Skip to main content

Privacy Without Borders: How Kontent.ai Applies GDPR-Grade Standards Globally

Privacy laws are changing quickly. In the United States, more states are introducing their own consumer privacy rules. In Europe, GDPR continues to shape how organizations think about transparency, security, and individual rights. Around the world, customers increasingly expect the same thing: clear, responsible, and trustworthy handling of personal data.

Written by Matej Zachar

For content teams, marketers, and digital leaders, this can feel complicated. You may not work in legal or compliance every day, but you still need to choose platforms that help your organization work responsibly.

At Kontent.ai, we are monitoring relevant US privacy laws to understand how they apply to our services and what they mean for our customers. The key finding is straightforward: most comprehensive US state privacy laws do not directly apply to Kontent.ai's standard processing activities. At the same time, our privacy program is built around mature global standards, including GDPR-style principles and ISO/IEC 27018 controls for protecting personal data in public cloud environments.

In other words, even where a specific US state privacy law does not directly apply, we continue to operate with a high privacy baseline.

Download the whitepaper

We have prepared a full whitepaper that walks through how US state privacy laws relate to Kontent.ai's services, our compliance posture, and what it means for your organization.

↓ Download: US Privacy Laws and Kontent.ai (PDF)

Why US privacy laws can be confusing

Unlike the European Union, the United States does not currently have one single comprehensive federal privacy law. Instead, privacy rules are developing state by state. As of 2026, multiple US states have comprehensive consumer privacy laws, each with its own scope, definitions, consumer rights, and applicability criteria.

Many of these laws focus on questions such as:

  • Does the organization decide why and how personal data is processed?
  • Does the organization sell personal data?
  • Does the organization process certain volumes or categories of consumer data?
  • Does the organization process sensitive personal data?
  • Does the organization use personal data for targeted advertising, profiling, or similar activities?

For customers, the important point is not simply whether a specific law applies. The more useful question is: does the platform follow strong privacy practices even when requirements vary by region?
That is where Kontent.ai focuses its efforts.

What is our compliance status

Our compliance monitoring covers the US privacy-law landscape and how it relates to Kontent.ai's standard services.

The main finding: most comprehensive US state privacy laws do not directly apply to Kontent.ai in its standard role as a content management platform provider.

This is because many US state privacy laws are designed around specific applicability criteria, such as consumer data volumes, data sale activities, targeted advertising use cases, or particular categories of regulated data. Based on our review, Kontent.ai's standard processing activities do not fall within most of those direct applicability triggers.

Just as importantly, Kontent.ai does not treat this as a reason to lower the bar. Instead, we apply a consistent privacy approach based on internationally recognized principles.

We do not sell customer personal data

One of the most common questions in US privacy discussions is whether a company "sells" personal data.

For Kontent.ai, the answer is simple: we do not sell customer personal data.

Our service terms and data processing materials describe Kontent.ai as processing customer personal data to provide the services, with the customer acting as controller and Kontent.ai acting as processor or sub-processor where applicable. Customer personal data is processed for service delivery and compatible purposes under the applicable agreement. 

For content and marketing teams, this matters because your CMS should support your governance model rather than create unnecessary privacy complexity. Your content platform should help you manage content, workflows, and digital experiences, not introduce unexpected uses of customer data.

GDPR principles guide our global privacy approach

Even when a particular US privacy law does not directly apply, Kontent.ai continues to align its privacy program with core GDPR-style principles.

In everyday terms, this means we focus on principles that customers already recognize:

  • using personal data for clear and legitimate purposes;
  • limiting personal data to what is needed;
  • protecting personal data with appropriate security controls;
  • supporting individual rights;
  • keeping records of processing activities;
  • embedding privacy thinking into systems and processes.

These principles are familiar to organizations operating under GDPR, UK GDPR, Swiss FADP, Australian Privacy Principles, and other modern privacy frameworks. Our blog post explains that these frameworks share themes such as transparency, minimization, security, access rights, and breach response.

ISO/IEC 27018: cloud privacy that customers can understand

Privacy is not only about policies. It is also about how cloud services are governed and audited.

