Curated Island Experiences
PRIVACY POLICY
Version 1.0 | Effective: April 2026
Republic of Maldives
YOUR PRIVACY MATTERS: Maldives Diaries is committed to protecting the personal data of our clients, website visitors, and business partners. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and what rights you have over your information. Please read this document carefully.
This Privacy Policy applies to Maldives Diaries (hereinafter "the Company," "we," "us," or "our"), a duly licensed tour operator incorporated under the laws of the Republic of Maldives. This Policy applies to all personal data collected and processed by the Company through:
This Policy is published in compliance with the Maldives Data Protection Act 2017 (Law No. 29/2017) and in anticipation of further obligations under the Privacy and Personal Data Protection Bill (as consulted upon in 2023 and any successor legislation enacted thereafter), as well as the General Data Protection Regulation (GDPR) of the European Union and the UK General Data Protection Regulation (UK GDPR) to the extent applicable to our processing of personal data of individuals resident in those jurisdictions.
For the purposes of applicable data protection law, Maldives Diaries acts as the Data Controller with respect to personal data collected from Clients, website visitors, and business partners. Our details are:
Maldives Diaries
Email (Privacy): privacy@maldivesdiaries.com
Phone: [+960 XXX XXXX]
Address: [Address, Malé, Republic of Maldives]
"Data Controller" means the entity that determines the purposes and means of processing personal data.
"Data Processor" means an entity that processes personal data on behalf of the Data Controller.
"Data Subject" means a natural person whose personal data is processed by the Company.
"Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to names, identification numbers, location data, online identifiers, or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
"Processing" means any operation performed on personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, combination, restriction, erasure, or destruction.
"Sensitive Personal Data" means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification purposes, health data, or data concerning sexual orientation.
"Third Party" means a natural or legal person, public authority, agency, or body other than the Data Subject, Data Controller, or Data Processor.
The Company collects and processes the following categories of personal data:
Health data constitutes Sensitive Personal Data. We process such data only where strictly necessary for the safe delivery of our services and with the explicit consent of the Data Subject.
We collect personal data through the following channels:
We process personal data on the following legal bases:
We process personal data for the following purposes:
We share personal data with third parties only where necessary and on a lawful basis. Recipients of personal data may include:
Guesthouses, transport operators, activity providers, dive centres, and local guides engaged to deliver elements of the Package receive the minimum personal data necessary to deliver their specific service. All Service Providers engaged by the Company are required under our Service Provider Agreements to process personal data only for the purposes for which it is shared and in compliance with applicable law.
Where a Booking is received through a foreign tour operator or travel agent operating under an affiliation agreement with Maldives Diaries, personal data may be shared with that partner to the extent necessary for the coordination of the Package. Foreign partners are required to maintain appropriate data protection standards and to process personal data only for the purposes of the Booking.
Payment transactions are processed by third-party payment processors who are PCI-DSS compliant. We do not store full credit or debit card details. Payment processors operate under their own privacy policies and data security standards.
We may disclose personal data to the Ministry of Tourism, Maldives Immigration, Maldives Customs Service, the Maldives Inland Revenue Authority (MIRA), the Maldives Police Service, or any other competent Maldivian government authority where required by law, where necessary for the safe delivery of our services, or in response to a lawful order from a court or authority. Clients should be aware that Maldivian immigration authorities require advance passenger information for all arrivals.
In the event of a medical or safety emergency, the Company may share personal data, including health information, with emergency services, medical facilities, and evacuation services to protect the vital interests of the Data Subject or others.
Our legal advisers, auditors, accountants, and insurers may receive personal data where necessary in connection with their professional services, subject to professional confidentiality obligations.
In the event of a merger, acquisition, or restructuring of the Company, personal data held by the Company may be transferred to the successor entity as part of the business transfer, subject to the receiving entity being bound by equivalent data protection obligations.
The nature of our business requires that personal data is shared with Service Providers, partners, and authorities in the Republic of Maldives. Clients from the European Economic Area (EEA), the United Kingdom, or other jurisdictions with data transfer restrictions should be aware that the Maldives does not currently hold an adequacy decision from the European Commission or equivalent body.
