Code of practice for protecting PII in public clouds
ISO/IEC 27018
ISO/IEC 27018 is the code of practice for protection of Personally Identifiable Information (PII) in public clouds acting as PII processors. It adds cloud-specific PII safeguards on top of ISO/IEC 27002, covering consent and choice, purpose limitation, transparency, and the handling of customer data by cloud service providers.
For organizations processing PII as a cloud processor on AWS, Azure, GCP, or OCI, ISO/IEC 27018 sets expectations around data handling, access, and transparency. Cloudanix continuously validates the security controls that support these safeguards and evidences them for certification.