BLOG POST

Tech & Sourcing @ Morgan Lewis

TECHNOLOGY TRANSACTIONS, OUTSOURCING, AND COMMERCIAL CONTRACTS NEWS FOR LAWYERS AND SOURCING PROFESSIONALS

Contract Corner: The Contracts Behind Cruise Ship Technology

Contract Corner

Operating technology at sea presents challenges that do not arise in a conventional office or resort. The ship is moving, connectivity varies by location, and providers may rely on infrastructure controlled by other vendors. The contracts must account for these operational realities and allocate responsibility when something goes wrong.

A February 2026 IT disruption illustrates how technology dependencies can affect cruise operations. Carnival Cruise Line said the issue arose during planned maintenance and affected embarkation, disembarkation, and other technology tools. Reports of the disruption also identified impacts to Wi-Fi and the Carnival HUB app, while navigation and safety systems remained operational.

A cruise ship may be designed to help passengers disconnect, but it depends on extensive connectivity behind the scenes. Passengers boarding a cruise ship may see a floating hotel, restaurant, shopping center, and entertainment venue. The ship also operates as a sophisticated technology environment supporting internet access, mobile applications, payment processing, digital room keys, entertainment platforms, passenger services, and crew operations.

Those services depend on an interconnected group of satellite operators, telecommunications providers, software vendors, payment processors, content licensors, equipment manufacturers, and managed service providers. The passenger experience may appear seamless, but the contracts behind it rarely are.

Connectivity Without a Cable

Once a cruise ship leaves port, its communications services may depend on satellite constellations, onboard antennas, ground stations, network-management platforms, and cloud infrastructure. As we discussed in our recent post on direct-to-device satellite services, satellite connectivity often involves multiple providers delivering different components of one service. That structure can make responsibility for an outage difficult to determine.

Connectivity agreements should address geographic coverage, capacity, traffic management, prioritization among passenger and business uses, onboard equipment, redundancy, and upstream providers. Coverage is not a simple yes-or-no question. Performance may differ based on location, weather, passenger volume, satellite availability, and restrictions in particular jurisdictions.

The agreement should anticipate changes to routes and technology. Change-control provisions should establish how new destinations or network migrations affect coverage, pricing, equipment, and performance commitments.

Service Levels on a Moving Platform

A general availability commitment provides limited protection if it does not identify what is measured, where performance is measured, and which events are excluded. Shipboard service levels may address network availability, throughput, latency, peak capacity, payment-processing times, platform availability, incident response, restoration times, and technical support.

The measurement point is important. A satellite network may satisfy its commitment even though passengers cannot connect because onboard equipment has failed. The operator should consider whether performance is measured at the provider's infrastructure or on an end-to-end basis.

Providers may seek exclusions for weather, vessel position, maintenance, regulatory restrictions, and upstream failures. Reasonable exclusions should not be so broad that the commitment loses practical meaning. As discussed in our Contract Corner on service-level methodology, objective metrics should be supported by reporting and meaningful remedies, including credits, remediation plans, alternative connectivity, or termination rights for chronic failures.

Allocating Cybersecurity Responsibilities at Sea

A cruise ship's technology environment may include passenger Wi-Fi, mobile applications, payment systems, crew networks, administrative systems, connected devices, and operational technology. Different vendors may manage those systems, but a cybersecurity incident may quickly cross contractual boundaries.

Security obligations should reflect the component each party controls and address network segmentation, access management, encryption, vulnerability management, patching, monitoring, onboard equipment, and subcontractors. A security schedule focused only on a vendor's cloud environment may not cover onboard devices, remote-maintenance tools, or integrations with other providers.

Incident-response provisions should define a security incident, establish notice and remediation responsibilities, and identify who communicates with passengers, payment networks, and regulators. The agreements should allocate investigation, notification, restoration, and response costs. Liability caps, indemnities, and insurance requirements should align with those obligations.

Payments That Must Work Offshore

Many cruise ships are largely cashless environments. Passengers may use a room key, wearable device, mobile application, or onboard account to purchase meals, excursions, merchandise, and other services. Those transactions can involve an onboard point-of-sale platform, passenger-account system, payment gateway, processor, acquiring bank, and card network.

The contracts should address what happens when a transaction cannot immediately be transmitted for authorization. If transactions are stored and processed later, the parties should allocate the risk of declined, duplicate, fraudulent, or incorrectly recorded transactions. Other key issues include settlement and reconciliation, refunds and chargebacks, payment-card requirements, tokenization, fraud losses, and continuity procedures during a connectivity outage.

The operator should identify where each vendor's responsibility begins and ends. A processor may exclude failures involving the onboard platform, while the platform provider may exclude problems caused by connectivity or banking networks. The agreements should close those gaps.

Aligning the Contractual Framework

Shipboard technology may be governed by services agreements, equipment leases, software licenses, content agreements, payment-processing terms, security schedules, and service-level documents. Operators should evaluate them as one framework.

The contracts should establish which document controls, whether obligations flow down to subcontractors, how dependencies are documented, and who coordinates incidents. Data rights, service levels, liability provisions, and transition obligations should remain consistent.

A cruise ship may operate far from the nearest data center, but passengers and crew expect the connectivity, convenience, and security available on land. The ship may be at sea, but the contracts supporting its technology services should reflect that unique operating environment and establish clear accountability when problems arise.