Who We Are
UPDATED: December 28, 2022
At Norwegian Cruise Line Holdings Ltd., our mission is to provide superior cruise holidays for our guests. This mission applies to all our activities including the products and experiences we offer on board our ships, at our destinations and ports of call, and online through websites and interactive features, including applications, widgets, blogs, social networks, social network "tabs," and other online or mobile offerings (which we collectively call the "Services"). Our Services are owned and/or operated, either directly or through our service providers and business partners, by Norwegian Cruise Line Holdings Ltd. (together with its subsidiaries and brands, Norwegian Cruise Line, Oceania Cruises, and Regent Seven Seas Cruises, the "Company," "we," "our," or "us").
Data We Collect
When you cruise with us, register to cruise with us, set up an account through one of our websites, request information about our Company, communicate with us, visit our websites, apply for employment with us, sign up for our promotions, contests, sweepstakes, or webinars or access our Services through various other methods, we collect data about you and those interactions.
Data we collect directly from you or other sources
We may collect the following categories of data either directly from you or from our business partners or third parties and in accordance with applicable law:
- Personal details (e.g., name, salutation, title, date of birth, place of birth, gender, photographs, and images)
- Contact details (e.g., email address, telephone number, mobile number, address, and emergency contact information)
- Health details (e.g., past medical history, temperature readings, test results, and vaccination history)
- Travel/holiday preference details (e.g., flight number, hotel booking, cabin number, special occasion dates, special accommodations, loyalty programme information, dietary preferences, travel companions, and family members)
- Your location and activities (e.g., CCTV footage of public areas and records of your entries and exits from the ship)
- Details regarding your previous travels, locations you have visited and contacts
- Government-issued documents (e.g., passports, alien resident cards, visas, residency permits, social security numbers, national and state identification numbers, driver’s licenses, and redress numbers)
- Details regarding your use of websites and applications (e.g., usernames, passwords, security answers, geolocation information, details regarding your interaction with websites, applications, and emails, such as whether you opened an email, which may permit us to recognise you across multiple devices, or to know if you watched the health and safety video or viewed certain content on our websites and applications)
- Financial details (e.g., credit card information, transactional history and purchases, amount paid for Services, bank information, income, and business information)
- Details of your play and spend at casinos, loyalty rewards, and, if you apply for credit for use at our onboard casinos, credit-related information
- Information available via public records and publicly available content on social media platforms
- Details regarding your interactions with our team members and call centres, including email communications and recordings of your calls
- Employment application details (e.g., name, employment history, telephone number, address, email address, education history, reference details, military service, and immigration status)
We operate closed circuit television ("CCTV") cameras on our ships, including at all access points and throughout public areas. These CCTV cameras record continually and images of you may appear in these recordings.
Please be aware that we have photographers on board taking photographs for guests to purchase. If you would not like to be photographed, please let our photographers know and they would be happy to take reasonable steps to comply with your request. Please note that we are unable to guarantee that you will not be included in photographs on an incidental basis.
Data we collect automatically
Special or sensitive categories of personal data
Some of the categories of data that we collect in connection with the provision of our Services or through the employment application process may constitute special categories of personal data (also known as sensitive personal data). In particular, we may collect personal data revealing racial or ethnic origin, religious, philosophical, or political beliefs, sexual orientation, or data concerning health, such as medical history or dietary restrictions, if in connection with our provision of Services or through the employment application process.
We collect this information when you choose to provide it to us or to a service provider or third party such as a travel agent or through the employment application process. We use this information to provide a service you request, such as medical care on board one of our cruises (whether in person or through our telehealth services), or special dietary accommodations, or in connection with your application for employment.
If, whilst travelling with us, you allege a personal injury or submit a claim after alleging a personal injury, we may collect personal data concerning the alleged incident, including healthcare information.
Optional facial recognition technology
On participating ships and with your consent, we may use facial comparison technology to facilitate and expedite your embarkation and/or disembarkation by taking your photograph and matching it against the photograph we collected from you during embarkation. When there is a match, you will be able to board the ship or be checked out of your cruise.
