Italian Data Protection Authority fines Lusha 2 million euros
On 27 July 2026 Italy's Garante per la Protezione dei Dati Personali imposed a 2 million‑euro administrative fine on U.S. data‑broker Lusha Systems Inc. and ordered the company to stop processing and to erase the personal data of individuals located in Italy. The regulator concluded that Lusha’s platform, which collects, updates and resells enriched contact profiles—including phone numbers, email addresses and job titles—violated core GDPR principles of lawfulness, fairness, transparency and data minimisation.
Lusha gathers information from publicly available online sources, such as social‑network scraping, and purchases data from other brokers. The authority determined that, despite having no establishment in the EU, Lusha is subject to the GDPR because its activities amount to monitoring the behaviour of persons in the Union. The decision also bars any further processing of Italian personal data by the company.
Entities: Garante per la protezione dei dati personali · General Data Protection Regulation · Lusha Systems Inc.