When the UK left the EU, data protection law changed with it. The EU's GDPR no longer applied directly in the UK, which introduced its own framework: the UK GDPR, alongside the Data Protection Act 2018.
The good news? UK GDPR is very similar to EU GDPR. Both are built on the same principles of transparency, fairness, and strong safeguards for personal data. There are some differences, such as the UK's flexibility in certain compliance areas and its own regulator, the Information Commissioner's Office (ICO).
What's Changed: The Data (Use and Access) Act 2025
The UK's framework continues to change. The Data (Use and Access) Act 2025, which received Royal Assent in June 2025, introduced targeted updates to the UK's data protection rules. The European Commission reviewed these changes and concluded that the UK continues to offer protection essentially equivalent to the EU's. In other words, the core principles you rely on remain firmly in place, and we keep track of these developments so you don't have to.
Implications for Kontent.ai Customers
As a European entity, Kontent.ai is regulated under EU GDPR, and we extend the same high standards to our UK customers. Here's what that means for you:
EU Data Centers Remain Available
UK customers can continue using our EU-based infrastructure without extra paperwork. Thanks to the EU's adequacy decision for the UK, which was renewed in December 2025 and runs until December 2031, personal data can flow freely between the EU and the UK. There is no need for Standard Contractual Clauses (SCCs) or similar mechanisms.
Domestic Storage Options
If your organization needs data to stay within the UK, we offer dedicated environment options. If this is part of your compliance strategy, contact our sales team and we'll work with you to find the right solution.
Kontent.ai Privacy Safeguards
We take privacy seriously, everywhere we operate. Here's how we protect your data:
- Certified Information Security Management System (ISMS): Our privacy program is backed by top management and a dedicated privacy team.
- ISO/IEC 27018 Certification: This international standard reflects our commitment to protecting personal data in the cloud.
- Global Compliance: With customers worldwide, we comply with major privacy laws, including EU/UK GDPR, the Australian Privacy Principles, and others.
Why This Matters
For us, compliance is about more than a legal checkbox. It's about trust. When you use Kontent.ai, you can be confident that your content and customer data are handled responsibly, wherever you operate.
Want to learn more?
Visit our Trust Center for details on certifications and privacy practices.
Information in this article is for informational purposes only and does not constitute legal advice. It discusses how Kontent.ai helps with compliance of key requirements from the UK GDPR. The information provided is based on general principles of United Kingdom law and regulations as of the publication date. The information provided in this article may not reflect recent changes in UK privacy laws or legal interpretations. Readers are advised to consult legal professionals for tailored advice and guidance. While efforts have been made to ensure accuracy, no representation or warranty, express or implied, is made regarding completeness, accuracy, reliability, or suitability. Kontent.ai is not liable for any direct, indirect, incidental, consequential, punitive, or special damages arising out of or in connection with the use of this article or reliance on the information contained herein. Customers are responsible for their own compliance with UK GDPR and any other regulations and for ensuring that Kontent.ai application is used in compliance with applicable laws.