CARNIVAL PLC.
CCL.LSE | Sea and coastal passenger water transport
Carnival PLC is a global cruise company that operates a fleet of cruise ships, offering a variety of vacation experiences to passengers worldwide. The company's brands include Carnival Cruise Line, Princess Cruises, Holland America Line, Seabourn, Costa Cruises, AIDA Cruises, P&O Cruises (UK), and P...Show More
Better Health for All
-60
Carnival Corporation has demonstrated a severe lack of risk transparency, pleading guilty to six probation violations
1
and seven felony charges for falsifying training records and redefining environmental compliance non-conformities to avoid detection
2
. This constitutes systematic concealment of known health risks and regulatory deception. The company also has a long history of major health-harming externalities, including dumping plastic waste, oily discharge, and contaminated waste into the ocean
3
, resulting in criminal penalties of $20 million
4
and $40 million
5
, and over $72.5 million in environment-related offenses since 2000
6
. These operational impacts contribute significantly to a negative net health effect from its principal services. Furthermore, Carnival has incurred over $10.4 million in fines for three privacy violations
7
, with a $5 million fine in 2022
8
, indicating basic data protection with vulnerabilities. In contrast, the company shows positive efforts in nutrition and food safety, being highly diligent about food allergies
9
and accommodating a wide variety of special dietary needs fleet-wide with programs like Menu Mate™
10
.
Fair Money & Economic Opportunity
0
Carnival PLC is a global cruise company, and its core business does not involve lending, insuring, moving, or storing money in the context of consumer financial services. The provided evidence does not indicate that the company offers consumer credit products, deposit services, or other financial products that would generate data relevant to the specific quantitative thresholds of the 'Fair Money & Economic Opportunity' KPIs. Therefore, all KPIs are scored as 0, indicating they are not applicable to the company's business model as assessed by the rubric.
Fair Pay & Worker Respect
0
No evidence available to assess CARNIVAL PLC on Fair Pay & Worker Respect.
Fair Trade & Ethical Sourcing
-10
Carnival requires all business partners and their supply chain partners to contractually comply with its Business Partner Code of Conduct and Responsible and Sustainable Sourcing Policy.
1
The company reported no complaints related to modern slavery practices or concerns within operations or supply chains for fiscal years 2023 and 2024
2
, and no incidents of forced child labor were identified on site during audits in 2024.
3
Audits have a validity of 1, 2, or 3 years, meaning they occur at most every 36 months.
4
Honest & Fair Business
0
No evidence available to assess CARNIVAL PLC on Honest & Fair Business.
Kind to Animals
0
In FY2024, the company sourced 39% of its chicken, 62% of its pork, and 80% of its eggs from responsible or cage-free systems
1
. The company aims to achieve 100% cage-free eggs, 100% responsible chicken sourcing, and 100% gestation crate-free pork by the end of 2025
2
. As a service-oriented cruise company, the KPIs for cruelty-free product certification, alternative testing usage, animal testing policy, and animal testing volume are not applicable to its operations.
No War, No Weapons
0
No evidence available to assess CARNIVAL PLC on No War, No Weapons.
Planet-Friendly Business
-50
The company has a goal to achieve a 20% greenhouse gas (GHG) emission intensity reduction by 2026 compared to 2019 levels.
1
While it performed a refresher education program covering the Science Based Target initiative in 2024
2
,
3
, there is no evidence that its targets are SBTi-validated. The company provides disclosures in accordance with the Task Force on Climate-related Financial Disclosures (TCFD) framework
4
, with its latest disclosure available in the 2024 Annual Report.
5
It employs both qualitative and quantitative scenario analyses to evaluate potential short-, medium-, and long-term climate impacts on its business.
6
,
7
Respect for Cultures & Communities
-10
Carnival has at least three formal partnerships with local community groups, including Te Kura Waka, Nature's Wonders, and Bay Bush Action.
1
The company supports the regeneration of the Opua State Forest and the return of Kororā (Little Blue Penguins) along the shoreline of the Waitangi Treaty Grounds.
2
Carnival provides a dedicated compliance reporting hotline and other channels for reporting concerns, available 24/7.
3
The company responded to concerns regarding the limitation of hip-hop and rap music in onboard clubs by stating they implemented themed nights covering various music genres.
4
Safe & Smart Tech
-30
Carnival Corporation has not experienced any material cybersecurity incidents in the last three fiscal years (2022-2024/2025).
1
However, between 2019 and 2021, the company experienced four security breaches, including ransomware attacks, which exposed sensitive customer data, compromised 124 employee email accounts, and led to unauthorized use such as sending internal spam.
2
The company was fined $5 million by a New York state regulator
3
and settled for $1.25 million with 45 U.S. states and Washington, D.C., for violating cybersecurity regulations, failing to report an incident for 10 months, and filing improper compliance certifications from 2018 to 2020.
4
Currently, Carnival employs strong encryption, with all passwords, data at rest, data in flight (using TLS 1.3 with 2048-bit RSA key exchange or above), and backup media being encrypted.
5
The company has a comprehensive vulnerability management program, including patch management, software composition analysis scans, adherence to OWASP Top 10 and NIST NVD, regular risk assessments, vulnerability assessments, and third-party penetration testing for shoreside and shipboard assets.
6
Privacy is integrated into design through three-tier systems, data separation, separation of duties, and distinct development environments.
7
Security testing is comprehensive, covering risk assessments, vulnerability assessments, penetration testing, external attack surface mitigations, network monitoring, and regular static analysis scans.
8
Users are offered extensive control over their data, including rights to access, correct, delete, restrict processing, object, and opt-out of data sales or targeted advertising.
9
Multi-factor authentication is used for remote access, alongside strong password policies.
10
The company conducts routine data privacy and security training, including phishing simulations and annual training, but past training was deemed inadequate.
11
Zero Waste & Sustainable Products
0
No evidence available to assess CARNIVAL PLC on Zero Waste & Sustainable Products.