Skip to content
Enforcement · Garante per la protezione dei dati personali (Italy) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Garante fines Lusha Systems Inc. over unauthorized B2B contact database

Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database.

Original title: Garante per la protezione dei dati personali (Italy) - 542/2026

Summary

It was a US company wholly owned by Lusha Systems Ltd. In April 2025, the Italian DPA (Garante) initiated an investigation after media reports revealed that telephone numbers of senior Italian officials were available on the platform. The DPA later received one complaint and one report from data subjects who had received unsolicited advertising communications. The data subjects further stated that after requesting information about the source of their contact details, they discovered that their data were available on the controller’s platform without their consent. The controller explained that, for a subscription fee, it provided its Clients with a Business Contact Card for each Contact. The controller further distinguished between “Clients”, namely customers who used the platform and accessed its B2B database, and “Contacts”, namely the individuals whose personal data were included in that database, regardless of whether they used or were aware of the platform. Clients received Contact Cards containing information such as names, professional email addresses, telephone numbers, job titles, roles and locations, which could be used for sales, marketing, recruitment, business intelligence and fraud prevention. The DPA limited its investigation to the processing of Contacts’ personal data. The controller stated that it collected and combined data from publicly available sources, specialised providers, affiliated companies and commercial partners. It also inferred missing professional email addresses through algorithms that identified standard company email patterns. Through its Community Program and integrations with email, calendar and CRM services, it could also obtain information from Clients’ professional networks and communications. The data were cross-referenced, enriched and regularly updated to reflect changes in Contacts’ professional circumstances. The controller argued that the GDPR did not apply because it was established outside the EU and provided services only to businesses. It additionally claimed that the weekly updating of Contact Cards ensured accuracy rather than constituting monitoring or profiling. The controller maintained that the collection and disclosure of the data were necessary for its own economic interest in providing accurate professional contact information and for its Clients’ interests, including fraud prevention. According to the controller, it processed only a limited range of information concerning the Contacts’ professional lives. It further claimed that individuals who made professional information publicly available, particularly through services such as LinkedIn, could reasonably expect that the information might be reused and that they could be contacted regarding professional opportunities. Regarding transparency, the controller stated that its Personal Information Notice was sent to each Contact before their information became available in the database. It explained that it notified Contacts that they had a seven-day period during which they could opt out before their information became available to Clients. The controller also maintained that excluding public officials and public figures from the database was not a requirement under the GDPR. It attributed the presence of certain public officials to technical limitations in its filtering system. It also argued that public figures had a lower expectation of privacy. After the proceedings began, the controller removed profiles connected with Italian public bodies and officials, strengthened its filters and customer-verification measures, discontinued the Community Program in Italy and extended the opt-out period to fourteen days. Holding — Regarding the territorial scope of the GDPR, the DPA acknowledged that Article 3(2)(a) GDPR could apply to the processing of Clients’ data, but not to Contacts, since they were not recipients of the service. However, it held that Article 3(2)(b) GDPR applied because the controller systematically combined, enriched and updated Contacts’ professional information in order to assess their circumstances and determine whether and how they would appear in the database. Referring to Recital 24 and Recital 30, the DPA held that monitoring did not require profiling. It noted that the systematic observation of online traces and changes in a person’s professional situation was sufficient. The fact that the processing also served data accuracy did not alter that conclusion. It emphasised that the fact that the controller also updated the information to ensure its accuracy did not prevent the processing from constituting monitoring. Regarding transparency, the DPA found that the information concerning the collection of the Contacts’ data, the purposes of the processing and the legal basis relied upon was scattered across several documents. Also, the relevant information was not easily accessible from the controller’s homepage, while the Personal Information Notice could not be located directly through the website without prior knowledge of its existence. It further pointed out that the documents were provided in English rather than in the language of the affected data subjects. The DPA held that presenting the information in this manner did not satisfy the requirement that information be concise, transparent, intelligible and easily accessible. It therefore found an infringement of Article 5(1)(a) GDPR and Article 12 GDPR. Moreover, the DPA assessed whether Article 6(1)(f) GDPR provided a valid legal basis for the processing. It examined the controller’s Legitimate Interest Assessment and considered it essentially non-existent, as it contained only generic statements on necessity and proportionality and no genuine balancing assessment. The DPA then applied the three-part test under Article 6(1)(f) GDPR. It held that making the Contacts’ data available to Clients for their own marketing and sales activities could not constitute a legitimate interest, since the disclosure of contact information to third parties for their independent advertising purposes required prior consent under the applicable national and ePrivacy framework . However, it acknowledged that the controller’s interest in fraud prevention could be considered legitimate. The DPA nevertheless found that the processing was not necessary for the purposes pursued. It held that the controller collected information extending beyond ordinary professional contact details, including third-party data contained in CRM databases, email headers and subject lines, information about calendar meetings, and browsing data collected through browser extensions or other software integrations used by Clients. It pointed out that much of this information was not publicly available but was extracted from private interpersonal communications, disclosed by Clients, obtained through integrations with information systems or acquired from third-party providers. The DPA held that the collection and combination of such extensive information was neither strictly necessary nor proportionate for creating professional Contact Cards. Furthermore, it stressed that fraud prevention could also have been achieved through less intrusive means. The DPA therefore concluded that the necessity requirement and the principle of data minimisation were not met. Regarding the balancing test, the DPA emphasised that there was no prior relationship between the controller and the Contacts. Creating a professional profile on LinkedIn or another professional platform did not create a reasonable expectation that unpublished contact details would be collected from multiple sources, continuously updated and disclosed to an unspecified number of paying customers. It further noted that the processing could expose Contacts to communications from unknown third parties for purposes they could not reasonably anticipate. The DPA concluded that the Contacts’ interests, rights and freedoms prevailed over the controller’s economic interests and that the safeguards adopted by the controller could not change this outcome. Therefore, the DPA held that Article 6(1)(f) GDPR did not provide an appropriate legal basis and found that the controller infringed Article 5(1)(a) GDPR, Article 5(1)(c) GDPR, and Article 6 GDPR. Regarding public officials, the DPA held that their status did not reduce their entitlement to data protection and that no public interest justified disclosing their direct contact details for commercial purposes. The DPA further found that the controller had been aware of the risk that public officials could be included in its database but had failed to implement sufficiently effective technical and organisational measures. Its filters recognised general titles such as “President” but failed to exclude more specific titles such as “President of the Italian Republic” and “Vice Prime Minister”. The DPA therefore found an infringement of the principle of data minimisation under Article 5(1)(c) GDPR and the obligation of data protection by design and by default under Article 25 GDPR. The DPA imposed a fine of €2,000,000. Furthermore, it prohibited any further processing of personal data of data subjects located in Italy that had been collected without an adequate legal basis and ordered their deletion.

How it connects

212 of 221 paragraphs apply legislation or carry a topic — see them in the full text ↓
15625/2026 Cass.Civ. - 15625/2026 Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its… Supreme Court May 21, 2026 DPIA Privacy Impact Assessment Privacy by Design
C-507/17 Google LLC v CNIL C-507/17 (Google Territorial Scope) CJEU Sep 24, 2019 Right to be Forgotten Right to Object Child Consent
CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is Processing: Communication of personal data in response to a request for access to documents constitutes processing. (¶69) Jun 29, 2010 Personal Data Right to Restriction Processors
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities Supervision Consent

Full text 221 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

[Web Doc. No. 10275035] Decision of July 14, 2026 Register of Decisions No. 542 of July 14, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter the “Regulation” or “GDPR”); HAVING REGARD TO the Code on Data Protection (Legislative Decree No. 196 of June 30, 2003, hereinafter the “Code”); HAVING REGARD TO the documentation on file; HAVING REGARD TO the observations submitted by the Secretary General pursuant to Art. 15 of the Data Protection Authority’s Regulation No.

§

1/2000, adopted by resolution of June 28, 2000; RAPPORTEUR: Prof. Pasquale Stanzione; 1. 1. Origin of the Investigation 1. In light of several news articles reporting that the telephone numbers of the most senior officials of the Italian Republic were present on the Lusha platform, in April 2025 the Office launched a preliminary investigation into the company Lusha Systems Inc. (hereinafter “Lusha,” the “Company,” or the “Data Controller”), represented by its pro tempore legal representative, with registered office in Boston, MA 02199, USA, a wholly-owned subsidiary of Lusha Systems Ltd. 2. Subsequently, the Data Protection Authority received a complaint and a report from data subjects who, after receiving unsolicited advertising messages and calls from third-party companies and upon requesting clarification regarding the source of their contact information, discovered that their data was available on the Lusha platform without their consent to such processing.

