Single Blog Title

This is a single blog caption

Data, Electronic System, and Software Licensing Issues in Yacht Contracts

Data, Electronic System, and Software Licensing Issues in Yacht Contracts

What are the issues related to data, electronic systems, and software licensing in yacht contracts? A comprehensive legal guide explaining the risks of software licensing, user access, remote support, data security, and data transfer abroad in yacht sales, charter, management, refit, and maintenance contracts, within the framework of the Turkish Personal Data Protection Law (KVKK), the Turkish Intellectual Property Rights Law (FSEK), the Turkish Code of Obligations (TBK), and the Turkish Private International Law Act (MÖHUK).

Entrance

The yachting industry is no longer limited to just the hull, engine, and equipment. A modern yacht includes navigation electronics, engine control units, stabilizer software, alarm systems, CCTV, guest Wi-Fi infrastructure, entertainment systems, electronic circuit updates, remote maintenance modules, cloud-based monitoring panels, and sometimes access systems operated via mobile applications. Under the Turkish Commercial Code, yachts may qualify as "ships" under certain conditions; however, the software, data, and electronic systems operating on these vessels often simultaneously involve provisions of contract law, intellectual property law, personal data protection law, and international private law. Therefore, the main risk in current yacht contracts is not only the delivery of the vessel, but also whether the "digital control" and "legally usable software infrastructure" of that vessel are being transferred.

A common mistake in practice is assuming that the electronic systems on a yacht are a natural extension of the physical equipment. However, for many navigation, safety, engine, and entertainment systems, the real determining factor is not the device itself, but the software license, update rights, user access, manufacturer account, and remote service infrastructure running on that device. Even if the boat is physically transferred in a sale, the software account may not be transferred, the license may be tied to an individual or company, cards and subscriptions may expire, and GDPR obligations may arise for data transferred to a foreign server. This is why data, electronic system, and software license issuesare no longer secondary, but core aspects of yacht contracts.

What does software represent legally?

In Turkish law, computer programs are protected under the Law No. 5846 on Intellectual and Artistic Works. Article 2 of the Law on Intellectual and Artistic Works lists computer programs and their preparatory designs among "scientific and literary works." This means that navigation software, engine management interfaces, CCTV recording platforms, or special automation modules on a yacht can be considered not only technical tools but also works protected by intellectual property law. Therefore, the use of software is often evaluated within the framework of licensing or financial rights, rather than a transfer of ownership.

This distinction is extremely important from a contractual standpoint. The sale of the physical ownership of the boat does not always mean that the buyer also acquires unlimited and transferable rights to use the software installed on the system. The provisions of the Copyright Law regarding the transfer of financial rights and licensing indicate that financial rights or usage rights over the software can be transferred by contract, but this requires separate legal assessment. In particular, current legislative reflections regarding Article 52 of the Copyright Law clearly state that contracts and dispositions concerning financial rights in writing and that the rights subject to transfer be specified separately . Therefore, single-sentence clauses such as "all software is transferred along with the boat" do not always provide sufficient protection in high-value systems.

The biggest digital risk in yacht sales: Hardware available, licenses missing

Classic points of contention in yacht sales contracts relate to the engine, hull, equipment, and title. However, nowadays, electronic system licenses are equally important. The yacht for sale may include chartplotter licenses, electronic chart subscriptions, engine monitoring panels, remote diagnostic modules, camera recording software, media servers, or automation software. Some of these may be tied to the yacht, some to a user account, and some may be limited to a specific subscription period. Due to the fact that software is considered a work under the Law on Intellectual and Artistic Works and the need for written licensing/transfer, even if the seller transfers the yacht's equipment, they may not actually transfer certain usage rights. This can result in the buyer acquiring the yacht but being unable to use some of the digital systems.

