The Italian Data Protection Authority (Garante Privacy) imposed a €2 million penalty on Lusha Systems Inc., a U.S.-based data broker, and issued an order for the company to cease all processing of Italian residents' personal information and delete the data it holds. The ruling, issued on July 27, 2026, underscores the Authority's increasingly aggressive enforcement stance on foreign tech firms that harvest personal data without proper legal grounding.
Why This Matters:
• Enforcement action issued: The Garante has ordered Lusha to delete all personal data it collected on Italians without valid legal basis, including contact details of public officials, judges, and law enforcement officers.
• €2M fine signals tougher oversight: This penalty reflects the Authority's strengthened commitment to privacy enforcement.
• Your contact data may be compromised: If you've received unsolicited commercial calls or emails, your information may have been sourced from platforms like Lusha.
• Sensitivity concerns: The presence of sensitive government and judiciary data on a commercial platform raises concerns about data protection and the exposure of officials who should not be commercial targets.
The Business Model Behind the Fine
Lusha Systems operates a subscription-based platform that sells "enriched" personal data—job titles, email addresses, mobile phone numbers—to businesses seeking leads for sales or fraud prevention. The company aggregates this information by scraping social networks, purchasing from other data brokers, and mining public and semi-public sources. According to the Garante, Lusha continuously updates and monitors these profiles over time, a practice that constitutes "tracking" under GDPR regulations.
The investigation found that Lusha had collected data on a "large number" of individuals within Italian territory, including high-ranking officials in government, public administration, police forces, and the judiciary—groups that are not typical commercial targets and whose exposure creates legitimate privacy concerns.
Why the Garante Rejected Lusha's Legal Defense
The core legal dispute centered on whether Lusha could rely on "legitimate interest" as its basis for processing personal data. Under GDPR Article 6, companies can invoke legitimate interest if their business needs outweigh the privacy rights of individuals, provided the data processing is transparent and limited in scope.
The Garante Privacy ruled that Lusha's approach failed on multiple fronts. First, the company's privacy notices were not clear or easily accessible to the individuals whose data was being harvested. Second, the Authority determined that legitimate interest was inadequate as a legal basis given the scale and sensitivity of the data involved. The Garante emphasized that the company's activities went far beyond passive collection—they involved ongoing monitoring and profiling of individuals' online behavior, which triggers heightened scrutiny under EU law.
Crucially, the Authority also addressed the jurisdictional question. Despite having no physical establishment within the European Union, Lusha falls under GDPR enforcement because its platform monitors the behavior of individuals located in the EU. This precedent is significant for Italy-based residents: it confirms that foreign data brokers cannot escape Italian privacy law simply by operating from overseas.
What This Means for Residents
If you live in Italy, this ruling has several practical implications. First, under GDPR, you have the legal right to request deletion of your personal data from data broker platforms, even if you never directly provided that information. Under GDPR Article 17 (the "right to be forgotten"), companies must respond within the timeframe specified by law, and notify any third parties with whom they've shared your data.
Second, the Garante's decision reinforces that consent cannot be buried in vague terms of service or inferred from publicly available information. If a company wants to use your data for marketing or profiling, it must obtain explicit, informed consent—a standard that many data brokers struggle to meet.
For professionals in sensitive sectors—magistrates, police officers, civil servants, and government officials—the breach is particularly concerning. The Garante noted that the availability of such individuals' contact details on a commercial platform was problematic because these groups are not legitimate commercial targets. The exposure of this data creates privacy risks for these officials.
How Data Brokers Operate in Italy
Data brokers in Europe function in a regulatory gray zone. Unlike the United States, the European Union does not have specific legislation defining or directly regulating traditional data brokers. However, the Data Governance Act (DGA), in effect since September 2023, introduced rules for "data intermediation services"—neutral third parties that facilitate data sharing. These services are explicitly prohibited from profiting by reselling data or using it for their own products.
The GDPR, which has been in force since May 2018, is the primary regulatory framework. In Italy, it is supplemented by the Privacy Code (Legislative Decree 196/2003, as amended), which adds specific requirements for employee monitoring, video surveillance, marketing practices, and biometric data processing.
Despite robust legal protections, enforcing rights against data brokers remains challenging. Many operate without transparent processes, making it difficult for individuals to know which companies hold their data or how to request deletion. The Garante Privacy encourages residents to file complaints if they suspect their data has been unlawfully processed.
Next Steps for Affected Individuals
If you believe your data may have been collected by Lusha or similar brokers, you can exercise your right of access by submitting a formal request to the company. This should include your full name, contact details, and a request for confirmation of what data they hold and the legal basis for processing it.
Should the company fail to respond or refuse your request, you can file a complaint with the Garante Privacy through its online portal. The Authority is required to investigate and, if necessary, impose corrective measures, including fines and data deletion orders.
The Lusha ruling sends a clear message: foreign companies cannot bypass Italian privacy law by operating remotely, and the Garante Privacy continues to hold violators accountable through enforcement actions. For residents, this is a reminder that your personal data has value—and that Italian regulators are actively working to protect it.