Frameworks
ISO/IEC 27018 — PII Protection in Public Clouds
The cloud-processor privacy code of practice enterprise DPAs love to see.
Book a demoISO 27018 is the code of practice for protecting personal data as a public cloud processor: consent boundaries, no advertising use of customer data, disclosure transparency, and return/deletion commitments. It's the certification that makes data protection addendum negotiations shorter.
Processor promises, certified
Its controls read like the clauses in every DPA you've signed: process only on instructions, disclose subprocessors, notify on law-enforcement requests where allowed, purge data at contract end. Certifying against it converts contractual promises into audited practice.
How Compriska helps
Compriska maps 27018 controls into your existing ISMS, keeps the subprocessor register current in vendor management, and evidences the deletion and disclosure workflows auditors and customers both probe.
Frequently asked questions
ISO 27018 or ISO 27701 — which one?
27018 is narrower (PII as a public-cloud processor) and cheaper; 27701 is the full privacy management system covering controller duties too. Cloud processors often start with 27018 and grow into 27701.
Other frameworks
Automate ISO 27018 with Compriska
See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.
Book a demo