ucstoolkitucstoolkitucstoolkit

ISO/IEC 27018 Cloud Privacy Documentation Toolkit

$499.00 Was: $599.00

Shipping calculated at checkout.

Achieve alignment with ISO/IEC 27018:2025 with our comprehensive, ready-to-use documentation toolkit. Designed for cloud service providers, SaaS businesses, managed service providers, data centre operators, and any organisation that processes personal information in the cloud on behalf of its customers. This toolkit provides all the policies, procedures, forms, templates and registers required to implement a structured, standards-aligned cloud privacy programme — without starting from scratch.

DeliveryDownload immediately after purchase, delivered straight to your inbox
FormatFully editable DOCX / XLSX files
IncludesTemplates, procedures, manuals, registers and forms
Suitable forCloud providers, SaaS businesses and MSPs of all sizes
Secure CheckoutSafe & encrypted payment
Lifetime SupportHelp from our team anytime

What's included in our ISO/IEC 27018 Toolkit?

  • ✔
    ISO/IEC 27018:2025 required documents and templates, built on the third edition published 26 August 2025.
  • ✔
    Ready-to-use Word and Excel documents — all policies, procedures, forms, templates, and registers aligned to the ISO/IEC 27002:2022 control themes adopted by the third edition.
  • ✔
    74 template documents.
  • ✔
    Full coverage of all 25 controls of the Annex A public cloud PII processor extended control set.
  • ✔
    118-entry Statement of Applicability and a gap analysis workbook with a readiness dashboard.
  • ✔
    System Manual and landscape clause map included.

Documents

Select toolkit content to view documents

Product Description

  • Product Type: Digital Download
  • File Format: MS Word (.docx) & MS Excel (.xlsx)
  • Total Documents: 74
  • Delivery: Instant — direct to your email inbox

What Is ISO/IEC 27018?

ISO/IEC 27018 is the international standard for protecting personally identifiable information in public clouds where the provider acts as a PII processor. It provides cloud-specific guidance on the controls of ISO/IEC 27002 as they apply to personal data, plus an extended control set that addresses obligations arising only from the processor role — processing on customer instruction, disclosure of sub-processors and processing locations, assistance with individual rights, and the handling of legally binding requests for customer data.

The third edition, published on 26 August 2025, replaces the 2019 second edition. Its main change is structural: the text is now aligned to the four themes and 93 controls of ISO/IEC 27002:2022 rather than the fourteen-clause structure used previously. The Annex A extended control set for public cloud PII processors is retained, with 25 controls arranged under the privacy principles of ISO/IEC 29100, and a correspondence table to the 2019 edition is provided in Annex B.

Whether you are a SaaS provider answering enterprise due diligence, a managed service provider handling client data, or a cloud platform being asked where your support team works from and whether your staff can read customer records, ISO/IEC 27018 provides the recognised framework to demonstrate that you can answer those questions.

Please note: ISO/IEC 27018 is a code of practice and is not separately certifiable. It is audited as an extension to the scope of an ISO/IEC 27001 certification, and this toolkit is built to serve exactly that purpose.

What’s Included in Our ISO/IEC 27018 Documents

Our toolkit gives you every document needed to extend your information security management system to cover the personal data your customers place in your service — without starting from scratch. All documents are pre-built, clause-mapped, and ready to customise:

