The full text of Italy's decision against Lusha Systems Inc., adopted on 14 July 2026 and running to 220 numbered paragraphs, shows that the regulator's authority over a company with no European office rests on one product feature: the weekly refresh of a contact card. The same document sets a 60-day clock for proving Italian records have been deleted.

Italy's data protection authority fined the Boston-based sales intelligence company 2 million euros and ordered the erasure of every Italian record in its database, a decision the Garante per la Protezione dei Dati Personali summarised in a press release on 27 July 2026. The reasoning behind that summary is now public. Registered as provvedimento n. 542 of 14 July 2026 and carrying document reference 10275035, the order was decided in Rome by a panel comprising president Pasquale Stanzione, vice-president Ginevra Cerrina Feroni, member Agostino Ghiglia and secretary general Luigi Montuori, with Stanzione acting as rapporteur.

What the press release compressed into four principles, the full text spreads across 30 pages of jurisdictional argument, a three-limb dismantling of the company's legal basis, and a description of the collection pipeline that reaches considerably further than social media scraping.

Jurisdiction narrowed, then rebuilt

The Garante did not accept its own investigators' first theory. The office that opened the case had argued that the GDPRapplied under Article 3(2)(a), on the basis that Lusha offered services to natural persons in the Union because it could not reliably prove its customers were companies. The authority noted that, unlike other operators in business-to-business markets, Lusha did not ask for a VAT number, a power of representation or a delegation, and relied instead on rejecting free email domains such as Gmail, Yahoo and Hotmail at sign-up.

That reasoning survived only in part. According to the decision, the offering criterion could establish GDPR application to the processing of customer data, but not to the processing of the Contacts, the individuals whose details fill the database and who were the entire subject of the investigation. On that point the authority sided with the company.

Everything therefore rests on Article 3(2)(b), the monitoring criterion. Lusha argued there was no monitoring because there was no profiling and no behavioural analysis, and that recording a job change is an accuracy measure under Article 5(1)(d) rather than surveillance. The Garante separated the two concepts at length, working through recital 24, recital 30, the Article 29 Working Party impact assessment guidelines of 4 April 2017, its own cookie guidelines of 10 June 2021 and its April 2026 guidance on tracking pixels in email. Profiling, it concluded, is described in recital 24 as an eventual and subsequent operation, which makes it a possible consequence of tracking rather than a precondition for it.

Applied to the product, that reading captures ordinary database maintenance. Lusha builds a single Business Contact Card for each person, containing name, email address, phone number, job title, seniority, role and location, and refreshes it at least weekly. According to the decision, tracking a person's role, position or location in order to decide whether to include them in a database, and then watching for changes to those attributes over time, satisfies both the wording and the purpose of the monitoring criterion.

Giulio Coraggio, a lawyer who published an analysis of the ruling on LinkedIn, put the consequence in one line: "Monitoring does not require profiling." He noted that the reach of that finding extends well past the company sanctioned, since the Garante applied the regulation despite the absence of any EU establishment.

A deliberate break with Paris and Luxembourg

Lusha's defence leaned on two earlier assessments by other regulators. The CNIL had examined comparable processing in decision SAN-2022-024 of 20 December 2022, and Luxembourg's Commission Nationale pour la Protection des Données had addressed the question in an email dated 9 June 2022. Both, the company argued, found the regulation inapplicable. Departing from them without reason would breach the duty of sincere cooperation under Article 4(3) of the Treaty on European Union and the consistency objective of recital 10.

The Garante rejected the argument on structural grounds. The Luxembourg email concerns a specific case, was never published, and can bind only the parties involved. The French decision produces legal effects only between the parties to it, as recital 143 indicates. Chapter VII cooperation applies to controllers with an establishment in a member state, which Lusha does not have, so no cooperation duty was engaged. Article 57(1) leaves each authority competent within its own territory, and the authority cited the Court of Justice ruling in WhatsApp Ireland v EDPB, C-97/23 P, of 10 February 2026, on the board's role in securing consistent application.

