Italy's data protection authority fined Lusha Systems Inc. 2 million euros on July 27, 2026, and ordered the US-based sales intelligence company to stop processing and to erase the personal data of individuals located in Italy, after finding the platform had collected, updated and sold enriched contact profiles without a valid legal basis.

The Garante per la Protezione dei Dati Personali, the Italian data protection authority commonly known as the Garante, published its press release on July 27, confirming a decision it had formally adopted thirteen days earlier, on July 14, 2026. According to the Garante, the underlying order carries the reference number assigned in its own case file and was the product of an instructional proceeding examining how Lusha's platform sources, refreshes and resells what the company itself calls "enriched" information on individuals.

What the Garante found

Lusha Systems Inc., headquartered in Boston, Massachusetts, operates a paid platform that supplies customers with job titles, email addresses and phone numbers tied to named individuals. According to the Garante's press release, the company gathers this information from a mix of sources, including scraping activity directed at social networks and purchases made from other data brokers. The regulator's own description places the platform squarely within the sales intelligence and lead generation category that has grown alongside programmatic and account-based marketing.

What drew regulatory attention was not simply that Lusha collects professional information. According to the Garante, the platform's dataset extended further than typical business-card details: it included contact information tied to representatives of senior institutions, public administration, law enforcement bodies and the judiciary. That detail, buried in a single sentence of the press release, gave the case its most striking texture: a commercial contact database that had, according to the authority, come to include figures whose positions carry particular sensitivity.

The Garante's finding rested on four principles it said Lusha had violated: lawfulness, fairness, transparency and data minimization, all core requirements under the General Data Protection Regulation. On transparency specifically, the authority determined that the information Lusha provided to the individuals whose data it processed - the privacy notice a data subject would need in order to understand what was happening to their information - was neither clear nor easily accessible. That finding matters because it goes to a structural feature of the data broker business model. When a company has no direct relationship with the people in its database, as is common with third-party enrichment platforms, transparency obligations become the primary mechanism through which those individuals can even learn that their data is being processed at all.

The legitimate interest question

The most consequential part of the ruling concerns the legal basis Lusha relied on to justify its processing. According to the Garante, the company's pursuit of a legitimate interest did not constitute an adequate legal foundation under the GDPR. Legitimate interest is one of six lawful bases for processing personal data set out in Article 6 of the regulation, and it has become the default justification cited by companies that collect data without direct consent from the individuals concerned - precisely the situation facing most data enrichment platforms, whose business model depends on aggregating information about people who never opted into the collection.

The Garante's reasoning did not treat this as a marginal or technical failure. The authority determined, in effect, that a legitimate interest cannot support a business model built on continuous monitoring and resale of personal data at this scale, without the individual's knowledge and without an adequate transparency mechanism in place. That conclusion sits within a broader pattern documented across European enforcement in 2025 and 2026, where regulators and courts have repeatedly found that companies treat legitimate interest as a flexible fallback rather than a carefully documented legal basis requiring a genuine balancing test. The Court of Justice of the European Union addressed the same tension in a 2024 ruling involving a Dutch sports federation's sale of member data, and the European Data Protection Board's own analysis, published in March 2026, traced how controllers across the bloc systematically underestimate what that balancing exercise demands.

Extraterritorial reach under Article 3

Lusha has no establishment in the European Union. That fact would, under a narrower reading of the GDPR, place the company outside the regulation's reach entirely. The Garante rejected that interpretation. According to the authority's decision, the GDPR applies to the processing of personal data belonging to individuals included in Lusha's database precisely because such processing falls within the monitoring criterion set out in the European regulation - a reference to Article 3(2)(b), which extends GDPR jurisdiction to non-EU companies whenever their processing amounts to monitoring the behavior of individuals within the Union, regardless of where the company is physically based.

The Garante's justification for applying that criterion turned on a specific technical distinction. Lusha, the authority found, does not simply collect professional information once and leave it static. According to the decision, the company also maintains and periodically checks that information over time. The Garante characterized these update and verification operations as constituting monitoring of the behavior and personal positions of data subjects on the internet - what the authority explicitly termed a genuine form of "tracking" relevant under the GDPR. That reasoning transforms what might otherwise look like routine database maintenance into a jurisdictional trigger, and it does so through a chain of inference: continuous updating implies ongoing observation, and ongoing observation of behavior qualifies as monitoring under European law.

The remedy: a processing ban and erasure order

Having established that Lusha's conduct was unlawful, and that the processing operations - which the Garante noted were still ongoing at the time of the decision - had lacked a valid legal basis from their origin, the authority imposed two remedies rather than the fine alone. It prohibited Lusha from processing the personal data of individuals located in Italy, and it ordered the company to erase that data.