Therefore, simply stating "electronic equipment is included in the sale" is insufficient in a yacht sales contract. It is crucial to clearly investigate which systems are licensed, whether the license is transferable, whether manufacturer or distributor approval is required, whose account holds the usernames and passwords, when subscription and update periods expire, and whether the cloud platform account is registered in the seller's name or the yacht's name. Failure to conduct this investigation may result in the buyer receiving physical hardware but inheriting a digital infrastructure with a locked or expired license. This is particularly common with software from foreign manufacturers. The outcome here is a significant practical risk derived from the licensing logic within the framework of the Copyright Law and freedom of contract.

Standard manufacturer contracts and EULA risk

A significant portion of modern yacht systems operate through standard license agreements prepared by the manufacturer or integrator. These agreements are often accepted upon device startup, activation screen, service portal, or distributor account. Article 20 of the Turkish Code of Obligations defines unilaterally prepared provisions as general terms and conditions of business, intended for use in numerous similar contracts in the future. It is also accepted that clauses granting the drafter the unilateral right to make changes within the same system may be considered null and void, and that aggravating provisions contrary to the principle of good faith are subject to content review. This framework demonstrates that the standard EULA texts of the software manufacturer on the yacht may not always have unlimited effect in relationships governed by Turkish law.

In practice, this risk manifests as follows: the software provider sets standard clauses regarding unilateral updates, service discontinuation, remote access, data usage policy, or the non-transferability of the license; the seller or management company then assumes that these clauses will automatically transfer to the boat buyer or charterer. However, in Turkish law, such standard clauses can be evaluated separately in the specific case. In particular, very stringent unilateral modification authorizations, unexpected limitations, or restrictions unrelated to the nature of the contract can create controversy. Therefore, instead of simply stating in the yacht contract that "all embedded software licenses are transferred with the existing EULA provisions," critical licenses should be listed separately.

Data issues in charter contracts: Guest, crew, and tracking data

In yacht charter agreements, data is just as important as software licenses. During the charter process, passport and identity card data, passenger lists, payment information, contact information, route information, in some cases CCTV recordings, entry and exit data, Wi-Fi session logs, and crew information are processed. Under the Personal Data Protection Law (KVKK), explicit consent is not always the sole legal basis for processing personal data. Official texts and explanations regarding Article 5 of the Law state that processing personal data belonging to the parties of a contract may be necessary if it is directly related to the establishment or performance of the contract; if the data controller can fulfill its legal obligations; or if a right can be established, exercised, or protected. Therefore, the charter company or management company should process data not simply on the basis of "I obtained/must obtain consent," but through a proper analysis of the legal basis.

However, it must also be clearly explained which data is processed and for what purpose. In its statements regarding Article 10 of the KVKK (Law on Protection of Personal Data), the Authority explicitly states that the data controller must disclose their identity, the purpose of data processing, to whom and for what purpose the data may be transferred, the method of collection and the legal basis, and the rights of the data subject. This obligation is directly relevant for passenger lists, charter reservations, data transferred to marinas and agencies, crew identity files, and digital check-in forms. If applications or online check-in systems are used in yacht charters, the disclosure and data flow diagram must become an integral part of the contract.

Who is the data controller in management agreements?

One of the most challenging questions in yacht management contracts is determining who is the data controller with respect to personal and operational data . The roles of the yacht owner, management company, charter operator, marina, and SaaS software provider are not the same. The Personal Data Protection Law (KVKK) system considers the person who determines the purposes and means of data processing as the data controller; data security obligations are also established based on this role. According to official statements, the data controller is obliged to take the necessary technical and administrative measures to prevent the unlawful processing and access of personal data and to ensure the preservation of data. This shows that the management company cannot shift all the security burden by saying "the data belongs to the yacht owner," and the owner cannot completely evade oversight by saying "the management handles everything."

Therefore, data headings should be written separately in management agreements. Which data will be processed on behalf of the owner and which will be used for the management company's own processes; for what periods will reservation data, crew payroll data, technical maintenance logs, and CCTV recordings be stored; who will inform whom and within what timeframe in case of a data breach; how will the authorized access list be maintained; how will the accounts and access of departing crew members be closed? All of these must be clearly defined in the agreement. Management relationships established without separating the data controller/processor roles, especially when using foreign cloud software, quickly generate GDPR and compensation risks.

