GDPR Compliance for Maritime and Shipping
Crew data, ship-shore transfers, and passenger manifests for shipping operators
Shipping lines, ship managers, and cruise operators process crew records, seafarer medical data, and passenger manifests across flag states, crewing agencies, and ports worldwide. GDPR follows EU-established operators and EU data subjects onto every vessel. TruePrivacy governs the fleet's data the way class societies govern its steel.
What GDPR requires of maritime & shipping
Crew data across the employment chain
Seafarer records — passports, STCW certificates, contracts, appraisals — flow between owners, managers, and manning agents, each needing a defined controller or processor role.
Article 9 seafarer medical data
Fitness certificates, medical logs, and telemedicine records are special-category data processed under occupational-medicine conditions — documented per activity.
Ship-shore and third-country transfers
Crew and operational data moving to non-EEA managers, crewing agencies, flag registries, and port agents needs SCCs, TIAs, and mapped onward flows.
Onboard monitoring proportionality
CCTV, bridge audio, vessel tracking, and crew welfare apps monitor a workplace that is also a home — demanding strict necessity and transparency.
Passenger data for cruise and ferry
Manifests, API/PNR obligations, health declarations, and onboard purchases make passenger operations a full controller programme of their own.
DSARs and breach response at sea
One-month DSAR deadlines and 72-hour breach clocks run regardless of connectivity — incident processes must work from vessel to DPA.
How TruePrivacy helps
Crew data inventory and role mapping
Every party in the employment chain — owner, DOC holder, manager, manning agent, P&I club — classified as controller or processor with Article 28 contracts tracked.
Medical data governance
Seafarer health records mapped to their Article 9 conditions, quarantined behind role-based access, and retained per flag-state and MLC requirements.
Transfer compliance for global operations
SCC and TIA management across crewing hubs, with each flow's mechanism documented and reassessment alerts as destinations change.
Monitoring proportionality register
Onboard surveillance and tracking systems inventoried with necessity assessments, crew notices, and retention limits — evidence for inspections and works councils.
Fleet-wide DSAR and incident workflows
Deadline-tracked rights requests and breach response spanning shore offices and vessels, with master's reporting channels feeding one incident record.
“Crew files for eight thousand seafarers were scattered across owners, our Manila agent, and each vessel's master. TruePrivacy mapped every flow, fixed the processor contracts, and when a laptop went missing off a vessel in Rotterdam, the 72-hour clock was met with a filing, not a panic.”
Frequently asked questions
Does GDPR apply on a vessel flying a non-EU flag?
The flag matters less than the operator and the people. GDPR applies if the controller is EU-established or the processing targets EU data subjects — so an EU-based owner or manager brings crew processing into scope regardless of flag. TruePrivacy maps applicability per entity and per processing activity.
Who is the controller for crew data — owner, manager, or manning agent?
Typically the employing entity controls employment data, the ship manager processes under a management agreement, and manning agents act as processors or separate controllers for recruitment pools. TruePrivacy documents each role per contract so DSARs and breach duties land on the right party.
Can we keep seafarer medical records, and for how long?
Yes — occupational-medicine conditions under Article 9(2)(h) and flag-state or MLC record-keeping rules justify them, for as long as those obligations run. TruePrivacy holds medical classes under documented bases with access restricted to those with a medical need to know.
How do we handle a DSAR from a former crew member?
Same one-month deadline as ashore: assemble records from crewing systems, vessel files, appraisals, and medical stores; redact third parties; and cite retention where records must be kept. TruePrivacy automates the assembly and generates the split response.
Get GDPR-ready
Book a 30-minute demo and see how TruePrivacy handles GDPR compliance for maritime & shipping.
Free 14-day trial · No credit card required · Setup in minutes