Italy’s data protection authority has fined US data broker Lusha Systems Inc. €2m and ordered it to stop processing, and delete, the personal data of everyone located in Italy held on its platform. The Garante adopted decision no. 542 on 14 July and announced it on 27 July, finding breaches of GDPR Articles 5(1)(a), 5(1)(c), 6, 12 and 25. Lusha is incorporated in Boston, wholly owned by Israeli-founded Lusha Systems Ltd, and has no establishment in the European Union. That last fact is why this decision matters well beyond one company.
What the Garante found
Lusha operates a subscription platform selling “enriched” contact records: job titles, email addresses and phone numbers, assembled from social network scraping, purchases from other data brokers, and contributions from its own users, including calendar and email integrations and CRM uploads through its community programme. The records on the platform included contact details for senior institutional figures, public administration staff, law enforcement officers and members of the judiciary. The investigation began in part from reports of those institutional contacts appearing on the platform, and from complaints by people in Italy who had received commercial communications.
The Garante found the processing unlawful from the origin. Legitimate interest was not an adequate legal basis, the privacy notice was neither clear nor accessible, and the principles of lawfulness, fairness, transparency and data minimisation were all breached, along with data protection by design under Article 25.
One point of precision matters for anyone reporting or reading about this case. The Garante criticised the way Lusha handled notification to people who never had any relationship with it, and found the Article 12 transparency obligation breached. But the separate Article 14 allegation, concerning the duty to inform data subjects whose data is obtained indirectly, was archived, not upheld. Reports describing an Article 14 violation are wrong.
The fine of €2m represents 10% of the applicable ceiling. Lusha must prove deletion of Italian-territory data within 60 days, may settle for half the fine within the appeal window, and the decision itself is ordered published. The number of people affected is redacted throughout the decision; the Garante describes it only as a large number, and no reliable estimate exists.
The email address as manufactured data
The first reason this is an email industry story sits at paragraph 85 of the decision. Where Lusha did not hold a person’s email address, the decision records, the address could be inferred by an algorithm, constructed from the person’s name and their employer’s corporate domain pattern. Phone numbers were bought from US vendors and matched in.
An inferred address is still personal data the moment it identifies a person, and the Garante treated it as such. For the deliverability community the practical point is familiar: pattern-built B2B addresses are guesses, and guessed addresses are how purchased lists come to contain spam traps, dormant mailboxes and people who never consented to anything. This decision puts a regulator’s finding behind what senders already know operationally. If a vendor cannot explain where an address came from, the answer may be that it came from nowhere.
Monitoring without an office
The second reason is jurisdictional. Lusha argued, in effect, that a US company with no EU establishment sits outside the GDPR. The Garante rejected this under Article 3(2)(b): because the platform continuously checks and refreshes its contact records, on a weekly cycle, it is monitoring the behaviour of people in the Union. The weekly refresh of a contact card, the routine hygiene function of every data enrichment product, is the very feature that establishes jurisdiction.
No EU establishment also means no one-stop-shop mechanism, so any member state authority can act alone, as Italy just did. The theory reaches every non-EU B2B contact data vendor whose product involves keeping records current, which is to say all of them. It arrives in the same season as Rome’s tracking pixel provision and the wider European enforcement pattern we analysed in the spring, and the direction of travel is consistent: the mechanics of data operations, not just their outputs, are what regulators are examining.
For EU-based senders and their agencies, the buying-side question writes itself. Any B2B contact data supplier, wherever incorporated, should be able to answer: what is the provenance of each record, what is the legal basis, and were any of these addresses inferred rather than collected? A supplier that cannot answer is a supplier holding your compliance risk.
Lusha had not published a response to the decision at the time of writing.








