731 901 601
ISO 27018 – protecting personal data in the cloud, step by step

ISO 27018 – protecting personal data in the cloud, step by step

An ever-increasing proportion of personal data is now processed and stored in cloud environments. Organisations use the cloud for its scalability, availability and cost-effectiveness, but this presents a significant challenge: how to ensure an adequate level of protection for personal data (PII – Personally Identifiable Information) in a model where the infrastructure and some processes are located outside the organisation?

The answer to these needs is ISO/IEC 27018 – an international standard that sets out the principles for the protection of personal data processed in the public cloud. It is an extension of ISO 27001 and focuses exclusively on the privacy and security of personal data in cloud services.

What is ISO 27018 and what data does it cover?

ISO 27018 is a code of practice for the protection of personal data in the cloud. This standard has been designed for cloud service providers who process data on behalf of their customers. In the context of this standard, personal data (PII) includes any information that can identify a natural person, such as:

  • first name and surname,
  • email address,
  • telephone number,
  • identification details (e.g. national identity number, passport number),
  • location data,
  • online identifiers (e.g. IP address, cookies in certain cases).

ISO 27018 does not operate independently – it is an extension of ISO 27001 and utilises its information security management system, adding requirements relating to privacy.

Key data protection principles according to ISO 27018

The ISO 27018 standard is based on several fundamental principles designed to enhance control over personal data in the cloud:

  1. data minimisation – processing only the data necessary to achieve the purpose,
  2. purpose limitation – data may only be used in accordance with the specified purpose,
  3. transparency – the user should know who is processing their data and to what extent,
  4. security of processing – the use of appropriate technical and organisational safeguards,
  5. control over data – the ability to manage consents and access to data,
  6. restriction on data sharing – no transfer of data without an explicit legal basis or consent.

ISO 27018 imposes specific obligations on cloud service providers acting as data processors. Their main tasks include:

ISO 27018 nakłada szczególne obowiązki na dostawców usług chmurowych, którzy pełnią rolę procesorów danych (data processors). Do ich głównych zadań należą:

  • protecting data against unauthorised access,
  • ensuring transparency in data processing,
  • assisting the client in fulfilling the rights of data subjects,
  • deleting or returning data once the service has ended,
  • refraining from using clients’ data for their own marketing purposes without consent.

This standard is closely linked to the GDPR, as it helps organisations meet its requirements in a cloud environment. In particular, it supports principles such as data minimisation, purpose limitation and the obligation to ensure an appropriate level of security.

The significance of ISO 27018 for organisations

ISO 27018 is of significant importance to organisations using cloud services, as it standardises the approach to the protection of personal data and introduces uniform rules for its processing. Above all, it reduces the risk of privacy breaches by clarifying how PII should be collected, stored and used. The standard also provides greater control over the entire data lifecycle – from the moment data is collected, through processing, to its deletion or return to the customer.

ISO 27018 also helps to clearly define responsibilities between the cloud service provider and the customer, which reduces the risk of misunderstandings and incorrect data processing. Furthermore, it helps to minimise the potential for unauthorised use of data by the provider and facilitates compliance with audit and regulatory requirements relating to the protection of personal data. As a result, organisations gain a more structured and predictable approach to data management in a cloud environment.

 

Read other posts

Key requirements of ISO 22716 – what must a cosmetics manufacturer comply with?

Key requirements of ISO 22716 – what must a cosmetics manufacturer comply with?

Implementing ISO 22716 involves much more than simply drawing up a set of procedures and instructions. It involves establishing a management system that covers every stage of a cosmetic product’s life cycle – from the receipt of raw materials to the dispatch of the finished product to the customer. read more
ISO 22716 and cosmetics exports – what do you need to know before entering foreign markets?

ISO 22716 and cosmetics exports – what do you need to know before entering foreign markets?

You have a finished product, a refined formula and the ambition to expand beyond the Polish market. Initial discussions with potential foreign partners are going well – until the question of GMP certification comes up. read more
EN 1090 – without this certificate, your welding shop cannot legally sell steel structures

EN 1090 – without this certificate, your welding shop cannot legally sell steel structures

If you manufacture steel or aluminium structures for the European market – industrial buildings, bridges, staircases, machine bases, load-bearing building components – the EN 1090 standard is not an option for you. read more
More posts