§

2. The Authority’s Request for Information and the Company’s Response 3. On April 7, 2025 (Ref. No. 47069 of the same date), the Office issued a request for information to Lusha and another company, headquartered in Germany, which Lusha had designated as its EU contact point, a request for information pursuant to Article 157 of the Code, asking them to provide details on the number of Italian data subjects in their database (hereinafter also referred to as the “B2B database”), the sources from which the data was obtained, and information on the processing operations carried out. The Data Protection Impact Assessment (DPIA) and the Legitimate Interest Assessment (LIA) were also requested. 4. The Company submitted its response on May 29, 2025 (Ref. No. 78434 of May 30, 2025), after obtaining an extension until May 30, 2025 (Ref. No. 53505 of April 17, 2025). 5. The Company first stated that it did not consider itself subject to the Regulation or the Code, as it does not have an establishment in the EU; therefore, the additional criteria set forth in Art 3(2) of the Regulation would not apply.

§

It also declared that it was not required to appoint a representative. The Company designated a point of contact in Germany solely to be easily accessible to individuals and authorities in the EU and the United Kingdom; furthermore, although not required to do so, it voluntarily applied the provisions of the Regulation to comply with international and European standards. 6. The Company has also stated the following: - According to its own nomenclature, “Customers” (or “Clienti”) are defined as Users who have registered for the service and can access the data contained in the B2B contact database. In contrast, there are “Contacts,” meaning those whose data is collected and made available in the database regardless of whether or not they are also Customers of the Company; - that it acts as the controller for: the processing of data related to visits to its website; the collection and processing of data related to joining the Lusha group, the Facebook fan page, or the LinkedIn page; the collection and processing of data related to company profiles whose data is accessible via the platform; - to process information relating to approximately XX Italian data subjects, including individuals who do not use the platform (Contacts), who would, however, be informed by means of a specific privacy notice containing the provisions of Art.

§

, phone number, email, location, or occupation); - to exclude from the database the data of Contacts who hold public office or who are otherwise considered public figures; - to limit data collection to: names, email addresses, and phone numbers, as well as a Contact’s professional title, tenure, role, and location; - to ensure the accuracy and correctness of the data by verifying multiple sources, cross-checking data, and updating the data weekly, which entails erasure or correction of data deemed inaccurate. 7. With regard to the sources of personal data collection, the Company has identified the following: publicly available information on the Internet, such as public social media profiles, as well as from professional blogs and forums; entities specializing in the provision of information from which Lusha purchases or licenses data; from its own “Community Program,” which involves the collection of data from Program members to the extent that they consent to sharing information; and through an email generation algorithm.

§

8. Finally, with regard to the legal bases, Lusha conducted a Legitimate Interest Assessment (LIA) within the VIP, concluding that the processing of Contact data and the related communication to Customers meets the requirements of legitimate interest. 2. INITIATION OF PROCEEDINGS FOR THE ADOPTION OF CORRECTIVE AND SANCTIONARY MEASURES 9. Based on the information gathered during the activities described above, by notice dated August 6, 2025 (Ref. No. 109501), served pursuant to Article 166(5) of the Code, the Office initiated proceedings for the adoption of the measures referred to in Article 58(2) of the Regulation against the Company as the controller. 10. Having noted the Company’s lack of an establishment in the Union and given that the collection and processing of personal data of European citizens was undisputed, the Office considered that Lusha also offered its service to natural persons established in the EU.

§

11. Since it could not be ruled out that the individuals accessing the platform are also, and above all, natural persons whose data are thus subject to processing and, therefore, are to be considered “data subjects,” the Office concluded that Lusha offered its services to European data subjects and met the criterion set forth in Article 3(2)(a) of the Regulation. 12. The documentation on file also showed that the Company did not merely collect contact data from multiple sources but reorganized it into a “Company Contact Profile” that was unique and identifiable, in order to make the data contained in the database easily retrievable using various filters; furthermore, it enriched the data to ensure its completeness and constantly updated it to provide up-to-date information. In particular, both the data enrichment and updating activities (for example, to verify whether the person still held a certain job position or had changed positions or workplaces), including through “cross-checks,” appeared to involve monitoring the Contact’s job position over time to the extent that it constituted monitoring of their conduct.

§

13. The Office therefore concluded that the Company was monitoring the work-related behavior of the Contacts—a practice necessary to assess the personal/work-related positions held by them over time—which could constitute monitoring of the data subjects’ behavior pursuant to Art 3, para 2, subparagraph (b) of the Regulation. 2. Compliance with the Principles of Lawfulness and Data Minimisation 14. ) and, for most of the purposes pursued, states that it processes such data to pursue its legitimate interest. The Office has limited its investigation to the processing of “Contacts” data. 15. With regard to Contacts, Lusha has stated that it processes the data typically contained on business cards or in the “signature block” of emails: name, professional title, role, years of experience, email address, phone number, and the country where the individual works. 16. Nevertheless, additional data is collected through other channels such as: - the “Community Program”: community members share data from their professional corporate network, such as email headers and signature blocks, client names, company names, professional titles, work phone numbers, and email addresses.

§

com); - corporate social media profiles when a User uses the Lusha browser extension while on LinkedIn. 17. The “Privacy Policy” published online (or “Privacy Notice”) did not identify a specific legal basis for the collection of Contact data but referred to legitimate interest as the basis for lawfulness to allow Customers to access the database, and thus, technically, to allow the disclosure of Contact data to Customers. Only in the VIP (§5) sent in response to the Office’s request for information was it clarified that the legal basis for collecting Contact data was legitimate interest. 18. The enormous volume of data collected—from diverse sources and third parties—for the purpose of carrying out processing that, on the one hand, is difficult for data subjects to foresee or expect and, on the other hand, is likely to have significant impacts on them—making them contactable by third parties for unforeseeable purposes—raised doubts about the adequacy of the legitimate interest as a legal basis.

§

19. In addition, Article 129 of the Code requires the consent of contracting parties for the inclusion of their data in paper or electronic directories available to the public and for the use of such data for the purpose of sending advertising or direct sales material or for conducting market research or commercial communications; and Art 130 of the Code, in summary, requires the consent of Users and contracting parties for the sending of advertising or direct sales material or for the conduct of market research or commercial communications. 20. In the case of particularly extensive and intrusive processing based on a vast amount of data—and likely to have a significant impact on unsuspecting data subjects—the Office took issue with the Company for failing to justify in any way the use of legitimate interest as a legal basis or to demonstrate the lawful origin of the data. 21. Finally, with regard to information and the right to object, the Office noted that allowing data subjects such a short period to exercise their right to opt out (7 days from the date the notice was sent via email) created the risk that the data subject might fail to object due to circumstances beyond their control.

§

22. ” 23. With regard to the data contained in the calendars of Community Program members, meeting titles, participants and their email addresses, as well as email account data, the Office found that this information was unnecessary. Such collection was therefore, in theory, capable of constituting a violation of the principle of data minimization set forth in Art. 5(1)(c) of the Regulation. In light of the foregoing, the Office found that, with regard to the collection and processing of Contact data, the Company had not identified any valid legal basis for lawfulness, since, under the circumstances and in the manner described above, reliance on legitimate interest did not appear to constitute an adequate legal basis for lawfulness. This constitutes a possible violation of the principles of lawfulness and fairness set forth in Article 5(1)(a) and (c) of the Regulation, as well as Articles 6 and 7 of the Regulation.

§

These violations were compounded by a violation of Article 129 of the Code. 3. Compliance with the Principles of Transparency 25. The privacy notice published on the Company’s website, which at the time of the preliminary investigation was last updated on February 5, 2025, did not clarify the lawfulness of the collection of Contact data nor who the Company’s representative in the EU was. These omissions were, in theory, capable of violating the principles of fairness and transparency, as well as the requirement to provide adequate information to data subjects, as set forth in Articles 5(1)(a); 12; and 13(para 1)(a) and (c) of the Regulation. 4. Information to the Applicants 26. Although the Company stated that it provided the privacy notice to all Contacts, the Authority received reports and complaints (in particular, case files nos. 459328 and 465278, made available to the Company and resolved, respectively, by decisions nos.

