Evaluate cloud privacy controls per ISO/IEC 27018:2019 for protection of Personally Identifiable Information (PII) in public cloud environments, complementing GDPR and HIPAA requirements
ISO 27018 Clause 5: Informed consent for PII collection and processing
Purpose limitation: Process PII only for specified, legitimate purposes
ISO 27018: Inform customers where PII is stored and processed geographically
Transparency: Clear communication of privacy practices to data subjects
GDPR Article 5(1)(c): Adequate, relevant, and limited to what is necessary
ISO 27018 & GDPR: Retain PII only as long as necessary
GDPR Article 25: Privacy by design - anonymization/pseudonymization
Accountability: Track who accessed, modified, or deleted PII
GDPR Article 15: Right of access to personal data
GDPR Article 16: Right to rectification of inaccurate personal data
GDPR Article 17: Right to erasure within 30 days (with legal exceptions)
GDPR Article 20: Right to receive PII in machine-readable format
ISO 27018: Strong encryption protects PII from unauthorized access
Protect PII during transmission between clients, cloud, and services
Key management: Separate keys from data, rotate regularly, limit access
ISO 27018 & GDPR Article 28: Transparency about downstream processors
GDPR Article 28(3): Bind subprocessors to same obligations as processor
GDPR Article 28(2): Prior notification or opportunity to object
GDPR Article 33: Notify supervisory authority within 72 hours of awareness
GDPR Article 33(2): Processor must inform controller immediately
Please answer all required questions to see your results