Personal data processing statutory notice
Costa Crociere S.p.A. (hereinafter also “Costa Crociere”), as data controller, in accordance with article 13 of the General Data Protection Regulation (EU) 2016/679 (hereinafter the “GDPR”), is providing the following information about the processing of the personal data which you, as the data subject, have provided us:
a) for buying a travel package;
b) within the context of cruises (e.g. purchases made);
c) registration on the Costa Crociere web site and/or app or the filling in of forms on the Costa Crociere web site.
Purposes and legal basis of processing
In addition, the data which you have provided may also include some personal data defined by the Code and the GDPR as “special category data”. Sensitive/special category data shall be processed according to the purposes shown further on and only with your consent.
a) Purpose regarding contractual performance. Your personal data shall be processed for the purpose of performing obligations arising out of the contract for the purchase of the travel package, for allowing Costa Crociere to deliver the service in an optimal manner and, specifically, for:
(i) the formation, management and performance of contractual relations between you and Costa Crociere;
(ii) responding to your requests;
(iii) notification of information regarding the travel package (e.g. changes to contractual terms and conditions, etc.);
(iv) the creation of activities which serve to make your cruise enjoyable and pleasant and to guarantee high entertainment standards on board ships (i.e. party events, photo shoots and video recordings, games, etc.). In addition, in relation to the photos taken and videos recorded by photographers and video operators on board our ship, who work with us to make the cruise experience is unforgettable, please note that whenever you do not wish to be part of photos/videos or whenever you do not want your photos to be displayed on the display board at the Photoshop, you may go to the Photoshops which will record your wishes from time to time. The removal of a photo that features you may only be made after you have reported it.
b) Legal, health and safety purposes. Your personal data shall also be processed for the following purposes:
(i) legal, regulatory, domestic and EU compliance and that arising out of orders issued by authorities within the scope of their legal authority;
(ii) establishing, exercising and/or defending a Costa Crociere legal claim before the courts;
(iii) guaranteeing the necessary medical assistance during the cruise;
(iv) complying with the requirements of the CLIA association and the USPHS.
c) Business and statistics-related purposes. Your personal data shall also be processed for purposes relating or relevant to Costa Crociere business operations and for the processing of statistics in anonymous form and market research.
d) Additional purposes. Furthermore, whenever you expressly give your consent, your personal data shall be processed for the following purposes:
(i.) Marketing purposes, including:
a. promotional activities of Costa Crociere, companies in the Carnival Corporation & PLC Group (hereinafter the “Group”), also abroad, and/or commercial partners, implemented using both automated methods (e.g. e-mail, sms, instant messaging apps, etc.) and non-automated methods (e.g. regular mail, telephone with operator, etc). Specifically, Costa Crociere may use your e-mail address provided at the time you purchased a travel package, for sending you information and promotional notifications linked to services and products similar to those offered by Costa Crociere and the Group and/or commercial partners, also without your consent, provided you have not opposed said use.
The Carnival Group companies are: Carnival Corporation (CCL), Carnival PLC (P&O, Cunard, Princess Asia), Costa Croceire S.p.A. (AIDA and Costa), Holland America Line N.V., general partner of Cruiseport Curacao C.V. (Holland America Line and Seabourn) Princess Cruise Lines, Ltd (Princess, Alaska, P & O Australia and Cunard), SeaVacations Limited (CCL business in UK).
The commercial partners belong to the following product and market categories:
a) tourism-related activities;
b) airlines/transport services;
c) travel agencies;
d) insurance companies.
b. profiling activities, i.e. analysis of your travel preferences and market research for the purpose of enhancing the offering of services and sales information from Costa Crociere, matching them more closely to your interests. Said activity may also be implemented by submitting customer satisfaction questionnaires and/or the use of profiling cookies used during browsing Costa web sites.
(ii.) Purposes for the provision of accessory services, including:
a. registration on sites (e.g. MyCosta) and digital platforms, for allowing you to access and use the services provided on the portal and reserved for registered users and for guaranteeing you a customised vacation (e.g. for the purchase of wellness packages, beverage packages, photos, Costa-branded gifts and party events, etc.).
Processing for Marketing Purposes (i.e. for both promotional and profiling activities) may be implemented only with your consent.
Nature of data provision and consequences arising out of any refusal
The provision of your personal data is optional; however, without the data requested for the purposes shown in a) and b), the service requested or part thereof may not be performed and you may not be able to take advantage of above-mentioned opportunities.