§

349 (web doc. No. 10262105) and 350 (web doc. No. 10262367) of May 14, 2026), in which the collection and processing of data by Lusha without any notification to the relevant individuals was complained of. This omission, too, was theoretically capable of constituting a possible violation of the principles of fairness and transparency, as well as the obligation to provide adequate information to data subjects, as set forth in Articles 5(1)(a) and 14 of the Regulation. 5. Data Relating to Public and Institutional Figures 27. The preliminary investigation revealed that the platform contained, by way of example only, the contact information of the following individuals: the President of the Italian Republic, Sergio Mattarella; the Deputy Prime Minister and Minister, Antonio Tajani; Minister Guido Crosetto—all expressly identified by their institutional titles—as well as former Minister and later Vice-President of the European Commission, Raffaele Fitto; Member of Parliament Chiara Appendino and Senator Stefano Patuanelli; Commissioners Elisa Giomi and Massimiliano Capitanio of the Communications Regulatory Authority; as well as Saverio Valentino, a member of the Italian Competition and Market Authority.

§

Furthermore, among the various contacts found in the database were German Chancellor Friedrich Merz and former Chancellor Angela Merkel. 28. These circumstances appear to indicate that the Company was unable to exclude information that it itself considered it should not process. This demonstrated the absence of technical and organizational measures aimed at implementing the data protection principles set forth in Art. 25 of the Regulation, as well as a violation of the principle of data minimisation to the extent that the Company collected and stored information that it itself deemed irrelevant. Such conduct thus constitutes a possible violation of Articles 5(1)(c) and 25 of the Regulation. 3. EXERCISE OF THE RIGHT OF DEFENSE BY THE DATA CONTROLLER 29. The Company, exercising its right of defense, submitted its “defensive arguments and observations” on October 6, 2025 (Ref. No. 132076 of October 7, 2025) and requested a hearing.

§

30. Lusha first clarified that, with regard to Contacts, it collects the data typically contained in business cards that Customers use to carry out sales, marketing, and recruiting activities, committing to comply with applicable regulations. 31. 1. Inapplicability of the Regulation 32. According to the Company, its processing activities do not meet the requirements of Article 3(2) of the Regulation; in support of this, it cited the French supervisory authority, the Commission Nationale de l’Informatique et des Libertés (hereinafter “CNIL”), in its decision of December 20, 2022 (SAN-2022-024), and the Luxembourg supervisory authority, the Commission Nationale pour la Protection des Données (or “CNPD”), based on an email dated June 9, 2022. 33. Both the CNPD’s decision and the CNIL’s decision reportedly concern the same processing activities under review. Therefore, given these precedents that have recognized the inapplicability of the Regulation, the Company concluded that: “the Data Protection Authority should give due weight to their decisions and not deviate from them without justification,” under penalty of violating the principle of: loyal cooperation pursuant to Art.

§

4(3) TEU; consistent and uniform application of EU law, as expressed in Recital 10 and Chapter VII of the GDPR; and legal certainty and consistent interpretation of EU law. 1. Inapplicability of Article 3(2)(a) of the GDPR 34. More specifically, with regard to the criterion set forth in Art. 3(2)(a) of the Regulation, Lusha argued that it does not offer goods or services to natural persons in the EU. On the contrary, its services are designed, offered, and provided solely to legal entities for professional use, not to natural persons for private use. 35. According to the Company, pursuant to that provision: - the applicability of the GDPR must be assessed with reference to specific processing activities; - since the provision refers to the offering of goods or services to “data subjects”—that is, natural persons as defined in Article 4(1) GDPR, the Regulation does not apply where processing is limited to the offering of goods or services to corporations, partnerships, or other legal entities; - the mere presence, in a database, of personal data relating to Union residents is not sufficient to determine the applicability of the GDPR; rather, the controller must explicitly address or demonstrate a clear intention to offer goods or services to data subjects; - The GDPR applies only when the data being processed pertains to the data subjects themselves (“the aforementioned data subjects”) to whom the provision of goods or services is offered.

§

36. As can be seen from the website, the “Terms and Conditions,” and the “Privacy Policy” (updated on February 5, 2025), Lusha’s services are designed for enterprises. It is clear that the actual registration on the platform is carried out by a natural person acting as a representative of the legal entity, and whoever accepts the contractual terms declares that they are acting as a member of an organization. 37. Lusha considers the GDPR a “golden standard” in data protection and, for this reason, adopts its principles and concepts; however, this does not imply that the Regulation applies to or binds the Company. 38. Furthermore, contrary to the Office’s contention, Lusha has taken a series of measures to prevent individuals from accessing its services. , the individual registering on behalf of the legal entity) is required to provide a business email address. ) are not accepted; - Through the “Know Your Business” (KYB) program, Lusha uses external verification tools and databases to ensure that potential customers are registered and operate within a recognized legal system; 39.

§

According to the Company, the notice initiating the sanctioning proceedings does not cite any provision requiring the submission of documents—such as a power of attorney—to certify the legal entity status of the Clients. 40. Furthermore, even if, in isolated cases, individual professionals manage to register and are accepted as Clients, this does not alter the B2B nature of the services offered and does not justify the applicability of Art. 3(2)(a) of the GDPR. 41. In any case, according to Lusha, the Regulation would not apply because the recipients of its service (the Clients) are not the data subjects whose data is being processed (the Contacts). 2. Inapplicability of Art 3(2)(b) of the GDPR 42. With regard to the criterion set forth in Article 3(2)(b) of the Regulation, Lusha argued that the contested processing does not involve Tracking Contacts, nor profiling, nor behavioral analysis capable of falling under the concept of monitoring identified in Recital 24 of the Regulation and in the European Data Protection Board (EDPB) Guidelines No.

§

3/2018 on the territorial scope of the GDPR. 43. The Company concluded that it is not sufficient for the data of data subjects to be processed—even over an extended period of time—for the Regulation to apply; rather, the processing must involve profiling and behavioral analysis. 44. Therefore, according to Lusha, Article 3(2)(b) of the Regulation would not apply to the processing of Contacts’ data for the following reasons: - Absence of behavioral analysis: The Company processes only personal data such as name, email address, phone number, job title, role, and location. Such data neither reflects nor reveals behaviors, habits, or preferences and is not subject to any “subsequent behavioral analysis”; - Absence of monitoring: According to the Company, “monitoring” involves tracking the online or offline behavior of data subjects, for example, by recording Internet browsing activity or through video surveillance in public or private spaces.

§

This therefore constitutes “systematic and intrusive processing of personal data,” which Lusha does not carry out because it limits itself to processing professional contact information for the purpose of ensuring its accuracy; - Data accuracy: Measures aimed at ensuring the accuracy of the information available in the database do not fall under the concept of monitoring but serve the sole purpose of ensuring data accuracy pursuant to Art. 5(1)(d) of the GDPR and are functional to the protection of the Contacts; - Absence of profiling: Lusha does not engage in profiling within the meaning of Article 4(4) of the Regulation, insofar as it neither “evaluates” the Contacts nor “analyzes” or “predict” aspects pertaining to their professional, economic, health, or personal lives, but is limited to providing accurate professional contact information. 2. Inapplicability of the Privacy Code 45. The inapplicability of the Regulation would entail the inapplicability of the Code as a complementary and supplementary act, operating within the limits of Art.

3 of the GDPR

§

With Legislative Decree No. 101 of August 10, 2018, the legislature repealed the provisions of the Code that were incompatible with the GDPR and, in particular, Art. 5, which extended the application of Italian law to data controllers established outside the Union. 3. Transparency and Information Regarding the Legal Basis and the EU Representative 46. As of February 5, 2025 (the date of the update to the Privacy Policy or “Privacy Notice”), Lusha would already have been transparent regarding the legal basis for data collection and with respect to its representative. 47. As for the legal basis, contact data is not collected directly from the data subjects; therefore, Art 13 of the GDPR does not apply. Furthermore, although not required to do so, Lusha has nonetheless published notices (namely the “Privacy Notice” and the “Personal Information Notice,” the latter updated in January 2023) which, “if read correctly and in context” (p.

