Person viewing data profiles on their laptop.

Lusha Fined 2 Million Euros: Important Lessons About Data Enrichment

The Italian Data Protection Authority (Garante) has fined Lusha Systems, a US-based data broker, 2 million euros. The case provides interesting compliance lessons for any company evaluating data enrichment services.

Lusha runs a paid B2B platform that gives its subscribers access to information on individuals (“Contacts”): name, professional email, phone number, job title, seniority, and location. Such data is acquired via multiple different sources, such as LinkedIn, Salesforce, web scraping activities, other data brokers, and others, and each profile is continuously updated.

Once the investigation was initiated, the company tried to exclude the applicability of the GDPR, arguing that no special categories under Art. 9-10 GDPR were involved, only ordinary professional data, and only in a B2B context. The Garante once again clarified that this data remains personal data in every respect, even when collected in a B2B context and even when already publicly visible elsewhere (a LinkedIn profile, for instance). Public availability of a data point does not amount to authorisation for its commercial reuse by third parties.

The Garante also ruled that the GDPR is applicable despite the company's defense that it has no EU establishment, because the ongoing updating of data subjects' employment status amounts to “monitoring of behaviour” under Art. 3 para. 2 lit. b GDPR.

Legitimate Interest and Consent

Within the same proceeding, the Garante references its own prior sanctions against companies that had acquired contacts for marketing purposes without an adequate legal basis, confirming a consistent line of enforcement on data brokers.

Legitimate interest cannot support the collection and disclosure of contact data to third parties for their own marketing, sales, or recruiting purposes. Where the processing serves to make a person's data available to third parties for their own commercial ends, Italian law requires the data subject's consent. This holds regardless of how the data was sourced (collected directly, scraped, or purchased from another provider).

The Garante also found that Lusha's legitimate interest assessment (LIA) was, in substance, non-existent, with no real balancing between the interest pursued and the rights of the data subjects, tucked inside a broader impact assessment rather than standing as its own document. A properly conducted LIA needs to be a standalone document that specifically and thoroughly addresses lawfulness, necessity, and the balancing of interests, not an accessory paragraph.

Transparency Failures

Even when information technically exists, if it is hard to find or hard to understand, it does not satisfy the transparency requirement. In Lusha's case, the legal basis was, in theory, disclosed in the privacy notice, but that notice was published several clicks deep on the website, with no direct link from the homepage, and drafted in a language other than that of the affected individuals (English rather than Italian). The Garante found this insufficient under the transparency principle.

Lessons Learned

The practical takeaway for any company considering a data enrichment provider like Lusha, or building a similar contact database internally, is straightforward: getting transparency and the correct legal basis right is paramount. Before signing up for such a service, or launching an internal effort to collect and enrich professional contacts, the DPO or privacy counsel should be brought in to assess:

  • whether the provider's legal basis is actually valid for the intended use (marketing, sales, and recruiting typically fall under consent, not legitimate interest);
  • whether the underlying data was lawfully collected in the first place, since the duty to verify its origin also falls on whoever reuses it;
  • whether additional information needs to be provided to data subjects, and whether the organisation may already be unknowingly processing data with no valid legal basis simply by purchasing it from a third party.

The fine in this case falls on the provider. But the compliance risk extends just as much to whoever buys its services without doing that check first.



No comments


« Previous post