Information security, cybersecurity and privacy protection - Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors (ISO/IEC 27018:2025); German and English version prEN ISO/IEC 27018:2026
new

Draft standard

DIN EN ISO/IEC 27018:2026-08 - Draft

Information security, cybersecurity and privacy protection - Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors (ISO/IEC 27018:2025); German and English version prEN ISO/IEC 27018:2026

German title
Informationssicherheit, Cybersicherheit und Datenschutz - Leitlinien zum Schutz personenbezogener Daten (PD) in öffentlichen Clouds, die als Auftragsverarbeiter für PD tätig sind (ISO/IEC 27018:2025); Deutsche und Englische Fassung prEN ISO/IEC 27018:2026
Date of issue
2026-07-03
Publication date
2026-08
Original language
German, English
Pages
95

from 143.40 EUR VAT included

from 134.02 EUR VAT excluded

Format and language options

PDF download
  • 143.40 EUR

Shipment (3-5 working days)
  • 183.30 EUR

Monitor with the Standards Ticker

This option is only available after login.
Easily subscribe: Save time and money now!

You can also subscribe to this document - together with other important standards in your industry. This makes your work easier and pays for itself after a short time.

Sparschwein_data
Subscription advantages
Sparschwein Vorteil 1_data

Important standards for your industry, regularly updated

Sparschwein Vorteil 2_data

Much cheaper than buying individually

Sparschwein Vorteil 3_data

Useful functions: Filters, version comparison and more

Date of issue
2026-07-03
Publication date
2026-08
Original language
German, English
Pages
95
Loading recommended items...

Quick delivery via download or delivery service

Buy securely with a credit card or pay upon receipt of invoice

All transactions are encrypted

About this product

What is DIN EN ISO/IEC 27018 about?

DIN EN ISO/IEC 27018 specifies measures for the protection of personally identifiable information (PII) in public cloud services. The standard is aimed at cloud providers that process personal data on behalf of their customers as processors and supplements the requirements of ISO/IEC 27001 and ISO/IEC 27002 with privacy-specific controls. It takes into account the privacy principles of the ISO/IEC 29100 Privacy Framework and supports privacy-compliant processing of personal data in public cloud environments.

The aim of the standard is to strengthen data protection in the cloud and information security, and to create transparent requirements for processing personal data in public cloud environments. In this way, it supports consistent cloud privacy and the trustworthy use of cloud computing.

What content does the standard cover?

DIN EN ISO/IEC 27018 describes organizational, technical and contractual measures for protecting personal data in public clouds. The focus is on transparency, purpose limitation, data minimization and support for data protection requirements.

Topics covered at a glance:

  • Protection of personally identifiable information (PII) in public clouds
  • Requirements for cloud providers acting as processors
  • Implementation of privacy principles according to the ISO/IEC 29100 Privacy Framework
  • Transparency, purpose limitation and data minimization in data processing
  • Data subject rights as well as deletion and return of data
  • Handling of privacy breaches and international data transfers 

Why is the standard relevant in practice?

DIN EN ISO/IEC 27018 helps cloud providers demonstrate the protection of personal data in accordance with recognized international standards. It establishes clear requirements for cloud privacy, cloud compliance and privacy-compliant processing of personal data in public cloud environments.

The requirements relating to transparency, data security, privacy breaches, deletion concepts, and the handling of subcontractors and international data transfers are particularly relevant. In doing so, the standard incorporates the privacy principles of the ISO/IEC 29100 Privacy Framework and supports the trustworthy use of cloud computing.

What changes have been made compared with the previous edition?

Compared with the previous edition, the standard has been adapted to current requirements in the fields of data protection and cloud computing. The key areas include:

  • Updated privacy-specific requirements for cloud services
  • Expanded provisions on transparency and information obligations
  • Greater consideration of privacy breaches and notification processes
  • Adjustments to current data protection and compliance requirements
  • Updated normative references and supporting guidelines

Target audience

  • Providers of public cloud services
  • Data protection officers and compliance managers
  • Information security officers
  • IT security managers
  • Auditors and certification bodies
  • Organizations with cloud-based personal data processing activities

Conclusion

DIN EN ISO/IEC 27018 is a key standard for the protection of personal data in public clouds. It supplements existing information security standards with specific requirements for cloud privacy, transparency and privacy-compliant processing of personal data. By taking into account the privacy principles of the ISO/IEC 29100 Privacy Framework, it supports cloud providers and organizations in the secure and trustworthy use of cloud services.

Content

ICS

35.030

Cooperation at DIN

Loading recommended items...