§

4, defense arguments), ensure that Contacts are adequately informed about the legitimate interest, including the related data collection phase. In any case, the Personal Data Notice also complies with the requirements of Art 14 and was sent to each Contact prior to the inclusion of their data in the database. 48. 1 of the Privacy Policy clarifies that the purpose of “enriching, updating, cross-checking, and validating Lusha’s B2B database” is based on legitimate interest. This statement makes it clear that Lusha collects and processes Contacts’ data to create and maintain its database. Furthermore, other sections of the Privacy Policy refer to the “collection” of data. 49. Second, the Personal Information Notice clarifies that Contact data is collected for the purpose of inclusion in the database based on legitimate interest and informs data subjects of their right to opt out, as well as other options and rights available to them.

§

50. ” 51. Finally, with regard to the complaints and reports received by the Authority, the Company stated that it had sent the Privacy Notice to the respective data subjects, indicating the dates of dispatch and the corresponding timestamps. 4. Validity of the legitimate interest 52. With regard to the legal basis for the processing of Contacts’ data, the Company cited the Judgement of the Court of Justice of the European Union of December 7, 2023, SCHUFA Holding AG, C-26/22 and C-64/22, para. 83, insofar as it demonstrates the possibility of basing processing on legitimate interests even when data are collected indirectly, that is, when collection takes place through third parties. 53. The Data Protection Authority itself has previously acknowledged that the development of B2B activities based on legitimate interest is compatible with the regulatory framework provided it is accompanied by adequate safeguards (for example, transparency and the option to opt out).

§

In particular, the Company cited the decisions of February 22, 2018, January 15, 2020 [9256486], [8080493], and April 29, 2025 [10145986]. 54. Similarly, in Opinion 28/2024 on legitimate interest in the context of artificial intelligence models, the EDPB reportedly reiterated that this legal basis is admissible even when information about data subjects is collected from public sources or third parties and made available to customers, provided that this is supported by a thorough balancing of interests and appropriate safeguards. 55. ” 56. Lusha’s primary interest consists of the economic interest in providing reliable services to customers, in particular by ensuring they have access to accurate and up-to-date professional contact information in order to prevent fraud and to establish meaningful and effective business interactions with other enterprises and their respective representatives.

§

57. The Company thus emphasized that the concept of legitimate interest must be understood broadly, also encompassing the legitimate interests of its Customers, which include: - Protection against identity theft, impersonation, and online fraud. By providing validated and up-to-date information derived from public sources, community contributions, and reliable partnerships, Lusha enables customers to verify and authenticate the consistency between the professional attributes declared by an individual and the data that actually corresponds to them; - Business development, marketing, and recruitment. Through access to up-to-date contact information, organizations can identify and connect with potential clients, qualified candidates, and strategic decision-makers. 58. With regard to the requirement that processing be necessary for the pursuit of legitimate interests, the Company has reiterated that it processes only limited, clearly defined categories of data of a professional nature (such as name, contact information, job title, and position).

§

This data must necessarily be enriched, verified, and updated. 59. The Company decided to avoid collecting data directly from data subjects, deeming this approach “structurally incomplete,” as it would have excluded a large portion of professional contacts and would have been of little help for anti-fraud and identity theft prevention purposes. 60. With regard to balancing the fundamental rights and freedoms of data subjects, the Company has chosen to prevent the ability to conduct free and extensive searches on its database to avoid massive data extraction or misuse of the platform. Instead, it has adopted a “credit”-based system that customers must purchase and use to access the data; this is intended to encourage targeted and contextualized searches, thereby limiting overall access to contact data. 61. , financial information); that the processing does not affect the private lives of Contacts because Lusha has no direct relationship with them and the processing relates to professional data, which is often already publicly available; 62.

§

, on LinkedIn)—falls within the reasonable expectations of the data subjects. 63. The Company has also identified certain professional opportunities and benefits that the processing provides for Contacts, namely: the possibility of being contacted by recruiters regarding job openings; the receipt of relevant commercial communications; and more targeted and efficient professional communication. 64. Finally, the Company has adopted additional measures to mitigate risks, namely the implementation of a voluntary seven-day cooling-off period for the data subject to opt out; while the right to object remains at any time, even beyond this period, this serves as a voluntary safeguard allowing those who request it to prevent their data from being added to the database from the outset. 65. With regard to the Community Program, the Company has determined that the data collected in this manner is necessary, as this program serves to ensure and improve the accuracy of the database.

§

Only in this way can the database be kept up-to-date and accurate, in accordance with Art 5(1)(d) of the GDPR (and, at the same time, to the benefit of balancing legitimate interests under Art 6(1)(f) of the GDPR). 66. The Company further specified, with regard to the data contained in the calendars of Community members, that it offers—separately—a calendar feature for Community members. This would constitute an independent processing operation (“Lusha Over Calendar”) that integrates with users’ calendars (Google/Outlook) to facilitate more effective meetings. 5. Inapplicability of Title X of the Privacy Code 67. With reference to Articles 129 and 130 of the Code, the Company stated that it is not an “electronic communications provider” but rather operates as an online platform that provides access to commercial data. ” 68. Similarly, Art 130 of the Code would not apply insofar as the Company does not send marketing communications; rather, these are carried out by its customers, who assume full accountability for compliance with applicable regulations.

§

6. Compliance with the Principles of Data Protection by Design and by Default 69. ” 70. In the absence of a “specific” obligation under the Regulation, the adoption of safeguards beyond those provided for by the legislation cannot be transformed into an obligation whose violation would entail accountability and sanctions. Furthermore, the Authority confuses the Company’s voluntary decision, made as a precautionary measure, with a non-existent admission that the excluded data are not necessary. The Authority has not demonstrated why the possible residual presence of professional data pertaining to government officials would constitute unlawful processing. On the contrary, according to the Company, the processing of such data also falls within the scope of the communication purposes. 71. Citing European case law and guidelines on the right to be forgotten, the Company asserted that public figures have a lower expectation of privacy than other data subjects.

§

72. In any case, to exclude the contact information of public officials from the database, Lusha has for years been implementing voluntary measures and advanced technologies, such as specific filters, domain suppression, and periodic checks. 73. The residual presence of a small number of profiles, identified in the complaints, was caused by a technical flaw in the exclusion algorithm, which failed to detect particularly specific job titles. ) from its database. 7. Additional Voluntary Measures 74. To demonstrate its willingness to cooperate in ensuring full compliance with the regulations, Lusha reported that it had adopted the following new measures: - updating the World Map of Direct Marketing Regulations for Italy, to provide customers with clearer information on Italian direct marketing regulations; - initiated the process of integrating the Public Opt-Out Registry into the corresponding feature within Lusha; - strengthened the customer registration process by introducing additional verifications (requirement to provide the company name and registered office, and a checkbox declaration confirming authorization to act on behalf of the represented company); - Update of the Privacy Policy and Personal Data Notices to further clarify the use of legitimate interest and resend the updated Personal Data Notice to Italian contacts in Italian; - Extension, effective October 2025, of the cooling-off period from 7 to 14 days granted to new Contacts to exercise their right to opt out; - Gradual phase-out and blocking of access to the Community Program in Italy; - strengthening of measures to exclude data relating to public officials and similar figures, including the removal of any remaining profiles linked to the public sector in Italy and the introduction of: (i) a weekly AI-based scan of official institutional websites to identify and eliminate any matching names in the database; and (ii) quarterly audits conducted by a third-party consultant aimed at ensuring continuous monitoring and constant improvement of the measures adopted.

§

8. Mitigating Circumstances 75. With regard to the nature, severity, and duration of the violation, the Company has: - contested the characterization of its processing as “particularly extensive and intrusive,” since the data being processed are only basic professional identifiers, normally made available by the professionals themselves in work contexts. Lusha does not process the categories of data referred to in Articles 9 and 10 of the GDPR; - argued that the professional context mitigates the severity; - specified that Lusha’s service is structurally different from an “open” or “public” directory; - argued that no actual harm to the data subjects has been identified; - stated that the violation is characterized by “low offensiveness” insofar as the objections relate to matters of interpretation and the effectiveness of voluntary safeguards that exceed the legal minimum. 76. Furthermore, Lusha has always acted in good faith, and any violation cannot be attributed to either willful misconduct or negligence; it has also cooperated with the Authority by strengthening the Company’s compliance.

