ISO/IEC 27018 is the international standard for protecting personally identifiable information (PII) in public cloud environments where the provider acts as a PII processor. For cloud, SaaS and IT services organisations in Bengaluru, it demonstrates that customer data handled on your infrastructure is governed by documented, auditable privacy controls.
One point matters before anything else: ISO 27018 is not awarded as a standalone certificate. It is implemented and audited as an extension to ISO 27001, with its controls declared in your Statement of Applicability. An existing or concurrent ISO 27001 certification is the prerequisite.
What ISO 27018 Certification Covers
ISO/IEC 27018 sets out control objectives and implementation guidance for cloud service providers that process PII on behalf of their customers. It builds on the ISO/IEC 27002 control set and adds roughly 25 to 30 privacy-specific controls that address obligations a processor carries that a general information security standard does not cover.
The standard is currently in its third edition, ISO/IEC 27018:2025, published in August 2025. It replaces the 2019 edition, aligns the control structure with the restructured ISO/IEC 27002:2022, and adds a further annex of implementation guidance. Any Bengaluru organisation beginning implementation now should be working from the 2025 text rather than the superseded version. Core areas the standard governs:
- Consent and purpose limitation: PII is processed only for purposes the customer has specified, never for the provider’s own advertising or marketing without explicit consent.
- Transparency and disclosure: Sub-processors, processing locations and the circumstances under which data may be disclosed are documented and communicated.
- Data subject rights: Mechanisms exist to support access, correction and erasure requests passed down from the customer.
- Security controls: Encryption, access management, media handling and secure disposal are applied specifically to PII.
- Breach notification: Defined procedures and timelines for notifying the customer of incidents affecting their data.
- Return and deletion: PII is returned, transferred or securely deleted at the end of the contract on documented terms.
Is ISO 27018 a Standalone Certification?
No, and this is the most common misunderstanding organisations bring to the process. There is no separate accredited certification scheme for ISO 27018. Auditors assess the standard’s controls as part of an ISO 27001 certification audit, once those controls have been brought into scope through the Statement of Applicability.
In practice, this means one of two routes. Organisations already holding ISO 27001 extend their existing ISMS scope to include the 27018 controls, usually confirmed at the next surveillance or recertification audit. Organisations without ISO 27001 implement both together, treating 27018 as an additional control set inside a single certification project.
Certificates issued on completion typically reference ISO/IEC 27001 with ISO/IEC 27018 noted in the scope statement. Any provider offering a standalone “ISO 27018 certificate” with no ISO 27001 basis is worth questioning closely.
Why ISO 27018 Matters for Bengaluru Cloud and SaaS Companies
Bengaluru hosts a dense concentration of SaaS product companies, managed service providers, data centres and global capability centres, most of which process personal data belonging to customers headquartered elsewhere. In that relationship, the Bengaluru entity is almost always the processor rather than the controller, which is precisely the role for which ISO 27018 was written.

Three commercial pressures make the standard relevant here:
- Enterprise procurement. Security questionnaires from European, UK, US, and Singapore customers increasingly ask for cloud privacy assurance beyond ISO 27001—a certificate scope that names ISO 27018 —and for answers that address the question directly rather than through a bespoke response.
- Contractual flow-down. Controllers subject to GDPR, the UK Data Protection Act or Singapore’s PDPA must impose processor obligations by contract. Demonstrating certified alignment shortens both the negotiation and the customer’s own audit burden.
- Domestic regulation. India’s data protection framework now places explicit obligations on processors, which the next section covers.
ISO 27018 and India’s DPDP Rules 2025
The Digital Personal Data Protection Act, 2023 gained its operational detail when the Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 and gazetted the following day. The Rules are being introduced in phases, with consent manager registration opening from 13 November 2026 and the substantive obligations covering consent, notice and security safeguards taking effect on 13 May 2027.
The framework distinguishes the Data Fiduciary, which determines the purpose and means of processing, from the Data Processor, which processes data on the Fiduciary’s behalf. Bengaluru cloud and SaaS providers overwhelmingly occupy the second role. The Rules require appropriate security provisions in the contract between Fiduciary and Processor, which places a direct evidentiary burden on the processor to show what safeguards are actually in place.
ISO 27018 addresses much of that burden. Its controls on purpose limitation, sub-processor disclosure, breach notification, and the return or deletion of data at the end of the contract map closely onto the commitments a Data Fiduciary needs to secure from its processors. Implementing the standard ahead of the May 2027 deadline provides Bengaluru organisations with documented evidence rather than a contractual assertion.
ISO 27018 certification does not by itself constitute DPDP compliance, and no certification can. It provides a structured control framework that covers a substantial portion of the processor-side obligations.
ISO 27018 and CERT-In Directions
The CERT-In Directions issued on 28 April 2022 under Section 70B(6) of the Information Technology Act, 2000 took effect on 27 June 2022 and apply expressly to cloud service providers, data centres, VPS and VPN providers, intermediaries and body corporates. Two requirements are directly relevant to an ISO 27018 implementation:
The ISO 27018 Certification Process
The route to certification follows the ISO 27001 audit cycle, with the 27018 controls assessed alongside it.