The combination of measures distinguishes this case from a purely financial penalty. A 2 million euro fine against a company that has raised 245 million dollars in venture funding, according to third-party financial data, represents a modest direct cost. The processing ban and erasure order strike at something closer to the operational core: they instruct Lusha to stop selling access to a defined subset of its database and to delete the underlying records, rather than simply pay a penalty and continue business as usual.

Industry reaction

The decision generated visible reaction within Europe's privacy and compliance community in the days following its publication. Aner Rabinovitz, founder and chief executive of the Tel Aviv-based privacy consultancy PrivacyTeam, published an analysis of the ruling on LinkedIn describing the Garante's jurisdictional reasoning as "debatable" while noting his satisfaction with the outcome. Rabinovitz framed the more consequential question as what the decision means for businesses that rely on Lusha and similar platforms to qualify and enrich prospect data for marketing, sales or recruitment purposes.

In his analysis, Rabinovitz argued that the case was not a marginal or ambiguous example of legitimate interest failing to apply. He wrote that there was no relationship between Lusha and the individuals in its database, no reasonable expectation on their part that this processing would occur, and their data was monetized for the commercial purposes of Lusha's customers. He characterized obtaining consent at the scale Lusha operates as unrealistic, and argued that this unrealism threatens the underlying business model more severely than the fine itself.

Rabinovitz raised a further question with direct relevance to companies purchasing data from brokers rather than operating as brokers themselves. He noted that buying data does not, on its own, cure the data's unlawful origin: a customer becomes a data controller once it obtains and uses that data for its own purposes, and that customer must independently comply with core processing principles and establish its own lawful basis. He described what he called a familiar routine in the industry - a customer asks a broker about the legality of its data, the broker cites legitimate interest and perhaps shares its legitimate interest assessment, a blind eye is turned, and the transaction proceeds. Rabinovitz asked whether the Garante's decision could end that routine, questioning how a customer's processing could satisfy the GDPR's fairness principle when the underlying data was unlawfully collected and offered to that customer in the first place. He also raised the possibility that, rather than confronting that question directly, parts of the industry might instead focus on disputing the Garante's jurisdictional reasoning, avoid doing business tied to Italy for the time being, and continue largely unchanged until other regulators intervene.

The post drew substantial engagement, accumulating dozens of reactions and several comments from other privacy professionals. One commenter, identified as Lior Etgar and described as head of a data protection and privacy practice, asked what the ruling would bring to the scraping industry more broadly. Another commenter, identified as Suze P. and described as an external data protection officer, expressed a wish that regulators would take similar action against other data brokers, naming ZoomInfo specifically alongside a general reference to comparable companies in the sector.

How Lusha describes its own data sourcing

Lusha's own published materials describe a data collection architecture consistent with several of the elements the Garante examined. According to the company's data sources page, Lusha's proprietary algorithm cross-checks data from multiple sources and combines numerous data points to construct a single business contact or company profile every time a customer performs a search on the platform. The company describes four categories of information sources: contributions from members of what it calls the Lusha Community, who volunteer to share contact details from their own business email accounts; licensed information from third-party business partners who maintain established directories; publicly available information retrieved through the company's own scanning tools; and an internal system the company describes as its insight and analysis engine, which uses machine-learning models to auto-complete business information, including generating email addresses based on standard corporate patterns.

The same page states that Lusha's technology identifies the most up-to-date information for each business profile while simultaneously removing outdated data from the system - a description that aligns closely with the ongoing update and verification activity the Garante cited as the basis for applying the GDPR's monitoring criterion. Lusha's materials also note that the company is registered as an official data broker with the California Data Broker Registry, and separate legal notices published by the company indicate registrations in additional US states as well as in Israel, where Lusha Systems Ltd. is registered as a data broker under Israeli law.

Context for the marketing and advertising community

The Lusha decision arrives within a wider enforcement trend that PPC Land has tracked across multiple jurisdictions targeting the data broker and sales intelligence sector specifically. Spain's data protection authority fined business data firm Informa D&B 1.8 million euros in January 2025 for processing the personal data of more than 1.6 million individual business owners without a valid legal basis, in a case that similarly centered on the gap between accessing public registry information and commercially exploiting it. A California enforcement action separately resulted in a 45,000 dollar penalty against a data broker for selling lists tied to health conditions, establishing that written compliance policies must be specific enough to prevent inadvertent collection and resale of personal information rather than relying on informal or periodic screening.

The broader legitimate interest question that anchors the Lusha ruling has surfaced repeatedly across European enforcement this year. A 746 million euro fine against Amazon over its reliance on legitimate interest for behavioral advertising was confirmed as substantively correct by Luxembourg's Administrative Court in March 2026, even though the court annulled the decision on a separate procedural ground and sent it back to the regulator to redo its fault and sanction analysis. The underlying finding that legitimate interest could not justify Amazon's processing was not disturbed. The European Data Protection Board's own July 2026 guidelines on web scraping in the context of generative AI, adopted less than three weeks before the Garante's Lusha decision was made public, established that organizations scraping publicly available data cannot rely on legitimate interest as a legal basis without implementing specific safeguards - a framework that maps closely onto the scraping-based collection methods the Garante identified in Lusha's own data sourcing.

