Italian Data Regulator Fines US Broker Lusha €2 Million for GDPR Breach
Italy’s data‑protection authority, the Garante Privacy, has imposed a €2 million fine on U.S. data‑broker Lusha Systems Inc. for unlawful collection, enrichment and sale of personal data belonging to many individuals in Italy. The regulator said Lusha obtained information—including job titles, email addresses and phone numbers—through web‑scraping of social‑media platforms and purchases from other brokers, and that its platform also contained data on senior government officials, public‑administration staff, law‑enforcement personnel and members of the judiciary.
The Garante concluded that Lusha’s processing violated GDPR principles of lawfulness, fairness, transparency and data minimisation, and that the company’s reliance on “legitimate interest” was invalid. It also clarified that the GDPR applies to companies without an EU establishment if they monitor individuals’ online behaviour. Lusha has been ordered to cease processing personal data of individuals located in Italy and to delete the data it holds.
The decision underscores the reach of European privacy rules to foreign firms that target EU residents, reinforcing enforcement of data‑protection standards across borders.
Entities: Garante Privacy (Italian Data Protection Authority) · Italy · Lusha Systems Inc. · United States