Where personal data is transferred from the EEA or UK to Maldives-based recipients, we rely on Standard Contractual Clauses (SCCs) or other appropriate safeguards where contractually feasible. Where SCCs are not in place, we rely on the necessity of the transfer for the performance of the contract between the Data Subject and the Company (Article 49(1)(b) GDPR).
Personal data may be transferred to foreign tour operator partners in the Client's country of residence. Such transfers are made pursuant to contractual necessity and, where applicable, supported by SCCs or equivalent safeguards.
For Clients from jurisdictions outside the EEA and UK, the Company complies with applicable local data protection law regarding cross-border transfers to the extent notified in writing by the Client's jurisdiction.
We retain personal data for no longer than is necessary for the purposes for which it was collected, subject to applicable legal requirements.
The following indicative retention periods apply:
At the end of the applicable retention period, personal data will be securely deleted or irreversibly anonymised.
Maldives Diaries implements appropriate technical and organisational security measures to protect personal data against unauthorised access, accidental loss, disclosure, alteration, or destruction, commensurate with the nature and sensitivity of the data processed.
Security measures include, but are not limited to:
Notwithstanding the foregoing, no method of transmission over the internet or electronic storage is completely secure. The Company cannot guarantee absolute security and encourages Clients to use secure channels when transmitting sensitive personal information.
Payment card data is handled exclusively by PCI-DSS compliant payment processors. The Company does not store, transmit, or process full card numbers.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of Data Subjects, the Company will:
Notifications to Data Subjects will describe the nature of the breach, the likely consequences, the measures taken or proposed to address the breach, and provide the contact details of the Company's privacy contact.
Subject to applicable law and any exemptions therein, Data Subjects have the following rights with respect to their personal data held by Maldives Diaries:
You have the right to request a copy of the personal data we hold about you and information about how it is processed. We will respond to such requests within 30 days (or such other period as required by applicable law). We may require verification of your identity before fulfilling an access request.
You have the right to request correction of inaccurate personal data. If you believe any personal data we hold is incorrect or incomplete, please contact us and we will rectify it without undue delay.
You have the right to request deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected, where consent has been withdrawn, or where the data has been unlawfully processed. This right is subject to our legal obligations to retain data for tax, regulatory, or legal purposes, which may override a deletion request.
You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data or where you have objected to processing pending verification of our legitimate interests.
Where processing is based on consent or contractual necessity and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
You have the right to object to the processing of your personal data for direct marketing purposes at any time, without giving reasons. You also have the right to object to processing based on our legitimate interests, on grounds relating to your particular situation.
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects concerning you. Maldives Diaries does not currently engage in such automated decision-making.
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
You have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction. For EEA residents, this is the data protection authority of your EU Member State. For UK residents, this is the Information Commissioner's Office (ICO). For Maldivian residents or for complaints relating to Maldivian law, you may contact the relevant Maldivian authority responsible for data protection matters.
To exercise any of the above rights, please submit a written request to privacy@maldivesdiaries.com. We may ask you to verify your identity before processing your request. We will respond within 30 days, or within the timeframe required by applicable law.
Our website uses cookies and similar tracking technologies to enhance user experience, analyse website performance, and support our marketing activities. A cookie is a small data file stored on your device when you visit a website.
Types of Cookies We Use:
We obtain your consent before placing non-essential cookies on your device through our cookie consent tool. You may withdraw or modify your consent at any time by accessing your cookie settings on our website.
You may also control cookies through your browser settings. Disabling certain cookies may affect the functionality of our website.
Our website may include social media sharing features, embedded content, or links to third-party websites. The Company is not responsible for the privacy practices of third-party websites and encourages you to review their respective privacy policies.
When you interact with our social media channels, your personal data will also be processed by the operator of the relevant platform (e.g., Meta, Instagram, Facebook) in accordance with their privacy policies. We do not control this processing.
We may use your contact details to send you promotional communications about our Packages, special offers, new itineraries, and travel content. We rely on:
You may unsubscribe from marketing communications at any time by clicking the unsubscribe link in any marketing email, or by contacting us at privacy@maldivesdiaries.com. Unsubscribing from marketing does not affect communications necessary for the performance of an existing Booking.