Kontent.ai holds ISO/IEC 27018 as part of its broader security and privacy assurance program. We are compliant with ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, ISO/IEC 42001, SOC 2 Type 2, and CSA STAR as part of the Kontent.ai program, with certificates and assurance materials available through the Kontent.ai Trust Center. 

ISO/IEC 27018 is specifically focused on protecting personally identifiable information in public clouds when the cloud service provider acts as a PII processor. The standard provides guidance for protecting PII in public cloud services, including controls and principles tailored to cloud environments, transparency, accountability, and responsible handling of PII. 

For non-legal teams, the practical message is simple: ISO/IEC 27018 helps show that a cloud provider takes personal-data protection seriously in the way its service is operated.

That matters for content teams because modern content operations often involve many people, workflows, integrations, regions, and publishing channels. A mature cloud privacy program helps keep that complexity manageable.

What this means for content and marketing teams

Privacy can sometimes feel like something that belongs only to legal teams. But content and marketing teams make privacy-relevant decisions every day.

For example:

  • What information do you collect through forms?
  • Which teams can access campaign data?
  • How do you manage permissions for editors, translators, agencies, and partners?
  • How do you avoid publishing information that should stay private?
  • How do you support requests to update or remove personal information?

A content platform cannot answer every governance question for you, but it can give your teams a stronger foundation.

With Kontent.ai, customers can build digital experiences on a platform backed by established privacy and security controls, clear processing roles, and internationally recognized assurance standards. Kontent.ai's ISMS is implemented within the scope of ISO/IEC 27001, 27017, 27018, and 42001 standards. That gives content and marketing teams more confidence when working across brands, regions, campaigns, and digital channels.

Privacy maturity matters even when legal requirements differ

A key takeaway from our US privacy-law review is that compliance is not only about checking whether a law applies. It is also about having a consistent privacy posture that customers can trust.

The US privacy landscape will continue to evolve. New state laws may appear. Existing laws may change. Customer expectations will keep rising.

Our approach is to maintain a global privacy baseline that is practical, understandable, and aligned with recognized standards. That includes GDPR-style privacy principles, ISO/IEC 27018 cloud privacy controls, security governance, contractual data protection commitments, and customer access to assurance materials through the Kontent.ai Trust Center. 

For customers, this creates a simpler message: Even where a specific US privacy law does not directly apply to Kontent.ai, our privacy and security maturity remains aligned with global expectations.

Key takeaways

  • The US privacy landscape is made up of many state laws, each with different scope and requirements.
  • Most comprehensive US state privacy laws do not directly apply to Kontent.ai's standard processing activities.
  • Kontent.ai does not sell customer personal data and processes customer personal data to provide the service under applicable agreements.
  • Kontent.ai applies GDPR-style privacy principles such as transparency, minimization, purpose limitation, privacy by design, and support for individual rights.
  • Kontent.ai maintains ISO/IEC 27018 controls for protecting personally identifiable information in public cloud environments, as part of a broader assurance program that also includes ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 42001, SOC 2 Type 2, and CSA STAR.

↓ Download the full whitepaper: US Privacy Laws and Kontent.ai (PDF)

Frequently Asked Questions

Most comprehensive US state privacy laws do not directly apply to Kontent.ai's standard processing activities. These laws have different applicability criteria, and our review found that Kontent.ai's standard role as a content management platform provider generally falls outside most direct applicability triggers.

Popular articles

Creative team discussing evergreen content
  • For business
The ultimate guide to evergreen content

What if we told you there was a way to make your website a place that will always be relevant, no matter the season or the year? Two words—evergreen content. What does evergreen mean in marketing, and how do you make evergreen content? Let’s dive into it.

Lucie Simonova

A marketer writing a blog post structure
  • For business
7+1 steps to structure a blog post

To structure a blog post, start with a strong headline, write a clear introduction, and break content into short paragraphs. Use descriptive subheadings, add visuals, and format for easy scanning. Don’t forget about linking and filling out the metadata. Want to go into more detail? Dive into this blog.

Lucie Simonova