Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us

Governance, Risk & Compliance

ISO 27018: proving what you do not do with the data.

An ISO 27018 certification consultant is usually engaged for one commercial reason: a customer wants assurance that the personal data they hand to your cloud service will not be used for anything they did not agree to, and that they will be told if a government asks for it.

ISO 27018 is a code of practice for protecting personally identifiable information in public clouds where the provider acts as a processor. Its distinguishing controls are commitments rather than technologies: no use of customer PII for advertising or marketing without express consent, disclosure of sub-processors and the countries data may be processed in, notification of law-enforcement requests unless legally prohibited, and a documented return, transfer and disposal policy.

Because those commitments map directly onto processor obligations under GDPR and India's DPDP Act, certification does double duty. It is contractual assurance for customers and evidence for regulators. It is assessed as an extension of an ISO 27001:2022 ISMS, and pairs naturally with ISO 27017.

Why you need it

01 / 06

Why processors certify to ISO 27018.

01

Customers need assurance they can put in a contract.

Any organisation handing personal data to your platform is a controller with legal accountability for that transfer. Independent certification of your processor commitments is far more persuasive than the same promises in your own marketing.

02

Its controls are the processor obligations, restated.

Processing only on instruction, sub-processor transparency, breach notification, return and deletion, and assistance with data subject rights are simultaneously ISO 27018 controls and legal duties under GDPR Article 28 and the DPDP Act.

03

Transparency about disclosure is a differentiator.

The commitment to disclose which countries data may be processed in, and to notify customers of law-enforcement requests where the law permits, addresses the concern that dominates cross-border cloud procurement.

04

The privacy questions get answered once.

Certification converts a recurring, bespoke privacy review into a document, which shortens due diligence for every enterprise deal that follows.

Instrument

02 / 06

Where privacy obligations converge.

ISO 27018, GDPR and the DPDP Act ask overlapping questions. The overlap is the work you only have to do once.

What we deliver

03 / 06

What we deliver.

01

PII handling assessment

Where personal data enters your cloud environment, what happens to it, who can reach it, where it is replicated and how long it is kept, assessed against ISO 27018 and against the processor obligations you already carry.

02

Scope definition

Which services and environments are covered and, critically, where you act as processor and where as controller. The standard addresses public cloud processors; getting that boundary right determines what the certificate means to a customer.

03

PII control implementation

Encryption and key management, access restriction and logging for PII, secure disposal of media, restrictions on the creation of hardcopy, temporary file handling, and the data transmission controls the standard specifies.

04

Privacy commitments and policy

The documented commitments that distinguish the standard: no advertising use without express consent, sub-processor disclosure, geographic transparency about processing locations, law-enforcement disclosure notification, and the return, transfer and disposal policy.

05

Data subject rights support

The mechanisms by which your customers can meet their own obligations through you: access, correction and deletion requests passed through to the platform, with the timelines and interfaces to serve them.

06

Training and audit preparation

Training for the engineers and support staff who can reach customer PII, internal audit against the extended scope, and support through the certification body's assessment.

How we run it

04 / 06

Six stages.

  1. 01

    Assess current practices

    Gap analysis of PII handling against ISO 27018, including data mapping across the cloud environment. Existing ISO 27001:2022 and privacy programme coverage is credited so the gap is incremental.

    Weeks 1-3
  2. 02

    Define scope

    The boundaries of certification and your role in each processing relationship, documented so the certificate reads unambiguously to a customer reviewing it.

    Weeks 3-4
  3. 03

    Implement controls

    The PII-specific technical controls (encryption, access restriction, logging, disposal, transmission and temporary file handling) implemented in the live environment.

    Months 1-4
  4. 04

    Develop policies

    The privacy commitments documented and, where they affect customers, reflected in your data processing agreement and public documentation. A commitment that exists only in an internal policy is not the assurance a customer is buying.

    Months 2-4
  5. 05

    Train staff

    Anyone who can access customer PII (engineering, support, operations) trained on what the commitments mean for their daily work, particularly around access, export and disclosure.

    Month 4
  6. 06

    Audit and certify

    Internal audit, corrective action, and certification assessment alongside your ISO 27001:2022 audit.

    Months 5-7

Key benefits

05 / 06

What changes after.

Your processor commitments are independently verified

Which is materially more persuasive in an enterprise privacy review than the same statements made in your own documentation.

Regulatory evidence comes with it

The same controls evidence GDPR Article 28 processor duties and DPDP Act obligations, so one programme serves the customer and the regulator.