Separately, we may securely provide your disembarkation photograph to U.S. Customs and Border Protection (“CBP”), who uses its own facial comparison technology to match the photograph against images of you that CBP already has on file from your passport, other travel documents or prior CBP border inspections. Once we receive verification of your identity from CBP, we will delete your disembarkation photograph immediately. We do not retain your facial recognition data beyond the duration of your cruise or use it for any other purpose other than those described above. If you are a U.S. citizen, CBP will maintain your photograph for no more than 12 hours. For certain non-U.S. citizens, the U.S. Department of Homeland Security (DHS) will store your photograph for a longer period. For more information on how CBP uses your biometric data, please visit www.cbp.gov/travel/biometrics.
COVID-19 and global health data
For the health and safety of our guests and crew, we may process additional personal data during a pandemic or other global health crises. Passengers may be asked to undergo COVID-19 testing and provide us with proof of a negative result, disclose their vaccination status, and/or have their temperature taken. Temperature readings may be collected via thermal imaging cameras located on the gangway.
If we are made aware that an individual is exhibiting symptoms of COVID-19, we may evaluate our transaction data and photographs taken during your cruise and may run facial recognition technology on our CCTV footage to notify the persons who were in close proximity with the affected individual and take appropriate action to mitigate the spread of COVID-19. Such steps may include medical examinations, testing, containment, and/or disembarkation of the affected persons.
How We Use Personal Data
We may use your personal data for the following purposes:
- Identify and authenticate you: We use your identification data to verify your identity when you access and use our Services and to ensure the security of your personal data. We do this to comply with our contractual obligations to you.
- Provide emergency and security services: We provide you with emergency and security services to protect your vital interests or based on our legitimate interest of providing the services needed in case of urgent emergency or security situations on board.
- Provide you and your group with Services: We process your personal data to provide the Services you or your organisation have requested. We do this to comply with our contractual obligations to you or your organisation. For multi-guest bookings, we may allow all guests on the reservation to access and administer booking-related personal data of the guests on the same reservation in furtherance of our legitimate interest of allowing guests to conveniently administer their reservations.
- Advertise and market our Services: We may use your personal data, where permitted, to build a profile about you and place you into marketing segments to understand your preferences better and personalize the marketing messages we send to you. It is in our legitimate interest to provide more relevant and interesting advertising messages. We may contact you with marketing communications, and where necessary, we will obtain your consent before contacting you with such marketing communications.
- Communicate with you: We may use your personal data when we communicate with you. For example, if we are providing information about changes to our terms and conditions, in response to a question you submitted, or to notify you of changes to your itinerary or important health and safety information. It is in our legitimate interest to provide you with appropriate responses, verify your contact information, provide you with medical testing results, and provide you with notices about our Services.
- Comply with our obligations under applicable laws: We may process your personal data to comply with applicable legal or regulatory requirements. For example, we may provide certain information to governmental and recognised law enforcement agencies, such as the Transportation Security Administration in connection with commercial air travel you book through us, public health authorities, or port agents in connection with local and country requirements.
- Customize your experience and improve our Services: When you use the Services, we may use your personal data to improve your experience of the Services, such as by providing interactive or personalized elements on the Services and providing you with content, offerings, and experiences based on your interests, including shore excursions. Where necessary, we will obtain your consent before using your personal data in this way. We frequently seek to improve our Services to provide you with a better experience, and we may collect data about how you are using our Services to do so. We use this data to understand what content on our Services interests you, make the booking process more convenient, fix operational issues with our Services, and maintain the safety and security of our Services.
- Exercise our rights:We may use your personal data to exercise our legal rights where it is necessary to do so, for example to detect, prevent, and respond to legal claims, intellectual property infringement claims, or violations of law or our terms and conditions.
- Prevent fraud and comply with legal obligations: We may process your personal data to prevent fraud and comply with our legal obligations. For example, to carry out fraud prevention checks, which include building fraud-related profiles, making decisions on that basis by fraud prevention experts, and using CCTV images to prevent and detect fraud in our casinos.
- Protect the health and safety of guests and crew: We may process your personal data to protect the health and safety of all individuals on board our ships. For example, we may check your information against a publicly available criminal record database and our internal records to protect the safety of our guests and crew or use your personal data, including your health data, to protect against the spread of communicable diseases.
- Evaluate you for potential employment: We may process your personal data if you apply for a position as a team member with us, including by verifying any entitlements, monitoring equal opportunity employment, performing medical screenings (in some cases), and by making inquiries into any criminal and/or credit history based on our legitimate interests, to the extent necessary, and where permitted under applicable laws and regulations.
We may publish guest testimonials on our mailings, brochures, websites, and social media pages. Prior to publishing the testimonial, we obtain guests' consent to publish their names, usernames, cruise dates, photos, videos, and travel destinations along with their testimonial, as applicable. If you wish to update or delete your testimonial, you can contact us via the methods described under "How to Contact Us."
How We Share Personal Data
We may share any of the categories of personal data described above with third parties under the following circumstances, as permitted under applicable laws and regulations:
- Where required by law: We may provide certain personal data to governmental and recognized law enforcement agencies or other third parties where we believe necessary to comply with a legal obligation. We are required to cooperate with government and law enforcement agencies and public authorities of any country in your itinerary, including customs and immigration and public health and port authorities. Personal data about you, which may include health data, may be shared with these agencies (such as customs and the U.S. Department of Homeland Security and the Centres for Disease Control and Prevention) prior to boarding, during your cruise, or after disembarkation for security, immigration, or public health purposes.
- To protect our rights or the rights of a third party: We may share your personal data to identify, investigate, contact, or bring legal action against an individual who may be causing injury to or interference with our rights or property or the rights or property of a third person if we believe in good faith that disclosing this personal data is necessary or advisable. We may share your personal data with third parties to prevent or detect fraud with respect to our casinos and payment transactions. Personal data about you may also be shared with governmental and recognised law enforcement agencies to prevent and detect crime as well as to safeguard children and vulnerable adults.
- With your family members, friends and groups: When you book with a group or charter, we may share booking-related personal data about you with your group leader, such as your contact information so that they may contact you with group activities. If you make a multi-guest reservation, guests may be able to access the booking-related personal data of the other guests on the same reservation. This means that a guest on your same reservation may be able to: (1) complete online check-in for you and others in your reservation; (2) view your boarding pass and the boarding pass of others in your reservation; (3) pay for a product or activity for you or others in your reservation; and (4) update your contact information. If you have any questions or concerns about the processing of data for multi-guest reservations, please contact us via the methods described under “How to Contact Us.”
- Norwegian Cruise Line Holdings Ltd. family companies: NCL Corporation Ltd., NCL (Bahamas) Ltd., Norwegian Cruise Line Group UK Limited, NCL US IP CO 1, LLC, NCL US IP CO 2, LLC, NCL UK IP Co Ltd., Oceania Cruises S. de R.L., Seven Seas Cruises S. de R.L., Sixthman Ltd., and our brands, Norwegian Cruise Line, Oceania Cruises, Regent Seven Seas Cruises, and Sixthman, are owned by Norwegian Cruise Line Holdings Ltd., and we work closely with other businesses and companies in the Norwegian Cruise Line Holdings Ltd. family. We may share certain personal data about you with our family of Norwegian Cruise Line Holdings Ltd. companies, including your buying and browsing history on the Services, contact details, past cruising details, including your use of onboard products and services like casinos, and enquiries you have made about or products and services, for the purposes set forth above. We may also share your personal data to enable our family companies to market to you, where permitted by applicable law. Where necessary, we will obtain your consent before doing so.
We implement physical, technical, and organizational security measures designed to safeguard the personal data we process. These measures are aimed at providing on-going integrity and confidentiality of your personal data. We evaluate and update these measures on a regular basis.
The Company takes reasonable precautions to attempt to ensure the safety and security of our customers' online transactions. Billing information is encrypted and transmitted through SSL (Secure Sockets Layer) technology. SSL is the industry standard for securing Web-messaging transactions.
