Skip to content

ISO 27018:2019

ISO 27018 certification online: Cloud Privacy by self-assessment

With the ISO 27018 certificate from Zertify, you demonstrate your management system online. ISO 27018 certification works by self-assessment: you receive the certificate within 4 hours and pay once, CHF 799. It is not an accredited certificate and does not replace an audit.

Questions
30
Validity
3 years
One-time price
CHF 799

01: Overview

What is ISO 27018?

ISO 27018:2019 is the first international standard that deals specifically with the protection of personally identifiable information (PII) in public cloud environments. It extends ISO 27001 with privacy-specific controls and helps cloud providers meet the requirements of the GDPR and other data protection laws. The standard strengthens customer trust in the privacy practices of cloud services.

02: Benefits

Your benefits

  • Evidence of GDPR compliance in the cloud
  • Protection of personal data in cloud environments
  • Trust among privacy-conscious customers
  • Clear data protection responsibilities
  • Competitive edge where privacy requirements apply
  • Complements ISO 27001 and ISO 27017

03: Who it is for

Who is ISO 27018 for?

  • Cloud service providers handling personal data
  • SaaS providers in the B2B and B2C sectors
  • Processors under the GDPR
  • Healthcare cloud providers
  • HR and payroll software providers
  • E-commerce platforms

04: Requirements

Key requirements

  1. Ensure transparency about data processing

  2. Ensure purpose limitation of data processing

  3. Enable deletion and return of PII

  4. Engage sub-processors in a privacy-compliant manner

  5. Carry out data protection impact assessments

  6. Ensure notification in the event of data breaches

05: Demand

Who asks for ISO 27018?

ISO 27018 is asked for by customers who put personal data into the cloud and are liable for it as controllers.

Controllers under GDPR and the Swiss FADP
Anyone who hands personal data to a cloud service has to choose the processor carefully. ISO 27018 documents its data protection practice.
HR, payroll and health data
Vendors of HR software, patient administration and payroll are asked about purpose limitation, deletion and subprocessors in tenders.
Privacy reviews and contract negotiations
Data protection officers and legal departments use the standard as a checklist for data processing agreements.

06: Cost

What does ISO 27018 cost? Audit, consulting or self-assessment

ISO 27018 is usually audited together with ISO 27001. The figures below therefore describe the surcharge for a cloud provider with 10 to 50 employees.

Indicative SME ranges compared: accredited audit, consulting and self-assessment
RouteIndicative rangeWhat is behind it
Accredited auditAs an extension of ISO 27001, CHF 2,000 to 5,000 on topThe surcharge comes from audit days for instruction binding, subprocessors and deletion. The cost of ISO 27001 certification is added if it is missing.
Consulting and implementationCHF 5,000 to 15,000 one-offPrivacy law support, record of processing, contracts with subprocessors and a deletion concept.
Zertify self-assessmentCHF 799 once, valid 3 yearsYou check whether instruction binding, subprocessors, deletion, encryption and breach notification are demonstrably settled. It does not replace an officially recognised data protection certification.

All amounts are non-binding indicative ranges for Swiss SMEs, not quotes. The offers of the individual providers are what counts.

07: Duration

How long does ISO 27018 take?

With an existing ISMS you add ISO 27018 in a few months, because mainly contracts and procedures have to be clarified.

Timeline: accredited route compared with the self-assessment
PhaseAccreditedZertify
Clarify data protection2 to 5 months for record of processing, subprocessors and deletion conceptNone. You rate the current state of your data protection
AssessmentExtra audit days within the ISO 27001 audit, samples from contracts and deletion evidenceAbout 20 to 30 minutes online, scored immediately
CertificateRelease after 2 to 6 weeks, valid within the ISO 27001 certification cyclePDF with QR verification within 4 hours

08: Sample questions

Sample questions from the ISO 27018 assessment

Four of 30 questions from the catalog, with the reason each one counts.

  1. Are controllers informed about all sub-processors used before those sub-processors process PII?

    Customers are liable for their processors. They need to know who sees their data before it happens.

  2. Is PII deleted completely and verifiably at the end of the contract or on the customer's instruction?

    At the end of the contract personal data must demonstrably disappear. A deleted database entry is not enough if copies remain.

  3. Is PII in the cloud encrypted both in transit and at rest?

    Encryption in transit and at rest is the baseline that customers and authorities expect.

  4. Are customers notified without undue delay (within the agreed period) about data breaches affecting their PII?

    After a data breach a notification deadline starts running for the customer. The earlier and more completely you inform, the better they can react.

09: Assessment

How the assessment works

The assessment consists of 30 yes/no questions. You answer them online, at your own pace. With 20 or more yes answers you pass.

The questions are grouped by these topics:
The questions are grouped by these topics:Questions
PII processing and purpose limitation5 questions
Transparency and sub-processors5 questions
Return and deletion of PII4 questions
Encryption and technical safeguards4 questions
Disclosure and government requests3 questions
Breach notification and incident response3 questions
Data subject rights and access3 questions
Governance and privacy management3 questions

10: Price

Price and validity

One-time price

CHF 799

Renewal after 3 years
CHF 479
Validity
3 years
Start assessment

What is included

  • Online assessment with 30 questions
  • Certificate as PDF, issued by SICE
  • QR code for public verification
  • 3 years of validity
  • Support by email

The certificate is based on a self-assessment. It is not an accredited certification. Read more in the FAQ

11: More standards

More standards

Many companies combine several standards. From two standards you get a discount.

  • ISO 27001:2022: View standard

    Information Security Management

    ISO 27018 extends the ISMS with data protection. Without ISO 27001, risk analysis and audits are missing.

    from CHF 849

  • ISO 27017:2015: View standard

    Cloud Security

    Security and privacy in the cloud belong together. ISO 27017 secures configuration and access, ISO 27018 the handling of personal data.

    from CHF 799

12: Questions

Frequently asked questions about ISO 27018

ISO 27018 certificate within 4 hours.

Start the assessment for free. You only pay after you pass.

The certificate is based on a self-assessment. It is not an accredited certification.