Speak to the Team









Products of Interest










Sedna needs the contact information you provide to us to contact you about our products and services. Please be advised that photographs and video recordings will be taken at the event for use on our website, social media, marketing materials, and other publications. You may unsubscribe from these communications at any time. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, please review our Privacy Policy.

What Shipping Companies Get Wrong about GDPR

The Geography Question

GDPR is often described as European data protection law. But that is not quite right, and the difference matters.

GDPR does not apply only to companies based in the European Union. It can also apply to organisations outside the EU that process the personal data of people in the EU.

This is known as GDPR's extraterritorial scope. It is set out in Article 3 and has important implications for an industry that operates across borders.

For shipping, the key point is simple: where your company is based does not always determine whether GDPR applies.

For example:

  • A Singapore-based tanker operator processing personal data relating to people in the EU may fall within GDPR's scope.
  • A Hong Kong-registered ship agency handling crew change documents for EU nationals may also be affected.
  • A US-headquartered shipping line managing employment or contracts involving people in the EU may be within scope.

In a global industry like shipping, data often crosses borders. GDPR can cross them too.

The question is NOT "Are we in Europe?" 
The question is "Do we process personal data relating to EU nationals?

For the majority of internationally operating shipping companies, the answer is yes.

GDPR is not the only data privacy law with global reach. More countries are introducing similar laws, each with its own rules about where it applies and what organisations must do.

These laws share similar principles around lawful data processing, individual privacy rights, and accountability. The United States does not have a single federal privacy law. Instead, it has a mix of state laws, with California's Consumer Privacy Act (CCPA) among the most significant.

For shipping companies, this can make compliance more complex. Every port call, crew nationality, and commercial relationship can add new requirements.

A single operator may need to comply with several privacy laws at the same time, depending on where its seafarers and business partners are based and where its data is processed.

What "processing" means in shipping

GDPR has a broad definition of "processing". This matters because personal data is processed throughout everyday shipping operations.

Processing does not just mean storing data in a database or using an HR system.

It includes collecting, recording, storing, organising, retrieving, using, sharing, or otherwise handling personal data.

For example:

  • Forwarding a crew list by email is processing.
  • Receiving a passport scan in a shared inbox is processing.
  • Opening and reading a medical certificate is processing.

In shipping, everyday work in a crewing department or port agency often involves continuous processing of personal data.

This is not a legal technicality. GDPR is concerned with how information about real people is handled.

That can include sensitive information about someone's identity, health, employment, or immigration status. Whether the data sits in a database, an email inbox, or an attachment, it still needs to be handled appropriately.

The enforcement reality

A common argument is that, while GDPR may technically apply to a company outside the EU, the chances of enforcement are low. That argument is becoming harder to make.

GDPR enforcement has increased in recent years, with regulators issuing a growing number of fines and other penalties.

Regulators can also work together across borders. For shipping companies operating in multiple countries, an issue in one market may create wider regulatory attention.

And regulators are not the only source of risk.

For example:

  • A data subject, such as a seafarer, can complain about how their personal data was handled.
  • A customer or commercial partner may identify concerns during vendor due diligence.
  • A data breach in one location may lead to questions about data practices elsewhere in the business.

For global shipping companies, distance does not necessarily provide protection from scrutiny.

The contractual dimension

Regulatory risk is one reason to take data protection seriously. But for many shipping companies, the more immediate risk may be commercial.

Charterers, oil majors, and major cargo customers increasingly include data protection requirements in contracts and vendor assessments.

Companies may be asked to demonstrate that they have appropriate controls in place before winning or renewing a contract.

GDPR compliance is not just a regulatory issue. It can also be a commercial requirement. The company that can demonstrate strong data controls may be in a better position than one that cannot.

The data creating the exposure

Shipping operations handle more personal data than many organisations realise.

Everyday activities can involve:

  • Crew changes: Passports, seafarer identification documents, and national ID cards.
  • Health certification: Medical and health-related information.
  • Port calls: Immigration and travel documents.
  • Voyages: Crew lists containing personal, employment, and contractual information.

This information often moves through shared email inboxes, forwarded email threads, and attachments sent between multiple organisations and countries.

The issue is not usually that people are handling data carelessly or with bad intentions. They are doing what the operation requires. The problem is often systemic. Over time, sensitive information can build up in shared inboxes because email is central to how shipping teams work.

Operational needs come first. But that does not remove the need for appropriate data controls. GDPR focuses on the personal data being handled and the safeguards in place to protect it.

What demonstrating compliance requires

Another common misconception is that having a data protection policy means an organisation is compliant. It does not.

A policy explains what an organisation intends to do. Compliance means putting that intention into practice and being able to show that the controls are working.

For shipping companies, this means looking beyond the policy document. Organisations need appropriate technical and organisational controls to help them:

  • Identify personal data as it moves through their systems.
  • Manage how long data is retained.
  • Control who can access sensitive information.
  • Keep records of how data is handled.

It requires evidence, not just assertions. The organisations building that evidence now will be in a stronger position when customers, partners, or regulators ask questions. Those that assume data protection is someone else's problem may find themselves unprepared.

Find out how much personal data is moving through your email environment: Calculate Your Risk Exposure

See how Sedna Personal Data Redaction works: Explore the PDR product page →

Keep every voyage on course

Sedna helps shipping teams stay in control, resolve faster, and scale execution with confidence.
Call to action banner encouraging shipping teams to request a Sedna VMS demo