Italy Italy Garante GDPR AI enforcement

Italy's €2M Fine on Data Broker Lusha Shows GDPR's 'Monitoring' Test Now Reaches Any Foreign Contact-Enrichment Vendor

Garante fined Lusha €2M for scraping Italians' data, including officials', and grounded jurisdiction in weekly profile refreshes, not EU sales.

Italy's Data-Broker Crackdown, By the Numbers People of Internet Research · Italy €2M Lusha GDPR Fine Imposed by Italy's Garante on July… 60 days Erasure Compliance Deadline Lusha must prove all Italian recor… €20M 2022 Clearview AI Precedent Prior Garante fine against a US sc… peopleofinternet.com
Italy's Data-Broker Crackdown, By the … People of Internet Research · Italy €2M Lusha GDPR Fine 60 days Erasure Compliance Deadl… €20M 2022 Clearview AI Precedent peopleofinternet.com

Key Takeaways

A €2 million fine with an outsized legal reach

On July 14, 2026, Italy's data protection authority, the Garante per la Protezione dei Dati Personali, formally adopted a decision fining Lusha Systems Inc., a Boston-based sales-intelligence data broker, €2 million. The Garante published its findings on July 27 (garanteprivacy.it). Lusha builds contact profiles — job titles, emails, phone numbers, seniority, location — by scraping social networks such as LinkedIn, buying records from other brokers, and mining customer email integrations, then resells the enriched profiles through a subscription platform marketed for sales and anti-fraud use.

The Authority found the company had monitored and offered for sale the data of "an elevated number of people," including senior officials in public institutions, law enforcement, and the judiciary. It ordered Lusha to stop all processing of Italian residents' data immediately and to prove, within 60 days, that every Italian record has been erased (ppc.land).

The case for the crackdown

The steelman here is straightforward, and largely correct on the facts. Lusha never had a relationship with the people in its database — it built profiles about them, not with their participation, then sold access to strangers. GDPR's Article 6 does allow processing on "legitimate interest," but Recital 47 conditions that on a balancing test: the controller's interest cannot override the data subject's own rights, and must sit within what the person could reasonably expect. Someone whose LinkedIn title was scraped into a commercial contact database, refreshed weekly without their knowledge, plainly did not expect that. The Garante's finding that legitimate interest failed on "the interest itself, necessity, and the balancing test" tracks the letter of the law, not an aggressive reinterpretation of it.

The inclusion of judiciary, law-enforcement, and senior-official profiles sharpens the case further. A commercial database that lets any subscriber pull a prosecutor's current role, employer, and direct phone number is a plausible security and harassment vector, independent of any privacy-in-the-abstract argument. Regulators are right to treat that combination — sensitive population, no consent, resale for profit — as a serious violation rather than a technical paperwork lapse. This is not the case of a start-up tripping over a disclosure form; it is a business model built entirely on data the individuals never agreed to share.

Where the ruling overreaches

The substance of the fine is defensible. The jurisdictional theory behind it is not something the tech sector should wave through quietly. Rather than resting on Lusha's earlier claim of offering services to EU residents, the Garante grounded jurisdiction in Article 3(2)(b)'s "monitoring" criterion — the provision meant to capture behavioral tracking and profiling of people inside the EU. Its reasoning: because Lusha refreshes contact cards weekly, watching for changes in a person's role, seniority, or location, that qualifies as "monitoring," full stop, without any need to show profiling of behavior or intent (ppc.land).

That reading stretches "monitoring" a long way from its original target — think ad-tech tracking pixels and location analytics — to cover routine database hygiene at any company, anywhere in the world, that periodically updates records concerning EU residents. A CRM vendor, an alumni-directory service, or a credit-reference agency headquartered outside the EU could all find themselves newly within GDPR's territorial scope under the same logic, regardless of whether they ever marketed into Europe. Broadening extraterritorial reach this far, through a press release rather than legislative amendment or CJEU guidance, creates real uncertainty for any global data business, not just the scrapers the Garante is actually trying to stop.

Precedent, and a narrower path available

This is not Italy's first swing at a foreign scraper. In March 2022 the Garante fined facial-recognition firm Clearview AI €20 million for building its database from scraped images without a valid legal basis, similarly rejecting the company's legitimate-interest defense (TechCrunch). Both cases share a pattern: a US company scrapes public web content at scale, resells derived profiles commercially, and cannot point to any relationship with the people involved. On that narrower ground — no consent, no relationship, sensitive subject pool, resale at scale — the Lusha fine sits comfortably within precedent and does not need the monitoring-criterion theory to succeed.

Legitimate interest was rejected because the processing scale, the sensitivity of some of the profiles involved, the absence of any direct relationship with data subjects, and the commercial purpose of the activity meant the interest could not survive the required balancing test.

Regulators pursuing genuinely bad actors like Lusha and Clearview deserve support: scraping officials' contact details for resale is exactly the kind of harm GDPR was built to stop. But the Garante did not need to expand "monitoring" to reach that result, and having done so, it has handed every future respondent — and every ordinary data-enrichment vendor with no EU footprint — a jurisdictional theory broad enough to reach almost any company that keeps its records current.

What comes next

Lusha's 60-day erasure deadline runs into mid-September 2026. Whether the company appeals to Italy's administrative courts, and whether it contests the jurisdictional theory specifically rather than just the merits, will determine if this monitoring-criterion reasoning becomes settled Italian enforcement practice or remains an outlier theory from a single case.

Sources & Citations

  1. Garante Privacy — official press release on Lusha decision
  2. EUR-Lex — GDPR (Regulation 2016/679) full text
  3. ppc.land — Lusha's 60-day erasure deadline and jurisdictional analysis
  4. TechCrunch — Italy fines Clearview AI €20M