Tag: ISO 27018 Certification

International standard that extends ISO 27001 with specific controls for the protection of personal data (PII) in public cloud environments. Defines requirements for cloud service providers on data processing transparency, purpose limitation, minimization, data subject rights, breach notification, geographical location, subprocessing, and secure deletion. Relevant for GDPR compliance and data processing contracts in SaaS, IaaS, and PaaS contexts.