Privacy Policy
Information notice on the processing of personal data
Costa Crociere S.p.A. (hereinafter also “Costa Crociere”), as data controller, in accordance with article 13 of the General Data Protection Regulation (EU) 2016/679 (hereinafter the “GDPR”), as well as in accordance with Legislative Decree no. 196/2003 as subsequently amended and supplemented (hereinafter, the “Privacy Code”), is providing the following information about the processing of personal data that regard you, collected by Costa Crociere and/or that you, as data subject, have provided us with:
- for the booking and/or purchase of the package tour;
- within the cruise (for example, purchases made); and
- for registering to Costa Crociere's website and/or app or for filling in the forms available on Costa Crociere's website.
Purposes and legal basis of the processing.
a) Purpose regarding the purchase of the package tour. Your personal data shall be processed for the purpose of performing obligations arising out of the contract for the purchase of the package tour, in order to allow Costa Crociere to provide the service in an optimal manner and, specifically, for:
- The formation, management and performance of pre-contractual and contractual relations between you and Costa Crociere;
- responding to your requests;
- The communication of service information, regarding the package tour purchased (e.g. changes to contractual terms and conditions, booking information, etc.);
- The organisation of activities which serve the purpose of making your cruise enjoyable and pleasant and to guarantee high entertainment standards on board ships (e. g. party events, photo shoots and video recordings, games, etc.). In addition, in relation to the photos taken and videos recorded by photographers and video operators on board our ships, who work with us to make the cruise experience unforgettable, please note that whenever you do not wish to be part of photos/videos or whenever you do not want your photos to be on the display board at the Photoshop, you may go to the Photoshops which will take note of your desires from time to time. Any photo in which you appear may be removed only when you request so;
- At the end of the cruise, Costa Crociere may contact you to ask for your opinion on the experience on board our ships. Your answers shall be used for the sole purpose of assessing the degree of customer satisfaction and shall not be used for other purposes.
Moreover, the data you disclose may include some personal data defined by the Privacy Code and the GDPR as "special categories of personal data" (for example, data relating to your state of health, the collection of which is necessary to guarantee that you benefit from services in line with your special needs, if any). These data shall be processed for the sole purposes connected with the package tour and only subject to your prior consent, as legal basis of the processing, which you may give when filling in the specific form that shall be sent to you by email in the case that, when finalising the purchase of the package tour, you have informed us that you have special needs.
b) Emailing of informational and promotional notices relating to the package tour. The legal basis of the processing is Costa Crociere's legitimate interest in ensuring that you receive notices relating to services and similar products offered by Costa Crociere.
In any case, you may at any time decide to object to the sending of the above-mentioned communications by clicking on the appropriate link appearing in any such communication by Costa Crociere.
The request in question shall not affect the sending of any notice for marketing purposes under paragraph e) below, should you have expressly consented to that.
c) Legal, health and safety purposes. Your personal data, including the data relating to your state of health, if necessary, shall also be processed in order to:
- fulfil legal obligations and comply with regulations, domestic and Community legislation as well as legislation deriving from provisions imposed by authorities entitled to do so by operation of law;
- request the ascertainment, exercise and/or defend a right of Costa Crociere in court;
- and guarantee that you have access to the necessary medical assistance during the cruise.
d) Statistical purposes. Your personal data shall also be processed for the anonymous elaboration of aggregate statistics regarding or relevant to the activity performed by Costa Crociere in the context of the sale of package tours. In this case, no consent shall be required on your part, because the processing specified shall be carried out exclusively on anonymous data.
e) Costa Crociere's direct and indirect Marketing purposes, which include promotional activities carried out by Costa Crociere on Costa Crociere's products and/services (so-called direct marketing), as well as on the products of third parties qualifying as Costa's business partners belonging to various product categories (for example, tourist activities, airlines/transportation services, travel agency, insurance, suppliers of electricity and gas, etc.) or other companies of the Carnival Group to which Costa Crociere belongs (so-called indirect marketing), implemented by using both automated means (for example emails, text messages, advertising messages through social networks, etc.) and non-automated means (for example, ordinary mail, telephone with operator, etc.).
The Carnival Group companies are: Carnival Corporation (CCL), Carnival PLC (P&O, Cunard, Princess Asia), Costa Croceire S.p.A. (AIDA and Costa), Holland America Line N.V., general partner of Cruiseport Curacao C.V. (Holland America Line and Seabourn) Princess Cruise Lines, Ltd (Princess, Alaska, P & O Australia and Cunard), SeaVacations Limited (CCL business in UK).
The processing for Marketing purposes (involving Costa Crociere’s direct and indirect marketing activities), carried out according to the modalities specified above, may only take place with your free, specific and express consent, which represents the legal basis of the relevant processing and which you may revoke at any time. Therefore, the processing of your data for the purpose specified above is completely optional.
f) Profiling purposes, in order to analyse your travel preferences and consumption habits and carry out market surveys with electronic means, even through satisfaction questionnaires, in order to improve the range of services offered and the commercial information presented by Costa Crociere, making them more in line with your interests.