  • System Manual & Usage Guide: Get your team up and running quickly with a clear, practical Cloud PII Protection Manual that explains the third-edition structure, maps all 25 Annex A extended controls to the documents that implement them, and sets out a seven-phase implementation roadmap
  • Policies & Governance Documents: Define the intent, boundaries and direction of your cloud privacy programme from day one — including Cloud PII Protection Policy, PII Processing & Customer Instruction Policy, PII Principal Rights & Consent Support Policy, Data Minimization Retention & Disposal Policy, and Transparency Openness & Customer Notice Policy
  • Customer Instruction & Rights Documents: Establish that you process personal data on instruction rather than assumption — with an instruction intake and change procedure, source verification, a rights assistance procedure that routes individual requests back to the controller, and the registers that evidence both
  • Disclosure & Law Enforcement Documents: The documents nobody wants to write under pressure: a disclosure request handling procedure, a legal assessment form covering jurisdiction and non-disclosure orders, and a register that records refusals as well as disclosures
  • Sub-processor & Supply Chain Documents: Full due diligence package including a selection and due diligence procedure with risk tiering, a Sub-processor Due Diligence Questionnaire, a change notification and objection procedure, and a register that doubles as the source of your published sub-processor list
  • Technical Control Procedures: Complete operational suite covering encryption in transit and at rest, cryptographic key management with per-tenant keys, user ID lifecycle and unique identifiers, privileged access with just-in-time elevation, logging and monitoring of PII access, multi-tenancy segregation, storage reuse, and secure erasure of temporary files
  • Incident & Breach Documents: Privacy Incident Detection, Triage & Response Procedure with a severity matrix and characterisation set, PII Breach Notification Procedure with a jurisdiction deadline schedule, and a notification template built for phased disclosure
  • Return, Disposal & Restoration Documents: A return, transfer and disposal procedure with a seventeen-location data inventory checklist, a customer-facing disposal certificate that states backup expiry honestly, and a restoration control procedure that stops a restore silently undoing a deletion commitment
  • Registers & Logs: Seventeen live Excel workbooks — Master Document Register, PII Inventory & Data Flow Register, Risk Register, Statement of Applicability, Customer Instructions Register, Sub-processor Register, Disclosure Register, Rights Request Register, Incident & Breach Register, Retention & Disposal Schedule, Authorized Users Register, Data Restoration Log, Media & Hardcopy Register, Geographic Location & Transfer Register, Legal Requirements Register, Training Register, and a Privacy Regulation Cross-Reference Matrix
  • Contract & Transparency Templates: A processor annex clause set covering roles, instructions, sub-processing, breach notification, location and audit rights, plus a customer-facing transparency statement template that satisfies the Annex A disclosure obligations
  • Internal Assessment Tools: Gap Analysis & Implementation Workbook with a 118-control assessment, a 74-document tracker and a formula-driven readiness dashboard, structured around the questions certification auditors actually ask about a 27018 scope extension

