Threat feed liveUpdated — 01.08.2026 10:21 CET72 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 01.08.2026 10:21 CET72 dossiersMITRE ATT&CK mapping

Lusha Systems Inc., a US data broker with no establishment in the European Unionhigh

Two million to a data broker: Italy's DPA says keeping a profile current is monitoring

On 27 July 2026 the Italian Data Protection Authority announced a EUR 2 million fine against Lusha Systems Inc., a US data broker reselling "enriched" information about individuals: job title, email addresses, phone numbers. The database also included senior institutional figures, public administration, law enforcement and the judiciary. The legally significant passage is not the amount: it is the finding that the GDPR applies to a company with no EU establishment because updating and checking profiles over time amounts to monitoring behaviour. Beyond the fine, the Authority banned processing of the data of people located in Italy and ordered its erasure.

You were the product, and the catalogue was browsable

There is a category of company almost nobody talks about, because it has no consumer customers and does no advertising: data brokers. The model is easy to explain and unpleasant to read. You collect information about real people from various sources, assemble it into a profile, and sell access to that profile to whoever pays.

Lusha Systems Inc. does this. Through its platform it provides, for a fee, "enriched" information about individuals: job position, email addresses, telephone numbers. The Italian DPA describes the two acquisition routes precisely: scraping from social networks and purchase from other data brokers. The stated purposes are commercial or anti-fraud.

Among the information available on the platform, the Authority writes, was data relating to senior representatives of institutions, public administration, law enforcement agencies and the judiciary.

The findings, one by one

EUR 2,000,000
fine
decision of 14 July 2026, announced on the 27th
Ban
on processing data
of people located in Italian territory
Erasure
ordered
because the processing was unlawful from the outset

The Authority found violations of the principles of lawfulness, fairness, transparency and data minimisation. Specifically:

The privacy notice was neither clear nor easily accessible. That is the classic defect of this industry: the people whose data sits in the catalogue are not platform customers, never went there, and in the vast majority of cases do not know they are in it.

Legitimate interest is not an adequate legal basis. This is the position on which the entire data-enrichment industry rests: professional data is public, and our commercial interest is legitimate. The Authority found that balancing test does not hold.

The processing lacked a valid legal basis from the outset, and was still ongoing at the time of the decision. Hence not only the fine, but the ban and the erasure order: if there never was a basis, there is nothing to fix going forward.

The passage that matters more than the two million

The part destined to be cited is a different one, and it concerns jurisdiction.

Lusha is a US company with no establishment in the European Union. The natural defence in such cases is that the GDPR does not apply. The Authority held the opposite, and the reasoning is worth following because it does not rest on where the servers sit or where the customers are.

The European regulation also applies to controllers not established in the Union when the processing relates to monitoring the behaviour of people located in the Union. The Authority observed that Lusha does not merely collect professional information: it also updates and checks it over time. That continuous maintenance of the profile — verifying whether a person has changed role, employer or contact details — amounts, in the DPA's view, to monitoring individuals' behaviour and positions online: genuine "tracking" within the meaning of the GDPR.

  1. 01
    One-off collection
    arguably questionable, but it is a snapshot
  2. 02
    Updating over time
    the profile is kept alive and verified
  3. 03
    Monitoring
    and with monitoring comes European jurisdiction

The principle, if it holds, is broad. It is not only about Lusha: it concerns anyone maintaining a live database of European individuals from outside the Union, and it draws a sharp line between taking a photograph and leaving a camera running.

Why this belongs on a cybersecurity site

Because such a catalogue is not merely a nuisance-marketing problem. A database pairing name, corporate role, verified and current email and phone is the exact raw material of targeted social engineering: pretexting, CEO fraud, phishing built on the real org chart rather than on a randomly bought list.

And here the heaviest detail of the decision returns: the catalogue also contained law enforcement and the judiciary. A current list of who holds those roles, with contact details, is not an abstract privacy problem. It is a targeting capability, and whoever buys it does not have to say why.

What an individual can do, and what a company must do

If you are an individual: the rights of access and erasure apply to entities like this too, and they apply even if you never had any relationship with them — that is precisely the point the Authority affirmed. You do not need to demonstrate harm in order to ask.

If you are a company buying contact lists: buying does not transfer the problem to the seller. Whoever uses that data to contact people is a controller in their own right and answers for the legal basis they rely on. The question to put to the supplier before signing is the least comfortable one: where does this come from, and what were the people in it told?

If you are a security lead: it is worth knowing how much of your org chart is already purchasable. Not to remove it — often you cannot — but because it changes the plausibility threshold of the messages your staff receive. A fraud attempt quoting the right name, the right role and the right internal number requires no prior intrusion: it requires a subscription.

A note on sources and limits: this dossier is based on the Authority's official press release of 27 July 2026 and its reference to the decision of 14 July 2026. At the time of writing no public statement from the company is available, nor information about any appeal: the decision is administrative and, like all such decisions, can be challenged through the applicable channels.

More dossiers