§

77. The Company has also certified its entire legal and compliance team through CIPP (Certified Information Privacy Professional) certifications, and its data processing activities are subject to independent audits conducted by third parties based on various certifications. 78. Finally, the Company described its revenue as “modest,” “limited,” and with “negative margins,” while also emphasizing that it is not a dominant player in its target market and continues to invest in compliance without deriving any profit from it. 9. The Company’s Hearing and Subsequent Communication 79. On February 11, 2026, the Company’s hearing took place at the Authority’s headquarters, during which the Company first confirmed that it had adopted certain measures to address the allegations. In particular, it clarified that it had: - completely removed all remaining contacts attributable to Italian public bodies and institutions from the database, as well as updated and strengthened the exclusion system to also include the public administration, law enforcement agencies, and judicial authorities; - completed the process of resending the Personal Data Notices “to all contacts, including those residing in Italy (numbering over XX for Italy), an operation concluded on January 29, 2026”; - updated its Terms and Conditions; - discontinued and blocked access to the Community Program for Customers who register using Italian IP addresses or for individuals associated with domains linked to Italian organizations; 80.

§

With regard to the applicability of the Regulation pursuant to Art 3, para 2, subparagraph (a), the Company argued that what matters for jurisdictional purposes is the intention to offer its services to natural persons established in the EU. In this specific case, Lusha’s intention is to offer its services only to companies and organizations as a B2B service. What must therefore be demonstrated is not the User’s intention to act as a legal entity but Lusha’s intention to target other companies rather than private individuals. ). 81. it). This is because the Company does not intend to offer its services to entities with their own accounts, such as freelancers and sole proprietorships, and their access to the service would constitute a violation of the terms of service because the User cannot act as an individual. 82. Following the Authority’s investigation, the Company introduced additional measures, such as requiring users to enter the company name, the legal name, and a checkbox to declare that they are acting on behalf of the company.

§

Furthermore, the email address provided is now cross-checked against those contained in a database of companies, corporations, and external suppliers maintained by the Company. Information such as the company’s tax identification number or VAT number, an invoice, or a power of attorney is not required. 83. With regard to the monitoring criterion set forth in Article 3, para 2, subparagraph b) of the Regulation, the Company highlighted the similarities between the Data Protection Authority’s investigation and the one previously conducted by the CNIL. Following its investigation, the CNIL reportedly concluded that: “there was no monitoring, as there is no profiling activity within the meaning of the Regulation. Lusha records changes in the employment status of the individuals in its database, but this does not constitute profiling; it is merely an update of the data. The fact that someone changes jobs—and consequently Lusha updates the job title in the database—does not constitute profiling insofar as it does not lead to an understanding of behavioral preferences.

§

” Furthermore, the Company specified that: “To update the contacts in the database, it must check them all periodically and consistently. ” 84. With regard to the legal basis for processing, the Company confirmed that it relies on lawful interest pursuant to Art. 6(1)(f) of the Regulation both for the collection of Contact data and for its disclosure to third parties for the purposes of those third parties. Furthermore, data subjects have a legitimate expectation of being contacted by companies and professionals, as they are the ones who have made their information public. 85. On this issue, after the Office noted that Users’ contact information (phone number and email address) is not available on their LinkedIn profiles (which the Company identified as the primary source of data), the Company stated that: “If a person signs up for LinkedIn, it means they want to present themselves as a professional in the job market.

§

[…] As for data not available on LinkedIn—specifically email addresses—these can be inferred using an algorithm, which then attempts to send a privacy notice, or obtained from other sources. ’” 86. Finally, in a communication dated February 18, 2026 (Ref. No. 26323), the Company provided a written account of the clarifications offered during the hearing regarding the proceedings involving Lusha before the CNIL. On that occasion, while acknowledging “the full autonomy and decision-making authority of this Authority, as well as the lack of formally binding effect of the CNIL’s decision,” the Company reiterated that: with regard to Art. 3(2)(a) of the GDPR, the CNIL had acknowledged that Lusha’s offering of goods and services is directed exclusively at Customers; with regard to the criterion set forth in Art. 3(2)(b) of the GDPR, however, the CNIL concluded that Lusha’s processing activities do not constitute tracking, profiling, or monitoring of the behavior of data subjects.

§

4. THE AUTHORITY’S ASSESSMENTS 87. Following the preliminary investigation, and having assessed the arguments put forward by the Company—to which the declarant responds pursuant to Art. 168 of the Code—the Authority considers that these arguments are only partially sufficient to exclude the Company’s accountability. 1. Operation of the Service Offered 88. The service offered by the Company consists of making the information contained in its database available to Customers—in exchange for payment of a monthly, annual, or customized subscription fee, and subject to a limited period of free use. 89. This information is organized into a “Business Contact Card” (“Business Contact Card”) for each individual Contact, which is updated weekly and contains data relating to a specific natural person, including the following information: name, email address, phone number, professional title, years of service, role, and location.

§

This information constitutes personal data pursuant to Article 4(1) of the Regulation. 90. The business model is centered on making the personal data of Contacts available to Customers. ) or through automatic suggestions using recommendation algorithms based on interests inferred from the Clients. 91. With regard to such processing and as acknowledged by the Company in its response of May 29, 2025, the Authority considers that Lusha qualifies as the controller pursuant to Article 4, paragraph 7, of the Regulation, since it is Lusha that determines the purpose (making the data available) and the means of processing (the various methods comprising the processes of collection, merging, enrichment, updating, and making data available and/or excluding it from the database). In turn, Customers may use the data obtained in this manner for their own purposes, acting as independent controllers of data processing.

§

92. The main sources of data collection are the LinkedIn and Salesforce platforms, as well as blogs, websites, and professional forums. In addition, there is contact data that the Company obtains from its Customers who agree to the contractual terms of the Community Program, as well as through the integration of the Lusha API with other Customer services and CRMs (for example, Gmail, Outlook, Outreach). 2 of the Privacy Notice on file states: “By connecting your email account as an Integration, Lusha may scan and/or extract business contact details from your inbox and may use them to improve its services”) and through the use of “Lusha integrations,” such as Lusha browser extensions or other software that enables data collection while the customer who has installed such extensions is browsing online. 93. Finally, any missing information is reconstructed through various processing operations.

§

dominio). Once an email address is generated, an attempt is made to send a privacy notice. As for phone numbers, these are purchased from other “vendors” or partners that collaborate with the Company and are primarily based in the United States. 2. On the Applicability of the Regulation 94. As a preliminary matter, it is necessary to address the applicability of Regulation (EU) 2016/679 to the processing of data of data subjects located in the EU carried out by a controller (or processor) not established in the Union. In doing so, it is appropriate to set aside assessments made by other entities and, in particular, the aforementioned precedents established by the authorities in Luxembourg and France. 95. Given that the Data Protection Authority holds the assessments made by its European counterparts in the highest regard—with whom, as is well known, maintains constant relations and exchanges within the framework of the cooperation and consistency mechanism described in Chapter VII of the Regulation, in accordance with European law and outside the aforementioned cooperation and consistency mechanism, the Data Protection Authority is not bound by their assessments and is not legally subject to any prior rulings.

§

This circumstance is also acknowledged by the Company in its communication of February 18, 2026, in which it filed a clarification note regarding the statements made during the hearing. 96. More specifically, with regard to the email from the Luxembourg authority, the Data Protection Authority notes that, since it concerns a specific case, the email can only be considered a communication between third parties unrelated to the Data Protection Authority and therefore, if applicable, is binding only among the parties involved. This document, which, moreover, has not been published, must be considered to have no legal effect erga omnes and is not binding on other European supervisory authorities. 97. With regard to Decision SAN-2022-024 of December 20, 2022, issued by the French supervisory authority (“CNIL”), regardless of the specific case under analysis, this ruling is also the result of an assessment of the specific factual situation submitted to that authority and is likewise not binding on the Data Protection Authority or other supervisory authorities.

§

As can also be inferred from Recital 143 of the Regulation, this decision, too, produces legal effects only with respect to the parties involved in the lawsuit. 98. Given that, in general, the EU legal system has entrusted the Court of Justice, through the preliminary ruling procedure provided for in Art. 267 of the TFEU, with the fundamental function of ensuring the uniform application of European law, which entails the obligation to apply EU law consistently and uniformly, the Data Protection Authority’s compliance with the principle of sincere cooperation set forth in Art. 4(3) of the TEU must be assessed in light of the cooperation procedures provided for in Chapter VII of the Regulation. Since the Company does not have an establishment within the territory of a Member State, the aforementioned cooperation procedure does not apply and, therefore, there is no violation of the principle of sincere cooperation on the part of the Data Protection Authority vis-à-vis other European supervisory authorities (see EDPB Guidelines 3/2018, p.

