KML is XML tied to Google Earth's way of styling, and not all GIS tools read every feature. CSV is plain text that every spreadsheet, database and script can read. KML is at home in places, routes and tours viewed in Google Earth; CSV is the usual choice for moving tabular data between systems.
Every format is read into plain GeoJSON features and written out from there, so coordinates, names and properties carry over wherever the target has a place for them. XML that declares custom entities is refused, and KML files are parsed without touching the network. Each point, and each vertex of a line, becomes one row with name, lat and lon columns, plus elevation and time when the data has them. Areas cannot be written as rows, so a file with polygons is refused. Text that starts with =, +, - or @ is escaped so a spreadsheet does not run it as a formula.