We do not sell, rent, or exchange your personal data with third parties for their own marketing purposes.
Where you provide us with a review, testimonial, or photograph for publication on our website or marketing materials, we will publish this content only with your explicit written consent.
You may withdraw consent for publication of your testimonial or photograph at any time by contacting us. We will remove such content within a reasonable time, acknowledging that content already distributed in physical print materials cannot be recalled.
Our services are marketed to adults aged 18 and over. Where a Package includes minors (persons under 18 years of age), the personal data of such minors is processed only with the explicit consent of and under the authority of the minor's parent or legal guardian, who accepts full responsibility for compliance with these terms on behalf of the minor.
The personal data of minors will be used only to the extent necessary for the delivery of the booked Package and compliance with Maldivian immigration and safety requirements.
The Company does not knowingly collect personal data from children for marketing purposes. If we become aware that we have inadvertently collected such data, we will delete it promptly.
We recognise that health data is among the most sensitive categories of personal data. We process health-related information provided by Clients solely for the following purposes:
Health data is shared with Service Providers only to the extent strictly necessary for safety, and is not disclosed for any other purpose.
We process health data on the basis of explicit consent, which you provide by completing the health declaration section of our Booking Form. You may withdraw this consent at any time; however, withdrawal may mean that the Company is unable to assess the suitability of certain activities for your participation.
Passport and travel document data is collected solely for the purposes of coordinating travel logistics and fulfilling Maldivian immigration requirements. Copies of passports are held in encrypted digital storage and are not shared beyond the parties necessary for immigration, transport, and accommodation check-in purposes.
Maldivian law and immigration regulations require that certain passenger data be provided to Maldivian immigration authorities. Provision of this data is a legal requirement and is not subject to Client objection.
Where we process personal data of individuals in the EEA or UK, we do so in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK GDPR respectively. This includes observing all applicable data subject rights described in Section 13, maintaining records of processing activities, and implementing appropriate safeguards for international transfers.
Our lawful basis for international transfer from the EEA or UK to the Maldives is primarily the necessity of the transfer for the performance of a contract between the Data Subject and the Company (Article 49(1)(b) GDPR). Where we engage EEA or UK-based data processors, we ensure Standard Contractual Clauses are in place where required.
EEA and UK Clients have the right to complain to their local data protection authority: for EEA residents, the supervisory authority of the relevant EU Member State; for UK residents, the Information Commissioner's Office (ico.org.uk).
Clients resident in countries with applicable data protection legislation (including but not limited to Australia, Canada, Singapore, India, and other jurisdictions with privacy frameworks) retain their rights under applicable local law. The Company will endeavour to accommodate rights requests from Data Subjects in all jurisdictions within a reasonable timeframe.
Clients are encouraged to contact privacy@maldivesdiaries.com to exercise any jurisdiction-specific rights or to request information about how we comply with applicable local data protection law.
We review and update this Privacy Policy periodically to reflect changes in our data processing activities, applicable law, and best practice. The current version and its effective date are displayed at the top of this document.
Where we make material changes to this Policy, we will notify affected Data Subjects by email (where we hold an active email address) and will publish the updated Policy prominently on our website. Continued use of our services following notification of a material update constitutes acceptance of the updated Policy.
We encourage you to review this Policy periodically.
This Privacy Policy is governed by the laws of the Republic of Maldives. To the extent required by applicable law in the jurisdiction of the Data Subject, the applicable data protection law of that jurisdiction also applies to the processing of that Data Subject's personal data.
For all data protection enquiries, rights requests, or concerns, please contact our Privacy Office:
Maldives Diaries — Privacy Office
Email: privacy@maldivesdiaries.com
Phone: [+960 XXX XXXX]
Address: [Address, Malé, Republic of Maldives]
Data Protection Commitment: Maldives Diaries is committed to handling your personal data with the highest standard of care, transparency, and respect. If you believe your data has been mishandled, please contact us directly so we may address your concern. You also have the right to escalate to your local supervisory authority at any time.