Garante vs Lusha: €2M fine for data brokering without legal basis
Italy’s Garante fined Lusha €2,000,000 for collecting/selling professional contacts without a legal basis and adequate information. A strong signal for the use of data enrichment tools in the EU.
Italy’s data protection authority (Garante) fined Lusha Systems Inc. €2,000,000 for collecting and reselling “enriched” personal contact data (roles, emails, phone numbers) without a valid legal basis and without transparent information. The decision orders the cessation of unlawful processing and deletion of the affected data (adopted 14/07/2026, announced 27/07/2026).
The facts
The authority found that Lusha aggregates and markets contact details of EU residents for clients’ commercial prospecting. The GDPR’s extraterritorial scope applies due to monitoring of individuals in the EU. The official publication and media reports confirm the date and amount of the fine.
Official references: the Garante’s decision and its press release, plus ANSA coverage.
Legal framework and grounds
- Territorial scope (Art. 3(2) GDPR): extraterritorial applicability based on monitoring of individuals in the EU. See our reference page on the GDPR.
- Lawfulness (Art. 6 GDPR): no valid basis (legitimate interests not demonstrated) for mass scraping, enrichment, and resale of contact data.
- Transparency and information (Arts. 12, 13, 14): privacy notices deemed deficient, lacking clear, intelligible, and complete information.
- Corrective powers and fines (Arts. 58(2) and 83): order to stop processing, delete data, and payment of a €2,000,000 fine.
Case-law interest: the decision reiterates the value of EDPB guidelines as soft law recognized by the CJEU (C‑911/19) and the “ignorance of the law is no excuse” principle for controllers.
What this means for Luxembourg companies
- Direct exposure if you use data enrichment/B2B contact tools (prospecting, CRM, ABM). Even with non-EU vendors, your legitimate interests (Art. 6(1)(f)) must be balanced against data subjects’ rights. The Luxembourg GDPR compliance approach may mirror the Garante’s analysis for local residents.
- Tangible corrective measures: outright bans on certain datasets and deletion orders that can break marketing pipelines.
- Burden of proof: demonstrate effective information (Arts. 13–14), rights handling (access, objection), lawful sources, and a robust LIA covering indirect collection, enrichment, and any resale.
Practical actions to take this week
- Map and freeze enrichment flows: inventory all enrichment/lead-gen vendors and plug-ins across Sales/Marketing/Recruiting; suspend auto-ingestion until the LIA and Art. 14 notice are validated.
- Check legal basis and information: update notices (including B2B) to cover indirect collection and enrichment; implement an easy marketing opt-out and access/erasure process that also covers third-party data.
- Demand vendor guarantees: contract for lawful provenance, source logs, cascading deletion, and auditability; favor EU-based compliant providers or deploy client-side minimization.
- GDPR governance: where needed, entrust remediation and oversight to a certified DPO mandate to secure processing and records.
For management teams in Luxembourg and the Greater Region, the takeaway is clear: purchasing or using enriched lists faces heavy regulatory pressure and requires reinforced due diligence before campaigns go live. Need a quick discussion? Reach us via contact.
Article generated by Luxgap regulatory watch. For tailored guidance on this topic, contact us.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →