Information Center

Baidu Cloud has passed the most authoritative international personal data security standard certification

  

On July 6, the British Standards Institute (BSI) officially released the latest ISO/IEC27018:2014 international certification to Baidu Cloud, which became the first cloud service provider to obtain a certificate.

Baidu Cloud's personal information protection certified by the ISO/IEC27018 standard has won international acclaim

ISO/IEC27018 is the first international code of conduct focused on protecting personal data on the cloud. It is the most authoritative, rigorous and widely accepted information security system in the world. ISO/IEC27018 international certification not only enables Baidu Cloud to provide users with reliable protection in the accuracy, transparency and security of personal information processing, but also reflects that Baidu Cloud data security management has reached the top level in the world and is one of the cloud computing platforms with the most complete global certification compliance.

Appendix: What is ISO27018?

The British Standards Institute (BSI) has defined ISO27018 to ensure customer data privacy and security and cloud service providers need to meet the following five key indicators:

Agreed: Cloud service provider CSP) shall not use the personal information received for publicity or marketing unless the customer has clear instructions.

2. Control: customers know how their information is used.

Transparency: cloud service providers must explain to customers where their data is stored, disclose the secondary processes used by "subcontractors", and how to deal with data.

4. Communication: In case of an accident, the cloud service provider must notify the customer and clearly record the event record and response.

5. Independent audit and annual audit: independent third-party auditors of cloud service providers need to maintain document consistency, and their regulatory obligations must be trusted by customers. In addition, CSPs must also be subject to an annual third party review