ISO 27018 Certification in Malaysia – Cloud PII Protection & PDPA Requirements
SCS Certification – Malaysia Office
SCS Certification
Jalan Pinang
50450 Kuala Lumpur
Malaysia
Phone: +60 11 6263 6611
Enquiry: Contact SCS Certification
https://scscertification.com/contactus.php
A Malaysian company running a cloud platform may be doing everything right from a security perspective and still face difficult questions from customers about personal information.
Where is customer data stored? Who can access it? What happens when a contract ends? Which subcontractors can see the information? How is personal information deleted? What happens if there is a privacy incident?
These questions become particularly relevant for public-cloud providers, SaaS companies, managed service providers, BPO organizations and other businesses processing personally identifiable information (PII) for customers.
ISO/IEC 27018:2025 addresses this particular environment. The standard provides guidance for protecting PII in public-cloud services where the cloud service provider acts as a PII processor. The current edition was published in August 2025 and replaced the withdrawn 2019 edition. ISO also states that ISO 27018 complements an ISO 27001-based Information Security Management System (ISMS).
For Malaysian organizations, there is another layer to consider. The Personal Data Protection Act 2010 (Act 709), the Personal Data Protection (Amendment) Act 2024 and related regulatory guidance form part of Malaysia's personal-data protection framework. ISO 27018 does not replace these legal obligations.
That distinction matters when a Malaysian organization is deciding whether ISO 27018 is appropriate and what kind of independent assessment or assurance it actually needs.
What Is ISO/IEC 27018:2025?
ISO/IEC 27018:2025 provides guidance for protecting personally identifiable information in public-cloud services when the cloud provider acts as a PII processor.
It is built on the ISO/IEC 27002 control framework and adapts security and privacy considerations to the public-cloud environment. ISO says the 2025 edition has been aligned with ISO/IEC 27002:2022 and includes additional implementation guidance.
The standard is concerned with practical questions surrounding cloud-based PII processing, including:
-
How customer PII is handled
-
Who is authorized to access it
-
How processing instructions are managed
-
How information is stored and transmitted
-
How subcontractors are controlled
-
What happens to information when services end
-
How privacy-related incidents are handled
-
How transparency and accountability are maintained
The focus is narrower than a general information-security management system.
A cloud provider may have a mature security programme, for example, but still need to explain its approach to customer PII processing. ISO 27018 provides guidance specifically for that part of the environment.
Why ISO 27018 Matters to Malaysian Cloud Providers
For a cloud provider, privacy questions often appear during the sales process rather than after a security incident.
A large Malaysian enterprise customer might ask for evidence of security and privacy controls before approving a SaaS or cloud contract. An overseas customer may have its own supplier questionnaire. A procurement team may ask how data is deleted after termination. Another customer may want to know whether subcontractors are involved.
The provider needs consistent answers.
ISO 27018 can help organize the underlying controls and responsibilities so that privacy is addressed as part of the cloud service rather than through ad-hoc responses to individual customers.
ISO identifies several benefits, including clearer responsibilities between cloud providers and customers, support for legal and contractual obligations, transparency and accountability in PII processing, and stronger customer confidence.
For Malaysian businesses competing for enterprise and international customers, that practical assurance can be more useful than simply displaying another standards logo.
ISO 27018 and Malaysia's Personal Data Protection Act 2010
Malaysia's Personal Data Protection Act 2010, commonly referred to as Act 709, regulates the processing of personal data in commercial transactions and protects the interests of data subjects. The Personal Data Protection Department publishes the Act, associated regulations, standards, guidelines and sector-specific codes of practice.
ISO 27018 and the Malaysian PDPA have different roles.
The PDPA is Malaysian legislation.
ISO 27018 is international guidance for protecting PII in public-cloud processing.
A cloud provider should therefore avoid treating ISO 27018 as a substitute for legal compliance.
Instead, the organization can use ISO 27018 to strengthen the controls surrounding its public-cloud PII processing while separately identifying the Malaysian legal requirements that apply to its activities.
This is especially important where the organization provides services to different types of customers or operates across more than one jurisdiction.
ISO 27018 and Malaysia's Personal Data Protection Amendment Act 2024
Malaysia's Personal Data Protection (Amendment) Act 2024 amended the principal Act and introduced changes to the country's personal-data protection framework. The official legislation includes changes to terminology, including the replacement of references to “data user” with “data controller” in specified provisions.
The Malaysian regulator has subsequently published guidance and circulars dealing with areas such as data-breach notification, Data Protection Officers, data-controller registration and Data Protection Impact Assessments.
For a cloud provider, this makes it worthwhile to examine the complete processing relationship rather than focusing on the ISO standard alone.
Questions worth asking include:
-
What role does the organization perform?
-
Whose PII is being processed?
-
What instructions govern that processing?
-
Which suppliers or subprocessors are involved?
-
Where does processing take place?
-
What happens to information when the customer terminates the service?
-
How are privacy incidents identified and handled?
ISO 27018 can support the control side of these questions. The organization's Malaysian legal obligations still need to be assessed separately.
Who Should Consider ISO 27018 in Malaysia?
ISO 27018 is most relevant to organizations involved in public-cloud PII processing, particularly where the provider is acting as a processor for customers.
That can include:
-
Cloud service providers
-
SaaS companies
-
Managed cloud providers
-
Hosting and data-centre service providers
-
IT service providers
-
BPO and shared-service organizations
-
Fintech technology companies
-
Healthcare technology providers
-
E-commerce platforms
-
Digital-service businesses
-
Telecommunications and technology companies
The fact that a company uses cloud computing does not automatically mean ISO 27018 is the right standard.
The better question is whether its public-cloud service processes PII for customers and whether customers, contracts or business objectives require evidence of appropriate PII protection.
ISO 27018 for Malaysian SaaS Providers
A SaaS provider can sit between the customer and several layers of cloud infrastructure.
For example, a Malaysian HR platform might store employee information for dozens of corporate customers. The SaaS provider may operate the application itself while relying on a public-cloud infrastructure provider underneath.
That arrangement creates several control questions.
Who can access customer records? How are privileged accounts managed? What happens when a customer closes its account? Are support engineers permitted to access production data? Which external providers are involved?
ISO 27018 provides guidance relevant to these PII-processing relationships.
The focus here is different from a general SaaS security programme. SCS already has separate content covering ISO 27001 for SaaS organizations and broader information-security management.
This Malaysia-specific ISO 27018 page should therefore remain focused on PII processing in the public-cloud service, rather than becoming another general SaaS cybersecurity article.
ISO 27018 for Malaysian Fintech Businesses
Fintech companies can process substantial amounts of customer information through cloud applications.
Depending on the service, this may involve customer account information, contact details, identity-related information, application records and transaction-related information.
A fintech company outsourcing part of its cloud environment should understand exactly which organization is processing which information and under what contractual arrangements.
ISO 27018 can provide useful cloud-privacy guidance where the relevant public-cloud provider is acting as a PII processor.
It does not, however, replace financial-sector regulation, contractual requirements or Malaysian cybersecurity obligations.
ISO 27018 for Malaysian Healthcare Technology
Healthcare technology presents a different operational challenge because personal information can be embedded throughout an application.
Consider a cloud-based appointment platform. Patient information may enter through registration, move through scheduling and customer support, and remain in backups or other systems after the original transaction.
A provider therefore needs more than a statement that its servers are secure.
It needs a clear understanding of how PII moves through the service, who can access it, which suppliers are involved and what happens at the end of the retention period.
ISO 27018 can provide relevant guidance for the public-cloud PII processing component of such an environment.
Organizations should separately determine the Malaysian healthcare, privacy, contractual and cybersecurity requirements applicable to their services.
ISO 27018 for Malaysian BPO and Shared Services
BPO operations often process information on behalf of another organization.
A Malaysian service provider may, for example, operate customer support for an overseas business while using cloud applications to manage customer records and service requests.
The customer may want evidence covering:
-
Access to customer information
-
Staff permissions
-
Third-party providers
-
Data retention
-
Data deletion
-
Incident management
-
Processing responsibilities
ISO 27018 can be relevant where public-cloud services are used for this type of PII processing.
The contractual relationship remains important. A BPO provider should understand exactly what the customer requires rather than assuming that one standard addresses every privacy obligation.
ISO 27018 for Malaysian Data Centres and Managed Cloud Services
Data-centre and managed-service organizations may support cloud environments containing customer PII.
The practical concerns can range from privileged access and infrastructure security to monitoring, incident handling, supplier management and information disposal.
For example, a managed cloud provider may administer infrastructure for several customers. The organization needs controls that prevent one customer's information from being exposed through another customer's environment or through inappropriate administrative access.
ISO 27018 can contribute to the privacy-control framework for the public-cloud PII processing within the defined service scope.
ISO 27018 for Malaysian E-Commerce and Digital Platforms
E-commerce platforms process personal information throughout ordinary business operations.
A customer may create an account, place an order, receive delivery updates, contact support and later request changes to account information. Several cloud applications can be involved in that journey.
The relevant issue for ISO 27018 is not simply that the company has an online store. The question is whether a public-cloud provider is processing PII on behalf of the customer organization and what responsibilities apply to that arrangement.
Where a business needs a broader privacy-management system covering its own controller responsibilities, ISO 27701 may address a different requirement.
ISO 27018 and Malaysia-Singapore Cloud Operations
Johor has a particularly interesting position for technology companies serving both Malaysian and Singaporean customers.
A regional SaaS provider may have its commercial team in Johor, infrastructure distributed across cloud regions and customers in several countries.
That creates practical questions about data location, contractual responsibilities, suppliers and cross-border processing.
ISO 27018 can help address the cloud PII protection side of this environment. It does not, by itself, determine whether a particular cross-border transfer is legally permitted.
The organization must assess the applicable privacy requirements for the jurisdictions involved.
ISO 27018 Across Malaysia's Technology Hubs
The demand for cloud privacy assurance is not limited to Kuala Lumpur.
Kuala Lumpur and Selangor
These areas have a large concentration of technology, financial, professional-service and corporate businesses. SaaS providers and managed service companies serving enterprise customers may encounter ISO 27018 requirements during supplier assessments.
Cyberjaya
Cyberjaya is particularly relevant for cloud, software and digital-service businesses. A provider operating a SaaS platform from this ecosystem may use ISO 27018 guidance when designing its PII-processing controls.
Penang
Penang's technology and manufacturing ecosystem uses cloud applications across enterprise operations. For organizations providing cloud services to customers, the relevant question is whether those services process PII in the role covered by ISO 27018.
Johor and Iskandar Puteri
Regional operations connecting Malaysian and Singaporean markets can create additional customer-assurance requirements. Cloud providers should establish clear boundaries around processing, suppliers and data flows.
Kuching and Kota Kinabalu
Technology and digital-service businesses in East Malaysia can also consider ISO 27018 where their public-cloud services involve PII processing for customers.
The location itself does not determine applicability. The service, processing role and defined scope do.
ISO 27018 and Malaysia's Cyber Security Act 2024
Malaysia's Cyber Security Act 2024 (Act 854) came into operation on 26 August 2024. NACSA states that the Act establishes arrangements concerning National Critical Information Infrastructure (NCII), cybersecurity threats and incidents, and licensing of certain cybersecurity service providers.
NACSA identifies 11 NCII sectors:
-
Government
-
Banking and finance
-
Transportation
-
Defence and national security
-
Information, communication and digital
-
Healthcare services
-
Water, sewerage and waste management
-
Energy
-
Agriculture and plantation
-
Trade, industry and economy
-
Science, technology and innovation
ISO 27018 does not replace the Cyber Security Act.
For an organization operating within the NCII framework, the statutory cybersecurity requirements need to be considered independently. ISO 27018 may form part of a wider security and privacy programme where its scope is relevant.
ISO 27018 vs ISO 27001 in Malaysia
The two standards have different purposes.
ISO/IEC 27001 establishes requirements for an Information Security Management System.
ISO/IEC 27018:2025 provides guidance for protecting PII in public-cloud services where the provider acts as a PII processor.
ISO specifically describes ISO 27018 as complementary to an ISO 27001-based ISMS.
For example, a Malaysian SaaS company may use ISO 27001 as the foundation for its overall information-security management and apply ISO 27018 guidance to the part of its cloud service that processes customer PII.
That is a more accurate way to understand the relationship than treating the two standards as competing certifications.
ISO 27018 vs ISO 27017
ISO 27017 addresses information-security controls for cloud services.
ISO 27018 has a narrower privacy focus: protecting PII in public-cloud processing where the cloud provider acts as a processor.
The distinction is useful when a customer asks a Malaysian cloud provider for “cloud security certification.” That request needs to be clarified.
Is the customer asking about:
-
General information-security management?
-
Cloud-security controls?
-
Protection of PII?
-
Privacy management?
-
Or independent evidence covering several of these areas?
The answer determines which standard or assessment framework is appropriate.
ISO 27018 vs ISO 27701
ISO 27701 addresses Privacy Information Management.
SCS already has a dedicated Malaysia page covering ISO 27701, PIMS, Malaysian privacy requirements and the broader privacy-management context.
The distinction can be simplified:
ISO 27018: public-cloud PII processing by a cloud provider acting as processor.
ISO 27701: broader privacy information management for organizations handling PII.
A Malaysian company may have reasons to use both, but they should not be presented as substitutes.
Is ISO 27018 Independently Certifiable?
This is an important point for Malaysian organizations comparing certification options.
ISO describes ISO/IEC 27018:2025 as a guideline standard. Its official information-security and privacy compliance material states that ISO 27018 is not independently certifiable and complements ISO 27001 certification.
That means a company should be careful with the phrase “ISO 27018 certification.”
