
ISO 27018
ISO/IEC 27018 is the code of practice for protecting personally identifiable information in the cloud. It builds on ISO 27001 and 27017 with privacy-specific controls. Sledge is not certified today.
ISO 27018 is on the Sledge roadmap. There is no report or assessment to share yet, and this page will say so until there is.
Why ISO 27018 is on the roadmap
ISO 27018 is the internationally recognized way to show that personal data in a cloud product is handled only as the customer instructed.
Never used for advertising
Personal data is processed to deliver the service, and for nothing else. This one is true today.
Only as instructed
The provider acts on the customer’s documented instructions when handling personal data.
Subprocessors disclosed
Any third party that touches personal data is named to the customer.
Breach notification
A stated commitment to timely notice if personal data is ever affected.
What it covers
ISO 27018 protects personal data processed in the cloud:
Run your back office on software you can vouch for
Independently assessed. No contracts. No setup fees.