Course description
This course provides comprehensive guidance on ISO/IEC 27018:2019, the international code of practice for the protection of personally identifiable information (PII) in public cloud environments. As an extension to ISO/IEC 27001 and ISO/IEC 27002, ISO 27018 specifically addresses privacy risks for cloud service providers (CSPs) that process PII on behalf of customers. Participants will learn how to implement cloud-specific privacy controls, fulfill legal and contractual obligations, and ensure trust and transparency in cloud-based personal data processing.
What You’ll Learn
By the end of the course, you will be able to:
-
Understand the structure, purpose, and applicability of ISO/IEC 27018:2019.
-
Identify and implement PII protection controls in public cloud environments.
-
Distinguish between ISO 27001, 27002, 27017, and 27018 and their privacy roles.
-
Define responsibilities between cloud service providers (processors) and customers (controllers).
-
Implement privacy-by-design and privacy-by-default principles in cloud services.
-
Ensure lawful processing of personal data in accordance with ISO and applicable regulations (e.g., GDPR).
-
Manage consent, purpose limitation, access control, and data retention for PII.
-
Address data breach notification and accountability requirements in cloud environments.
-
Provide transparency and control to data subjects and customers.
-
Prepare for privacy and cloud security audits or third-party certifications.
Who Should Attend
-
Cloud Compliance and Data Privacy Officers
-
Information Security Managers and CISOs
-
Cloud Service Providers (IaaS, PaaS, SaaS)
-
Legal and Risk Management Professionals
-
DPOs and GDPR/Privacy Consultants
-
IT and Cloud Governance Professionals
Recommendations
-
Familiarity with ISO/IEC 27001 and cloud computing environments is helpful
-
No prior ISO 27018 experience required
-
Highly recommended for organizations acting as data processors in public cloud platforms
Skills
-
ISO/IEC 27018 clause interpretation and control application
-
PII data lifecycle management in cloud settings
-
Processor-controller obligation mapping
-
Consent and privacy policy implementation
-
Data subject rights and transparency measures
-
Data breach readiness and response
-
Integration with ISO 27001, ISO 27017, and GDPR
-
Privacy risk assessment and mitigation
-
Audit preparation for cloud privacy compliance