International

ISO/IEC 27018:2025

46 controls. 0 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

46 controls 0 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

No measured overlap with another framework in the corpus.

Every control

CodeControlAlso in
5.1Policies for information security0
5.14Information transfer0
5.16Identity management0
5.2Information security roles and responsibilities0
5.26Response to information security incidents0
5.35Independent review of information security0
6.3Information security awareness, education and training0
7.14Secure disposal or re-use of equipment0
8.13Information backup0
8.15Logging0
8.24Use of cryptography0
8.31Separation of development, test and production environments0
8.5Secure authentication0
A.10Accountability0
A.10.1Notification of a data breach involving PII0
A.10.2Retention period for administrative security policies and guidelines0
A.10.3PII return, transfer and disposal0
A.11Information security0
A.11.1Confidentiality or non-disclosure agreements0
A.11.10Records of authorized users0
A.11.11Contract measures0
A.11.12Sub-contracted PII processing0
A.11.13Access to data on pre-used data storage space0
A.11.2Restriction of the creation of hardcopy material0
A.11.3Control and logging of data restoration0
A.11.4Protecting data on storage media leaving the premises0
A.11.5Use of unencrypted portable storage media and devices0
A.11.6Encryption of PII transmitted over public data-transmission networks0
A.11.7Secure disposal of hardcopy materials0
A.11.8Unique use of user IDs0
A.11.9User ID management0
A.12Privacy compliance0
A.12.1Geographical location of PII0
A.12.2Intended destination of PII0
A.2Consent and choice0
A.2.1Obligation to co-operate regarding PII principals' rights0
A.3Purpose legitimacy and specification0
A.3.1Public cloud PII processor's purpose0
A.3.2Public cloud PII processor's commercial use0
A.5Data minimization0
A.5.1Secure erasure of temporary files0
A.6Use, retention and disclosure limitation0
A.6.1PII disclosure notification0
A.6.2Recording of PII disclosures0
A.8Openness, transparency and notice0
A.8.1Disclosure of sub-contracted PII processing0

Tell me when ISO/IEC 27018:2025 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Provider media sanitisation and disposal procedure
  • Disposal or destruction records
  • Customer review of the provider's disposal statement
  • Media sanitisation and disposal procedure covering equipment that held PII
  • Disposal records
  • Evidence that reassigned storage is wiped or not readable

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO/IEC 27018:2025, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition