obligations
- See why personal-data cloud guidance matters for debtor data
- Know what to ask a vendor and how Merion approaches it
7 min
What it is
ISO/IEC 27018 is a code of practice for protecting personally identifiable information (PII) in public cloud services that act as data processors. Where ISO 27017 addresses cloud security generally, ISO 27018 narrows the focus to the privacy of personal data when a cloud provider processes it on behalf of a customer.
It is intended to give cloud providers a recognised set of expectations for handling personal data, and to give their customers a way to ask about those expectations. It supports, rather than replaces, the privacy laws that an organisation must already comply with.
Key principles
ISO 27018 brings privacy principles into the cloud context. The general themes include:
- Processing only as instructed — personal data is handled for the customer's purposes, not the provider's own.
- Transparency — being clear about where data may be processed and who may have access.
- Restrictions on use — not using personal data for unrelated purposes such as the provider's own marketing without consent.
- Support for individuals' rights — helping the customer respond to requests from the people whose data it is.
- Disclosure and return of data — handling government access requests appropriately and returning or deleting data when a service ends.
These themes echo broad privacy principles familiar from privacy law, expressed in a way that fits a cloud provider acting as a processor.
Why it matters for debt recovery
Debtor data is, almost by definition, personal information about identifiable people. When such data is processed in a public cloud, the privacy questions ISO 27018 addresses become directly relevant: is the data used only for the agreed purpose, is access controlled and transparent, and can individuals' rights be supported?
For a risk team, ISO 27018 complements an organisation's own privacy obligations. It does not discharge those obligations, but it offers a recognised reference for asking a provider how personal data is protected once it sits in the cloud, which is an area that general security questions can overlook.
What to ask a provider
Privacy-in-the-cloud questions worth raising include:
- Is personal data processed only on our instructions and for our purposes?
- Where may personal data be processed or stored, and who can access it?
- How do you avoid using personal data for unrelated purposes?
- How do you support requests from individuals, and how is data returned or deleted at the end of a service?
A provider that handles personal data thoughtfully will be comfortable answering these and will distinguish between its security controls and its privacy commitments. You can read about our broader approach to personal data on our privacy page.
How Merion approaches it
Merion aligns with the principles of ISO 27018 in how personal data is handled in cloud services: processing for agreed purposes, being transparent about access, and supporting the appropriate return or deletion of data.
This page is general information and not a claim that Merion holds any specific certification. Because arrangements and attestations change, please verify a provider's current certifications and privacy controls directly as part of your assessment.
Key takeaways
- ISO 27018 focuses on protecting personal data in public cloud services acting as processors
- It emphasises processing only as instructed, transparency and support for individuals' rights
- It complements, rather than replaces, an organisation's privacy law obligations
- Ask how personal data is used, accessed and returned, then verify current controls directly
Frequently asked questions
How does ISO 27018 differ from ISO 27017?
ISO 27017 addresses cloud security broadly, while ISO 27018 focuses specifically on protecting personal data in public cloud services. They are often considered together when personal data is processed in the cloud.
Does ISO 27018 replace privacy law?
No. It is a code of practice that supports compliance with privacy law by giving cloud providers recognised expectations for handling personal data. The underlying legal obligations still apply.
Why is this relevant to debt recovery?
Debtor data is personal information. When it is processed in the cloud, ISO 27018's themes, such as purpose limitation and transparency, speak directly to how that personal data is protected.
Security and compliance you can verify
Merion handles every account on the facts, within the rules, and with data protected by design. Ask us anything.