1. Gap assessment
Current controls, contracts, and processing activities are reviewed against the ISO/IEC 27018:2025 control set, and the processor role is confirmed for each in-scope service.
2. Scope definition and Statement of Applicability
The services, locations and data flows to be covered are fixed, and the 27018 controls are formally declared in the SoA. This step is what makes the standard auditable.
3. Control implementation and documentation
Policies, sub-processor registers, consent and disclosure records, breach procedures and deletion workflows are built or amended to meet the standard.
4. Internal audit and management review
The implemented ISMS is tested internally, findings are closed, and management formally reviews readiness.
5. Certification audit
An accredited certification body conducts a Stage 1 documentation review followed by a Stage 2 implementation audit. ISO 27018 controls are examined within that audit.
6. Surveillance and recertification
Certificates are issued on a three-year cycle, with annual surveillance audits confirming continued conformity.
The typical duration for an organisation starting without an ISMS is four to nine months, depending on scope, headcount, number of sites, and the maturity of existing documentation. Organisations already certified to ISO 27001 can often add 27018 within a single surveillance cycle.
ISO 27018 Compared With Related Standards
Selecting the right standard, or combination, depends on the role your organisation plays in the data lifecycle.

Bengaluru cloud providers frequently implement ISO 27017 and ISO 27018 together, since the two cover complementary halves of the same environment. Organisations acting as controllers as well as processors, or handling personal data outside cloud services, generally find ISO 27701 the broader fit.
Documentation Required for ISO 27018
Auditors look for evidence that privacy commitments operate in practice rather than only on paper. The documentation set usually includes:
- Statement of Applicability with ISO 27018 controls declared and justified
- PII processing inventory covering categories, purposes and storage locations
- Sub-processor register with disclosure and approval records
- Customer contracts and data processing agreements reflecting processor obligations
- Consent, notification and data subject request procedures
- Incident response plan with breach notification timelines
- Log retention and monitoring records
- Secure deletion and data return procedures with completion evidence
- Internal audit reports, corrective actions and management review minutes
What Influences ISO 27018 Certification Cost in Bengaluru
Cost is quoted against scope rather than as a fixed figure. The principal variables are:
- Number of employees and sites within the certification scope
- Number and complexity of cloud services covered
- Whether ISO 27001 is already certified or being implemented in parallel
- Current maturity of documentation and existing controls
- The accredited certification body selected for the audit
- Whether ISO 27017 or ISO 27701 are pursued in the same project
Consultancy fees and certification body audit fees are separate. Consultants prepare the organisation and build the management system; only an accredited certification body can conduct the audit and issue the certificate.
ISO 27018 Consulting Support from GQS in Bengaluru
Global Quality Services is an ISO consulting and training firm headquartered in Bengaluru, with offices in Chennai, Mangalore, Hyderabad and Goa. GQS was among the first consultancies in India to receive approval from NABET and from NRBPT under the Quality Council of India.
Support for an ISO 27018 implementation covers:
- Gap assessment against the ISO/IEC 27018:2025 control set
- Scope definition and Statement of Applicability development
- PII processing inventory and sub-processor register build
- Policy, procedure and record documentation
- Internal auditor and awareness training
- Internal audit and management review facilitation
- Certification audit support and closure of findings
Because GQS also implements ISO 27001, ISO 27017 and ISO 27701, these standards are commonly integrated into a single project rather than run as separate exercises.
GQS operates as an implementation consultancy. The certification audit is conducted by an independent accredited certification body, which maintains the impartiality required by accreditation rules.
Frequently Asked Questions
Can we get ISO 27018 certification without ISO 27001?
No. ISO 27018 has no independent certification scheme. Its controls are audited within an ISO 27001 certification, so ISO 27001 must either already be in place or be implemented alongside it.
Which version of ISO 27018 should we implement?
ISO/IEC 27018:2025, published in August 2025, is the current edition and replaces ISO/IEC 27018:2019. Implementations beginning now should work from the 2025 text, which aligns with the ISO/IEC 27002:2022 control structure.
Is ISO 27018 mandatory in India?
No. It is a voluntary standard. Obligations under the DPDP Act 2023 and the DPDP Rules 2025 are mandatory, and ISO 27018 provides a control framework that supports a substantial portion of the processor-side requirements.
How long does ISO 27018 certification take in Bengaluru?
Four to nine months is typical for an organisation implementing an ISMS from the start. Organisations already holding ISO 27001 can often bring ISO 27018 into scope within a single surveillance cycle.
What is the difference between ISO 27017 and ISO 27018?
ISO 27017 covers information security controls for cloud services in general and applies to both providers and customers. ISO 27018 covers the protection of personally identifiable information specifically, and applies to the provider acting as a PII processor. They are complementary and frequently implemented together.