The processing for profiling purposes may take place only on the basis of your specific and explicit consent, which represents the legal basis of the processing and which you may revoke any time. Therefore, entering the data in the database relating to profiling activities is completely optional.
g) Purposes relating to access to the My Costa portal, which include access to the My Costa portal via website and/or via the mobile App called "Costa App", in order to allow you to access and use the services provided through the portal and reserved to users with an option and/or active booking of a cruise (for example, for the purchase of wellness packages, beverage packages, wellness treatments, Costa-branded pictures and gifts, parties, etc.).
The legal basis of the processing is represented by the execution of your request to access the My Costa portal, to which the provisions of the My Costa Regulations.
Nature of data provision and consequences arising out of any refusal.
The disclosure of personal data requested when purchasing the package tour is compulsory and any refusal to disclose the personal data requested in whole or in part may make it impossible for Costa Crociere to allow the finalisation of your purchase.
The provision of your personal data for access to the My Costa portal is optional; however, any refusal to provide the personal data requested in whole or in part, may make it impossible for Costa Crociere to provide the services you request, including the possibility of proceeding with online booking.
Finally, you have the right to freely express your consent, which may be revoked at any time, respectively for the additional marketing and profiling purposes specified above. Any failure to give consent or any subsequent revocation of consent shall in no way prejudice the pursuance of the additional purposes specified above.
Categories of personal data recipients.
Your data shall not be disseminated, except for those cases in which dissemination is imposed by legal provisions or expressly authorised by you. Your data may be communicated only for the purposes stated above to the following categories of persons and entities:
- Costa Crociere in-house staff, expressly authorised to process personal data;
- companies belonging to the Costa Crociere Corporate Group, also based abroad;
- Costa Crociere's suppliers and/or agents/operators which, on board ships and ashore, providing services required during the cruise (e.g. port agents, entertainment operators, etc.);
- persons, companies or agencies that provide Costa Crociere with marketing services and analysis or consulting activities, including social media (e.g., Facebook); and
- persons whose right to access the personal data is granted under legal provisions and secondary legislation, or directives given by Authorities authorised to do so pursuant to law, including port authorities in disembarking places.
The parties belonging to the categories indicated above shall use the data in their capacity as independent data controllers or data processors, as the case may be.
The list of persons and entities to which your data are disclosed may be requested to the Company or to the Data Protection Officer at the following addresses: privacy(at)costa(dot)it or Costa Crociere S.p.A., Piazza Piccapietra 48, 16121 Genoa.
Transfer of personal data outside the European Union.
Your personal data may be transferred abroad to third-party companies belonging to or outside the European Union for the purposes stated above.
Whenever the data are transferred to States outside the European Union, said States shall guarantee an adequate level of protection, based on a specific decision of the European Commission or, alternatively, the recipient shall have a contractual obligation to protect data adopting an adequate level of protection comparable to that provided for under the GDPR.
Storage of personal data.
Personal data shall be stored for a period of time not exceeding that necessary for the purposes for which they were collected and subsequently processed. Personal data shall be stored throughout the duration of the contract which you have entered into and for a subsequent period:
- within the periods established under the legislation in force;
- within the periods established under legislation, including secondary legislation, which require data to be retained (for example tax returns); and
- within the period necessary to protect the rights of the data subject in the event of any dispute arising in connection with the provision of the service.
The photos/pictures and audio/video footage collected during on-board events shall be kept for a period limited to the duration of the cruise and then deleted.
Moreover, the personal data processed for emailing informational and promotional notices relating to the package tour shall be stored for the duration of the cruise only, unless you have made a prior request that such communications not be sent to you.
The personal data processed for marketing purposes on the basis of the express and specific consent given by you shall be kept for five (5) years, if you do not conclude the purchase of a Costa cruise within this period, or for ten (10) years, in case of purchase of one or more cruises.
The personal data collected and processed for profiling purposes shall be retained for a maximum period of ten (10) years, at the end of which they shall be automatically deleted and rendered permanently anonymous.
Data Controller.
The Data Controller is: Costa Crociere S.p.A. with registered office in Genoa, Piazza Piccapietra 48.
Data Protection Officer.
The Data Protection Officer or DPO may be contacted at the following addresses: privacy(at)costa(dot)it and/or Costa Crociere S.p.A., Piazza Piccapietra 48, 16121 Genoa.
Rights of the data subject.
