[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fPcBRIdateaU_EofKzoSGkQ79mCe-PmszZuUybnZvBIg":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":23,"category":24,"article_tags":28},"a601c7e1-ef85-483e-802d-6fc0ec3a0299","Garante per la protezione dei dati personali (Italy) - 542\u002F2026","garante-per-la-protezione-dei-dati-personali-italy-542-2026-58bcff","← Older revision Revision as of 14:10, 4 August 2026 Line 108: Line 108: }} }} The DPA fined a subscription-based B2B contact-data platform €2,000,000 for selling and processing professional contact data without a valid legal basis, in breach of transparency and minimisation requirements and for failing to implement privacy-by-design measures to exclude public officials’ data. The DPA fined a subscription-based B2B contact-data platform €2,000,000 for processing professional contact data without a valid legal basis, in breach of transparency and minimisation requirements and for failing to implement privacy-by-design measures to exclude public officials’ data. == English Summary == == English Summary ==","Italy's Data Protection Authority (Garante) issued a €2,000,000 fine to Lusha Systems Inc., a US-based B2B contact data platform, for processing professional contact information without valid legal basis and failing to implement privacy-by-design measures. The investigation was triggered by media reports revealing senior Italian officials' phone numbers on the platform and complaints from data subjects who discovered their data was shared without consent. The violations included breaches of transparency, data minimisation principles, and failure to exclude public officials' data through appropriate safeguards.","Italian DPA fines Lusha Systems €2M for processing B2B contact data without legal basis and privacy safeguards.","Help Garante per la protezione dei dati personali (Italy) - 542\u002F2026: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 11:28, 4 August 2026 view sourceFm (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators109 edits Tags: Reverted Visual edit← Older edit Latest revision as of 14:10, 4 August 2026 view source Fm (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators109 editsTags: Manual revert Visual edit Line 108: Line 108: }}}} The DPA fined a subscription-based B2B contact-data platform €2,000,000 for selling and processing professional contact data without a valid legal basis, in breach of transparency and minimisation requirements and for failing to implement privacy-by-design measures to exclude public officials’ data.The DPA fined a subscription-based B2B contact-data platform €2,000,000 for processing professional contact data without a valid legal basis, in breach of transparency and minimisation requirements and for failing to implement privacy-by-design measures to exclude public officials’ data. == English Summary ==== English Summary == Latest revision as of 14:10, 4 August 2026 Garante per la protezione dei dati personali - 542\u002F2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 3(2)(a) GDPR Article 3(2)(b) GDPR Article 5(1)(a) GDPR Article 12 GDPR Article 6(1)(f) GDPR Article 5(1)(c) GDPR Article 25 GDPR Type: Investigation Outcome: Violation Found Started: Decided: 14.07.2026 Published: Fine: 2000000.0 EUR Parties: Lusha Systems Inc. National Case Number\u002FName: 542\u002F2026 European Case Law Identifier: n\u002Fa Appeal: n\u002Fa Original Language(s): Italian Original Source: GPDP (in IT) Initial Contributor: ds The DPA fined a subscription-based B2B contact-data platform €2,000,000 for processing professional contact data without a valid legal basis, in breach of transparency and minimisation requirements and for failing to implement privacy-by-design measures to exclude public officials’ data. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an US company wholly owned by Lusha Systems Ltd. In April 2025, the Italian DPA (Garante) initiated an investigation after media reports revealed that telephone numbers of senior Italian officials were available on the platform. The DPA later received one complaint and one report from data subjects who had received unsolicited advertising communications. The data subjects further stated that after requesting information about the source of their contact details, they discovered that their data were available on the controller’s platform without their consent. The controller explained that, for a subscription fee, it provided its Clients with a Business Contact Card for each Contact. The controller further distinguished between “Clients”, namely customers who used the platform and accessed its B2B database, and “Contacts”, namely the individuals whose personal data were included in that database, regardless of whether they used or were aware of the platform. Clients received Contact Cards containing information such as names, professional email addresses, telephone numbers, job titles, roles and locations, which could be used for sales, marketing, recruitment, business intelligence and fraud prevention. The DPA limited its investigation to the processing of Contacts’ personal data. The controller stated that it collected and combined data from publicly available sources, specialised providers, affiliated companies and commercial partners. It also inferred missing professional email addresses through algorithms that identified standard company email patterns. Through its Community Program and integrations with email, calendar and CRM services, it could also obtain information from Clients’ professional networks and communications. The data were cross-referenced, enriched and regularly updated to reflect changes in Contacts’ professional circumstances. The controller argued that the GDPR did not apply because it was established outside the EU and provided services only to businesses. It additionally claimed that the weekly updating of Contact Cards ensured accuracy rather than constituting monitoring or profiling. The controller maintained that the collection and disclosure of the data were necessary for its own economic interest in providing accurate professional contact information and for its Clients’ interests, including fraud prevention. According to the controller, it processed only a limited range of information concerning the Contacts’ professional lives. It further claimed that individuals who made professional information publicly available, particularly through services such as LinkedIn, could reasonably expect that the information might be reused and that they could be contacted regarding professional opportunities. Regarding transparency, the controller stated that its Personal Information Notice was sent to each Contact before their information became available in the database. It explained that it notified Contacts that they had a seven-day period during which they could opt out before their information became available to Clients. The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Holding Regarding the territorial scope of the GDPR, the DPA acknowledged that Article 3(2)(a) GDPR could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that Article 3(2)(b) GDPR applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of Article 5(1)(a) GDPR and Article 12 GDPR. Moreover, the DPA assessed whether Article 6(1)(f) GDPR provided a valid legal basis for the processing. It examined the ","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542\u002F2026&diff=52607&oldid=52596","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002Fe\u002Fec\u002FLogoIT.png","2026-08-04T14:10:29+00:00","2026-08-04T16:00:18.583628+00:00",7,[18,21],{"name":19,"type":20},"Lusha Systems Inc.","vendor",{"name":22,"type":20},"Garante per la protezione dei dati personali","3f0f8451-91df-4b6c-9a73-ef3b2509b7f1",{"id":23,"icon":25,"name":26,"slug":27},null,"GDPR","gdpr",[29,34,39],{"category":30},{"id":31,"icon":25,"name":32,"slug":33},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":35},{"id":36,"icon":25,"name":37,"slug":38},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":40},{"id":41,"icon":25,"name":42,"slug":43},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]