Skip to main content
ISO/IEC 27018

Certifications

ISO/IEC 27018

The ISO/IEC 27001 extension dedicated to personal data handled in public cloud: it defines how information relating to identifiable people must be protected.

What it is

ISO/IEC 27018 is a code of practice for those handling personal data in public cloud as a processor. It covers transparency about how data is used, limits on processing it for purposes other than those agreed, handling of data-subject requests, and deletion at the end of the engagement.

What it means for you

When a project handles personal data belonging to your customers or employees, we know where it resides, who can access it and how long it is retained. We do not use it for purposes outside the project, and there are defined return or deletion procedures at the end of the engagement. All of this sits alongside the obligations the GDPR already places on you as controller.

How we maintain it

We maintain the processing register for the projects we run, restrict access to personal data to staff who genuinely need it, agree retention periods with you, and formalise our role through a data processing agreement.

Frequently asked questions

Certificate details, the certification body and the exact scope of certification are available on request: get in touch and we'll send you the current documentation.

No. The GDPR is law and remains fully applicable; ISO/IEC 27018 is a voluntary standard providing operational controls consistent with its principles. Holding it makes the measures easier to demonstrate, but it does not change any legal obligation.

Ready to kick off the digital transformation of your business?

Talk directly with our technical lead.