At any time, in accordance with articles 15 to 22 of the GDPR, you are entitled, also in relation to profiling, to:
- access your personal data;
- request that your personal data be corrected;
- revoke, at any time, consent to the use and disclosure of your personal data;
- request that your personal data be deleted;
- receive the personal data concerning you in a structured, commonly used and machine-readable format, as well as the right to send your data to another data controller;
- oppose the processing of personal data concerning you for marketing or profiling purposes;
- obtain restriction on the processing of personal data;
- lodge a complaint with a supervisory authority;
- receive a notification whenever there is a personal data breach; and
- request information about:
- the purpose of processing;
- the categories of personal data;
- the recipients or categories of recipients to whom personal data have been or will be disclosed, in particular, whether data have been sent to recipients in third countries or international organisations and the existence of adequate guarantees;
- the period for which personal data shall be stored;
- where the personal data are not collected from the data subject, any available information as to their source.
You may at any time oppose the sending of notifications linked to marketing and profiling activities, by clicking on the “unsubscribe” link at the bottom of the email received or by sending a relevant request to the addresses shown below or by accessing your Costa Club reserved area from the costacrociere.it website if you are a member of the aforementioned Club.
You may exercise these rights and/or obtain further information about personal data processing, by sending a notice:
- by email to privacy(at)costa(dot)it
- by sending a notice via ordinary mail to Costa Crociere S.p.A. Piazza Piccapietra 48, 16121 Genoa, for the attention of the Data Protection Officer.
Costa Club
Costa Crociere S.p.A. (hereinafter also “Costa Cruises”), as data controller, in accordance with article 13 of the General Data Protection Regulation (EU) 2016/679 (hereinafter the “GDPR”), provides the following information regarding the processing of the personal data which you (hereinafter also “Member”), as the data subject, have provided during registration for Programma Costa Club [Costa Club Programme] (hereinafter the “Programme”). The present information is also available in the “Privacy” section of the website www.costacruises.co.uk and aboard at the Hospitality Service Desk/Reception.
This disclosure refers to the processing of the Member’s personal data:
- provided when registering for the Programme through any Club registration channel;
- collected during the Club’s ordinary administration (total amount spent during a cruise, type of cruises taken, etc.)
Purposes and legal basis of processing. Members’ personal data will be processed for the following purposes:
- Purposes regarding the Programme, for managing a Member’s participation in the Costa Club Programme and, specifically, for:
- awarding the Member points and other advantages connected to participation in the Costa Club Programme;
- allowing the Member to benefit from the Privileges listed at Art. 8.1 of these General Conditions;
- managing aspects related to possession of a Costa Club Card;
- providing the related services in the modes set down in the present General Conditions;
- delivering to members the institutional communications with an impact on membership and the benefits included in the programme.
Specifically, Costa Cruises can use the Member’s email address, mobile phone number, and/or mailing address provided at the time of registration with Costa Club or during participation in the programme.
- Emailing of informational and promotional communications related to Costa Club.
The legal basis of the processing is Costa’s legitimate interest in ensuring that Members are always informed about initiatives related to the Club.
However, Members may at any time request not to receive the aforementioned communications any longer, by clicking on the appropriate link present in every communication that Costa sends.
Said request will not impact the sending of any communications for marketing purposes discussed below at d), as long as the Member has provided their express consent.
- Statistical Purposes. The Member’s personal information will also be processed for the elaboration of anonymous aggregate statistics connected or pertaining to Costa Cruises’ activities in the framework of Costa Club. In this case, Member consent is not required since the said processing will concern only anonymous data.
- Marketing purposes, which include promotional activities concerning products and/or services of Costa Cruises, third party commercial partners of Costa, or other companies in the Carnival Group to which Costa Cruises belongs (so-called direct and indirect marketing). Specifically, Members’ information can be processed for sending communications in both automated modes (email, fax, text, instant messaging applications, etc.) and non-automated modes (ordinary mail, telephone with operator, etc.)
Processing for marketing purposes may take place only with the Member’s specific and express consent, which represents the legal basis of such processing and which the Member may revoke at any time.
- Profiling purposes to use electronic tools to analyse customer choices, consumption habits, and market research for the purpose of improving Costa Cruises’ offering of services and commercial information and better aligning them with Members’ interests.
Processing for profiling purposes may take place only with the Member’s specific and express consent, which represents the legal basis of such processing and which the Member may revoke at any time. Therefore, the entering of data into the profiling database is entirely optional.
- Management of complaints, protests, legal disputes and/or transactions. The legal basis of data processing for the purposes illustrated is the pursuit of a legitimate interest on the part of Costa and/or third parties (as in the case of disputes) which, in accordance with assessments made by Costa, is not detrimental to a Member’s rights.
- Purposes related to the fulfilment of legal obligations, regulations, national and EU norms, as well as regulations set by authorities legitimated to do so by law. The legal basis of data processing for this purpose is the fulfilment of the legal obligations and applicable norms to which Costa is subject.