Data lifecycle is documented end to end

Where PII lives, who can reach it, how long it is kept, and how it is returned and deleted, answered from a record rather than reconstructed on request.

Tools we use

06 / 06

Named, and used on your engagement.

No “latest tech tools”. These are the ones your report will cite, alongside the manual work that a tool cannot do for you.

Standards

  • ISO/IEC 27018
  • ISO/IEC 27001:2022
  • ISO/IEC 27701
  • ISO/IEC 27017

Data discovery and mapping

  • Data flow mapping
  • Records of processing activities
  • Cloud data inventory

Technical controls

  • Cloud KMS and key inventory
  • Access logging and review
  • Secure deletion procedures

Customer-facing artefacts

  • Data processing agreement
  • Sub-processor register
  • Processing location disclosure

Mapping

  • GDPR Article 28
  • DPDP Act, 2023
  • ISO 27701 processor guidance

Why Aphelion

Shared

Four things you can check.

01

The work is done by people with names.

Darshap Nayak, formerly of KPMG, holds a master’s degree in cybersecurity and more than seven years in security operations. Jaimin Somani brings fifteen-plus years of academic and hands-on VAPT. Hemang Desai is an ICT network specialist from Australia. You will meet them, not a logo.

Meet the team
02

Evidence, not adjectives.

Every finding arrives with the reproduction steps, the affected asset and the fix, ranked by what it actually reaches in your environment, not by a CVSS number copied from a scanner. You get the report and the raw output, not a summary of a summary.

See how we test
03

Two offices, one practice.

Ahmedabad and Sharjah, working the same methodology on the same tooling. Indian data-residency requirements and UAE delivery are both ordinary here, and the AphelioNYX AD Pen-Test module runs entirely inside your perimeter when regulation says it must.

The platform
04

What we will not do.

Invent a statistic to make a slide land. Publish your name as a client without written permission. Print an award badge nobody awarded. Founded in 2024. We say so, and we attribute experience to the people who have it.

Ask us anything

100+ organizations secured

Across the globe, and across eight industries. We name a client only with their written permission.

  • Finance & Banking
  • Healthcare
  • Retail & E-commerce
  • Technology
  • SaaS
  • Hospitality
  • Manufacturing
  • Pharmaceuticals

AphelioNYX is SOC 2, ISO and GDPR compliant; attestations are available on request under NDA. We would rather hand you the report than print a badge.

Questions

FAQ

What clients ask about ISO 27018.

Does ISO 27018 apply to us if we are not a cloud provider?
The standard is written for public cloud providers acting as processors of personally identifiable information, so it fits SaaS platforms, managed service providers and hosting businesses most naturally. If you only consume cloud services, ISO 27017 and ISO 27701 are usually the better fit. Many SaaS companies are in scope without thinking of themselves as cloud providers: if customers upload personal data to your product, you are the processor the standard describes.
How does it relate to ISO 27701?
ISO 27018 is a focused code of practice for PII in public cloud processing. ISO 27701 is a full privacy information management system extending ISO 27001, covering both controller and processor roles across the whole organisation. If your concern is specifically the cloud service you operate, 27018 is proportionate. If you need an organisation-wide privacy management system that maps to GDPR comprehensively, ISO 27701 is the larger answer.
Is ISO 27018 enough to satisfy our EU customers on privacy?
No, and no certification does. It provides strong evidence for the processor-side security and transparency obligations under Article 28 and Article 32, which is a substantial part of what a controller will ask you to demonstrate. It does not address lawful basis, controller obligations, data protection impact assessments or the broader accountability requirements. Those need a GDPR programme of their own.
What exactly are we committing to?
The commitments that make the standard distinctive: not using customer personal data for advertising or marketing without express consent; disclosing your sub-processors and the countries in which data may be processed; notifying customers of law-enforcement requests for their data unless legally prohibited from doing so; documented return, transfer and disposal at the end of the relationship; and restricting and logging staff access to customer PII. They are real contractual undertakings, which is precisely why customers value them.
Can it be audited with our existing certification?
Yes, and that is the normal route. ISO 27017 and ISO 27018 are both assessed as extensions of an ISO 27001:2022 management system, typically at the same audit visit, and organisations offering a cloud service that handles personal data commonly hold all three. Doing them together is substantially cheaper than sequentially, because the evidence and the audit days overlap.

Forty-five minutes. Your environment, not a slide deck.

A personalised walkthrough and a free readiness assessment against the frameworks you are actually being asked for. Pick a time that suits you, or write to us. We reply within one business day.