We retain your personal data for as long as we have a relationship with you or in accordance with applicable law, and such relationship includes any request to receive marketing or other promotional materials from us or membership in our loyalty programmes. When deciding how long to keep your personal data after our relationship with you has ended, we take into account our legal obligations, including requirements of regulators and governmental agencies that have authority over us. We may also retain records to investigate or defend against potential legal claims.
We will delete or anonymize your personal data at the end of the retention period. If there is any information that we are unable, for technical reasons, to delete entirely from our systems, we will put in place appropriate measures to prevent any further processing or use of the data.
Managing Your Privacy Settings
Our marketing emails, text messages, and most other electronic messages you receive from us will include instructions on how to unsubscribe, and you may unsubscribe at any time from our marketing by taking one the following steps:
- Follow the instructions provided in the message
- Click on one of the following links to update your marketing preferences: Norwegian Cruise Line, Oceania Cruises, or Regent Seven Seas Cruises
- Send your request by post to the following address:
Norwegian Cruise Line Holdings Ltd.
Legal Department: Privacy Team
7665 Corporate Centre Drive
Miami, Florida 33126
Our Services may be used by, or collect personal data about, children under the age of 16 only with the involvement of and, as needed, consent from the child's parent or guardian. To the extent we process personal data about children, we do so for the purposes described in the consent request and to provide the requested Services.
If you have reason to believe that we have collected personal data from someone under 16 years of age in connection with our Services without adequate involvement from the child’s parent or guardian, please let us know by contacting us via the methods described under “How to Contact Us.”
You can find more information about how we process the personal data of California residents by reviewing our California Resident Privacy Notice here.
If you are a resident of Virginia, you have certain rights regarding your personal data. These include the following rights:
- confirm that we process your personal data and access such personal data
- erase your personal data
- rectify the data we hold about you
- receive personal data that you provided to us in a portable and readily usable format that allows you to transmit it to a third party (right to data portability)
- opt out of the processing of your personal data for targeted advertising purposes
For purposes of the Virginia Consumer Data Protection Act, whilst we may process your data for targeted advertising, we do not sell your data or profile you in furtherance of decisions that produce legal or similarly significant effects concerning consumers. If you would like to discuss, exercise these rights, or appeal a decision relating to your rights request, please click here.
- European Union, EEA, UK, and Brazil
If you are located in the European Union, the EEA, the United Kingdom, or Brazil, you have certain rights regarding your personal data, subject to local data protection laws. These include the following rights:
- access your personal data
- rectify the data we hold about you
- erase your personal data
- restrict our use of your personal data
- object to our use of your personal data
- receive your personal data in a usable electronic format and transmit it to a third party (right to data portability)
- lodge a complaint with your local data protection authority.
If you would like to discuss or exercise these rights, please click here.
Third Parties We Don’t Own or Control
Social Media Features
International Data Transfers
We are headquartered in the United States but have global operations and affiliates. Accordingly, your personal data may be transferred to, stored, and processed in various countries, including those that are not regarded as ensuring an adequate level of protection for personal data under the laws in certain jurisdictions, such as the European Union, UK, Japan, and Israel. We have put in place appropriate safeguards (such as contractual commitments) in accordance with applicable legal requirements to ensure that your data is adequately protected. For more information on the appropriate safeguards in place, please contact us at the details below.
How to Contact Us
To exercise any privacy rights you have under applicable law, please click here. We will contact you if we need additional data from you to honour your requests.
If you have any questions, comments, or concerns about how we handle your personal data, please contact us at PrivacyTeam@nclcorp.com and we will try to resolve your concern.
We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If you believe that we have not been able to assist with your complaint or concern, you can contact our Data Protection Officer or our representative in Germany by writing to PrivacyTeam@nclcorp.com or clicking here. You may have the right to make a complaint to the data protection authority of your country of residence.
If we make any revisions that materially change the ways in which we process your personal data, we will notify you of these changes, for example by sending an email to the email address we have on file, before applying them to that personal data.