§

14). 99. Similarly, outside the aforementioned cooperation procedures—which, with regard to personal data protection legislation, entrust the EDPB with the task of ensuring the consistent application of the GDPR (see Court of Justice, February 10, 2026, WhatsApp Ireland v. EDPB, C-97/23 P, para. 103), the Authority considers that the requirement set forth in Recital 10 of the Regulation, aimed at ensuring an equivalent level of protection of rights and freedoms in all Member States, does not, in and of itself, preclude a supervisory authority from deviating from the prior assessments of another authority. On the contrary, pursuant to Article 57(1) of the Regulation, each supervisory authority is competent to carry out the tasks and exercise the powers conferred upon it under that Regulation within the territory of its Member State. 1. The criterion of offering goods or services to data subjects in the EU referred to in Art.

§

3(2)(a) of the GDPR 100. With regard to the criterion set forth in Article 3(2)(a) of the Regulation, Lusha argued that its services are designed, offered, and provided solely to legal entities for professional use, not to natural persons for private use. 101. The documentation on file shows that, despite the Company’s stated interest and intention to offer its services only to legal entities, it lacks the organizational structure and appropriate mechanisms and measures necessary to prevent natural persons from accessing its services. While it is undisputed that the Company’s intent must and can be assessed—and thus also demonstrated—based on the actions it has taken to move from an abstract design to a concrete operational model (see Recital 23 of the GDPR), and thus the Company should have adequately implemented and concretized its intentions, it is precisely from an analysis of the practical outcome of its approach that it becomes clear the Company was unable to guarantee and demonstrate that it dealt only with legal entities and not also with natural persons.

§

102. In particular, unlike other operators in B2B markets—who, in order to limit the provision of their services solely to legal entities or, in any case, to individuals acting in an enterprise capacity, take care to request elements that unambiguously indicate enterprise activity (such as a VAT number or proof of authority to represent or a power of attorney), the Company has not implemented adequate measures. 103. That said, although it is not considered proven that the Company’s services are offered only to legal entities and not also to individuals who could theoretically be classified as “data subjects,” it is acknowledged that, based in part on EDPB Guidelines 3/2018, the application of the criterion set forth in Art. 3(2)(a) of the GDPR would result in the Regulation’s applicability to the processing of “Customers’” personal data. 104. Therefore, while the argument that the Regulation does not apply to the processing of personal data carried out by the Company cannot generally be accepted—since there remain processing activities that, as explained, may fall within the scope of the Regulation— the Authority acknowledges that the criterion set forth in Art.

§

3(2)(a) of the GDPR cannot also cover the processing of data pertaining to Contacts, to which this investigation is limited. 2. The criterion of monitoring the behavior of data subjects referred to in Art. 3(2)(b) of the GDPR 105. Art. ” 106. This criterion is clarified in Recital 24 of the Regulation, which states: “The processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union should also be subject to this Regulation where it relates to the monitoring of the behavior of such data subjects, to the extent that such behavior takes place within the Union. ” 107. According to the settled case law of the Court of Justice, for the purposes of a uniform interpretation of Union law, account must be taken not only of its literal wording but also of the context in which it is set and the objectives pursued by the legislation of which it forms part (judgments of December 18, 2025, Storstockholms Lokaltrafik, C-422/24, para.

§

28; August 1, 2025, Alace and Canpelli, C-758/24 and C-759/24, EU:C:2025:591, para. 91; November 28, 2024, Másdi, C-169/23, EU:C:2024:988, para. 39; December 7, 2023, UF and AB v. Land Hessen, C‑26/22 and C‑64/22, ECLI:EU:C:2023:958, para. 48). Furthermore, the objective of the GDPR is to ensure a high level of protection of the fundamental rights and freedoms of natural persons, in particular their right to privacy, with regard to the processing of personal data, as enshrined in Art. 8, para 1, of the Charter of Fundamental Rights of the EU and Art 16(1) TFEU (judgments of February 27, 2025, Dun & Bradstreet Austria, C-203/22, EU:C:2025:117, para. 51; October 4, 2024, C-446/21, Schrems v. , EU:C:2024:834, para. 45, and the case law cited therein). 108. ” 109. ” In this regard, the Court of Justice has held that the provisions of EU law must be interpreted and applied uniformly in light of the versions in force in all the languages of the Union and, in the event of a discrepancy, the provision in question must be interpreted in light of the general scheme and purpose of the legislation of which it forms part (see judgements of December 18, 2025, Storstockholms Lokaltrafik, C-422/24, ECLI:EU:C:2025:980, para.

§

31; February 13, 2025, Verbraucherzentrale Berlin, C-612/23, EU:C:2025:82, para. 31, and the case law cited therein). 110. According to Recital 24, monitoring or tracking occurs when the data subject is “tracked on the internet” (in English) or “suivies sur internet” (in French) and, in particular, when such tracking serves to make decisions concerning the data subject or, alternatively (the Recital uses the disjunctive “or”), to analyze or even predict: the data subject’s preferences, behaviors, and personal views. 111. These objectives may also be achieved through processing expressly defined in Recital 24 as “possible” and “subsequent” to Tracking that has already taken place, namely the use of profiling pursuant to Art 4(4) of the Regulation. It follows that profiling is not a sine qua non condition for the tracking of natural persons on the internet (and, therefore, of their monitoring or control) but rather a merely “potential” form of processing which, if present, certainly contributes to strengthening and making Tracking more efficient, as well as increasing the level of risk involved, but whose absence does not affect the ability to track the behavior of natural persons.

§

112. That “internet tracking,” as a form characteristic of the “monitoring” of data subjects’ behavior, is a distinct activity from profiling in a technical sense can also be inferred from a reading of Recital 30 of the Regulation and, consequently, from the legislation on tracking systems. 113. , cookies). ” In this sense, creating profiles does not mean engaging in profiling activities but rather compiling a “static” list of attributes relating to a natural person. This can be inferred from the provisions regarding cookies and other Tracking tools (among others, with reference to the Data Protection Authority, see: Guidelines on Cookies and Other Tracking Tools, June 10, 2021, web doc. no. 9677876; Guidelines on the Use of Tracking Pixels in Email Communications, April 17, 2026, web doc. no. 10241943). The operation of cookies and other tracking tools, such as pixels, allows for “tracking” a user’s activity but does not, instantly and concurrently with that same action, enable profiling—that is, carrying out evaluative and/or predictive activities regarding the individual.

§

Profiling is therefore a subsequent activity carried out using the information obtained from prior Tracking. 114. It follows that “internet Tracking,” which involves “monitoring the behavior of data subjects,” can certainly serve as a basis for a “subsequent” and “potential” profiling activity of the data subject but remains, in any case, a distinct processing operation that logically precedes profiling and is, in theory, also useful for other processing operations that do not involve profiling. As stated in the “Cookie Guidelines” of June 10, 2021: “Cookies can therefore perform important and diverse functions, including session tracking, storing information on specific configurations regarding Users accessing the server, facilitating the use of online content, etc. […]. ” 115. That the concepts of monitoring and profiling refer to ontologically autonomous and distinct activities can also be inferred, pursuant to Art.

§

01) and endorsed by the EDPB, in the section listing the criteria indicative of a high risk. ” Similarly, the Data Protection Authority, in Annex 1 to Decision No. 467 of October 11, 2018, web doc. No. 9058979, has also distinguished profiling from the observation, monitoring, or control of data subjects. Finally, one may cite Article 37(1)(c) of the GDPR, which considers “the regular and systematic monitoring of data subjects on a large scale”—and not profiling—as an activity that triggers the obligation to appoint a data protection officer. 116. Furthermore, in Guidelines 3/2018, the EDPB, while reiterating that “the monitoring of the behavior of data subjects located in the Union could therefore encompass a wide range of activities,” proposes a non-exhaustive list of processing operations that may constitute relevant monitoring within the meaning of Article 3(2)(b) of the Regulation.