Toolkit Documents by Clause

No. Clause Theme / Phase Document Title Type Format
1 Manual Manual & Usage Guide Cloud PII Protection Manual Manual Word
2 Manual Manual & Usage Guide Toolkit Documents by Clause (Clause Map) Document Word
3 Cl. 5.1 Governance & Policy Cloud PII Protection Policy Policy Word
4 Cl. 5.34 Governance & Policy PII Processing and Customer Instruction Policy Policy Word
5 Cl. 5.34 Governance & Policy PII Principal Rights and Consent Support Policy Policy Word
6 Cl. 5.33 Governance & Policy Data Minimization, Retention and Disposal Policy Policy Word
7 Cl. 5.5 Governance & Policy PII Disclosure and Law Enforcement Request Policy Policy Word
8 Cl. 5.19 Governance & Policy Sub-processor and ICT Supply Chain Privacy Policy Policy Word
9 Cl. 8.24 Governance & Policy Cryptography and Key Management Policy Policy Word
10 Cl. 5.15 Governance & Policy Access Control and User Identity Policy Policy Word
11 Cl. 7.10 Governance & Policy Storage Media, Hardcopy and Secure Disposal Policy Policy Word
12 Cl. 5.24 Governance & Policy Privacy Incident and PII Breach Notification Policy Policy Word
13 Cl. 5.34 Governance & Policy Transparency, Openness and Customer Notice Policy Policy Word
14 Cl. 5.31 Governance & Policy Geographic Location and Cross-Border Transfer Policy Policy Word
15 Cl. 5.33 Governance & Policy Documented Information and Records Control Policy Policy Word
16 Cl. 5.1 Organizational Cloud Privacy Risk Assessment and Treatment Procedure Procedure Word
17 Cl. 5.9 Organizational PII Inventory and Data Flow Mapping Procedure Procedure Word
18 Cl. 5.37 Organizational Customer Processing Instruction Intake and Change Procedure Procedure Word
19 Cl. 5.34 Organizational PII Principal Rights Assistance Procedure Procedure Word
20 Cl. 5.10 Organizational Restriction on Commercial and Secondary Use of PII Procedure Word
21 Cl. 5.5 Organizational PII Disclosure Request Handling and Recording Procedure Procedure Word
22 Cl. 5.19 Organizational Sub-processor Selection and Due Diligence Procedure Procedure Word
23 Cl. 5.22 Organizational Sub-processor Change Notification and Objection Procedure Procedure Word
24 Cl. 5.24 Organizational Privacy Incident Detection, Triage and Response Procedure Procedure Word
25 Cl. 5.5 Organizational PII Breach Notification Procedure Procedure Word
26 Cl. 5.11 Organizational PII Return, Transfer and Disposal Procedure Procedure Word
27 Cl. 5.16 Organizational User ID Lifecycle and Access Provisioning Procedure Procedure Word
28 Cl. 5.31 Organizational Geographic Location Disclosure and Transfer Assessment Procedure Procedure Word
29 Cl. 6.6 People Confidentiality and Non-Disclosure Agreement Procedure Procedure Word
30 Cl. 6.2 People Privacy Awareness and Role-Based Training Procedure Procedure Word
31 Cl. 7.9 Physical Storage Media Handling and Off-Premises Transport Procedure Procedure Word
32 Cl. 7.7 Physical Hardcopy Restriction and Secure Destruction Procedure Procedure Word
33 Cl. 8.10 Technological Secure Erasure of Temporary Files Procedure Procedure Word
34 Cl. 8.13 Technological Data Restoration Control and Logging Procedure Procedure Word
35 Cl. 8.24 Technological Encryption of PII in Transit and at Rest Procedure Procedure Word
36 Cl. 8.24 Technological Cryptographic Key Management Procedure Procedure Word
37 Cl. 8.2 Technological Privileged Access and Administrator Activity Control Procedure Procedure Word
38 Cl. 8.15 Technological Logging and Monitoring of PII Processing Procedure Procedure Word
39 Cl. 8.22 Technological Multi-Tenancy Segregation and Storage Reuse Procedure Procedure Word
40 Cl. 5.1 Forms & Templates Cloud Privacy Risk Assessment Form Form Word
41 Cl. 5.37 Forms & Templates Customer Processing Instruction Record Form Word
42 Cl. 5.34 Forms & Templates PII Principal Rights Assistance Request Form Form Word
43 Cl. 5.31 Forms & Templates PII Disclosure Request Assessment Form Form Word
44 Cl. 5.19 Forms & Templates Sub-processor Due Diligence Questionnaire Questionnaire Word
45 Cl. 5.26 Forms & Templates PII Breach Notification Template Template Word
46 Cl. 5.11 Forms & Templates PII Return, Transfer and Disposal Certificate Form Word
47 Cl. 8.13 Forms & Templates Data Restoration Authorisation and Log Form Form Word
48 Cl. 6.6 Forms & Templates Confidentiality and Non-Disclosure Agreement Template Agreement Word
49 Cl. 5.35 Forms & Templates Customer Audit Request and Response Form Form Word
50 Cl. 5.20 Forms & Templates Cloud Privacy Contract Clause Set (Processor Annex) Clause Set Word
51 Cl. 5.34 Forms & Templates Cloud Privacy Transparency Statement Template Template Word
52 Cl. 8.10 Forms & Templates Secure Erasure and Sanitisation Record Form Word
53 Cl. 5.35 Assessment & Review Customer Audit and Assurance Request Procedure Procedure Word
54 Cl. 5.35 Assessment & Review Internal Audit of Cloud Privacy Controls Procedure Procedure Word
55 Cl. 5.4 Assessment & Review Management Review and Continual Improvement Procedure Procedure Word
56 Cl. 5.31 Assessment & Review Privacy Legal and Regulatory Monitoring Procedure Procedure Word
57 Cl. 5.37 Registers & Logs Master Document Register Register (Excel) Excel
58 Cl. 5.9 Registers & Logs PII Inventory and Data Flow Register Register (Excel) Excel
59 Cl. 5.1 Registers & Logs Cloud Privacy Risk Register Register (Excel) Excel
60 — Registers & Logs Statement of Applicability Matrix Excel
61 Cl. 5.37 Registers & Logs Customer Processing Instructions Register Register (Excel) Excel
62 Cl. 5.19 Registers & Logs Sub-processor Register Register (Excel) Excel
63 Cl. 5.31 Registers & Logs PII Disclosure Register Register (Excel) Excel
64 Cl. 5.34 Registers & Logs PII Principal Rights Request Register Register (Excel) Excel
65 Cl. 5.24 Registers & Logs Privacy Incident and Breach Register Register (Excel) Excel
66 Cl. 5.33 Registers & Logs Retention and Disposal Schedule Register (Excel) Excel
67 Cl. 5.16 Registers & Logs Authorized Users and Unique ID Register Register (Excel) Excel
68 Cl. 8.13 Registers & Logs Data Restoration Log Register (Excel) Excel
69 Cl. 7.10 Registers & Logs Storage Media and Hardcopy Register Register (Excel) Excel
70 Cl. 5.31 Registers & Logs Geographic Location and Transfer Register Register (Excel) Excel
71 Cl. 5.31 Registers & Logs Privacy Legal and Regulatory Requirements Register Register (Excel) Excel
72 Cl. 6.3 Registers & Logs Privacy Training and Awareness Register Register (Excel) Excel
73 — Registers & Logs Privacy Regulation Cross-Reference Matrix Matrix Excel
74 — Registers & Logs Gap Analysis and Implementation Workbook Workbook Excel

How It Works

From Purchase to Implementation

  1. Select Your Toolkit: Choose the ISO toolkit that fits your organisation and objectives.
  2. Purchase & Download: Complete checkout and receive instant access to all documents via email.
  3. Customise: Edit the templates to match your services, sub-processors, processing locations and requirements.
  4. Implement: Follow the Manual and the gap workbook to deploy the system and start using it immediately.

Most organisations achieve full alignment and audit readiness within 4 weeks using our toolkits — compared to 3+ months when building documentation from scratch.

Why Buy from UCStoolkit

Reduce Implementation Time from 3 Months to 1 Month

Building ISO documentation from scratch takes significant time, expertise, and resources. Our pre-built, clause-mapped toolkits eliminate the research, drafting, and formatting work — so your team can focus on customisation and go live fast. Most customers are audit-ready within 4 weeks of purchase.

Built on the 2025 Third Edition — With the Annex Structure Verified

Most cloud privacy documentation on the market still maps to the 2019 edition and the withdrawn ISO/IEC 27002:2013 control set. Our toolkit is structured on the third edition throughout — the four ISO/IEC 27002:2022 themes and all 25 Annex A extended controls. We also checked the annex structure against the published contents page rather than secondary summaries, several of which incorrectly describe Annex B as extended implementation guidance when it is in fact the correspondence table to the 2019 edition.

Audit-Ready Documents — No Guesswork

Every document in our toolkits is structured with certification audits in mind. Content, terminology, and formatting are aligned directly to the relevant ISO standard’s clause requirements — reducing non-conformities, simplifying the audit process, and giving your team confidence when the assessor arrives.

Written for the Questions Customers Actually Ask

Where is our data, who else can reach it, can your staff read it, and can you prove a deletion reached the backups. The procedures answer those questions with step tables, named responsibilities, worked decisions and the common non-conformities raised in processor audits — not one-page outlines.

The Lowest Price on the Market — Guaranteed

UCStoolkit offers the most complete, expert-built ISO documentation packages at the lowest price available anywhere. You get enterprise-grade documentation at a fraction of what an ISO consultant would charge. If you find a comparable toolkit at a lower price, we’ll match it.

Not Sure Yet? Talk to Us

Not ready to buy? No problem. Our team is happy to answer your questions, walk you through the toolkit, or help you decide if it’s the right fit for your organisation — no pressure, no sales pitch.

Send Us a Message

📞 Melbourne: +61 460 766 472 | Dubai: +971 58 588 1553

📧 contact@ucstoolkit.store

⏱️ We respond within 24 hours

Frequently Asked Questions

What format are the documents in, and how are they delivered?

All documents are provided as fully editable MS Word (.docx) and MS Excel (.xlsx) files. After completing your purchase, you’ll receive an instant download link delivered directly to your email inbox — no waiting, no shipping.

Can I get certified to ISO/IEC 27018?

Not on its own. ISO/IEC 27018 is a code of practice rather than a requirements standard, so there is no separate certificate. It is audited as an extension to the scope of an ISO/IEC 27001 certification, and this toolkit is built to sit inside an existing ISO/IEC 27001 management system rather than alongside it. If you are not yet certified to ISO/IEC 27001, pair this toolkit with our ISO 27001 package.

What changed in the 2025 third edition?

The structure. The text moved from the fourteen-clause layout of the 2019 edition to the four themes and 93 controls of ISO/IEC 27002:2022. The Annex A public cloud PII processor extended control set is retained with its 25 controls, and a correspondence table to the 2019 edition has been added as Annex B. Note that several third-party summaries describe Annex B as extended implementation guidance — it is not, and our toolkit is built on the published structure.

We already hold ISO/IEC 27001. What does this add?

ISO/IEC 27001 asks whether information is protected. ISO/IEC 27018 asks whether you process personal data only on your customer’s instruction, whether you disclose where it is held and who else touches it, whether you can prove nobody browsed it, and whether you can demonstrate it was deleted. The Annex A extended control set covers exactly the ground a 27001 certificate does not — and it is what enterprise customers and their regulators ask about.

How long does it take to implement a toolkit?

Most organisations can customise and deploy a full toolkit within 3–4 weeks. This is a significant reduction compared to building documentation from scratch, which typically takes 3 months or more. The bulk of the effort sits in populating the registers rather than editing the documents.

Will these documents help us pass a certification audit?

Yes. Every document is structured to meet the clause requirements of its respective ISO standard and is designed to hold up under third-party assessment. Our customers consistently report fewer non-conformities and a smoother audit experience.

Does the toolkit apply if we are a SaaS company rather than an infrastructure provider?

Yes. The standard addresses any organisation processing personal data in a public cloud on behalf of a customer, whatever layer you operate at. Where a control is delivered by your infrastructure provider rather than by you, the toolkit shows you how to verify and evidence that through the sub-processor procedures rather than how to implement it yourself.

Does the toolkit cover GDPR and other privacy laws?

It is built around ISO/IEC 27018:2025 and includes a cross-reference matrix mapping requirement themes to GDPR, UAE PDPL, KSA PDPL, Qatar PDPPL, Singapore PDPA, Brazil LGPD and India DPDP, alongside a legal requirements register. Statutory references are bracketed for you to verify against current law in your jurisdictions. The toolkit is not legal advice.

Can we edit the templates to suit our organisation?

Absolutely. All documents are fully editable and built to be customised to your organisation’s specific context, processes, and terminology. The toolkit gives you the professional framework — you tailor the details.

Does the toolkit include a copy of the ISO standard itself?

No. ISO standards are protected by copyright and must be purchased separately from ISO or your national standards body. Our documents map to the published clause and control numbering of ISO/IEC 27018:2025, but the guidance text itself sits only in the standard. Organisations pursuing certification will need a licensed copy in any event.

Are the toolkits up to date with the current versions of the standards?

Yes. We monitor changes to international standards and update our toolkits accordingly, so you’re always working with accurate, current documentation recognised by accrediting bodies worldwide.

Are the documents compatible with standard software?

Yes. All documents are created in Microsoft Office (Word and Excel), ensuring compatibility with the latest versions of both applications. No specialist software is required.

What support is included after purchase?

Every purchase includes lifetime unlimited email support from our ISO-certified consultants. There is no time limit and no cap on questions — we support you through implementation and beyond.

Can I request a custom toolkit or a standard that isn’t listed?

Yes. We can build custom ISO documentation toolkits and training materials on request. Contact us with your requirements and our team will respond within 24 hours.

The documents are provided in digital formats, including Word and Excel files. They are available for download immediately after completing the payment process.

Purchasers receive lifetime unlimited email support from expert consultants to assist with any queries or guidance needed during implementation.

Absolutely. The toolkit provides all the necessary documentation and guidance to prepare for certification audits, reducing the likelihood of non-conformities.

Absolutely. All documents are editable and can be tailored to align with your organization's specific processes and requirements.

Yes. We keep a close eye on changes to international standards and update our toolkits as needed, ensuring you always have the latest, most accurate documentation recognized by accrediting bodies.

Yes, all documentation toolkits are created using Microsoft Office applications, ensuring compatibility and ease of editing with the latest versions of Microsoft Word and Excel.

Custom Product Request

We can create any ISO documentation toolkit or training material as per your request from our expert team. Contact us and share your inquiry details. Our team will get in touch with you within 24 hours.

Contact Us
Sunday,Monday,Tuesday,Wednesday,Thursday,Friday,Saturday
January,February,March,April,May,June,July,August,September,October,November,December
Not enough items available. Only [max] left.
Shopping cart

Your cart is empty.

Return To Shop

Add Order NoteEdit Order Note
Add A Coupon

Add A Coupon

Coupon code will work on checkout page

ISO/IEC 27018 Cloud Privacy Documentation Toolkit

$499.00Was: $599.00