
An ever-increasing proportion of personal data is now processed and stored in cloud environments. Organisations use the cloud for its scalability, availability and cost-effectiveness, but this presents a significant challenge: how to ensure an adequate level of protection for personal data (PII – Personally Identifiable Information) in a model where the infrastructure and some processes are located outside the organisation?
The answer to these needs is ISO/IEC 27018 – an international standard that sets out the principles for the protection of personal data processed in the public cloud. It is an extension of ISO 27001 and focuses exclusively on the privacy and security of personal data in cloud services.
ISO 27018 is a code of practice for the protection of personal data in the cloud. This standard has been designed for cloud service providers who process data on behalf of their customers. In the context of this standard, personal data (PII) includes any information that can identify a natural person, such as:
ISO 27018 does not operate independently – it is an extension of ISO 27001 and utilises its information security management system, adding requirements relating to privacy.

The ISO 27018 standard is based on several fundamental principles designed to enhance control over personal data in the cloud:
ISO 27018 nakłada szczególne obowiązki na dostawców usług chmurowych, którzy pełnią rolę procesorów danych (data processors). Do ich głównych zadań należą:
This standard is closely linked to the GDPR, as it helps organisations meet its requirements in a cloud environment. In particular, it supports principles such as data minimisation, purpose limitation and the obligation to ensure an appropriate level of security.
ISO 27018 is of significant importance to organisations using cloud services, as it standardises the approach to the protection of personal data and introduces uniform rules for its processing. Above all, it reduces the risk of privacy breaches by clarifying how PII should be collected, stored and used. The standard also provides greater control over the entire data lifecycle – from the moment data is collected, through processing, to its deletion or return to the customer.
ISO 27018 also helps to clearly define responsibilities between the cloud service provider and the customer, which reduces the risk of misunderstandings and incorrect data processing. Furthermore, it helps to minimise the potential for unauthorised use of data by the provider and facilitates compliance with audit and regulatory requirements relating to the protection of personal data. As a result, organisations gain a more structured and predictable approach to data management in a cloud environment.