The practical result is a company whose processing was assessed as outside the regulation in one member state and unlawful in another. That divergence sits alongside the jurisdictional questions raised when a Rome tribunal annulled the Garante's fine against OpenAI on one-stop-shop grounds, and within a wider record in which close to 40 percent of the 7.1 billion euros in GDPR fines has been annulled or challenged.

Three limbs, three failures

Article 6(1)(f) requires a legitimate interest, necessity, and a balance that does not favour the individual. According to the decision, the company failed each in turn.

The interest

Italian law requires the subscriber's consent before contact details are used for advertising, direct selling, market research or commercial communication. The authority has held consistently that passing personal data to third parties for their commercial purposes must rest on consent obtained at source, and that anyone assembling a contact database from multiple origins carries the burden of verifying the lawful origin of each list. Its 2013 anti-spam guidelines already stated that data drawn from public registers, directories or websites does not become available for promotional contact. An interest whose realisation requires a breach of national law cannot be legitimate, the Garante concluded. The anti-fraud interest, by contrast, was accepted as legitimate in the abstract.

Necessity

The legitimate interest assessment supplied to the authority consisted of a few lines inside paragraph 5 of the data protection impact assessment. According to the decision, its generic assertions of necessity and proportionality, unsupported by evidence, and the complete absence of any balancing analysis, allowed the document to be treated as omitted rather than merely incomplete.

Collection also exceeded the stated purpose. Beyond the seven fields Lusha said it needed, the record shows CRM contents including third-party details, email headers and subject lines, calendar entries covering meeting participants, descriptions, subjects, dates and times, and browsing data. None of that, the authority found, bears a strict relationship to producing a summary contact card, and the company offered no proportionality analysis, confining itself to reporting that it had halted the Community Program in Italy.

On fraud prevention the Garante proposed a design alternative. Rather than transferring the entire record on a person, the platform could accept the details a customer already holds and confirm whether they match, avoiding the definitive disclosure of a full profile. Handing over everything, it noted, can itself generate the identity theft risk the service claims to reduce.

Balancing

Here the ruling turns on expectations. There is no prior relationship between the company and the people in the database. Retention is set at as long as necessary, in a context where the person may remain unaware for years. Accuracy rests on a data point appearing in at least two sources, a recurrence the authority described as barely above one and possibly coincidental. Email addresses absent from public profiles are reconstructed by algorithm from standard corporate patterns; phone numbers are bought from vendors that are mostly American.

The company's own impact assessment supplied the sharpest evidence against it. Quoted in the decision in the original English, paragraphs 4.13 and 4.14 record that Lusha "collects personal data from data subjects where they may not expect it" and that the use cases for processing are not primarily for the benefit of those individuals. The Garante read that alongside the Court of Justice position in Mousse, C-394/23, of 9 January 2025, that rights may prevail precisely where processing falls outside what a person could reasonably anticipate.

Coraggio drew the same distinction in blunter terms, arguing that a professional who posts a job title on a networking site does not expect it to be enriched, packaged and dialled. The wider pattern is familiar: an analysis of European decisions published in March 2026 found the balancing test to be the stage where most controllers stumble, with reasonable expectations the most common failure mode.

Safeguards that did not rebalance anything

Two mitigation measures were offered and both were rejected. The credit system, under which customers buy access rather than search freely, was described as a reasonable measure whose protection is subordinate to a customer's budget: nothing prevents the purchase of enough credits to extract whatever volume is wanted.

The cooling-off period fared no better. Extended from seven to 14 days in October 2025, it depends on a notice sent to an address the person may not monitor, may no longer use, or may treat as a phishing attempt, since basic security practice discourages interaction with unsolicited mail inviting a click. Without reminders, the authority found the window too short to research the sender, understand the consequences and object. "Friction is not a legal basis," as Coraggio summarised the finding.

