Draft standard
Product information on this site:
Quick delivery via download or delivery service
All transactions are encrypted
DIN EN ISO/IEC 27018 specifies measures for the protection of personally identifiable information (PII) in public cloud services. The standard is aimed at cloud providers that process personal data on behalf of their customers as processors and supplements the requirements of ISO/IEC 27001 and ISO/IEC 27002 with privacy-specific controls. It takes into account the privacy principles of the ISO/IEC 29100 Privacy Framework and supports privacy-compliant processing of personal data in public cloud environments.
The aim of the standard is to strengthen data protection in the cloud and information security, and to create transparent requirements for processing personal data in public cloud environments. In this way, it supports consistent cloud privacy and the trustworthy use of cloud computing.
DIN EN ISO/IEC 27018 describes organizational, technical and contractual measures for protecting personal data in public clouds. The focus is on transparency, purpose limitation, data minimization and support for data protection requirements.
Topics covered at a glance:
DIN EN ISO/IEC 27018 helps cloud providers demonstrate the protection of personal data in accordance with recognized international standards. It establishes clear requirements for cloud privacy, cloud compliance and privacy-compliant processing of personal data in public cloud environments.
The requirements relating to transparency, data security, privacy breaches, deletion concepts, and the handling of subcontractors and international data transfers are particularly relevant. In doing so, the standard incorporates the privacy principles of the ISO/IEC 29100 Privacy Framework and supports the trustworthy use of cloud computing.
Compared with the previous edition, the standard has been adapted to current requirements in the fields of data protection and cloud computing. The key areas include:
DIN EN ISO/IEC 27018 is a key standard for the protection of personal data in public clouds. It supplements existing information security standards with specific requirements for cloud privacy, transparency and privacy-compliant processing of personal data. By taking into account the privacy principles of the ISO/IEC 29100 Privacy Framework, it supports cloud providers and organizations in the secure and trustworthy use of cloud services.