Italy Fines Lusha €2 Million, Says Data Broker's Business Crossed Into GDPR Monitoring
Key Takeaways
- Italy Says Lusha's Business Amounted to Monitoring: The Italian Data Protection Authority concluded that Lusha's continuous collection, updating and maintenance of professional profiles constituted monitoring under the GDPR, not merely the compilation of contact information.
- Data Broker Fined €2 Million: The regulator imposed a €2 million fine after finding Lusha unlawfully processed the personal data of a large number of individuals in Italy in breach of the GDPR's principles of lawfulness, fairness, transparency and data minimization.
- Legitimate Interest Rejected as Legal Basis: The authority found Lusha could not rely on legitimate interest to justify its processing and said the information provided to data subjects was not clear or easily accessible.
Deep Dive
The Italian Data Protection Authority imposed a €2 million fine on Lusha, the U.S.-based data broker, ordering it to stop processing the personal data of individuals in Italy while deleting the data it already holds. Read closely, the ruling is less about the existence of a commercial contact database than about what happens when that database is continuously refreshed, expanded and monetized over time.
Lusha sells access to what it describes as "enriched" information about individuals, including job titles, email addresses and telephone numbers. According to the Italian authority, the company assembled those profiles from multiple sources, including scraping social networks and purchasing information from other data brokers, before making the resulting data available to customers for commercial or anti-fraud purposes.
The database, the regulator said, also contained information relating to representatives of institutional leaders, public administrations, law enforcement agencies and the judiciary.
The investigation concluded that Lusha processed the personal data of a large number of people in Italy in breach of the GDPR's principles of lawfulness, fairness, transparency and data minimization. Among the shortcomings identified, the authority said information provided to data subjects was neither sufficiently clear nor easily accessible. It also rejected the company's reliance on legitimate interest as the legal basis for the processing.
Why the GDPR Applied
Perhaps the most consequential part of the decision concerns jurisdiction. Lusha does not have an establishment within the European Union. The company nevertheless fell within the scope of the GDPR, the authority said, because its activities amounted to monitoring individuals in Italy.
The regulator's reasoning turned on the nature of the service itself. Lusha was not found merely to have gathered professional information and left it unchanged. The authority said the company ensured that information was updated and monitored over time. Those ongoing activities constituted monitoring of individuals' behavior and personal positions online, amounting to the kind of tracking contemplated by the GDPR's territorial scope provisions.
That finding reflects an increasingly important line in European privacy enforcement. The question is no longer only where a company is based or whether some of the information it processes can be found publicly online. Regulators are paying closer attention to whether a business systematically observes, updates and commercializes personal information as an ongoing activity.
The fine is only one part of the enforcement action. Having concluded that Lusha's processing lacked a valid legal basis from the outset, the Italian authority prohibited the company from processing the personal data of individuals present in Italy. It also ordered the deletion of that data.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