A customer may be asking for:
-
An ISO 27018-based assessment
-
An independent control assessment
-
Evidence of conformity to ISO 27018
-
ISO 27001 certification incorporating relevant ISO 27018 controls
-
A broader cloud-security and privacy assurance programme
These are not necessarily the same engagement.
Before starting an assessment, the organization should clarify exactly what the customer, tender or contract requires.
What Should a Malaysian Organization Do Before an ISO 27018 Assessment?
Start with the cloud service rather than the certificate.
Map the service and identify:
-
Which PII enters the environment
-
Who provides the information
-
Which organization determines the processing
-
Which systems store or process it
-
Which employees can access it
-
Which external suppliers are involved
-
Where the information is processed
-
How long it is retained
-
What happens when the service ends
This exercise often reveals gaps that are difficult to see from a policy document alone.
A cloud provider may discover, for example, that a customer-support team has a level of production access that was never properly documented, or that an outsourced backup service needs to be included in the supplier review.
Those are the kinds of practical issues an ISO 27018-focused programme should bring to the surface.
What Evidence May Be Reviewed?
The exact evidence depends on the assessment scope, but an organization may need to demonstrate how its arrangements work in practice.
Examples can include:
-
Defined cloud-service scope
-
PII-processing information
-
Data-flow documentation
-
Customer contracts
-
Supplier agreements
-
Access-control records
-
Incident records
-
Data-retention arrangements
-
Data-deletion records
-
Risk assessments
-
Staff training
-
Supplier reviews
-
Internal audit evidence
-
Corrective-action records
A well-written policy is useful. It is much stronger when the organization can also show that the stated process is actually being followed.
What Does ISO 27018 Cost in Malaysia?
There is no standard price that applies to every Malaysian organization.
The effort can vary according to:
-
Size of the organization
-
Cloud-service scope
-
Number of locations
-
Number of systems
-
PII-processing activities
-
Existing ISO 27001 arrangements
-
Supplier environment
-
Customer requirements
-
Assessment scope
A small SaaS provider with one application and a defined customer base will have a very different assessment requirement from a regional managed-cloud provider supporting multiple enterprise platforms.
The most reliable way to obtain a quotation is to provide the actual scope and processing environment.
How Long Does ISO 27018 Assessment Take?
There is no universal implementation timeline.
An organization that already operates a mature ISO 27001-based ISMS may have many of the underlying information-security processes in place. A newer cloud provider may first need to formalize access management, supplier controls, incident management, data lifecycle controls and supporting documentation.
The practical timeline depends on the gap between the current environment and the required scope.
Benefits of ISO 27018 for Malaysian Cloud Businesses
For a Malaysian cloud provider, the strongest benefit may be practical rather than promotional.
A well-designed ISO 27018 control framework can help the organization answer customer questions consistently and identify weaknesses in its own PII-processing arrangements.
It can also help with:
-
Enterprise customer due diligence
-
Supplier questionnaires
-
Cloud privacy assurance
-
Contractual discussions
-
PII lifecycle management
-
Third-party oversight
-
Customer trust
-
International business requirements
The value is greatest when the controls are integrated into everyday cloud operations rather than maintained solely for an audit.
Why Choose SCS for ISO 27018 Support in Malaysia?
The first conversation should establish what the customer actually requires.
SCS can discuss the proposed scope based on factors such as:
-
Cloud services provided
-
PII-processing activities
-
Organization size
-
Locations
-
Existing ISO 27001 arrangements
-
Customer requirements
-
Contractual expectations
-
Assessment objectives
This is particularly useful because “ISO 27018 certification” can mean different things in commercial conversations.
A clear scope at the beginning helps avoid paying for an assessment that does not address the customer's actual requirement.
Get ISO 27018 Support in Malaysia with SCS
If your organization operates a SaaS platform, public-cloud service, managed cloud environment, BPO platform, hosting service or other technology service that processes customer PII, ISO 27018 may be worth evaluating.
SCS can discuss requirements for organizations operating in Kuala Lumpur, Selangor, Cyberjaya, Penang, Johor, Iskandar Puteri, Melaka, Ipoh, Kuching, Kota Kinabalu and other Malaysian locations.
Before making an enquiry, it is useful to have your company profile, cloud-service description, proposed scope, PII-processing activities, existing ISO certifications and customer requirements available.
Discuss your ISO 27018 requirements with SCS and determine the appropriate assessment route for your Malaysian cloud service.
https://scscertification.com/contactus.php
SCS Certification – Malaysia Office
SCS Certification
Jalan Pinang
50450 Kuala Lumpur
Malaysia
Phone: +60 11 6263 6611
Enquiry: Contact SCS Certification
Need ISO Certification for Your Business?
Speak with our certification specialists to understand certification requirements, audit process, implementation timelines and accredited certification services.