ISO 27018:2019
ISO 27018 certification online: Cloud Privacy by self-assessment
With the ISO 27018 certificate from Zertify, you demonstrate your management system online. ISO 27018 certification works by self-assessment: you receive the certificate within 4 hours and pay once, CHF 799. It is not an accredited certificate and does not replace an audit.
- Questions
- 30
- Validity
- 3 years
- One-time price
- CHF 799
01: Overview
What is ISO 27018?
ISO 27018:2019 is the first international standard that deals specifically with the protection of personally identifiable information (PII) in public cloud environments. It extends ISO 27001 with privacy-specific controls and helps cloud providers meet the requirements of the GDPR and other data protection laws. The standard strengthens customer trust in the privacy practices of cloud services.
02: Benefits
Your benefits
- Evidence of GDPR compliance in the cloud
- Protection of personal data in cloud environments
- Trust among privacy-conscious customers
- Clear data protection responsibilities
- Competitive edge where privacy requirements apply
- Complements ISO 27001 and ISO 27017
03: Who it is for
Who is ISO 27018 for?
- Cloud service providers handling personal data
- SaaS providers in the B2B and B2C sectors
- Processors under the GDPR
- Healthcare cloud providers
- HR and payroll software providers
- E-commerce platforms
04: Requirements
Key requirements
Ensure transparency about data processing
Ensure purpose limitation of data processing
Enable deletion and return of PII
Engage sub-processors in a privacy-compliant manner
Carry out data protection impact assessments
Ensure notification in the event of data breaches
05: Demand
Who asks for ISO 27018?
ISO 27018 is asked for by customers who put personal data into the cloud and are liable for it as controllers.
- Controllers under GDPR and the Swiss FADP
- Anyone who hands personal data to a cloud service has to choose the processor carefully. ISO 27018 documents its data protection practice.
- HR, payroll and health data
- Vendors of HR software, patient administration and payroll are asked about purpose limitation, deletion and subprocessors in tenders.
- Privacy reviews and contract negotiations
- Data protection officers and legal departments use the standard as a checklist for data processing agreements.
06: Cost
What does ISO 27018 cost? Audit, consulting or self-assessment
ISO 27018 is usually audited together with ISO 27001. The figures below therefore describe the surcharge for a cloud provider with 10 to 50 employees.
| Route | Indicative range | What is behind it |
|---|---|---|
| Accredited audit | As an extension of ISO 27001, CHF 2,000 to 5,000 on top | The surcharge comes from audit days for instruction binding, subprocessors and deletion. The cost of ISO 27001 certification is added if it is missing. |
| Consulting and implementation | CHF 5,000 to 15,000 one-off | Privacy law support, record of processing, contracts with subprocessors and a deletion concept. |
| Zertify self-assessment | CHF 799 once, valid 3 years | You check whether instruction binding, subprocessors, deletion, encryption and breach notification are demonstrably settled. It does not replace an officially recognised data protection certification. |
All amounts are non-binding indicative ranges for Swiss SMEs, not quotes. The offers of the individual providers are what counts.
07: Duration
How long does ISO 27018 take?
With an existing ISMS you add ISO 27018 in a few months, because mainly contracts and procedures have to be clarified.
| Phase | Accredited | Zertify |
|---|---|---|
| Clarify data protection | 2 to 5 months for record of processing, subprocessors and deletion concept | None. You rate the current state of your data protection |
| Assessment | Extra audit days within the ISO 27001 audit, samples from contracts and deletion evidence | About 20 to 30 minutes online, scored immediately |
| Certificate | Release after 2 to 6 weeks, valid within the ISO 27001 certification cycle | PDF with QR verification within 4 hours |
08: Sample questions
Sample questions from the ISO 27018 assessment
Four of 30 questions from the catalog, with the reason each one counts.
Are controllers informed about all sub-processors used before those sub-processors process PII?
Customers are liable for their processors. They need to know who sees their data before it happens.
Is PII deleted completely and verifiably at the end of the contract or on the customer's instruction?
At the end of the contract personal data must demonstrably disappear. A deleted database entry is not enough if copies remain.
Is PII in the cloud encrypted both in transit and at rest?
Encryption in transit and at rest is the baseline that customers and authorities expect.
Are customers notified without undue delay (within the agreed period) about data breaches affecting their PII?
After a data breach a notification deadline starts running for the customer. The earlier and more completely you inform, the better they can react.
09: Assessment
How the assessment works
The assessment consists of 30 yes/no questions. You answer them online, at your own pace. With 20 or more yes answers you pass.
| The questions are grouped by these topics: | Questions |
|---|---|
| PII processing and purpose limitation | 5 questions |
| Transparency and sub-processors | 5 questions |
| Return and deletion of PII | 4 questions |
| Encryption and technical safeguards | 4 questions |
| Disclosure and government requests | 3 questions |
| Breach notification and incident response | 3 questions |
| Data subject rights and access | 3 questions |
| Governance and privacy management | 3 questions |
10: Price
Price and validity
What is included
- Online assessment with 30 questions
- Certificate as PDF, issued by SICE
- QR code for public verification
- 3 years of validity
- Support by email
The certificate is based on a self-assessment. It is not an accredited certification. Read more in the FAQ
11: More standards
More standards
Many companies combine several standards. From two standards you get a discount.
- ISO 27001:2022: View standard
Information Security Management
ISO 27018 extends the ISMS with data protection. Without ISO 27001, risk analysis and audits are missing.
from CHF 849
- ISO 27017:2015: View standard
Cloud Security
Security and privacy in the cloud belong together. ISO 27017 secures configuration and access, ISO 27018 the handling of personal data.
from CHF 799
12: Questions
Frequently asked questions about ISO 27018
ISO 27018 certificate within 4 hours.
Start the assessment for free. You only pay after you pass.
The certificate is based on a self-assessment. It is not an accredited certification.