Type of data provision and the consequences of refusal. Providing the personal data that is requested during registration for the Costa Club Programme and marked by an asterisk (*) is obligatory for full participation in the Programme itself, related initiatives, and the fulfilment of pertinent legal obligations. Any refusal to provide the personal information requested, wholly or partly, even in the course of the Programme’s implementation, may make it impossible for Costa Cruises and the third party companies that provide services within the programme’s framework to implement the programme completely or correctly perform the obligations deriving from it.
Providing personal data that is not marked by an asterisk (*), on the other hand, is optional, and not doing so will have no consequences on registration and participation in the programme.
Finally, Members have the right to freely express their consent, which they may revoke at any time, for the further purposes of marketing and profiling mentioned above. The lack of or subsequent revocation of this consent will in no way affect the Member’s participation in the Costa Club Programme.
Personal data recipient categories. Data will not be disclosed except in those cases where disclosure is required by law or expressly authorised by a Member. A Member’s data may be disclosed for the purposes stated above to the following categories of persons and entities:
- Costa Cruises in-house staff expressly authorised to process personal data;
- companies belonging to the Group, even those located abroad;
- persons, companies, associations or professional firms providing services or consulting to Costa Cruises (e.g. chartered accountants, lawyers, tax consultants, auditors and consultants within auditing operations or due diligence, etc.);
- persons, companies or agencies providing marketing services and analysis or consulting activities to Costa Cruises;
- persons and entities whose right to access data is recognised by law and secondary legislation or by regulations set by authorities legitimated to do so by law.
The parties indicated above will process the data, depending on the circumstances, either as autonomous data controllers or as data processors.
The list of parties to which data has been disclosed may be requested from the Company or from the Data Protection Officer at the following addresses: privacy(at)costa(dot)it or Costa Crociere S.p.A., Piazza Piccapietra, n. 48, 16121 Genova.
Transfer of personal data outside the European Union. A Member’s personal data may be transferred to third-party companies in States outside the European Union, for the purposes stated above.
Whenever data is transferred to States outside the European Union, said States shall guarantee an adequate level of protection based on a specific decision of the European Commission or, alternatively, the recipient shall be contractually obligated to protect data by adopting an adequate and comparable level of protection to that provided under the GDPR.
Retention of personal data. Personal data shall be retained no longer than the period necessary for the purposes for which it was collected and subsequently processed. Specifically, personal data shall be retained for the full duration of the Programme and its subsequent editions and for a subsequent period:
- within the periods established under prevailing legislation;
- within the periods established under secondary legislation which require data to be kept (such as tax returns);
- for the period necessary to protect the rights of the data controller in the event of any disputes arising concerning their services;
- after expiry or on termination based on the limitation period of Members’ rights.
In addition, the personal data processed for emailing commercial and promotional information connected to Costa Club will be retained unless Members oppose this retention.
Members' data processed for marketing purposes, on the basis of their expressed and specific consent, will be retained for 5 years if they do not purchase any Costa cruises in said time period, or for 10 years if they purchase one or more cruises.
Personal data collected and processed for profiling shall be retained for a maximum period of ten (10) years, at the end of which they shall be automatically deleted or rendered permanently anonymous.
Data Controller. The Data Controller is Costa Crociere S.p.A., with offices in Piazza Piccapietra 48, Genova.
Data Protection Officer. The Data Protection Officer (or DPO) may be contacted at the following addresses: privacy(at)costa(dot)it and/or at Costa Crociere S.p.A., Piazza Piccapietra 48, Genova.
Member rights. At any time, in accordance with articles 15 and 22 of the GDPR, a Member shall be entitled to:
- access his/her personal data;
- request that his/her personal data be corrected;
- revoke consent to the use and dissemination of his/her personal data at any time;
- request that his/her personal data be deleted;
- the right to receive the personal data concerning him or her, in a structured, commonly used and machine-readable format, as well as the right to send said data to another data controller;
- oppose the processing of personal data for marketing or profiling purposes;
- obtain restriction on the processing of personal data;
- lodge a complaint with a supervisory authority;
- receive a notification whenever there is a personal data breach;
- request information about:
- the purposes of processing;
- the categories of personal data;
- the recipients or categories of recipients to whom personal data has been or will be disclosed, and specifically, whenever data has been sent to recipients in third countries or to international organisations and the existence of adequate guarantees;
- the period personal data will be retained;
- the origin of any data collected about the data subject from other sources.
A Member may oppose the sending of notifications related to participation in the Programme, marketing activities and/or profiling at any time, by clicking on the “unsubscribe” link at the bottom of the e-mail received, or by sending a request to the addresses shown above.
A Member may exercise these rights and/or obtain further details about personal data processing by sending a request:
- by e-mail to: privacy(at)costa(dot)it
- by ordinary mail to Costa Crociere S.p.A. Piazza Piccapietra 48, 16121 Genova, c/o The Data Protection Officer.