Transferring data abroad: One of the most critical topics for yachts using cloud systems

A significant portion of modern yacht systems are dependent on manufacturer servers or cloud infrastructures located abroad. Location data, engine alarm data, maintenance logs, CCTV access, remote support records, booking data, or crew files may be transferred to systems overseas. In its official statement regarding Article 9 of the Personal Data Protection Law (KVKK), the Authority states that, in the absence of a suitability decision, the transfer of personal data abroad requires the fulfillment of one of the processing conditions stipulated in the Law and the provision of appropriate safeguards. The Authority's "Transfer Abroad" page and guide also explain appropriate safeguards and standard contractual mechanisms.

More recently, the Authority's 2025 public announcement further emphasized technical details and procedural requirements, such as notarized Turkish translations, regarding standard contracts to be used for data transfer abroad. This demonstrates that the "the server is already abroad, everyone does it this way" approach is legally insufficient for yacht operators whose data flows to foreign software providers or global charter platforms. If foreign software, foreign CRM, foreign booking platform, or foreign engine monitoring infrastructure will be used in the yacht contract, the issue of data transfer abroad must be considered separately.

Electronic system malfunctions: Is it a defect, a licensing issue, or a service interruption?

Not all digital problems on a yacht fall into the same category. Sometimes the device is faulty; sometimes the system doesn't work because the license has expired; sometimes the manufacturer stops the cloud service; and sometimes the system becomes inoperable due to an integration error after a refit. The provisions of the Turkish Code of Obligations regarding sales and construction contracts are decisive here. In sales contracts, the liability regime for defects is based on the premise that the delivered item does not possess the intended use value agreed upon in the contract or expected according to the principle of good faith; in construction contracts, the contractor is obliged to produce the result in accordance with the contract and to act diligently. Therefore, the malfunction of the electronic system cannot always be dismissed as a "software problem outside the warranty"; the source of the problem—whether it's hardware, integration, licensing, or an update—must be identified.

Therefore, separate acceptance criteria must be specified for electronic systems in sales and refit contracts. There is a significant difference between stating "the engine display will be delivered in working order" and "the engine display will be delivered licensed, up-to-date, and with the remote access account transferred." Similarly, simply stating "a new navigation system will be installed" in a refit contract is insufficient; the specific software version, map subscription, integration, and user license must be specified. Otherwise, the contractor may have physically installed the system but delivered it legally incomplete. This outcome stems from adapting the concept of defects and obligations under the Turkish Code of Obligations to electronic systems.

Software licenses must be specifically regulated in refit and maintenance agreements

In refit projects, electronic system updates have become almost standard practice. However, a common mistake in these projects is that the contractor delivers the hardware, but fails to specify in whose name the licenses are activated, the validity period of the subscriptions, who retains access to the manufacturer's portal, whether maintenance rights are exclusive, and whether third-party service intervention will void the license. Since software is a matter of financial rights and licensing under the Copyright Law, the logic of "the device was installed on the boat, therefore the software was also transferred" is insufficient. The need to clearly and separately specify license rights is particularly important in refit projects.

Therefore, the refit agreement should include at least the following points: which software modules will be installed, will the license be perpetual or fixed-term, what will the update and support period be, in whose name will the manufacturer account be opened, can the departing shipyard/integrator later close access, will third-party service entries downgrade the license, will data backups and logs be delivered, and will configuration files and admin-level access be delivered, even if not the source code? Without these points, the boat may appear technically modernized after the refit, but it may become effectively dependent on a single integrator. This creates a significant risk of legal and commercial deadlock.

If a software license includes a foreign element, the applicable law must also be considered

Software and electronic system relationships in yacht contracts very often involve foreign elements. The manufacturer may be foreign, the server may be in another country, the license text may be in English, and the support agreement may be governed by a different legal system. According to Article 24 of the Turkish Private International Law Act, contractual obligations are subject to the law explicitly chosen by the parties; it may also be agreed that the chosen law applies to the whole or part of the contract. This means that a yacht sales contract may be governed by Turkish law, while the software support and licensing relationship within it may be governed by foreign law.

