P&O Ferries has reported a personal data breach after a link containing customer information was inadvertently shared with passengers during a cross-Channel sailing.
The incident affected a single Calais-to-Dover sailing on the morning of Monday 31 August 2026. P&O Ferries described the breach as an isolated incident and said it was contacting affected customers directly.
The Information Commissioner's Office (ICO), the UK's data protection regulator, has confirmed that P&O Ferries reported the incident and said it is assessing the information provided.
Passenger information shared during sailing
According to P&O Ferries, a link containing certain personal information relating to customers on the sailing was inadvertently shared with a number of those customers.
The company has not publicly specified exactly what information was contained in the link, how many passengers were affected or how many customers received access to it.
There has also been no public indication from P&O Ferries that the incident resulted from a cyberattack. Based on the company's statement, the confirmed issue is the inadvertent sharing of a link containing customer information.
P&O Ferries apologises to customers
P&O Ferries said it takes the security and confidentiality of personal information seriously and apologised for any inconvenience caused.
The ferry operator said impacted customers were being contacted directly and that it would continue to keep them informed through appropriate channels as further information became available.
The company has not publicly identified the vessel involved in the sailing. Deck7 is therefore not attributing the incident to a particular P&O Ferries ship.
Incident reported to the ICO
The Information Commissioner's Office confirmed that P&O Ferries had reported the incident to the regulator.
An ICO spokesperson said people have the right to expect organisations to keep their information secure and confirmed that the regulator was assessing the information supplied by P&O Ferries.
Under UK data protection rules, organisations must notify the ICO of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it when the breach is likely to result in a risk to people's rights and freedoms.
Details of exposed information remain unclear
Several important details about the incident have not yet been made public. P&O Ferries has not disclosed the precise categories of personal information involved or confirmed whether details such as passport information, payment data or booking records were included.
There is therefore no basis at present to conclude that any particular type of sensitive or financial information was exposed.
The number of affected passengers has also not been disclosed. The confirmed information relates only to customers on one sailing between Calais and Dover on 31 August.
What affected passengers should do
Passengers contacted by P&O Ferries about the incident should follow any instructions provided directly by the company and remain alert to unexpected communications that claim to relate to their booking or personal information.
The ICO provides guidance for people who believe an organisation has failed to keep their personal information secure, including steps that can be taken after being notified of a breach.
