ISO 27018 Singapore — PII Protection in the Cloud (ISO 27001 Extension)

ISO 27018 Singapore — PII Protection in the Cloud (ISO 27001 Extension)

ISO/IEC 27018 is the international code of practice for protecting personal data (PII) in public clouds — the standard a Singapore SaaS or cloud business presents when a customer asks “what happens to our people’s personal data on your platform?”. Like ISO 27017, it is not a standalone certificate: it certifies as an extension of your ISO 27001 ISMS, audited by the same certification body, often at your next surveillance audit. Sage Shield prepares the extension end to end — PII mapping, the additional privacy controls, customer-facing commitments and audit coordination — and it dovetails naturally with PDPA compliance work. We are an independent consultancy — we prepare your organisation; a SAC-accredited certification body certifies. We take no referral fees and do not lock you to any single auditor.

What is ISO 27018?

ISO/IEC 27018 (Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors) extends the ISO 27002 control set with privacy-specific implementation guidance and additional controls drawn from the ISO 29100 privacy principles. It is written for public cloud providers that process personal data on behalf of their customers — in practice, almost every SaaS product that stores names, emails, HR records, health data or customer lists.

Where ISO 27017 answers the security question about the cloud, ISO 27018 answers the privacy question: what you do and don’t do with the personal data your customers entrust to your platform.

Need a Legal Register for Your ISO Certification?

Stop maintaining spreadsheets. Our Legal Register platform covers 100+ Singapore legislation across 7 ISO standards — auto-updated, audit-ready.

Start Free Trial → See How It Works

The commitments ISO 27018 certifies

The additional controls translate into concrete, customer-facing commitments — the exact assurances enterprise procurement and data-protection teams ask for:

  • Customer data is processed only on the customer’s instructions — you act as a processor, not an owner.
  • No use of customer PII for advertising or marketing without explicit consent — and consent cannot be a condition of the service.
  • Transparency over sub-processors and locations — you disclose where PII is stored and which subcontractors touch it, before contracts are signed.
  • Disclosure requests are handled properly — law-enforcement requests for PII are notified to the customer unless legally prohibited, and logged.
  • Return, transfer and deletion — customers can get their PII back, and it is securely erased when the service ends or on request.
  • Breach notification — defined, prompt notification to the customer when their PII is affected, with the records to prove the process works.
  • Staff confidentiality and training — personnel handling PII are under confidentiality obligations and trained for it.

Who needs ISO 27018 certification in Singapore?

  • SaaS platforms processing customer personal data — HR and payroll systems, CRMs, edtech, healthtech, martech, booking and membership platforms.
  • B2B processors facing enterprise DPAs — if every enterprise deal comes with a data-processing agreement and a privacy questionnaire, 27018 is the certificate that pre-answers it.
  • Cloud businesses selling into regulated or MNC buyers — banks, insurers, healthcare groups and MNCs increasingly expect processor-side privacy assurance beyond a bare ISO 27001.
  • PDPA-conscious organisations — under Singapore’s PDPA, data intermediaries must make reasonable security arrangements for the personal data they process. ISO 27018 is strong, independently audited evidence of exactly that — and pairs naturally with our PDPA compliance and outsourced DPO services.

How ISO 27018 certifies — an extension of ISO 27001

ISO 27018 is a code of practice, so certification bodies do not issue a standalone “ISO 27018 certificate”. The privacy controls are added to the scope of your ISO 27001 certification: your Statement of Applicability is extended, the certification body audits the PII controls alongside your ISMS, and ISO 27018 is reflected on the certificate or in a statement of conformity. The practical consequences:

  • Already ISO 27001 certified? The extension can typically be assessed at your next surveillance audit — no separate certification cycle.
  • Going for ISO 27001 now? Build 27018 into the initial project — one audit, both outcomes.
  • Adding ISO 27017 too? The two extensions share scope, evidence and audit time; certifying them together is the norm for cloud businesses. See ISO 27017 Singapore.

ISO 27018 vs ISO 27701 vs PDPA — where each fits

FrameworkWhat it isBest when…
ISO 27018Cloud-processor PII controls, certified as an ISO 27001 extensionYou are a cloud/SaaS processor and buyers want audited assurance about their data on your platform — the fastest, lowest-cost privacy add-on to ISO 27001
ISO 27701A full Privacy Information Management System (PIMS) extending ISO 27001 — covers controller and processor roles across all processing, not just cloudYou need organisation-wide privacy management (both controller and processor obligations), e.g. for GDPR-heavy markets
PDPA complianceSingapore’s statutory baseline — DPO appointment, consent, protection and retention obligationsMandatory for every Singapore organisation regardless of certification; ISO 27018 evidences the protection obligation but does not replace the rest

Implementation roadmap — adding ISO 27018 to your ISMS

Stage 1 — PII scoping and gap assessment

Map what personal data your cloud service processes, for whom, where it is stored, and which sub-processors touch it. Assess current practice against the 27018 guidance and additional controls.

