Protecting Customer Data at a Charter Company: Everyday IT Hygiene
Customer data in charter beyond GDPR: role-based access, phishing, a seasonal worker's lost phone and backups. Practical hygiene, not an audit.

GDPR obligations are one side of protecting customer data; we cover the legal side of the topic and the compliance timeline in our guide to KSeF and GDPR at a charter company. The other side, discussed less often, is everyday IT hygiene: where customer data physically lives, who has access to it, and what happens when a seasonal worker loses a phone with access to the company mailbox. It is these everyday habits, not the privacy policy on your website, that decide whether customer data is actually safe.
Where customer data really lives
At a small charter company, data rarely sits in one place. A booking arrives by email, a scan of an ID card ends up on the reception's hard drive, a customer's phone number lands in a skipper's personal phone, and arrangements about a date change get lost in a WhatsApp thread. Each of these spots is a separate point where data can leak: a lost phone, a hacked personal mailbox, a computer without a password shared by several seasonal staff. The more such copies exist, the harder it is to answer a simple question: who has access to our customers' data today.
Role-based access, not "everyone gets everything"
The simplest change that actually reduces risk is to stop giving every employee full access to the customer database. A seasonal skipper needs the data for a specific trip, not the history of every booking from the last three years. The person at reception needs the current calendar, not access to financial settlements. Role-based access is not a formality on paper: it is a concrete limit on what a given person sees after logging into the system. We cover how to divide roles in a seasonal team in more detail in our guide to the team at a charter company.
If the whole team logs into one shared account with one password, you do not have role-based access, you have one shared password that will sooner or later end up on a sticky note by the computer or in every employee's phone.
Phishing: the easiest way to leak data
The most common source of a data leak is not a system break-in, but a fake email that looks like a message from a customer, a bank or a payment provider, asking you to click a link or enter a password. In season, when a team answers dozens of messages a day, such an email is easy to miss. The basic rule: no genuine payment provider or bank ever asks for a password by email, and any link to "change a customer's payment date" is always worth verifying directly in the booking system before clicking it.
A lost phone and what happens next
A seasonal worker with access to the company mailbox or the booking system on a personal phone is a typical situation in charter. The question is not whether such a phone will eventually get lost, but what happens to that access when it does. If access is assigned to a specific person and can be revoked remotely, a lost phone is an inconvenience. If everyone shares one password to one mailbox, a lost phone is potential access to every customer's data, with no way to cut it off quickly.
The backup nobody remembers to make
A spreadsheet of customer data kept locally on a single reception computer is a double risk: a leak if the computer is lost or infected, and data loss if the drive fails. An automatic backup within the system you already use for bookings solves both problems at once, without an extra task to remember in the middle of the season.

One system instead of scattered copies
The most effective way to protect customer data is not an extra tool to police security, but removing the opportunity for data to scatter in the first place. When the booking, the contract, the payment and the handover report all live in one record instead of four different places, the number of copies of a customer's data drops on its own, without extra discipline from the team. It also makes it easier to answer a customer's question about what data you hold on them: you have one source, not several versions to search through. We show what signing a contract and verifying a customer look like in one place in our guide to customer verification and e-signatures, and we cover regular communication that does not scatter across personal channels in our guide to customer communication in charter.
Frequently asked questions
Does a small charter company really need a role-based access policy?
Yes, regardless of fleet size. The risk does not depend on the number of boats, but on how many people have access to customer data and how easily that access can be revoked when someone's seasonal work ends.
How do you spot phishing pretending to be a customer or a bank?
The most common signal is time pressure and a request to click a link or enter a password. A genuine payment provider never asks for a password by email, and any change to a payment date is worth verifying directly in the booking system, not in the body of an email.
What should you do when an employee loses a phone with access to customer data?
If access is assigned individually, it can be revoked remotely right away, and the rest of the team keeps working without interruption. If everyone shared one common password, it has to be changed for the whole team, which is always slower and riskier.
Is a customer data backup a legal requirement or just good practice?
GDPR requires appropriate technical measures to protect data, and a backup is one of the basic such measures in case of lost equipment. We gather the details of the legal obligations in our guide to KSeF and GDPR at a charter company.
Want to keep customer data in one place instead of scattered across emails and your team's personal phones? See how fleet management in Portivo works, check pricing that depends on fleet size or book a meeting.


