ISO/IEC 27018:2025
ISO/IEC 27018:2025 is a compliance framework from International with 5 domains and 46 controls. The largest domains are Annex A – Public cloud PII processor extended control set – ISO/IEC 27018:2025 (33 controls), Organizational controls – ISO/IEC 27018:2025 (6 controls), Technological controls – ISO/IEC 27018:2025 (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Annex A – Public cloud PII processor extended control set – ISO/IEC 27018:2025
| Code | Title |
|---|---|
| iso-iec-27018-2025::A.10.1 | Notification of a data breach involving PII |
| iso-iec-27018-2025::A.10.2 | Retention period for administrative security policies and guidelines |
| iso-iec-27018-2025::A.10.3 | PII return, transfer and disposal |
| iso-iec-27018-2025::A.11.1 | Confidentiality or non-disclosure agreements |
| iso-iec-27018-2025::A.11.10 | Records of authorized users |
| iso-iec-27018-2025::A.11.11 | Contract measures |
| iso-iec-27018-2025::A.11.12 | Sub-contracted PII processing |
| iso-iec-27018-2025::A.11.13 | Access to data on pre-used data storage space |
| iso-iec-27018-2025::A.11.2 | Restriction of the creation of hardcopy material |
| iso-iec-27018-2025::A.11.3 | Control and logging of data restoration |
| iso-iec-27018-2025::A.11.4 | Protecting data on storage media leaving the premises |
| iso-iec-27018-2025::A.11.5 | Use of unencrypted portable storage media and devices |
| iso-iec-27018-2025::A.11.6 | Encryption of PII transmitted over public data-transmission networks |
| iso-iec-27018-2025::A.11.7 | Secure disposal of hardcopy materials |
| iso-iec-27018-2025::A.11.8 | Unique use of user IDs |
| iso-iec-27018-2025::A.11.9 | User ID management |
| iso-iec-27018-2025::A.12.1 | Geographical location of PII |
| iso-iec-27018-2025::A.12.2 | Intended destination of PII |
| iso-iec-27018-2025::A.2.1 | Obligation to co-operate regarding PII principals' rights |
| iso-iec-27018-2025::A.3.1 | Public cloud PII processor's purpose |
| iso-iec-27018-2025::A.3.2 | Public cloud PII processor's commercial use |
| iso-iec-27018-2025::A.5.1 | Secure erasure of temporary files |
| iso-iec-27018-2025::A.6.1 | PII disclosure notification |
| iso-iec-27018-2025::A.6.2 | Recording of PII disclosures |
| iso-iec-27018-2025::A.8.1 | Disclosure of sub-contracted PII processing |
Organizational controls – ISO/IEC 27018:2025
| Code | Title |
|---|---|
| iso-iec-27018-2025::5.1 | Policies for information security |
| iso-iec-27018-2025::5.14 | Information transfer |
| iso-iec-27018-2025::5.16 | Identity management |
| iso-iec-27018-2025::5.2 | Information security roles and responsibilities |
| iso-iec-27018-2025::5.26 | Response to information security incidents |
| iso-iec-27018-2025::5.35 | Independent review of information security |
People controls – ISO/IEC 27018:2025
| Code | Title |
|---|---|
| iso-iec-27018-2025::6.3 | Information security awareness, education and training |
Physical controls – ISO/IEC 27018:2025
| Code | Title |
|---|---|
| iso-iec-27018-2025::7.14 | Secure disposal or re-use of equipment |
Technological controls – ISO/IEC 27018:2025
| Code | Title |
|---|---|
| iso-iec-27018-2025::8.13 | Information backup |
| iso-iec-27018-2025::8.15 | Logging |
| iso-iec-27018-2025::8.24 | Use of cryptography |
| iso-iec-27018-2025::8.31 | Separation of development, test and production environments |
| iso-iec-27018-2025::8.5 | Secure authentication |
What is ISO/IEC 27018:2025 and who does it apply to?
ISO/IEC 27018:2025 is a compliance framework from International with 5 domains and 46 controls. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 27018:2025 actually require?
ISO/IEC 27018:2025 has 46 controls organised across 5 domains. The largest domains are Annex A – Public cloud PII processor extended control set – ISO/IEC 27018:2025 (33 controls), Organizational controls – ISO/IEC 27018:2025 (6 controls), Technological controls – ISO/IEC 27018:2025 (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 27018:2025 do I already cover?
ISO/IEC 27018:2025 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement ISO/IEC 27018:2025?
Start your ISO/IEC 27018:2025 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27018:2025 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 46 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required