GDPR check

Is Kaltura GDPR compliant? What universities should check

Kaltura hosts lecture recordings, virtual classrooms and LMS video at many universities. This page sets out what Kaltura publicly documents about hosting regions, its data processing agreement, subprocessors, transfers and AI features, and what that means for an institution storing years of teaching video.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Kaltura, Inc. is a US company that acts as a processor for universities using its video platform. It offers a data processing agreement incorporating the EU standard contractual clauses, states that Kaltura, Inc. is certified under the EU-US Data Privacy Framework, and offers an EU regional cloud, although its own FAQ says the platform and customer data are currently hosted in the US, with regional clouds available on request. Its public subprocessor list is long and includes optional AI and transcription providers. The detailed answer depends on which region your account is provisioned in, which optional services (captioning, AI) you switch on and how you set retention for recordings.

What Kaltura documents publicly

The table summarises what Kaltura states in its own documentation, read on 7 October 2026. It covers the Kaltura SaaS platform as used by an institution, including lecture capture, MediaSpace video portals and LMS integrations.

TopicWhat the vendor statesSource
Company and roleDocumented The DPA is entered into by Kaltura, Inc., a Delaware corporation based in New York, on behalf of itself and its affiliates. Kaltura describes itself as a processor of its customers' end-user data.GDPR FAQ [1], DPA [2]
Where data is stored and processedContract-dependent The FAQ says the platform and customer data are currently hosted in the US. Regional cloud environments in the EU, Singapore, Australia and Canada are available, and custom set-ups may add cost. CDN delivery and caching may happen where users are, and R&D and support staff in the EU, UK, Israel and the US may access data for support.[1]
Data processing agreementDocumented A public DPA incorporates the 2021 SCCs, with Irish law and courts chosen for the clauses. At termination, personal data is destroyed or returned on request, or destroyed within 90 days if the customer gives no instruction.[2]
SubprocessorsDocumented The list (last updated September 2026) includes Amazon Web Services (US, EU, Canada, Australia, Singapore), Akamai, Fastly, Cloudflare and Google. Optional services include Verbit, AmberScript and Descript for transcription, and AI providers such as OpenAI, 11Labs, OpenRouter and Replicate. Customers have 10 business days to object to a new subprocessor.Subprocessor list [3], [2]
International transfers (DPF, SCCs)Documented Kaltura states that Kaltura, Inc. is certified under the DPF for transfers from the EEA, UK and Switzerland (DPF status read from the vendor's GDPR FAQ; the official list API returned no results for any query on the check date). It transfers data to affiliates in the US, Singapore, Brazil and Israel, relying on adequacy for Israel, the DPF for the US and SCCs for countries without an adequacy decision.[1]
AI features and trainingPartly documented The AI Addendum lets Kaltura use inputs and outputs "to the extent necessary to provide, maintain, and improve the Kaltura AI Offering", and aggregated, anonymised data for product improvement. It prohibits customers from using Kaltura AI for purposes classified as high-risk under the AI Act, including evaluating students.AI Addendum [4]
Retention and deletionCustomer-controlled Content and user data are retained for the contract term unless administrators delete them or set custom deletion rules. Data subject requests go through the customer, and Kaltura can export or selectively delete personal data on request.[1]
Security certificationsDocumented Kaltura states that it holds ISO 27001 and ISO 27799 certifications and that its US and regional data centres undergo SOC 1 Type II and SOC 2 Type II assessments.[1]
Institution controlsDocumented Authentication can be configured to avoid collecting names and email addresses. A First Login Disclaimer can show privacy notices, a Privacy Banner can ask consent for an analytics cookie, and anonymisation tools are offered. Captioning vendors receive a processing region and a content deletion policy with each task.[1], REACH data privacy [5]

Kaltura is more open than many vendors about where staff may access data, which affiliates receive transfers and which subprocessors are optional. The explicit ban on high-risk AI uses in its AI Addendum also gives universities a contractual reference point that few video platforms offer.

What this means for a university

Validemic's analysis

Lecture recordings and students. Lecture capture records more than slides. Students who ask questions, present work or sit in the front rows are captured on video and audio, sometimes with their names in a chat window. Kaltura's own FAQ lists recorded live sessions, chat history, viewing history and quiz results among the data it processes [1]. Recordings are not biometric data merely because they show faces: under recital 51 GDPR, photographs count as special category data only when processed by technical means that allow unique identification [6]. That changes if face recognition or speaker identification is switched on.

Hosting region. Because the FAQ names the US as the current hosting location, the region must be agreed in the contract and checked on the account. An institution that assumes "EU" without confirming it may find its archive in the US. Even with EU hosting, CDNs, support access and some optional subprocessors operate elsewhere, which the FAQ states openly.

Optional services. Automated captioning, translation, voice and AI features each bring in additional subprocessors, some described as "services provided globally". Universities should switch these on deliberately, record which ones are in use and check the region settings for captioning tasks.

Retention. Kaltura keeps content for the contract term unless the customer deletes it. A university needs its own retention schedule for recordings, for example one academic year after the course ends unless there is a reason to keep them, and should use Kaltura's deletion rules to enforce it.

