Italian Garante Hits US Data Broker Lusha with €2 Million Fine and Processing Ban

Table of Contents

Italy’s data protection authority, the Garante, has imposed a €2 million fine on Lusha Systems Inc., a United States-based data broker, for extensive alleged violations of the EU General Data Protection Regulation. In addition to the financial penalty, the authority ordered the company to delete personal data relating to individuals in Italy and prohibited any further processing of that data.

The decision, formalized in mid-July 2026 and announced publicly on 27 July, underscores the Garante’s willingness to apply the GDPR’s extraterritorial reach to foreign companies that monitor and commercialize European residents’ information without an adequate legal basis or transparent notice.

How Lusha Operated

Lusha operates a paid platform that supplies “enriched” profiles of individuals, typically including job titles, email addresses, and telephone numbers. The company assembles these profiles by combining data scraped from social networks with information purchased from other data brokers. Customers use the platform for commercial prospecting or anti-fraud purposes.

According to the Garante, the database contained records on a large number of people located in Italy. Among them were senior figures from public institutions, the public administration, law enforcement, and the judiciary. The authority found that Lusha did not merely collect static professional details; it also performed ongoing updates and checks. These continuous activities constituted monitoring of data subjects’ online behavior and professional status, bringing the processing squarely within the GDPR’s territorial scope under the monitoring criterion of Article 3(2).

Core Violations Identified

The Garante determined that Lusha’s processing breached several foundational principles of the Regulation: lawfulness, fairness, transparency, and data minimisation.

On transparency, the privacy information provided to individuals was neither clear nor readily accessible. Data subjects therefore lacked meaningful notice about how their information was being collected, enriched, and sold.

On lawfulness, the company relied on legitimate interest as its legal basis. The authority rejected that justification. Given the scale of the data collection, the sensitive nature of some profiles, the lack of a direct relationship with the individuals, and the commercial purpose of the activity, legitimate interest did not meet the balancing test required under the GDPR.

Because the processing had lacked a valid legal basis from the outset and was still ongoing, the Garante ordered an immediate ban on any further processing of personal data relating to individuals in Italy and mandated the erasure of those records.

Extraterritorial Reach and Monitoring

A central element of the decision is the Garante’s application of the GDPR to a company with no establishment in the European Union. The authority emphasized that Lusha’s practice of continuously updating and verifying profiles amounted to systematic monitoring. Under Article 3(2)(b), the Regulation applies to the processing of personal data of data subjects in the Union where the processing relates to the monitoring of their behaviour within the Union. The Garante treated the ongoing enrichment and tracking of professional and contact information as precisely such monitoring.

This interpretation reinforces a growing body of enforcement actions against non-EU data brokers and people-search services. Companies that scrape, enrich, and resell European residents’ data cannot escape GDPR obligations simply by locating their operations outside the bloc when their activities involve continuous observation of individuals online.

Broader Implications for Data Brokers

The Lusha case illustrates several practical risks for the data-brokerage sector. First, reliance on legitimate interest for large-scale collection and sale of contact and professional data remains vulnerable to challenge, particularly when individuals have no relationship with the broker and receive inadequate notice. Second, ongoing updating of profiles can convert what might otherwise be viewed as a one-time collection into monitoring activity that triggers full GDPR applicability. Third, the presence of high-profile or sensitive categories of individuals—public officials, law-enforcement personnel, members of the judiciary—heightens regulatory scrutiny and potential reputational harm.

For companies operating similar platforms, the decision signals that European authorities are prepared both to impose significant fines and to issue deletion and processing bans. Compliance programs should therefore reassess legal bases, transparency mechanisms, data-minimisation practices, and the extent to which continuous enrichment constitutes monitoring. Where legitimate interest is claimed, a documented, rigorous balancing test that accounts for the nature of the data, the expectations of data subjects, and the commercial purpose is essential.

The Garante’s action against Lusha adds to the expanding list of cross-border enforcement measures targeting the secondary data market. As more supervisory authorities examine scraping, enrichment, and resale practices, data brokers serving European markets face increasing pressure to align their operations with the Regulation’s core principles or risk comparable financial and operational consequences.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.