// Privacy
ISO/IEC 27018 Cloud Privacy Compliance Software
Code of practice for protection of PII in public clouds.
Framework at a glance
Short name
ISO 27018
Version
—
Category
Privacy
Controls
25
What ISO 27018 covers
25 controls across 20 domains — every one tracked, owned and evidenced in Cyber Horizon.
Consent
1 controls- A.1 Consent and choice
Purpose Limitation
1 controls- A.2 Purpose legitimacy and specification
Data Minimisation
2 controls- A.3 Collection limitation
- A.4 Data minimisation
Retention
2 controls- A.5 Use, retention and disclosure limitation
- 5.12 Retention of PII
Data Quality
1 controls- A.6 Accuracy and quality
Transparency
1 controls- A.7 Openness, transparency and notice
Data Subject Rights
1 controls- A.8 Individual participation and access
Governance
2 controls- A.9 Accountability
- 5.6 Obligation of cloud service customer
Controls
1 controls- A.10 Information security
Legal
2 controls- A.11 Privacy compliance
- 5.5 Disclosure to law enforcement
Data Management
1 controls- 5.1 Return, transfer and disposal of PII
Disclosure
1 controls- 5.2 Disclosure of PII to third parties
Documentation
1 controls- 5.3 Records of PII disclosed to third parties
Third-Party
2 controls- 5.4 Notification re: sub-processors
- 5.8 Control of processing by sub-processors
Access Control
1 controls- 5.7 Access control for PII processing
Cryptography
1 controls- 5.9 Anonymisation and pseudonymisation
Testing
1 controls- 5.10 PII in testing
Data Handling
1 controls- 5.11 Temporary files
Breach Notification
1 controls- 5.13 Notification of PII breaches
Disposal
1 controls- 5.14 Cloud data return and deletion
How Cyber Horizon automates ISO 27018
Every ISO 27018 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is ISO/IEC 27018 Cloud Privacy?
Code of practice for protection of PII in public clouds.
How many controls does ISO/IEC 27018 Cloud Privacy have?
ISO/IEC 27018 Cloud Privacy has 25 controls in Cyber Horizon's catalogue, organised across 20 domains.
How does Cyber Horizon help with ISO/IEC 27018 Cloud Privacy?
Cyber Horizon maps ISO/IEC 27018 Cloud Privacy into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 27018 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
More Privacy frameworks
See ISO 27018 mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 27018 in Cyber Horizon.