[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2M9LJ7-sQd3_2sezgDY_fDhwEROI5PL6JRNQhUPvNlQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"e95caeb5-4e75-4d89-962d-c519ee58d203","lusha-fined-2m-for-unlawful-b2b-contact-data-processing-without-legal-basis","b324bf26-5277-40ca-b34a-ce4acbeae509","Lusha Fined €2M for Unlawful B2B Contact Data Processing Without Legal Basis","Lusha Systems Inc. was fined €2,000,000 by Italy's Garante for collecting and processing professional contact data without establishing a valid legal basis under GDPR, violating core principles of transparency and data minimisation. The company failed to implement privacy-by-design measures, including safeguards to exclude data relating to public officials. This case highlights that B2B data platforms are not exempt from GDPR obligations simply because they handle professional rather than personal contact details. The ruling underscores the regulator's expectation that organisations proactively embed data protection principles into their products from inception, not as an afterthought.","**Immediate actions:**\n- Conduct a Legal Basis Audit across all personal data processing activities to ensure each has a documented, valid GDPR legal basis (e.g., legitimate interest, consent).\n- Review data inventories to identify and remove or restrict categories of data (e.g., public officials) that carry elevated regulatory sensitivity.\n\n**Privacy-by-Design measures:**\n- Embed data minimisation controls into platform architecture so only strictly necessary data fields are collected and retained.\n- Implement automated suppression lists and data-subject category filters to exclude legally sensitive individuals from data scraping or enrichment pipelines.\n- Require a formal Privacy Impact Assessment (PIA\u002FDPIA) before launching any new data product or feature that processes third-party contact data.\n\n**Long-term compliance improvements:**\n- Establish a transparent, publicly accessible privacy notice that clearly explains data sources, processing purposes, and subjects' rights.\n- Appoint a dedicated Data Protection Officer (DPO) with authority to review and veto non-compliant data processing workflows.\n- Schedule annual third-party GDPR compliance audits covering legal basis documentation, transparency obligations, and data minimisation practices.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(a) – Lawfulness, fairness and transparency","GDPR Article 5(1)(c) – Data minimisation","GDPR Article 6 – Lawfulness of processing","GDPR Article 25 – Data protection by design and by default","GDPR Article 13\u002F14 – Transparency obligations (information to data subjects)","NIST Privacy Framework PR.DS-P1 – Data processing ecosystem risk management","NIST SP 800-53 IP-1 – Consent \u002F Authority","CIS Control 3 – Data Protection","ISO\u002FIEC 27701 – Privacy Information Management System (PIMS)","ITIL Service Design – Privacy and data protection requirements in service design","published","2026-07-30T16:21:36.84193+00:00","2026-07-30T16:21:36.727+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542\u002F2026&diff=52563&oldid=0","garante-per-la-protezione-dei-dati-personali-italy-542-2026-668dde","Garante per la protezione dei dati personali (Italy) - 542\u002F2026",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]