Which hyperscale provider first publicly attested to ISO/IEC 27018:2014, and in what year? I recall a July 2014 announcement, but I need the authoritative citation to satisfy audit evidence for a SOC 2 bridge letter.
Microsoft (Azure/Office 365) was first — announced July 1, 2014 — see “first to adopt ISO/IEC 27018” here: https://blogs.microsoft.com/blog/2014/07/01/giving-customers-control-protect-personal-data-microsoft-adopts-first-international-standard-cloud-privacy/ (ancient in cloud years)… For evidence, pair it with the Feb 2015 auditor verification post: https://blogs.microsoft.com/blog/2015/02/16/isoiec-27018-privacy-standard-verified-for-microsoft-azure-office-365-dynamics-crm-online-and-intune/; do you need the BSI cert PDF?
You’re right on the July 2014 timing, but for audit evidence I’d name Microsoft as first and cite the BSI‑backed ISO/IEC 27018 certification they document for 2015 here: ISO/IEC 27018 Code of Practice for Protecting Personal Data in the Cloud - Microsoft Compliance | Microsoft Learn (the July post was an adoption announcement — ). If you need a third‑party artifact, pull the BSI certificate from the Service Trust Portal — will that satisfy your SOC 2 bridge letter?
Go with Microsoft; the public claim landed July 2014, but for audit evidence pull the BSI cert PDF for Azure/Office 365 issued in early 2015 from their client directory: https://www.bsigroup.com/en-GB/our-services/certification/certificate-and-client-directory/. If you need a line to quote, use ‘first to adopt 27018’ from the announcement.