Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Purpose limitation of processed, customer-owned data in offered cloud services

Critical
High
Normal
Low

Personal data in offered cloud services that is processed under a contract can not be processed for any other purpose or differently from customers instructions.

Customer instructions for the data processor can be contained in the contract between the cloud service provider and customer including, e.g. the objective and probable time frame of the service.

Connected other frameworks and requirements:
A.3.1: Public cloud PII processor’s purpose
ISO 27018

Terms and conditions related to the offered digital services

Critical
High
Normal
Low

The terms and conditions related to the digital services provided by the organization have been mapped and documented. The terms of the contract shall include at least the following:

  • Nature and extent of the service provided
  • Cyber security requirements(including the Shared Security Responsibility Model)
  • Description of the change management procedure
  • Stored logs and their monitoring
  • Procedures for fault management and reporting
  • Right to audit and third party evaluation
  • Compatibility
  • Privacy requirements and descriptions of the processing of personal data
  • Termination of service
Connected other frameworks and requirements:
A.3.1: Public cloud PII processor’s purpose
ISO 27018
No items found.