[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjvOWJHkwMsgaXDXWe9_eC1pOgcJMnfwesyYImZyE74o":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"c892e27e-c925-4acc-a603-bf73e9472cb4","lusha-fined-2m-for-processing-contact-data-without-legal-basis-or-privacy-by-design","a601c7e1-ef85-483e-802d-6fc0ec3a0299","Lusha Fined €2M for Processing Contact Data Without Legal Basis or Privacy-by-Design","Lusha Systems Inc. collected and shared professional contact information — including data belonging to senior Italian public officials — without a valid legal basis under GDPR, violating core principles of transparency, consent, and data minimisation. The case highlights the risk of B2B data platforms that aggregate publicly available or scraped contact data and assume passive availability equates to lawful processing. Failure to implement privacy-by-design from the outset meant there were no technical or organisational safeguards to filter out sensitive categories of data subjects, such as public officials. This matters because regulators across the EU are increasingly targeting data brokers and contact intelligence platforms, signalling that 'business utility' is not a substitute for a legitimate processing ground.","**Immediate actions:**\n- Conduct a lawful basis audit for every data category your platform processes and remove any records lacking a documented, valid GDPR legal basis.\n- Establish a rapid takedown process allowing data subjects to request removal and have it actioned within 72 hours.\n\n**Privacy-by-Design improvements:**\n- Embed data minimisation checks into the data ingestion pipeline so that only the minimum necessary fields are collected and retained.\n- Implement automated flagging and exclusion rules for sensitive categories of data subjects (e.g., public officials, minors) before data reaches production systems.\n- Commission a Data Protection Impact Assessment (DPIA) for any new or existing data aggregation feature before go-live.\n\n**Governance & compliance measures:**\n- Appoint or empower a Data Protection Officer with authority to halt data processing activities that lack a confirmed legal basis.\n- Maintain a continuously updated Record of Processing Activities (ROPA) mapped to specific lawful bases and retention schedules.\n- Run annual third-party GDPR compliance audits covering data sourcing, consent mechanisms, and transparency obligations.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(a) – Lawfulness, fairness and transparency","GDPR Article 5(1)(c) – Data minimisation","GDPR Article 6 – Lawfulness of processing","GDPR Article 13 & 14 – Transparency obligations","GDPR Article 25 – Data protection by design and by default","GDPR Article 35 – Data Protection Impact Assessment (DPIA)","NIST Privacy Framework PR.DS-P1 – Data processing minimisation","NIST Privacy Framework GV.PO-P1 – Organisational privacy policies","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management System (PIMS)","published","2026-08-04T16:21:25.482273+00:00","2026-08-04T16:21:25.2+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542\u002F2026&diff=52607&oldid=52596","garante-per-la-protezione-dei-dati-personali-italy-542-2026-58bcff","Garante per la protezione dei dati personali (Italy) - 542\u002F2026",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]