Transfers. The European Commission's adequacy decision for the EU-US Data Privacy Framework applies to certified US companies since 10 July 2023 [7]. Kaltura states it is certified, and its DPA also includes SCCs. For affiliates in countries without an adequacy decision, Kaltura states that it relies on SCCs.

DPIA likelihood. Article 35 GDPR requires a DPIA where processing is likely to result in a high risk [8]. Systematic recording of teaching across an institution, long retention and AI processing of recordings together make a DPIA the safer course.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Kaltura before approving it

  1. In which regional cloud is our account provisioned, and which data categories (media, metadata, analytics, logs, backups) stay in that region?
  2. Which subprocessors apply to our implementation, given the products and optional services we use?
  3. Which AI features are enabled by default, and can administrators disable them at account and category level?
  4. Under the AI Addendum, are our lecture recordings, transcripts or AI outputs used to improve Kaltura's AI offering, and can we opt out?
  5. For captioning through REACH, which vendors process our media, in which region, and under which content deletion policy?
  6. Can we enforce automatic deletion of recordings after a set period, institution-wide?
  7. Can we receive the current ISO certificates and SOC 2 Type II report?
  8. To which address should notices of new subprocessors go, given the 10 business day objection period?

The EU AI Act angle

Kaltura's AI features (captions, summaries, AI tutors and avatars) are mostly productivity and accessibility tools. Annex III of the AI Act lists AI used to evaluate learning outcomes or to steer learning as high-risk, and Kaltura's AI Addendum already prohibits customers from using its AI for those purposes [4]. If a teacher used an AI tutor or quiz feature to grade students, that use would fall outside the contract and could fall under Annex III, whose obligations apply from 2 December 2027 under the amended Article 113 [9].

Article 4, as amended, requires deployers to take measures to support AI literacy among staff using AI systems [10]. Article 5(1)(f) prohibits AI that infers emotions in education institutions, except for medical or safety reasons [11]. We found nothing in Kaltura's public documentation describing emotion inference, but engagement analytics on recordings should be reviewed with that rule in mind.

Sources

  1. FAQ: Kaltura's Compliance with European Union Data Protection Laws, retrieved 7 October 2026
  2. Kaltura Data Processing Agreement (customers), retrieved 7 October 2026
  3. Kaltura, Inc. Subprocessor List (last updated September 2026), retrieved 7 October 2026
  4. Kaltura Artificial Intelligence Addendum, retrieved 7 October 2026
  5. Reach data privacy and content deletion, Kaltura Knowledge Center, retrieved 7 October 2026
  6. Regulation (EU) 2016/679 (GDPR), recital 51, retrieved 7 October 2026
  7. EU-US data transfers, European Commission, retrieved 7 October 2026
  8. Regulation (EU) 2016/679 (GDPR), Article 35, retrieved 7 October 2026
  9. AI Act Article 113: Entry into force and application, AI Act Service Desk, retrieved 7 October 2026
  10. AI Act Article 4: AI literacy, AI Act Service Desk, retrieved 7 October 2026
  11. AI Act Article 5: Prohibited AI practices, AI Act Service Desk, retrieved 7 October 2026

About this page

We read Kaltura's GDPR FAQ, data processing agreement, subprocessor list, AI Addendum, REACH privacy article and the relevant EU legal texts on 7 October 2026. The official Data Privacy Framework list API returned no results on that date, so DPF status comes from Kaltura's own statement. Every statement about Kaltura above comes from those pages, and our own view is labelled as Validemic's analysis. This page is not legal advice and does not say whether any particular use of Kaltura complies with the GDPR. If you spot an error or Kaltura has updated a document, please contact us and we will correct it.

Frequently asked questions

Is Kaltura GDPR compliant?

No platform is GDPR compliant on its own. Kaltura describes itself as a processor for its customers, offers a data processing agreement incorporating the EU standard contractual clauses, states that Kaltura, Inc. is certified under the Data Privacy Framework and offers an EU regional cloud. Whether a university's use complies depends on its contract, hosting region, settings and transparency to students and staff.

Does Kaltura host data in the EU?

Kaltura's GDPR FAQ says its SaaS platform and customer data are hosted in the US, with regional cloud environments in the EU, Singapore, Australia and Canada available for customers with hosting requirements. Content delivery networks, support staff in several countries and some subprocessors can still involve processing outside the EU.

Does Kaltura use customer videos to train AI?

Kaltura's AI Addendum gives Kaltura a licence to use inputs and outputs of its AI offering as needed to provide, maintain and improve that offering, and to use aggregated, anonymised data for product improvement. A university should ask what this means in practice for lecture recordings and transcripts, and whether it can opt out.

How long does Kaltura keep lecture recordings?

Kaltura says customer content is generally kept for the whole contract term unless administrators delete it or set custom deletion rules. Under its DPA, personal data is deleted or returned at termination and, without instructions, destroyed within 90 days. Retention of recordings is therefore mostly the university's decision.

Do universities need a DPIA for Kaltura?

Often yes. Lecture capture records students' images and voices at scale and over long periods, and automated captioning and AI features add further processing. These factors point towards a DPIA under Article 35 GDPR, or at least a documented screening.