GDPR for brokers and charter companies: a calm checklist
Yacht businesses hold passports, preferences, payment details and the private lives of wealthy people. A practical, unalarmed walk through what good handling looks like.
The Yachtbase team5 min read
A yacht business is, among other things, a collection of very personal information. Guest lists with dietary needs and allergies. Passport copies for crew and guests. Ownership structures. Who travelled with whom, and when. If that were mishandled, the harm would fall on people who chose you precisely because you are discreet.
The General Data Protection Regulation, and its UK counterpart, are the rules for handling such information. They have a reputation for being forbidding. In practice, most of what they ask is sensible and not especially dramatic.
This is practical guidance, not legal advice. Your obligations depend on where you operate, where your clients are and what you do with the data. For anything specific, ask a qualified adviser.
Start by knowing what you hold
You cannot protect what you have not listed. Spend an hour with one colleague and write down:
- What personal data you collect (names, emails, phone numbers, passports, payment details, preferences, photographs).
- Where it comes from (enquiry forms, email, messaging, show leads, owners, crew).
- Where it lives (CRM, inboxes, spreadsheets, phones, shared drives, paper).
- Who can see it inside and outside the company.
- Who you share it with (central agents, insurers, authorities, payment providers, software suppliers).
This exercise reveals more than any policy document. It usually finds a spreadsheet nobody remembered.
Know why you are allowed to use it
Data protection law expects you to have a lawful basis for each use of personal data. The common ones in this industry are:
- Contract. You need the data to deliver what the client asked for: a charter booking, a sale.
- Legal obligation. For example, identity checks and records required by law.
- Legitimate interests. Some reasonable business uses, balanced against the person's rights.
- Consent. Freely given, specific and clear. It is the basis you need for much marketing, and it can be withdrawn.
Do not default to consent for everything. Where another basis fits, use it and say so. Where you rely on consent, be able to show when and how it was given.
Collect less
The simplest improvement is to ask for less.
- Does the enquiry form really need a date of birth?
- Do you need a passport scan at enquiry stage, or only at booking?
- Is the data needed for the whole season, or only until the charter ends?
Collect what you need, when you need it. Information you never took cannot leak.
Be clear with people
People should know who you are, what you do with their data, why, and for how long. Put this in a short privacy notice on your website and link to it wherever you collect data, including forms. Write it plainly. A notice that nobody can understand is not much of a notice.
Marketing and consent
Marketing emails have rules of their own, in addition to data protection law. In the EU, these come from national rules implementing the ePrivacy framework. In the UK, the Privacy and Electronic Communications Regulations apply, which include a limited exception for existing customers. Details vary, so check what applies to you.
Good practice is the same everywhere:
- Ask clearly, with an unticked box.
- Record when, how and what the person agreed to.
- Make every email easy to unsubscribe from, and honour requests promptly.
- Do not treat a business card at a boat show as blanket permission to send a newsletter. A conversation is not consent.
Keep it safe
Security is part of the law, and most breaches are dull in origin: a lost laptop, a mis-sent email, a shared password.
- Use strong, unique passwords and a second step where available.
- Limit access to those who need it, and remove it when people leave.
- Avoid sending passports and payment details through ordinary chat or email where there is a safer alternative.
- Keep devices updated and encrypted.
- Back up data, and test that the backups work.
- Think about paper too: a printed crew list left in a car.
Suppliers and transfers
When another company handles personal data for you (a CRM, an email service, a payment provider, an IT contractor), you remain responsible for it. You should have a written agreement with them setting out what they may do. Check where the data is stored and processed, and whether it leaves the UK or EEA. Where it does, there must be an appropriate safeguard in place. Ask the supplier; reputable ones will have a clear answer.
When someone asks about their data
People have rights, including to see what you hold about them, to have errors corrected and, in many circumstances, to have data erased. Requests generally need an answer within one month, which can in some cases be extended. A request does not have to use any particular wording or reach any particular person.
So:
- Make sure staff recognise a request when it arrives, and know who handles it.
- Verify the identity of the person asking.
- Be able to find the data. This is where your inventory pays off.
- Keep a record of the request and what you did.
When something goes wrong
If personal data is lost, stolen or sent to the wrong person, act quickly.
- Contain it: recall the message, change the password, revoke access.
- Assess the risk to the people affected.
- Where the rules require it, notify the supervisory authority without undue delay, and generally within 72 hours of becoming aware. In some cases you must tell the individuals too.
- Write down what happened and what you changed.
Have a short plan agreed in advance, with names and phone numbers. Nobody thinks clearly at the moment of a breach.
Retention: the unglamorous part
Do not keep personal data for longer than you need it. Decide how long you keep enquiries that did not convert, completed charter files and marketing contacts, and delete or anonymise on schedule. Some records must be kept for tax or legal reasons; others should not linger.
A calm checklist
- Inventory of personal data and where it lives.
- Lawful basis noted for each main use.
- Short, plain privacy notice linked from forms and website.
- Consent recorded where relied upon, with easy unsubscribe.
- Access limited and reviewed when staff change.
- Written agreements with suppliers; transfers checked.
- A known route for data requests and for breaches.
- Retention periods set and followed.
Where Yachtbase fits
Keeping clients, enquiries, forms and conversations in one workspace makes the inventory and access questions easier to answer, and Yachtbase forms capture consent with the submission and the source of each lead. Compliance itself is still your responsibility.
In short
- Know what personal data you hold, where it lives and who sees it.
- Pick a lawful basis for each use, and keep consent for what truly needs it.
- Collect less, and delete on a schedule.
- Be clear with people through a plain privacy notice.
- Secure access, check your suppliers and plan for breaches.
- Seek professional advice for specifics.
- gdpr
- privacy
- data protection
- compliance