The pipeline, in the regulator's words

The decision identifies LinkedIn and Salesforce as the principal sources, supplemented by blogs, professional sites and forums. To those it adds the Community Program, under which members share email headers, signature blocks, client names, company names, job titles, business phone numbers and email addresses, and which can extend to members' calendars, tracking meeting titles, participants and their addresses.

It also adds direct integration with customers' own systems. Lusha connects through APIs to services including Gmail, Outlook and Outreach, and operates browser extensions that collect data while a customer browses. Paragraph 3.2 of the privacy notice on file states that by connecting an email account as an integration, Lusha may scan or extract business contact details from the inbox and use them to improve its services.

That mechanism produces the finding with the widest downstream reach. According to the decision, when Contacts' data is extracted from customers' email, what occurs is a disclosure of third-party personal data by the customer to the company, apparently without any legal basis, capable of giving rise to separate liability for the customer in another forum. The authority added that means of private communication attract specific protection under Article 15 of the Italian Constitution.

Named officials and a filter that missed titles

The case began in April 2025 after press reports that phone numbers belonging to the highest offices of the Italian Republic were present on the platform. The decision lists, by way of example, President Sergio Mattarella, deputy prime minister and minister Antonio Tajani, minister Guido Crosetto, former minister and European Commission vice-president Raffaele Fitto, deputy Chiara Appendino, senator Stefano Patuanelli, AGCOM commissioners Elisa Giomi and Massimiliano Capitanio, and AGCM member Saverio Valentino. German chancellor Friedrich Merz and former chancellor Angela Merkel also appeared.

Lusha attributed the presence of these records to a gap in its exclusion algorithm, which caught titles such as "Presidente" but not longer descriptive forms including "Presidente della Repubblica Italiana", "Vice Primo Ministro" or "Leader dell'Opposizione". It removed remaining Italian public sector contacts on 14 August 2025 and added weekly artificial intelligence checks of official institutional websites plus quarterly third-party audits.

The Garante treated the removal as proof of the point. If entire branches of Italian public administration, law enforcement, the judiciary, government and armed forces could be deleted without disturbing the business model, their inclusion was never necessary to it. The company's own risk table, appended to the impact assessment, showed it understood as much. Violations of Articles 5(1)(c) and 25 were confirmed.

What the authority dropped, and how the figure was set

Several charges were archived. The Garante closed the alleged breaches of Article 7, Article 13(1)(a) and (c), and Article 14 of the regulation, along with Article 129 of the Italian Code, accepting that the company's database is not equivalent to a public subscriber directory. It also accepted the company's later position that its German contact point qualifies as a representative under Article 27. Confirmed were breaches of Articles 5(1)(a), 5(1)(c), 6, 12 and 25.

Because Lusha Systems Inc. is wholly owned by Lusha Systems Ltd., which the May 2026 notice names as joint controller, the ceiling was calculated on the parent's consolidated turnover and set at 20 million euros. The 2 million euro penalty represents 10 percent of that maximum. Negligence counted against the company; the absence of prior sanctions, its cooperation, its certification adherence and its revenue figures counted in its favour. Lusha described its turnover as limited and modest, with negative margins.

Payment falls due within 30 days of notification, with the option under Italian procedure to settle for half that sum. Compliance with the processing ban and the erasure order must be reported to the authority within 60 days. Publication on the Garante's website was imposed as an accessory sanction, justified in part because the collection methods are liable to affect the subsequent processing carried out by the company's customers.

Why the erasure order matters more than the fine

For teams that buy enriched contact data, the financial penalty is the least consequential element. A national dataset has been ordered deleted, and the reasoning attaches to a product architecture common across the category rather than to conduct peculiar to one vendor. Weekly verification, algorithmic email construction, purchased phone numbers and inbox integrations are standard components of sales intelligence tooling.

"The fine is not the story. The erasure order is," Coraggio wrote, adding that sales intelligence built on the premise that professional data is fair game now requires a different answer.