For advertising and marketing professionals specifically, the ruling carries a distinct kind of relevance. B2B enrichment platforms comparable to Lusha have become embedded infrastructure across sales, marketing and account-based advertising workflows. The Trade Desk's B2B audience partnerships, including a July 2025 arrangement between MNTN and ZoomInfo bringing B2B advertising to connected television using access to 100 million decision-maker profiles, illustrate how deeply this category of data has been woven into programmatic targeting beyond simple prospecting use cases. A regulatory finding that a major player in this space lacked a valid legal basis "from the outset," in the Garante's own words, raises questions for any organization further downstream that has purchased or licensed comparable enrichment data for its own campaigns, since - as Rabinovitz's analysis noted - a purchaser's own compliance obligations do not automatically dissolve simply because the data changed hands.

The case also fits within a documented pattern of Italian regulatory activity targeting data-intensive commercial practices more broadly. The Garante fined Intesa Sanpaolo 17.6 million euros in March 2026 for unlawfully profiling 2.4 million bank customers ahead of an account transfer, and separately fined the same institution 31.8 million euros after a single employee accessed thousands of customer records without authorization. Those cases, together with the Lusha decision, indicate an Italian authority willing to scrutinize the legal architecture underlying large-scale data processing across sectors, from financial services to commercial data brokerage.

Whether the Lusha decision changes practice across the sales intelligence industry, as Rabinovitz's analysis suggested it might, or whether affected companies instead focus on contesting the Garante's jurisdictional theory while continuing largely unchanged in markets outside Italy, remains an open question the coming months will likely clarify.

Timeline

  • 2016: Lusha is founded, according to third-party company data.
  • November 10, 2021: Lusha closes a 205 million dollar Series B funding round, according to third-party financial data.
  • January 2025: Spain's data protection authority fines business data firm Informa D&B 1.8 million euros for processing personal data without a valid GDPR legal basis.
  • March 18, 2025: Luxembourg's Administrative Tribunal upholds a 746 million euro fine against Amazon over legitimate interest as a legal basis for behavioral advertising, according to the tribunal's ruling.
  • March 2026: Italy's Garante fines Intesa Sanpaolo 17.6 million euros for unlawfully profiling 2.4 million bank customers.
  • March 2026: Luxembourg's Administrative Court annuls the Amazon fine on procedural grounds while leaving the underlying legitimate interest finding intact, according to the court's ruling.
  • March 2026: The European Data Protection Board publishes an analysis documenting systematic failures in how controllers apply the legitimate interest legal basis across the EU.
  • July 7-8, 2026: The European Data Protection Board adopts and announces guidelines restricting reliance on legitimate interest for web scraping activity.
  • July 14, 2026: The Garante formally adopts its decision against Lusha Systems Inc.
  • July 21, 2026: Israel's Privacy Protection Authority imposes its first sanction under Amendment 13 to the country's Protection of Privacy Law, against Meuhedet Health Fund, according to third-party legal reporting.
  • July 27, 2026: The Garante publishes its press release announcing the fine, processing ban and erasure order against Lusha.

Summary

Who: Italy's Garante per la Protezione dei Dati Personali (the Garante), the country's data protection authority, took action against Lusha Systems Inc., a US-based data broker headquartered in Boston, Massachusetts, that operates a paid sales intelligence platform.

What: The Garante imposed a 2 million euro administrative fine, banned Lusha from processing the personal data of individuals located in Italy, and ordered the erasure of that data, after finding the company's collection, updating and resale of "enriched" contact information - including job titles, email addresses and phone numbers - violated the GDPR's principles of lawfulness, fairness, transparency and data minimization, and relied on an inadequate legal basis.

When: The Garante formally adopted its decision on July 14, 2026, and published its press release announcing the outcome on July 27, 2026.

Where: The decision applies to the processing of personal data belonging to individuals located in Italy, though the Garante's reasoning addresses Lusha's global data collection practices, including scraping activity directed at social networks worldwide.

Why: The authority found that Lusha's data enrichment platform, despite having no legal establishment in the European Union, fell within the GDPR's jurisdiction because its ongoing monitoring, updating and verification of individuals' professional information constituted behavioral tracking under the regulation's Article 3 monitoring criterion, and that the company's reliance on legitimate interest could not provide an adequate legal basis given the platform's lack of any relationship with, or transparency toward, the individuals whose data it processed and sold.