⚡ Every Mutex Systems product starts at £0 — create an account and go live today. See pricing →
grComply Compliance Frameworks Security Awareness Training TiLedger FlowChat Pricing Partners Resources About Reviews Contact Sign in to grComply Sign in to TiLedger Sign in to FlowChat
grComply framework · Cloud privacy extension

ISO 27018 cloud privacy, PII controls you can actually evidence.

ISO/IEC 27018 sets out controls for protecting personally identifiable information (PII) processed by public cloud service providers — consent and purpose, sub-processor disclosure, secure erasure, and breach notification. grComply models each obligation as its own trackable control with a specific evidence requirement, complementing an ISO 27001 ISMS and ISO 27017 cloud-security controls in the same tree rather than living as separate policy text nobody revisits.

3 PII-control themes — deletion, disclosure, and breach notification, each with its own evidence requirement.
Back to all frameworks WhatsApp us
3PII-control themes
2019ISO revision seeded
PII processorScope
StructuralSeed depth

What is ISO/IEC 27018? ISO/IEC 27018 is a code of practice for protecting personally identifiable information (PII) processed by public cloud service providers acting as PII processors — covering consent, sub-processor disclosure, secure data handling, and breach notification specific to the cloud-processing context.

Why it's different

How grComply benefits your ISO 27018 programme

PII governance modelled as controls, not policy text

Consent/purpose, sub-processor disclosure, and principal-rights obligations are each their own trackable control.

Deletion and return SLAs become evidence, not a promise

Secure erasure/return of PII assets has a contractual-evidence requirement attached, not a clause nobody checks.

Breach notification playbook lives with other incident evidence

PII breach notification shares the same evidence model as a HIPAA or DORA breach-notification control.

Complements 27001 and 27017 in one tree

A cloud processor running an ISMS plus cloud-security controls adds cloud-privacy without starting a new system.

Sub-processor list stays current, not a static annex

Contract evidence versions the same way any other artefact does, so it doesn't quietly go stale.

Encryption evidence ties to real technical proof

Encryption of PII in transit and at rest is a distinct control, not a self-attested checkbox.

Structure

Three PII-control themes, seeded with real control language

Covers governance, security, and operational transparency for PII a cloud processor handles on a customer's behalf.

PII governance in cloud

Consent and purpose for processing public cloud PII, PII disclosed to sub-processors, and obligations to PII principals — the accountability layer.

PII security & data return

Secure erasure or return of PII assets, handling of temporary files containing PII, and encryption of PII in transit and at rest.

PII operations transparency

Logging and monitoring of PII processing, disclosure of PII to law enforcement, and data breach notification involving cloud PII.

Evidence, mapped

Evidence grComply already models for ISO 27018

Real evidence-requirement examples from the seeded control library — the same evidence types every other framework in grComply uses, not a bespoke process for this one.

ControlEvidence typeExample
PII-A.1 — Consent and purposePolicy documentProcessing purposes / records of processing (cloud PII)
PII-A.2 — Sub-processor disclosureContract documentSub-processor list and data processing agreements
PII-A.5 — Secure erasure / returnProcedure documentPII deletion / return procedure
PII-A.12 — Breach notificationNarrative documentCloud PII breach notification playbook

Why this matters: Cloud PII obligations tend to live in a DPA nobody re-reads after signing — modelling each obligation as its own evidenced control is what turns a contractual promise into something an auditor (or a customer's due-diligence team) can actually verify.

Product screens

ISO 27018, in the live workspace

The same grComply workspace shown across the platform — control browser, mapping, evidence, and AI assist apply identically to ISO 27018.

FAQ

ISO 27018 in grComply

What is ISO/IEC 27018?

ISO/IEC 27018 is a code of practice for protecting personally identifiable information (PII) processed by public cloud providers acting as PII processors — consent, sub-processor disclosure, secure handling, and breach notification specific to the cloud context.

Who needs ISO 27018?

Cloud service providers processing customer PII on behalf of another organisation (the PII controller), and organisations that want formal evidence their cloud processor meets these obligations.

How does grComply evidence PII deletion commitments?

PII-A.5's secure erasure/return control carries a contractual-evidence requirement — a documented deletion or return procedure with an SLA, not an assumed clause in a master agreement.

Does 27018 replace a Data Processing Agreement?

No — it's a control framework a processor's ISMS can be evidenced against; the DPA remains the legal instrument, and grComply's contract-document evidence type links the two.

Can ISO 27018 run alongside GDPR compliance work?

Yes — while GDPR itself is loaded separately (see the full Compliance Frameworks catalog), 27018's cloud-specific PII controls complement GDPR-driven programmes rather than duplicating them.

How does breach notification evidence work here?

PII-A.12's cloud PII breach notification playbook uses the same structured evidence model as incident-response controls in other frameworks, so it's not a separate, disconnected process.

Does grComply track sub-processor lists as living documents?

Yes — the sub-processor list and associated DPAs are versioned contract-document evidence, so an out-of-date list is visible rather than silently stale.

Can we run 27018 alongside 27017 and 27001?

Yes — all three load in the same control tree with cross-mapping, so a cloud processor's full obligation set (security, cloud security, cloud privacy) is evidenced once, not three times.

See ISO 27018 mapped into your control library

Powered by Mutex Systems. Back to Compliance Frameworks → · grComply overview → · Security Awareness Training →

Get in touch

Talk to us about ISO 27018

Tell us where your ISO 27018 programme stands today, and we'll route it to the right product specialist.

  • A product specialist replies personally — not a bot
  • No obligation after the first conversation
  • WhatsApp support also available 24/7

By submitting, you agree to be contacted about your enquiry. We respect your privacy.

Prefer to talk it through?

Book a meeting directly

Pick a time that works for you — 30 minutes with a product specialist, no sales script.

Ready to bring ISO 27018 into one control library?

We respond within one working day — or reach us instantly on WhatsApp.

WhatsApp us