§

Among these, the following are the ones that most closely resemble the processing carried out by the Company: geolocation, particularly for marketing purposes; and monitoring or regular reporting on an individual’s health status. On page 17, the EDPB then provides an example of monitoring that does not necessarily require profiling: “By processing the data subject’s location data to deliver targeted advertising based on that location, the processing activities also involve the monitoring of the behavior of natural persons in the Union. S. ” 117. It must therefore be concluded that, in order for the monitoring or Tracking of data subjects’ behavior to be covered, it is necessary to demonstrate the “Tracking” of natural persons on the internet; the presence of profiling relevant under Art. 4(4) of the Regulation or behavioral analysis is not required. 118. ” 119. In this specific case, the Company carries out various processing operations on the Contacts’ data: from collection to organization and combination with other information, up to the enrichment and constant updating of such data, which enable it to analyze the employment status (as a subcategory of a personal characteristic) of several hundred thousand individuals and/or to make a decision about whether to make the data available (or exclude it, as will be seen in the case of public officials) from its database.

§

Furthermore, based on the information available in the case file, it appears that the Company constantly updates—at least on a weekly basis—the unique “contact profiles” for each individual listed in the database. In doing so, even in the absence of profiling activity as defined in Art. 4(4) of the Regulation, the Company continues over time to “track online” the personal circumstances of the Contacts, supplementing its prior decision regarding the data subjects—resulting from the monitoring activity—with the additional purpose of analyzing changes in their personal and professional circumstances. 120. Therefore, contrary to the Company’s assertion, the Authority considers that monitoring the behavior of data subjects does not require profiling or behavioral analysis in the technical sense, but rather the collection of information—or traces thereof—relating to the behavior and personal circumstances of data subjects within the Union, in order to make decisions concerning them with regard to their employment.

§

All of these activities are carried out by Lusha through the creation and subsequent ongoing updating of “contact profiles” unique to each individual. 121. The fact that updating the employment status of Contacts is also carried out as a measure aimed at ensuring the accuracy of information in accordance with the principle of accuracy under Art. 5(1)(d) of GDPR, does not preclude the actual monitoring of the data subjects’ behavior. 122. The Authority therefore considers that, first and foremost, tracking a natural person’s position, job title, location, or other element related to their work activity for the purpose of evaluating their inclusion in a database (and, thus, determining whether or not to make their data available to third parties), as well as, subsequently, monitoring the presence, modification, or erasure of the aforementioned data relating to work activities in order to analyze any changes, on a continuous and constant basis over time, is consistent not only with the letter but also with the rationale of the monitoring criterion set forth in Art 3, para 2, subparagraph b), of the Regulation, and provides the basis for protecting natural persons under EU law on an equal footing worldwide for all enterprises operating in EU markets.

§

123. It must therefore be considered proven that the Regulation applies to the processing of Contact data carried out by the Company, in its capacity as controller, pursuant to Art 3, para 2, subparagraph b), of the Regulation. 3. Applicability of the Code 124. The applicability of the Regulation to the processing operations under investigation also entails the applicability of the Code. 3. Transparency Regarding the Legal Basis and the EU Representative 125. The principle of transparency under Article 5(1)(a) of the Regulation, as set forth in the information obligations referred to in Articles 12 et seq. of the same Regulation, requires the controller to provide data subjects— “in a concise, transparent, intelligible, and easily accessible form, using clear and plain language”—the information necessary to describe the processing operations. In particular, this information must include the identity and contact details of the data controller and, where the data controller is not established in the EU, of its representative, as well as the processing purposes and the relevant legal bases.

§

126. The Company argued that both the Privacy Notice and the Personal Data Policy, “when read correctly and in context,” made it possible to identify legitimate interest as the legal basis. 127. 1, legitimate interest is frequently cited as the legal basis. Nevertheless, no reference is made to data collection, which was, in fact, the subject of the Office’s objection. Furthermore, while acknowledging that the data collection operation may be considered implicit in subsequent processing activities, in the absence of a specific indication of data collection, supported by the relevant legal basis, the data subject is deprived of information essential to a proper understanding of the processing and is therefore unable to fully exercise the rights granted to them by law. Furthermore, specifying the data collection activity helps determine the source from which the data was obtained, including for the purpose of assessing the scope of application of Articles 13 or 14 of the Regulation.

§

128. With regard to the Privacy Notice, it should be noted at the outset that this document is not readily accessible on the Company’s website. The legal documentation is not present on the home page but is available only by clicking on the “Resources” menu item and then on “About” to open the relevant page, which contains several hyperlinks at the bottom (see also the screenshot provided by the Company, Exh. 6, defenses and observations). Among these, in the “Legal” column, there are links to certain documents such as the Terms and Conditions, the Privacy Notice, and the Cookie Policy, but not to the aforementioned Personal Data Policy (“Personal Information Policy”). Thus, while it takes at least three clicks to reach the Privacy Policy, it is not possible to access the Policy for personal data due to the absence of the corresponding link. The only easy way to access this latter document turned out to be through a search engine query—a process that necessarily requires prior knowledge of the document’s online existence.

§

The Office itself was aware of this document because the Company submitted it along with its defense arguments. That said, the much more concise context and the indication of the sources from which the data was collected make it possible to infer the legal basis for data collection, which is also stated here as legitimate interest. 129. As a result of the foregoing, the Company’s defenses may be considered to partially address the allegations raised, to the extent that information regarding the lawfulness of data collection is in any case available to the data subjects. However, the manner in which the information was provided overall does not appear to be in line with the criteria established by Art. 12(1) of the Regulation. Precisely the fact that the relevant information was not available on the home page, as well as the need to pay particular attention when reading multiple documents in English—and thus not in the language of the data subjects’ nationality—prevents the information provided from being characterized as concise, transparent, intelligible, simple, clear, or easily accessible.

§

130. With regard to the representative pursuant to Article 27 of the Regulation, the Authority takes note of the changed approach demonstrated by the Company. In its response to the Office’s request for information, the Company had argued that it was not required to appoint its own representative in the EU and that it had identified a mere contact point in Germany. Similarly, the Privacy Policy referred to that entity as a “contact point” in the EU. However, when exercising its right of defense, the Company asserted that it had appointed its own representative and that the Privacy Notice expressly referred to the status provided for in Art. 27 of the Regulation. 131. The Authority agrees with the Company’s most recent position in considering the designated contact point to be its representative in the Union. 132. In conclusion, the Authority orders the dismissal of the specific violation of Article 13(1)(a) and (c) of the Regulation but confirms the violation of Articles 5(1)(a); and 12 of the Regulation with regard to the principle of transparency and its corollaries.

§

4. Regarding Information Provided to Contacts 133. With regard to the report (file no. 459328) and the complaint (file no. 465278) received, the Authority took issue with the Company’s failure to provide any information to the relevant data subjects in their capacity as Contacts. 134. The Company claimed that it had sent the Personal Data Notice and provided a text file containing a string with various values, including the data subjects’ email addresses, and a “timestamp” as proof of the date the notice was sent. Although there were no mechanisms in place to guarantee the authenticity and non-repudiation of the file, and although the Company did not provide conclusive evidence regarding the direct origin of the text file from its information systems or its direct connection to the specifically requested compliance, the Authority does not have sufficient evidence to confirm the alleged violation.

§

Consequently, the allegation regarding the possible violation of the principle of fairness and transparency, as well as the obligation to provide information to data subjects, as set forth in Articles 5(1)(a) and 14 of the Regulation, is hereby dismissed. 5. On the Legal Basis for the Processing of Contacts’ Data 135. With regard to the Contacts, Lusha stated that it collects and processes only the name, email address, phone number, professional title, years of experience, role, and location in order to make this information available to its Clients and for anti-fraud purposes, based on its own legitimate interest and that of its Clients. ” 136. As a preliminary matter, we confirm what was already stated in our objection regarding the Legitimate Interest Assessment (“LIA”). This document, which consists entirely of the few lines comprising Section 5 of the impact assessment, contains no elements useful for supporting the Company’s decision to rely on legitimate interest as the legal basis for processing Contact data.

§

The LIA, as prepared in such a generic manner and with unsubstantiated assertions, merely states that the processing is necessary and proportionate. Furthermore, there is no assessment whatsoever regarding the balancing of interests with the rights of the data subjects. These shortcomings are such that the LIA must be considered entirely omitted, and not merely incomplete. 137. During the preliminary investigation, in support of its reliance on the legitimate interest, the Company cited the case law of the Court of Justice and that of other supervisory authorities, including the Italian Data Protection Authority. The Authority does not intend to disregard these precedents, which, on the contrary, contain elements useful for analyzing the specific case at hand, nor does it intend to deny the abstract possibility of relying on legitimate interest as a basis for lawfulness. However, the possibility of relying on this legal basis must be assessed on a case-by-case basis and must comply with the conditions set forth in Art.

