A guest asks whether the boat still has her preference sheet from two years ago. It does — on a laptop that left with the last chief stew, in a WhatsApp group, and on a shared drive nobody has audited. Three copies, three owners, no control. That is a data problem, not a filing problem.
What the interior filing system has to hold
| Category | Examples | Sensitivity |
|---|---|---|
| Operational | Manual, SOPs, checklists, rotas, inventories | Internal |
| Financial | Petty cash logs, receipts, POs, budget trackers | Confidential |
| Crew | Contracts, appraisals, hours of rest, certificates | Highly confidential |
| Guest | Preference sheets, allergies, medical notes, itineraries, photographs | Highly confidential |
| Safety | COSHH file, safety data sheets, drill records, muster list | Internal, must be accessible |
Principles of a system that works
- One master location. A shared, backed-up drive with a folder structure everyone understands. Not personal laptops, not phones, not chat threads.
- Consistent naming.
2026-05-14_Charter-Smith_Preference-Sheet.pdfbeatsprefs final NEW. - Access by role, not by friendship. Not every crew member needs the crew appraisal folder.
- Backed up. Boats lose laptops, get wet and get stolen. A single copy is not a record.
- Handed over. The system belongs to the yacht, not to the chief stew. It stays when she goes.
Guest data is personal data
Preference sheets contain some of the most sensitive information you will ever handle: allergies, medical conditions, dietary and religious requirements, children names, travel patterns, and the private habits of identifiable people.
Treat it under three rules:
- Collect only what you need to deliver service. You do not need a guest passport number for a canape preference.
- Keep it only as long as you need it. Old sheets for guests who will not return are a liability, not an asset.
- Share it only with those who must have it. The chef needs the allergy. The deckhand does not need the itinerary.
Confidentiality is a condition of employment
Most yacht contracts contain a confidentiality clause or a separate NDA. It typically covers guest identities, movements, conversations, the yacht itself and its owner. In practice:
- No photographs of guests, ever, and no photographs where guests, guest possessions or identifiable interiors appear.
- No social media about who is aboard, where the boat is, or what happened.
- Do not discuss guests ashore, in bars, or with crew from other boats.
- Breach is normally grounds for dismissal and can be actionable.
Onboard Notes
- Data protection law (such as the EU GDPR) can apply to guest and crew data depending on the yacht operation, the flag and where data is processed. The yacht management company or DPO owns that analysis — flag it to the captain rather than deciding yourself.
- Deleting a guest file also means deleting it from the chat thread, the phone and the personal laptop. If you cannot say where every copy is, you do not control it.
- Never take guest or crew data with you when you leave a boat. Not as a reference, not as a template, not "just my own notes".
- Encrypt or password-protect the device holding guest data, and lock the crew office when it is unattended.