The regulatory direction is consistent. The European Data Protection Board's July 2026 guidelines closed off consent as a workable basis for large-scale scraping while tightening the conditions for legitimate interest. Spain's authority had already ordered a business data firm to delete records covering 1.6 million individuals, and a California regulator penalised a broker for selling health condition lists. Claims about how advertising data was obtained are also being tested in a US federal court against Zeta Global, while France's highest administrative court upheld a 40 million euro penalty against Criteo over consent and transparency failures.

The unresolved question is what happens to the buyers. The Garante stated that customers passing third-party data to the platform through inbox integrations may have done so without a legal basis, and that this exposure sits with them rather than with the vendor. No proceedings have been announced against any customer. Whether the Italian authority, or another, chooses to follow that thread will determine whether this decision remains a supplier problem or becomes a purchaser one.

Timeline

  • 20 December 2022: France's CNIL adopts decision SAN-2022-024, later cited by Lusha as finding the GDPR inapplicable to comparable processing.
  • 5 February 2025: Date of the privacy notice version examined by the Italian authority.
  • April 2025: The Garante opens a preliminary inquiry after press reports place phone numbers of senior Italian officials on the platform.
  • 7 April 2025: The authority sends a formal information request under Article 157 of the Italian Code, seeking sources, the impact assessment and the legitimate interest assessment.
  • 29 May 2025: Lusha replies, denying that the regulation applies to it.
  • 6 August 2025: The Garante opens the sanction procedure under Article 166(5).
  • 14 August 2025: Lusha removes residual Italian public sector contacts from its database.
  • 6 October 2025: The company files its defence submissions and requests a hearing.
  • October 2025: The opt-out cooling-off period is extended from seven to 14 days.
  • 29 January 2026: Re-sending of personal information notices to Italian contacts is completed.
  • 11 February 2026: The company is heard at the authority's offices in Rome.
  • 18 February 2026: Written clarifications on the French proceeding are filed.
  • 10 February 2026: The Court of Justice rules in WhatsApp Ireland v EDPB, C-97/23 P, cited by the Garante on consistent application.
  • 7 July 2026: The European Data Protection Board adopts guidelines restricting legitimate interest for web scraping.
  • 14 July 2026: Provvedimento n. 542 is adopted, imposing a 2 million euro fine, a processing ban and an erasure order.
  • 27 July 2026: The Garante publishes its press release on the sanction.

Summary

Who: The Garante per la Protezione dei Dati Personali, Italy's data protection authority, acting through a panel of Pasquale Stanzione, Ginevra Cerrina Feroni, Agostino Ghiglia and Luigi Montuori, against Lusha Systems Inc. of Boston, Massachusetts, wholly owned by Lusha Systems Ltd.

What: Provvedimento n. 542, document reference 10275035, confirming breaches of Articles 5(1)(a), 5(1)(c), 6, 12 and 25 of the GDPR, imposing a 2 million euro fine equal to 10 percent of the applicable ceiling, banning further processing of data belonging to people located in Italy, ordering the erasure of that data, and requiring proof of compliance within 60 days. Charges under Articles 7, 13(1)(a) and (c) and 14, and under Article 129 of the Italian Code, were archived.

When: The inquiry opened in April 2025, the sanction procedure in August 2025, the hearing took place on 11 February 2026, the decision was adopted on 14 July 2026 and announced by press release on 27 July 2026.

Where: Decided in Rome and applying to data belonging to individuals located in Italian territory, though the reasoning addresses collection carried out entirely outside the European Union by a company with no establishment in it.

Why: The authority found that weekly verification and enrichment of individual contact cards amounts to monitoring behaviour under Article 3(2)(b), bringing a US company within the regulation, and that legitimate interest could not support the collection because Italian law requires consent for the onward disclosure of contact details for third-party marketing, because collection extended to CRM contents, email headers, calendar entries and browsing data beyond what a contact card requires, and because people whose data was reconstructed by algorithm or bought from third-party vendors could not reasonably expect the processing.