Skip to content
Cyber Horizon
All frameworks

// Privacy

ISO/IEC 27018 Cloud Privacy Compliance Software

Code of practice for protection of PII in public clouds.

Framework at a glance

Short name

ISO 27018

Version

Category

Privacy

Controls

25

What ISO 27018 covers

25 controls across 20 domains — every one tracked, owned and evidenced in Cyber Horizon.

Consent

1 controls
  • A.1 Consent and choice

Purpose Limitation

1 controls
  • A.2 Purpose legitimacy and specification

Data Minimisation

2 controls
  • A.3 Collection limitation
  • A.4 Data minimisation

Retention

2 controls
  • A.5 Use, retention and disclosure limitation
  • 5.12 Retention of PII

Data Quality

1 controls
  • A.6 Accuracy and quality

Transparency

1 controls
  • A.7 Openness, transparency and notice

Data Subject Rights

1 controls
  • A.8 Individual participation and access

Governance

2 controls
  • A.9 Accountability
  • 5.6 Obligation of cloud service customer

Controls

1 controls
  • A.10 Information security

Legal

2 controls
  • A.11 Privacy compliance
  • 5.5 Disclosure to law enforcement

Data Management

1 controls
  • 5.1 Return, transfer and disposal of PII

Disclosure

1 controls
  • 5.2 Disclosure of PII to third parties

Documentation

1 controls
  • 5.3 Records of PII disclosed to third parties

Third-Party

2 controls
  • 5.4 Notification re: sub-processors
  • 5.8 Control of processing by sub-processors

Access Control

1 controls
  • 5.7 Access control for PII processing

Cryptography

1 controls
  • 5.9 Anonymisation and pseudonymisation

Testing

1 controls
  • 5.10 PII in testing

Data Handling

1 controls
  • 5.11 Temporary files

Breach Notification

1 controls
  • 5.13 Notification of PII breaches

Disposal

1 controls
  • 5.14 Cloud data return and deletion

How Cyber Horizon automates ISO 27018

Every ISO 27018 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is ISO/IEC 27018 Cloud Privacy?

Code of practice for protection of PII in public clouds.

How many controls does ISO/IEC 27018 Cloud Privacy have?

ISO/IEC 27018 Cloud Privacy has 25 controls in Cyber Horizon's catalogue, organised across 20 domains.

How does Cyber Horizon help with ISO/IEC 27018 Cloud Privacy?

Cyber Horizon maps ISO/IEC 27018 Cloud Privacy into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 27018 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See ISO 27018 mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 27018 in Cyber Horizon.