The provision of optional data shall allow Costa Crociere to enhance the services offered, for rendering them better tailored to the personal interests of its passengers.
The provision of sensitive/special category data is optional; however, without said consent, Costa Crociere may not be able to comply with a number of contractual obligations and guarantee you any necessary medical assistance.
Personal data recipient categories
Your data shall not be disseminated. Your data may be disclosed only for the purposes stated above to the following categories of persons and entities:
- Costa Crociere in-house staff, appointed as data processing agents and/or data processor;
- companies belonging to the Costa Crociere Corporate Group, also located abroad;
- to the suppliers and/or agents/operators which, on board ships and ashore, provide services required during the cruise (e.g. port agents, entertainment operators, etc.);
- persons, companies, associations or professional firms providing services or advisory or consulting services to Costa Crociere for protecting its claims (e.g. chartered accountants, physicians, lawyers, tax consultants, auditors and consultants within auditing or due diligence operations, etc.);
- persons, companies or agencies that provide marketing services and analysis or consulting activities to Costa Crociere;
- persons and entities that are authorised to access your data, both recognised by law and secondary legislation or by orders issued by authorities empowered by law, including port authorities at the place of landing.
The list of persons and entities to which your data have been disclosed is available at the company at the following addresses: firstname.lastname@example.org or Costa Crociere S.p.A., Piazza Piccapietra, no. 48, 16121 Genoa, to the attention of the Data Protection Officer.
Transfer of personal data outside the European Union
Your personal data may be transferred abroad to third-party companies belonging or outside the European Union for the purposes stated above.
Whenever data is transferred to States outside the European Union, said States shall guarantee an adequate level of protection, based on a specific decision of the European Commission or, alternatively, the recipient shall have a contractual obligation to protect data adopting an adequate and comparable level of protection to that provided under the GDPR.
Retention of personal data
Personal data shall be retained for a period of time not exceeding that necessary for the purposes for which they were collected and subsequently processed. Personal data shall be retained for the full duration of the contract which you have entered into and for a subsequent period:
i. within the periods established under prevailing legislation;
ii. within the periods established under legislation, including secondary legislation, which require data to be kept (for example tax returns);
iii. within the period necessary for protecting the rights of the data controller in the event of any disputes arising concerning performance;
The photos/images and audio/video recordings collected during events and happenings on board shall be retained for a period limited to the duration of the cruise and subsequently they shall be deleted.
Personal data collected and processed for profiling shall be retained for a maximum period of ten (10) years, at the end of which they shall be automatically deleted and rendered permanently anonymous.
Data Controller and Data Processors
The Data Controller is: Costa Crociere S.p.A., with address in Genoa, Piazza Piccapietra, no. 48.
Data Protection Officer
The Data Protection Officer may be contacted at the following addresses: email@example.com or Costa Crociere S.p.A., Piazza Piccapietra, no. 48, 16121 Genoa.
Data subject rights
At any time, in accordance with articles 15 to 22 of the GDPR, you are entitled, also in relation to profiling, to:
a) access your personal data;
b) request your personal data to be corrected;
c) revoke, at any time, consent to the use and disclosure of your personal data;
d) request your personal data to be deleted;
e) receive the personal data concerning you in a structured, commonly used and machine-readable format, as well as the right to send your data to another data controller;
f) oppose the processing of personal data concerning you for marketing or profiling purposes;
g) obtain restriction on the processing of personal data;
h) lodge a complaint with a supervisory authority;
i) receive a notification whenever there is a personal data breach;
j) request information about:
i. the purposes of processing;
ii. the categories of personal data;
iii. the recipients or categories of recipients to whom personal data have been or will be disclosed, specifically, whenever data have been sent to recipients in third countries or international organisations and the existence of adequate guarantees;
iv. the period personal data shall be retained;
v. whenever data have not been collected from the data subject, all information regarding their origin.
You may, at any time, oppose the sending of notifications linked to marketing and profiling activities, by clicking on the “unsubscribe” link at the bottom of the e-mail received or by sending a relevant request to the addresses shown further on.
You may exercise these rights and/or obtain further information about personal data processing, by sending a notification:
- via e-mail to: firstname.lastname@example.org or to Costa Crociere S.p.A. Piazza Piccapietra 48, 16121 Genoa, to the attention of the Data Protection Officer.