Stage 2 — Roles, contracts and customer commitments

Confirm your processor role per service, align customer contracts and DPAs with the 27018 commitments (instructions-only processing, no advertising use, sub-processor disclosure, return/deletion), and prepare the public-facing transparency statements.

Stage 3 — Extend the Statement of Applicability and documentation

Extend the SoA with the PII controls, update the risk assessment for privacy-specific risks, and refresh policies — data handling, retention and disposal, breach response, staff confidentiality.

Stage 4 — Implement and evidence the controls

Operationalise deletion and return procedures, disclosure-request logging, breach-notification workflow, sub-processor registers and staff training — with the records an auditor will sample.

Stage 5 — Internal audit and management review

Audit the extended scope internally and feed it into management review, using the ISMS cycle you already run.

Stage 6 — Certification body audit

Assessed at surveillance (existing certificate holders) or within Stage 2 (new certifications). We coordinate scope, dates and evidence with your certification body.

How Sage Shield delivers ISO 27018 consultancy

We run the extension as a compact project on top of your ISMS: PII and sub-processor mapping, contract and commitment alignment, SoA extension, control implementation and evidence, internal audit, and certification-body coordination through to the audit. Because the control set overlaps Singapore’s PDPA obligations, we frequently deliver ISO 27018 alongside PDPA programmes and DPO-as-a-Service — one body of evidence serving both the certificate and the statutory baseline. We prepare; a SAC-accredited certification body certifies.

ISO 27018 Singapore — frequently asked questions

Can I get ISO 27018 certified without ISO 27001?

No. ISO 27018 is a code of practice certified as an extension of an ISO 27001 ISMS. Without an existing certificate, the efficient route is one project delivering ISO 27001 with the PII controls built in — one audit cycle, both outcomes.

Does ISO 27018 make us PDPA compliant?

Not by itself. ISO 27018 is strong, audited evidence of the PDPA’s protection obligation for data intermediaries, but PDPA compliance also requires a DPO appointment, consent management, retention limitation and more. The two overlap heavily, which is why we usually deliver them together.

What is the difference between ISO 27018 and ISO 27701?

ISO 27018 is narrow and cloud-specific: PII protection by public cloud processors. ISO 27701 is a full privacy management system covering controller and processor roles across all processing. For a SaaS processor whose buyers ask about their data on the platform, 27018 is the faster, cheaper answer; 27701 suits organisation-wide privacy programmes.

Can ISO 27018 be added at my surveillance audit?

Usually yes — most certification bodies assess the extension at a scheduled surveillance audit via a scope extension, avoiding a new certification cycle. We confirm the mechanics with your certification body before the project starts.

Should we do ISO 27017 and ISO 27018 together?

If you are a cloud business processing personal data, almost always. The scoping, responsibility mapping and audit time overlap substantially, and together they answer both the security and privacy sections of enterprise vendor assessments in one audit.

Does Sage Shield issue the certificate?

No — Sage Shield is an independent consultancy. We prepare the extension and coordinate the audit; the certificate is issued by a SAC-accredited or otherwise IAF-recognised certification body of your choice. We take no referral fees.

What does ISO 27018 consultancy cost in Singapore?

It depends on how much personal data your service processes, your sub-processor chain, and whether you are extending an existing certificate or building a new ISO 27001 project. As a surveillance-audit extension it is highly cost-efficient — most of the system already exists. Contact us for a scoped proposal.

Get started with ISO 27018

Speak to an independent consultant about extending your ISO 27001 certificate with cloud privacy controls — or building ISO 27001, 27017 and 27018 into one certification project.

  • Phone: +65 8332 8220
  • Address: 261 Ponggol Seventeenth Avenue, Singapore 829711
  • WhatsApp: wa.me/6593859592

Related Sage Shield resources

Need a Data Protection Officer (DPO)?

Every Singapore organisation must appoint a DPO under the PDPA. Sage Shield can act as your named, registered outsourced DPO (DPO-as-a-Service) — fully managed PDPA compliance.

Related: ISO 27017 vs ISO 27018 — which cloud extension do you need?

Free
Consultation
Call Now WhatsApp
☍ Legal Register Platform — AI-Powered Compliance for 15 APAC Countries Try Free →