Therefore, when writing the "applicable law" clause in yacht contracts, it is necessary to consider both the physical sale of the boat and the software/service layer together. Otherwise, while the boat transfer may appear problem-free under Turkish law, the software license may be subject to foreign law and foreign forum conditions. It should be remembered that the licensing relationship constitutes a separate legal domain, especially for systems using remote access, cloud panels, map subscriptions, and manufacturer portals. The safest approach is to examine the manufacturer's license terms for critical systems in an appendix to the contract and to clearly align them with the yacht sale/management/refit agreement.

Technical and administrative measures in terms of the Personal Data Protection Law (KVKK) must be written into the contract

The institution's personal data security guidelines and official statements clearly state that data controllers are obligated to take technical and administrative measures to prevent the unlawful processing and access of personal data and to ensure its preservation. This obligation should not be left abstract in yacht contracts. Especially when camera recordings, passenger check-in systems, personnel files, remote engine monitoring panels, and mobile applications are involved, a password policy, authorization matrix, log logging, data backup, encryption, remote deletion, restriction of access for departing personnel, and data breach notification procedures should be included in the contract.

In practice, these items are often left to the IT team and are not included in the main contract. This is a wrong approach. Because when a data breach occurs, not only the technical team but also the legal chain of responsibility between the owner, management company, charter operator, and software provider comes into play. Therefore, technical and administrative measures should be written not only as internal policy but also as contractual commitments. Especially if outsourced IT or SaaS is used, the subcontractor's GDPR obligations and audit rights should be regulated separately.

Common contract errors

The most common mistake in this area is confusing hardware rights with software rights. Selling a boat doesn't necessarily mean the system software is transferred. A second mistake is accepting manufacturer EULA texts "as is" without reviewing them. A third mistake is failing to clearly define personal data processing roles in charter and management agreements. A fourth mistake is ignoring Article 9 of the Turkish Personal Data Protection Law (KVKK) for data sent to foreign servers. A fifth mistake is not explicitly stating license, update, and admin access in refit projects. Due to these errors, even if the boat appears physically operational, it may be legally unlicensed, data-incompatible, and operationally locked.

Another common mistake is thinking that the entire problem can be solved with a "privacy clause." However, data protection, privacy, software licensing, and electronic system performance are different legal topics. The privacy clause protects trade secrets; the Personal Data Protection Law (KVKK) regulates personal data; the Copyright Law (FSEK) determines the financial rights and licensing regime for software; and the Turkish Code of Obligations (TBK) governs defects, work obligations, and general terms and conditions. A good contract does not combine these areas into a single clause; it establishes separate but compatible provisions.

Conclusion

In yacht contracts, issues related to data, electronic systems, and software licensesare no longer secondary matters that can be delegated to the technical team. Computer programs are protected as works under the Law on Intellectual and Artistic Works (FSEK); licenses and transfers of financial rights must be established in writing, and the rights subject to the transfer must be specified separately. Regarding personal data processing and data security, the Personal Data Protection Law (KVKK) imposes clear obligations regarding data processing conditions, disclosure, data subject rights, data security measures, and data transfer abroad. The Turkish Code of Obligations (TBK) is decisive in terms of contracts and general terms and conditions, while the Private International Law Act (MÖHUK) is decisive in the area of ​​foreign-related licenses and services.

Therefore, when drafting a modern yacht contract, the following questions must not be left unanswered: Which software and electronic systems are being transferred with the boat? Is the license transferable? What is the subscription and update period? Who will retain admin access and the manufacturer's account? By whom and for what legal reason will passenger, crew, and technical data be processed? Will data be transferred abroad? In the event of a data breach, who will inform whom and within what timeframe? What will be the digital handover criteria at the end of a refit or maintenance? If these questions are clearly written, digital risk can be managed; otherwise, even the most expensive yacht can turn into a legal crisis due to a password, a license key, or a data breach. In yacht law, true handover is no longer just about handing over the keys, but also about handing over access, licenses, and data control.

Leave a Reply

Call Now Button