Speak to the Team

Sedna needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at any time. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, please review our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

What Shipping Companies Get Wrong about GDPR

In shipping organisations around the world, someone in legal or IT raises the question of GDPR compliance. Someone else responds with a variant of the following: "We're not based in Europe. This doesn't apply to us."

This widespread assumption is incorrect, and it needs urgent correcting. 

The territorial misconception

General Data Protection Regulation (GDPR) is often described as European data protection legislation. The description is incomplete and this matters enormously for shipping.

GDPR does not apply only to companies established in the European Union. It applies to any organisation that processes the personal data of individuals who are in the EU, regardless of where that organisation is based. This is the regulation's extraterritorial scope, established in Article 3, and it has significant implications for an industry that by definition operates across jurisdictions.

More specifically for shipping: GDPR applies to the processing of EU crew data regardless of where the processing organisation is headquartered.

This means:

  • A Singapore-based tanker operator with EU seafarers on its vessels is processing EU personal data under GDPR's scope
  • A Hong Kong-registered ship agency handling crew change documents for EU nationals is within scope
  • A US-headquartered shipping line that employs or manages contracts for European crew members is within scope
The question is NOT "Are we in Europe?" 
The question is "Do we process personal data relating to EU nationals?

For the vast majority of internationally operating shipping companies, the answer is yes.

The extraterritorial logic of GDPR is also not unique to Europe. A growing number of jurisdictions have enacted comparable data privacy frameworks, each with their own territorial reach and compliance obligations:

They all establish similar principles around lawful processing, data subject rights, and accountability. The United States, while lacking a single federal equivalent, has a patchwork of state-level legislation, California's Consumer Privacy Act (CCPA) being the most significant. 

For shipping companies, this regulatory landscape compounds with every port call, crew nationality, and commercial relationship: an operator may simultaneously owe compliance duties under several of these regimes depending on where their seafarers are from, where their counterparties are based, and where their data is processed.

What "processing" actually means in a shipping context

The breadth of GDPR's territorial scope matters more because of how broadly the regulation defines "processing." 

Processing is NOT limited to storing data in a database or running an HR system. 

It includes collecting, recording, organising, structuring, storing, adapting, retrieving, consulting, using, transmitting, or in any other way making available personal data.

  • Forwarding a crew list via email is processing. 
  • Receiving a passport scan in a shared inbox is processing. 
  • Opening an attachment and reading a medical certificate is processing. 
The routine operations of a crewing department or port agency are, under GDPR's definition, continuous data processing activities.

This is not a legal technicality designed to catch organisations out. It reflects the regulation's substantive concern: that personal data (information about real people, including their health, identity, and immigration status) should be handled with appropriate care, whatever technical form that handling takes.

The enforcement reality

The counter-argument to regulatory scope is often a probability argument: yes, technically the regulation applies, but enforcement against non-EU companies is limited. Regulators focus on companies within their jurisdiction. The practical risk is overstated.

This argument was more defensible five years ago than it is today. GDPR enforcement has become materially more active. We only need to research the number of fines issued and the total monetary value of these fines. 

Nordic data protection authorities, in jurisdictions where many of the world's major shipping companies are either headquartered or have significant operations, have developed a practice of coordinating enforcement across borders. A regulatory investigation opened in Norway can trigger parallel investigations in Sweden, Denmark, and Finland simultaneously. For companies with any operational footprint in those markets, the geographic insulation argument does not hold.

And the pathway to regulatory attention is not limited to regulators acting on their own initiative, for example:

  • A data subject (for example, a seafarer) can lodge a complaint about how their personal data was handled. 
  • A commercial counterparty conducting vendor due diligence can refer concerns to a regulatory authority. 

A breach that becomes visible in one jurisdiction can prompt investigation across all jurisdictions where that company operates.

The contractual dimension

Regulatory risk is one reason to take GDPR seriously. For many shipping companies, the more immediate commercial risk comes from a different direction.

Charterers, oil majors, and major cargo customers are increasingly including data protection requirements in their contracts and vendor qualification processes. These are not boilerplate legal clauses. They are specific requirements for demonstrable data handling controls, presented as conditions for contract award or renewal.

GDPR compliance is not only a regulatory question. 
It is a commercial prerequisite. 
The organisation that cannot suitably or sufficiently demonstrate systematic controls loses the contract to the one that can.

The data that creates the exposure

It’s imperative that we understand what personal data actually flows through maritime operations, it is more sensitive, and more voluminous than most organisations consciously appreciate.

  • Every crew change generates identity documents: passports, seafarer identification documents, national ID cards. 
  • Every health certification generates medical records. 
  • Every port call generates immigration paperwork.
  • Every voyage generates crew lists that combine personal identifiers with employment and contractual information.

Ship agencies report handling more than 200 crew documents daily. A tanker operation accumulates upwards of 1,600 sensitive pages per voyage. This data moves through email in shared inboxes, in forwarded threads, and in attachments copied to multiple parties across multiple jurisdictions.

None of this is handled maliciously or even carelessly by the people processing it. It is handled as operational necessity. The problem is systemic: no one set out to create a situation where sensitive biometric and medical data sits in shared inboxes without controls. It accumulated because of operational priorities.

GDPR does not care about operational pressures. It cares about the data and how it is handled.

What "demonstrating compliance" actually requires

The last misconception worth addressing is what GDPR compliance looks like in practice. Many organisations respond to the compliance question by pointing to their data protection policy document. The policy exists. The policy says the right things. Therefore, the organisation is compliant.

Policy is not compliance. Policy is the statement of intent. Compliance is the technical and organisational measures that implement the intent, as well the evidence that demonstrates they are actually working.

For shipping, answering that question requires something more than a document. It requires technical controls that detect personal data as it flows through systems, manage its retention, control who can access it, and log every action taken on it. 

It requires evidence, not assertions.

The organisations building that evidence base now, systematically, from a documented activation date, will be in a materially better position when the question is asked. 

The ones relying on the assumption that GDPR is someone else's problem will be in a worse one.

Find out how much personal data is moving through your email environment: Calculate Your Risk Exposure

See how Sedna Personal Data Redaction works: Explore the PDR product page →

Keep every voyage on course

Sedna helps shipping teams stay in control, resolve faster, and scale execution with confidence.
Call to action banner encouraging shipping teams to request a Sedna VMS demo