In short
The Italian DPA fined Lusha Systems Inc. EUR 2 million. The US company runs a contact enrichment platform: job title, email addresses, phone numbers. The decision is dated 14 July 2026 and was announced on 27 July.
Where the data came from
The company gathered information from several sources: scraping social networks and buying from other data brokers. It then made it available to platform customers for commercial or anti-fraud purposes. Among the searchable records were data on senior institutional figures, public administration officials, law enforcement officers and magistrates.
That is what makes this decision different from the usual marketing cases: none of those people had ever had any relationship with the company, and none knew they were in a catalogue for sale.
What the authority found
- Breach of the principles of lawfulness, fairness and transparency
- Breach of the data minimisation principle
- A privacy notice that was neither clear nor easily accessible to data subjects
- No adequate legal basis: legitimate interest was not accepted as a proper ground for this processing
Rejecting legitimate interest is the part that matters beyond this case. Data brokering has rested on that basis for years: collect publicly accessible professional data, enrich it, resell it, and treat the commercial interest as prevailing. The authority says that balancing does not hold when the data subject has no relationship with the controller, cannot reasonably expect the processing, and receives no intelligible notice.
The company is American, so what?
Lusha has no establishment in Italy, and that did not shield it. The decision is an example of the Regulation's extraterritorial reach: where processing concerns people located in the Union and is linked to offering services or monitoring their behaviour, the rules apply regardless of where the controller is established.
Beyond the fine, the authority banned the company from processing the personal data of people located in Italy and ordered the deletion of what had been unlawfully collected.
The question for clients who buy lists
If a client uses a contact enrichment platform for its sales force — and very many do — this decision concerns them directly. Not as the sanctioned party, but as a controller who sourced data from an unlawful supply: in proceedings it is the sender who answers, not the seller of the list. One question: where do these contacts come from, and can the platform demonstrate it for each one?
What changes in practice
- A contractual statement that 'data is collected in compliance with the GDPR' is not evidence, it is a promise
- The duty to inform the data subject within one month, where data was not collected from them, stays with whoever uses it
- If the supplier is hit by a processing ban, data already downloaded by the customer does not become lawful by having been downloaded earlier
- For every platform in use it is worth checking whether it has been the subject of decisions by European authorities: they are public
The market for professional contact data grew in the grey zone between 'public data' and 'freely usable data', which are not the same thing. This decision is among the clearest in saying that publicly accessible does not mean available for resale.
Official source:Garante privacy - Il Garante privacy sanziona Lusha per 2 milioni di euro. Monitorati e in vendita i dati di un elevato numero di persone (comunicato 27 luglio 2026)Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free