Italy's Garante fined Lusha Systems Inc., a Boston-based B2B contact-data provider, €2 million on July 27, 2026, and ordered it to erase all data it holds on people in Italy and stop processing it going forward. The decision, formally adopted July 14, is notable less for its size — modest next to the €20 million Clearview AI fine the same regulator issued in 2022 — than for what it says about how far GDPR's extraterritorial reach now extends. Garante press release
What Lusha Was Fined For
Lusha sells subscription access to "enriched" professional contact records: job titles, email addresses, phone numbers, sourced by scraping social platforms and buying data from other brokers. The Garante found the database included information on senior public officials, law enforcement personnel, and members of the judiciary in Italy, and that Lusha's stated legal basis — legitimate interest — was invalid "from the outset," given the volume of data, the sensitivity of the subjects, and the absence of clear, accessible information to the people whose records were held. Garante press release
The jurisdictional question was the harder one. Lusha has no EU establishment, doesn't market to EU customers as its primary business, and operates entirely from the US. Under GDPR Article 3(2), that would normally put it outside the regulation's reach — unless its activity counts as either offering goods/services to people in the Union, or "monitoring" their behavior. The Garante went with monitoring: it reasoned that Lusha's practice of periodically re-verifying and updating a person's job title and contact details amounts to "ongoing observation," and ongoing observation of a data subject's professional life qualifies as behavioral tracking under the law. EUR-Lex, GDPR Article 3
A Defensible Extension, Not a New Doctrine
The strongest case for this reading is that it closes an obvious loophole. If a US company can build a commercial surveillance product on Europeans' data and simply route around GDPR by declining to open an EU office, extraterritoriality becomes optional for anyone willing to stay offshore — which defeats the purpose of Article 3(2) entirely. The EDPB's own Guidelines 3/2018 on territorial scope contemplate a broad range of monitoring activities, including "market surveys and behavioural studies" and other non-obvious forms of tracking, precisely so that regulators aren't limited to catching cookie-based ad tech. EDPB Guidelines 3/2018 And the subject matter here is not abstract: a commercially available database listing home contact details for Italian judges and police officers is a real security concern, not a hypothetical one.
The Garante is also following, not inventing, precedent. Its 2022 Clearview AI decision applied the same monitoring logic to a facial-recognition company scraping billions of images with no EU presence — and that reasoning was echoed by regulators in Germany, France, Greece, Austria, and the UK. Lewis Silkin, Clearview AI decision Lusha is a logical next application of a test that is already four years old.
Where the Reasoning Gets Risky
The problem is what "ongoing observation" now covers. Clearview built a real-time identity-matching tool for law enforcement — an unambiguous surveillance product. Lusha's core function is closer to keeping a CRM record current: confirming that someone still holds the job title they held six months ago. If refreshing a contact field counts as monitoring behavior, the same logic sweeps in the ordinary data-hygiene layer beneath nearly every B2B sales, recruiting, and fraud-prevention tool sold globally — most of which have no EU establishment either. That is a much larger and more mundane category of company than facial-recognition vendors, and dragging routine contact maintenance into the same doctrinal bucket as biometric surveillance blurs a distinction GDPR's drafters plainly intended to preserve.
The Fine Nobody Can Collect
The deeper flaw is enforceability. Clearview's €20 million fine remains unpaid four years on; the Garante's own commissioner has acknowledged there is no international convention it can invoke to compel payment, and is instead asking the US FTC to intervene. Biometric Update A €2 million order against a company with zero EU assets is, practically, a press release with a number attached — symbolically important, operationally toothless. The regulatory cost instead falls on companies that do have something to lose in Europe: reputational exposure, EU customers, or ambitions to expand there later. That's an odd incentive structure — it punishes the compliant while the truly evasive shrug it off.
The Better Fix
Extraterritorial jurisdiction over genuine covert surveillance is worth defending. But the EDPB should draw a clearer line between behavioral tracking designed to profile or predict individuals, and routine data-currency checks on already-public professional information — and pair expansive rulings like this one with real cross-border enforcement mechanisms (formal FTC/DOJ cooperation agreements, asset-freeze tools) rather than relying on fines regulators openly admit they cannot collect. PPC Land Otherwise the practical effect of each new ruling is symbolic deterrence for headline-grabbing cases and a widening compliance target for everyone else.