ISO/IEC 27018:2019
Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
PII Processor
Public cloud PII processor shall process PII only as instructed by the cloud service customer who is the PII controller or by the PII principal.
- Customer agreement clauses
- Processing instructions log
- Use restriction policy
- Audit trail
- Vague processing instructions
- Marketing use of PII
- No audit trail
PII shall be protected with appropriate technical and organizational measures consistent with risk.
- Risk assessment
- Control implementation evidence
- Pen test reports
- Encryption standards
- Risk assessment dated
- Encryption gaps
- No regular pen tests
De-activated or expired user IDs shall not be granted to other individuals.
- IAM provisioning standard
- User ID uniqueness control
- Audit log of ID reuse attempts
- IDs recycled in legacy systems
- No prevention control
- Manual provisioning errors
Contracts between the public cloud PII processor and its customers shall specify the allocation of responsibilities for the protection of PII.
- Shared responsibility model documentation
- Customer-facing responsibility matrix
- DPA addendum
- Onboarding materials
- Ambiguous responsibility allocation
- No customer-facing matrix
- Conflicting clauses across documents
Contracts between the public cloud PII processor and any subcontractors involved in PII processing shall specify equivalent measures for protection of PII.
- Subprocessor DPAs
- Flow-down clause register
- Subprocessor security assessment reports
- Annual subprocessor review
- Subprocessor with weaker controls
- No reassessment after material change
- Flow-down missing key clauses
The cloud PII processor shall ensure that whenever data storage space is assigned to a customer, any previous PII residing on that storage space is not accessible.
- Storage sanitization procedure
- Crypto-erasure standard
- Multi-tenant isolation design
- Hypervisor and storage zeroization controls
- Residual data on reused volumes
- No zeroization on storage release
- Snapshots not purged
Personnel processing PII shall be under confidentiality obligations recorded in writing.
- Signed confidentiality agreements
- Contractor agreements
- Training records
- Exit confirmation
- Contractors missing
- No exit confirmation
- Training not specific to PII
Creation of hardcopy materials containing PII shall be restricted and controlled.
- Print policy
- Pull-print logs
- Hardcopy register
- Destruction records
- No print policy
- Hardcopy not registered
- Destruction unverified
Restoration of PII from backups shall be controlled and logged.
- Restoration runbook
- Approval log
- Restore test records
- Audit trail
- No approval workflow
- Restores not logged
- Test restores skipped
PII on media leaving premises shall be subject to authorization and protective measures including encryption.
- Removable media policy
- Encryption enforcement
- Movement log
- Authorization records
- Unencrypted USB allowed
- No movement log
- Authorization informal
PII transmitted over networks shall be encrypted and integrity-protected.
- TLS configuration
- Cipher inventory
- API gateway settings
- Network test reports
- Weak ciphers enabled
- Internal traffic unencrypted
- No integrity controls
Disclosures of PII to third parties including law enforcement shall be logged and where lawful notified to the customer.
- Disclosure register
- Customer notification policy
- Legal review records
- Transparency reports
- No customer notification
- Register absent
- Legal review skipped
If more than one individual has access to stored PII, then they shall each have a distinct user ID for identification, authentication, and authorization.
- IAM standard prohibiting shared accounts
- User account inventory
- Shared account exception register
- Privileged access logs
- Shared admin accounts
- Service accounts used interactively
- No audit trail per user
An up-to-date record of users or profiles of users who have authorized access to information systems handling PII shall be maintained.
- User access register
- Role-to-access mapping
- Quarterly access review records
- Joiner/mover/leaver workflow logs
- Stale access for departed users
- No ownership of role definitions
- Access reviews missed
Customer shall be informed of countries in which PII is or may be stored or processed.
- Data location disclosure
- Region pinning configs
- Subprocessor list
- Audit reports
- Region drift
- No customer disclosure
- Subprocessor regions hidden
PII shall be transmitted only to destinations agreed with the customer.
- Data flow diagrams
- Egress controls
- Approved destination list
- Network policy
- No data flow diagrams
- Unapproved destinations
- Egress wide open
The processor shall have a policy on the disposal of PII when it is no longer required, including for backup copies.
- Data retention and disposal schedule
- Backup expiration configuration
- Disposal verification records
- Customer-facing retention commitments
- Backups never expire
- Disposal not verified
- Customer not informed of backup retention
Temporary files containing PII shall be identified and securely deleted within a documented period.
- Temp file inventory
- Automated purge configuration
- Purge job logs
- Periodic review records
- No identification of temp PII locations
- Failed cleanup jobs unnoticed
- Long-lived caches with PII
The cloud PII processor shall ensure that information transmissions are routed and protected in a manner appropriate to the sensitivity of the PII.
- Data classification standard
- Transmission control matrix
- Network segmentation design
- DLP egress monitoring
- No DLP on email egress
- Internal transmissions unencrypted
- Insufficient segmentation
The processor shall promptly notify the customer of any incident leading to loss, disclosure or alteration of PII.
- Breach notification SLA
- Notification templates
- Incident records
- Customer communications log
- No SLA
- Notification informal
- Customer comms missing
On termination the processor shall return or securely dispose of PII as instructed by the customer.
- Exit clause
- Deletion certificates
- Backup purge evidence
- Return logs
- Backups retain PII
- No deletion certificate
- Return method unclear
The public cloud PII processor shall be subject to periodic audits and reviews of its PII protection controls by an independent third party.
- ISO 27018 certification or attestation report
- Third-party audit reports
- Audit schedule
- Management response to findings
- Audit findings not remediated
- Lapsed certification
- No customer-facing report (SOC 2 or ISO bridge letter)
PII shall be processed only for the purposes specified by the customer and not used for the processor's own purposes.
- Purpose register
- Use case approvals
- Internal use prohibition policy
- Marketing opt-in records
- Telemetry uses PII
- No purpose register
- Marketing reuse without consent
The processor shall not collect PII beyond what is required for the agreed purpose.
- Data minimization review
- Field-level necessity analysis
- Schema documentation
- Change control records
- No minimization review
- Over-collection by default
- Schema drift
Temporary files and copies of PII shall be erased or destroyed in a defined period.
- Retention schedule
- Temporary file purge job logs
- Cache policy
- Deletion certificates
- Cache retains PII
- No purge jobs
- Backups out of scope
PII shall not be retained beyond the timeframe required to fulfil the agreed purpose unless required by law.
- Retention policy
- Deletion logs
- Legal hold register
- Customer-driven deletion workflow
- No customer-driven deletion
- Indefinite logs
- Legal holds without review
PII processed shall be accurate and up to date to the extent necessary for the purpose.
- Data quality controls
- Correction workflow
- Customer correction requests log
- Validation rules
- No correction workflow
- Customer can't correct via portal
- Validation absent
The processor shall provide the customer with information about the processing of PII including subcontractors and locations.
- Subprocessor list
- Data location disclosure
- Trust page
- Notification process for changes
- Subprocessor list stale
- No location disclosure
- No change notification
The processor shall provide means for the customer to fulfil PII principal rights including access, correction and deletion.
- DSAR support runbook
- Customer APIs for rights
- Response time SLA
- Closure records
- No DSAR API
- Manual fulfilment slow
- No SLA tracking
The processor shall assign roles to manage PII protection and demonstrate compliance.
- Privacy officer appointment
- Privacy program charter
- Compliance reports
- Audit evidence
- No privacy officer
- Program informal
- No external audit
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO/IEC 27018:2019 framework page.