Cloud privacy

Protect personal information in public cloud services.

ISO/IEC 27018:2025 provides guidance for protecting personally identifiable information in public clouds when the provider acts as a processor. We help translate that guidance into owned technical and organizational practices.

Our implementation focus

Make the requirements operational.

  1. 01

    Clarify provider and customer roles and processing scope

  2. 02

    Map personal information flows and retention

  3. 03

    Implement access, disclosure, deletion, and transparency practices

  4. 04

    Set supplier oversight and incident coordination

  5. 05

    Align records with privacy management and cloud security controls

Independent assessment

ISO/IEC 27018 is guidance, not a substitute for applicable privacy law or an independent privacy assessment.

Questions we hear

Get the distinctions right.

Who is the primary audience for ISO/IEC 27018?

Public cloud providers acting as processors of personally identifiable information, and organizations that need to evaluate those services.

Does ISO/IEC 27018 establish GDPR compliance?

No. The guidance can support cloud privacy practices, but legal duties depend on the processing and jurisdiction and must be evaluated separately.

Work with Normstone

Build a defensible path to readiness.

Tell us the outcome you need and the markets involved. We’ll help define the work.

Start a conversation