Italy Fines US Data Broker Lusha More Than $2.2 Million Over Personal Data Handling Practices

Abeerah Hashim  - Security Expert
Last updated: July 29, 2026
Share
Italy Fines US Data Broker Lusha €2 Million Over Personal Data Handling Practices
  • Italy's privacy regulator has fined US data broker Lusha Systems Inc. €2 million over personal data handling.
  • The regulator said Lusha gathered data from social media and other data brokers to build user profiles.
  • Italy ordered Lusha to stop processing affected data and delete it after rejecting its legal basis.

The authority that protects Italy’s data just gave a data broker that operates from the US, Lusha Systems Inc. a fine of €2 million (approximately over $2.2 million in USD). The Italian Data Protection Authority, Garante Privacy, announced the penalty after investigating Lusha’s data practices. The company runs a subscription-based platform that gives customers detailed professional information about people.

The data can include job roles, email addresses, and telephone numbers. Customers can use the service for business and anti-fraud purposes, according to the regulator. ANSA also reported the €2 million fine against the US-based company.

Italy launches investigation into Lusha

The Italian authority said Lusha collected personal information from several sources. These sources included social media platforms and information bought from other data brokers. Lusha then enriched the data and made the resulting profiles available to customers.

The regulator also found information linked to senior institutional figures among the data available through the platform. The information also covered public administration workers, law enforcement personnel, and members of the judiciary.

ANSA’s report reported the authority’s concerns about the availability of such information. The case started in April 2025 when the authority opened a preliminary investigation.

The investigation followed reports about telephone numbers linked to well-known Italian public figures. The authority’s decision said the case later included a complaint and a report from individuals. The Italian regulator has been active in enforcing privacy laws, previously banning ChatGPT over data protection concerns.

Those people said third-party companies had sent them unwanted advertising messages and calls. They asked those companies how they had obtained their contact information.

The individuals then discovered that Lusha’s platform contained their information, according to the regulator. The authority said those individuals had not agreed to the processing of their personal data.

The Garante said Lusha’s data processing broke several key GDPR rules. The authority cited concerns about lawfulness, fairness, transparency, and data minimisation. The regulator also found problems with the information Lusha gave to affected people.

According to the decision, the company’s privacy notice was not clear or easy enough for people to access. The authority also rejected Lusha’s use of legitimate interest as a legal basis for the data processing.

The 14 July 2026 regulatory decision explains the findings against the company. The decision also looked at whether European data protection rules applied to a US-based company. Lusha operates from the United States and does not have an establishment in the European Union.

However, the Italian authority said the company’s activities still fell under the GDPR. The regulator noted that Lusha did more than collect professional information and leave it unchanged.

The company also updated and checked information about people and their professional profiles online. The authority viewed those activities as monitoring people’s behaviour and professional profiles.

That finding brought the company’s data processing within the GDPR’s reach, according to the regulator’s decision. The case shows how European data protection rules can apply to companies based outside the European Union. The regulator’s decision focused on Lusha’s activities involving people in Italy and the way it handled their information.

Italy orders data deletion

The Italian authority ordered Lusha to stop processing the personal data of people located in Italy. It also ordered the company to delete the affected information. The regulator further imposed an administrative fine of €2 million on Lusha Systems Inc.

The official decision records both the fine and the orders issued against the company. The case also raises concerns about how data brokers collect and combine personal information.

Lusha gathered information from social media platforms, other data brokers, and other sources. The company then enriched that information and made profiles available through its platform.

The Italian regulator’s action shows that data described as professional information can still receive protection under European data rules. The decision also makes clear that companies outside the European Union can face GDPR rules in certain cases. That can happen when their data processing involves people in Europe and meets the regulation’s territorial conditions.

For Lusha, the Italian authority has now ordered an end to the processing of affected data. It has also required the deletion of that information and imposed a €2 million administrative penalty.

Share this article

About the Author

Abeerah Hashim

Abeerah Hashim

Security Expert

Abeerah is a passionate technology blogger and cybersecurity enthusiast. She yearns to know everything about the latest technology developments. Specifically, she’s crazy about the three C’s; computing, cybersecurity, and communication. When she is not writing, she’s reading about the tech world.

More from Abeerah Hashim

Comments

No comments.