Enriched contact databases: the Lusha fine is a lesson for buyers, not just the seller
7 min read
“The Garante fines Lusha 2 million euro. The data of a large number of people has been monitored and put up for sale”: that is the headline the Italian data protection authority used on 14 July 2026 to announce its enforcement order against Lusha Systems Inc. (register of measures no. 542, web doc. no. 10275035; panel: Stanzione, president and rapporteur, Cerrina Feroni, vice-president, Ghiglia, member, Montuori, secretary-general — our translation, as for every quotation below). Lusha sells access to a database of professional contacts — “sales intelligence”, B2B contact enrichment — from its Boston headquarters, wholly owned by Lusha Systems Ltd. The investigation did not start as a routine check: it started in April 2025, after press reports that the platform held the phone numbers of the most senior officials of the Italian Republic. A complaint and a report followed, from people who had received unwanted marketing calls from third parties, asking where their data came from.
What this market actually sells
The data, the Company says, are “usually found on business cards or in the email ‘signature block’”: name, title, role, seniority, email, phone number, country of work. Reorganised into a unique “Company Contact Card”, retrievable “on the basis of different filters”. Among the declared ways of obtaining them is an “email-creation algorithm”: when an address is unavailable, it is inferred — even for people not on LinkedIn, since “the email […] can be inferred through an algorithm […] or acquired from other sources”.
”We are not subject to the GDPR”
The first strong point is jurisdiction. Lusha argued it was not subject to the Regulation: no EU establishment, the criteria of Article 3(2) not met, no obligation to appoint a representative. Its German contact point, it explained, exists “only to be easily reachable for individuals and authorities in the EU and the UK”; applying European rules voluntarily would be an alignment with international standards, not an obligation.
The Garante found both criteria of Article 3(2) met. On (a): it could not be excluded that, among those accessing the platform, there were natural persons whose data in turn become subject to processing — and are therefore data subjects. On (b), the passage that carries the whole order: enriching and updating contacts — “for example to check whether the person still held a certain job position or had changed position or place of work”, including through “cross-checks” between sources — “seemed to imply monitoring of the Contact’s job position over time […] capable of amounting to monitoring of data subjects’ behaviour within the meaning of Article 3(2)(b)”. The database is not a snapshot: it is a continuous update, and that is what brings it under the GDPR.
The Garante had already stretched “monitoring” beyond the obvious: it blocked a plug-in that read employees’ stress levels in workplace chats, and the same logic runs through the obligation, already Italian law, to disclose in writing the logic of systems that monitor workers.
Same conduct, two different readings
In its defence the Company invoked an earlier CNIL investigation: as the order reports it, as Lusha’s own argument, the French authority had concluded that “there was no monitoring since there is no profiling activity under the Regulation. Lusha records the job change of the individuals on file but this does not amount to profiling, only to updating the data […] updating the job position is an application of the accuracy principle.” The Italian Garante disagreed. Same processing, two regulators, two diverging readings: exactly the uncertainty anyone buying these services has to manage, not ignore.
What the Garante decided
For most purposes the Company declared legitimate interest as its legal basis, backed by a Legitimate Interest Assessment inside the impact assessment, concluding that processing “Contacts’” data and disclosing it to Clients met the requirements. The Garante disagreed, declaring the processing unlawful for breach of Articles 5(1)(a) and (c), 6, 12 and 25 GDPR — lawfulness, minimisation, legal basis, information to data subjects, protection by design. It prohibited, under Article 58(2)(f), further processing of data of subjects in Italy acquired without adequate legal basis, ordering erasure under point (g), with compliance due within 60 days. The fine, payable within 30 days: €2,000,000. The statutory maximum was Article 83(5) — €20 million or 4% of worldwide turnover, if higher — with Article 83(3) applied for a single course of conduct. The reduced-settlement route under Article 166(8) of Italy’s Privacy Code remains available: comply, or pay half. Publication on the Garante’s website was also ordered, as an ancillary sanction.
But this piece is not about the seller
The order hits Lusha. But the real question is different: what happens if that database, or an equivalent one, is already inside your CRM? You become an independent controller. The supplier’s compliance does not travel with the downloaded file.
Three operational points follow. First: continuously updating a person’s role and position — the feature making any contact database useful — is exactly what the Garante classified as behavioural monitoring. In the decision that classification serves to establish jurisdiction over a company with no European establishment; for a business established in Italy the GDPR applies in any case, and the jurisdictional question does not arise. What remains is the judgement on the nature of the activity — and that activity is the same one performed by anyone running a live CRM enriched with third-party data. Second: an email inferred by an algorithm remains personal data, just like a collected one; being computed does not change its nature — the same caution that applies to tracking pixels in email, another front where the Garante measures the gap between what looks technical and what is, legally, personal. Third: provenance stays traceable. Those who reported to the Garante got there after calls from third parties, asking where their data came from: that question travels back up the chain, to whoever bought the contact, not only whoever sold it.
A fourth point concerns our readers more than the other three: this investigation started because a commercial database held the direct contacts of the most senior officials of the Italian state. An archive tying together name, role, seniority and direct contact for an organisation’s leadership — public or private — is not only a data protection issue: by construction, it is a map of who decides what, useful to anyone planning a targeted attack, from spear phishing to social engineering. For a public-sector body, for defence, or for a business with sensitive functions, the question is not only “who has my data”, but “who has the map of my organisation”.
What to do now
- Take stock of your CRM contact sources: what was bought or enriched by third parties, when, under what basis.
- Ask the supplier, in writing, for the LIA: not the reassurance, the document.
- Check you can answer a data subject who asks where their data came from: the question that started this investigation.
- Treat an algorithmically inferred email as personal data in every respect, even if the supplier calls it “generated”.
- Look at the problem the other way round: how much of your organisation — roles, hierarchy, contacts — is already for sale, and who needs to know.
How we solve this
Checking the provenance and legal basis of every contact entering your systems is not a legal opinion filed away: it is a control running on the CRM and acquisition flows, with a source register — who supplied what, when, on what basis, with what document — ready for an inspection, or a data subject asking where their data came from. The same set-up brings together CRM, archives, business systems, documents and organisational systems into a single operating model, on which AI agents execute decisions with a human operator in command — for large enterprises, defence, the public sector and healthcare. Worth stating here more than elsewhere: if the model runs in-house, your contact data and the map of your organisation never cross a third party’s system. Always in two modes: on-premises, on self-contained machines without deep integration into the client’s network, or a dedicated cloud, with a data centre in Italy; always with joint management.
Want to know where the contacts in your CRM really came from? Half an hour with one of our experts, at no cost, for the first map of your sources.