§

6(1)(f) of the Regulation. 138. , C-252/21, EU:C:2023:537, para. 106, and the case law cited therein. In this regard, see also the “Guidelines 1/2024 on the processing of personal data based on Article 6(1)(f) of the GDPR,” ver. 3, also cited by the Company itself). The data controller must therefore demonstrate that it has satisfied three cumulative conditions, namely: that it has pursued a legitimate interest; processing only the data necessary to pursue that interest; and, finally, that the interests or fundamental rights and freedoms of the data subjects do not override the legitimate interest pursued by the controller (the so-called “balancing test”). Compliance with these conditions will be examined in the following subsections. 1. The Condition of Lawfulness of the Pursued Interest 139. The pursuit of specific interests by a data controller may be considered legitimate to the extent that it is not prohibited by law.

§

In other words, to be “legitimate,” the interest pursued must first and foremost be lawful. 140. With specific reference to direct marketing, although this is a fully lawful activity—constituting the exercise of freedom of enterprise and the right to economic initiative under Art. 41 of the Constitution—it remains a regulated activity under both national and European law. The general principles governing advertising require that it always be transparent and recognizable as such, as well as fair and not misleading. When such activity involves the processing of personal data, consumer protection regulations are supplemented by those governing the proper processing of personal data. In addition to the general provisions of the Regulation, Article 13 of Directive 2002/58/EC and Article 130 of the Code (which transposes it into Italian law) apply, requiring the prior consent of the contracting party or user for the sending of commercial communications.

§

, Articles 26(3) and 28(2) of EU Regulation 2022/2065). 141. Although the Office did not allege that the Company had violated Article 130 of the Code—since it is not the entity sending advertising material—the regulatory framework summarized above makes it clear that, with regard to direct marketing, both national and European legislation share the same underlying rationale: the need for an activity that is lawful but nonetheless potentially impactful on the freedom and autonomy of data subjects to be carried out under their control. 142. It should also be noted that, according to the Authority’s established case law, the disclosure of personal data to third parties for the purpose of conducting commercial and/or advertising activities in the interest of third parties must in any case be based from the outset on valid consent from the data subject, and it is the responsibility of those who create a contact database, drawing from various sources, to verify the lawful origin of the data and, therefore, to exercise effective control over the acquired lists to ascertain the possibility of lawfully transferring the contacts thus collected (among others, decision “Realmaps” of January 16, 2025, No.

§

11, web doc. No. 10110241. 3, web doc. No. 2542348). 143. Furthermore, as early as the “Guidelines on Promotional Activities and Combating Spam” of July 4, 2013, the Data Protection Authority had clarified that, in the absence of consent from the contracting party or User, promotional communications may not be sent, even if the data is derived from public records, directories, websites, or documents known or accessible to anyone. It follows that, whether data is collected directly from Users and/or data subjects or indirectly through scraping, the use of algorithms, or the purchase of data from third parties, the Company should have taken steps to obtain consent covering the purpose of disclosing data to third parties for their commercial purposes. 144. ” 145. ” 146. Conversely—with regard to the fulfillment of the first condition of the “three-part test” identified by the Court of Justice, as summarized in paragraph 138 of this decision—the Authority considers, in the present case, the processing of data for anti-fraud purposes to be, in principle, legitimate.

§

147. ” 148. The same considerations set forth above with regard to the Company’s interest can be applied to the pursuit of interests for the benefit of Lusha’s customers. 2. The Condition of Strict Necessity of the Processing 149. With regard to the second condition, concerning the necessity of the processing, it requires verifying that the pursuit of the interest cannot reasonably be achieved just as effectively by other means that are less detrimental to the fundamental rights of the data subjects, in particular the rights to respect for private life and to data protection guaranteed by Articles 7 and 8 of the Charter of Fundamental Rights of the EU. 150. , C-252/21, ECLI:EU:C:2023:537, paragraphs 108 and 109, and the case law cited therein. See also the EDPB’s “Guidelines 1/2024 on the processing of personal data based on Article 6(1)(f) of the GDPR,” dated October 8, 2024, paragraph 29).

§

Furthermore, based on Recital 47 of the GDPR, which refers to the “strict necessity” of the processing in relation to the interest pursued, according to the Court’s case law, the concept of necessity must be interpreted in a manner that fully reflects the objectives of data protection law. , C-252/21, ECLI:EU:C:2023:537, paras. 99, 102). 151. For the purpose of creating a unique “Company Contact Profile,” the Company stated that it needed to collect personal data such as name, email address, phone number, professional title, years of service, role, and location. 152. However, the documentation on file shows that the Company also collected other data from various sources: from its own customers as part of the Community Program or through integrations with other services, such as information related to “CRM databases”—including information from third parties—email headers and subject lines, information on scheduled meetings (meeting participants, meeting description, subject, date, and time of the meeting), as well as browsing data.

§

With regard to this information, there is no clear demonstration of a strict necessity in relation to the purpose of providing customers with a summary sheet of a person’s contact information. On the contrary, the collection of such information appears excessive and is not justified by the Company. The Company has not provided any basis for assessing the proportionality and necessity of collecting such data but has merely announced the termination of the Community Program in Italy. 153. Anticipating what will be discussed in greater detail below, the findings of the preliminary investigation also show that the Company collected data relating to public officials and other public office holders—including those in senior positions—in order to make such data available to customers for commercial purposes. It must be noted, however, that those working in the public administration do not pursue business purposes; therefore, there are no valid and lawful reasons—nor has the Company provided any evidence to that effect—why a business entity should obtain the data of individual officials for marketing or commercial purposes.

§

This applies all the more to senior officials in the public administration and/or constitutional bodies. Consequently, the Authority considers that the Company has not provided adequate justification for making information regarding individuals working in the public sector available to customers for a commercial purpose or for the pursuit of its own economic interests. On the contrary, in the summary table of risks associated with the processing, included at the end of the VIP, Lusha acknowledges that the processing of such data is unnecessary. 154. With regard to anti-fraud processing, the Company has stated that the interest in preventing fraud consists in protecting against identity theft and impersonation by providing Customers with validated and up-to-date information to verify and authenticate the consistency between the professional attributes declared by a natural person and those obtained by Lusha.

§

In other words, this interest is achieved by making information regarding a natural person available to the requester. This therefore constitutes a method that results in the definitive transfer of a set of personal data to a third party, as well as a volume of information that may even exceed what is necessary. 155. Conversely, with regard to the specific case at hand and limited to the circumstances under analysis here, the Authority considers that the pursuit of an anti-fraud interest could be achieved just as effectively by avoiding the permanent transfer of all available information relating to a particular individual. ). Therefore, rather than providing customers with all information about the individual, the customer could have been asked to enter the information in their possession so that the platform could verify (or not) whether there was a match with the person stated to be the subject of the search.

§

156. The Authority considers that—with regard to the fulfillment of the second condition of the “three-part test” identified by the Court of Justice, as referred to in para 138—in violation of the principle of data minimization set forth in Art 5(1)(c) of the Regulation, the Company collected data that was excessive and unnecessary for the purpose of making the data available to Customers. Consequently, the criterion of strict necessity of the processing for the pursuit of the legitimate interest is not considered to have been met. 157. In particular, the criterion of strict necessity of the processing is not satisfied even with regard to anti-fraud processing, insofar as the Company has not demonstrated that this interest could not reasonably be achieved just as effectively by means less detrimental to the fundamental data subject rights. 158. , C-252/21, ECLI:EU:C:2023:537, para. , C-597/19, EU:C:2021:492, paragraph 111, and the case law cited therein).

§

159. In this specific case, the Company pursues an economic interest in providing a service that is profitable for itself: providing access to Contact Data to enable Customers to reuse such data for their own commercial purposes or to prevent fraud. In this sense, the interest pursued for the benefit of Customers is also commercial in nature but dependent on the Company’s interest and available only within the limits and under the conditions imposed by the Company. Unlike in other cases, the Customers’ interest is not distinct or independent from that of the data controller and may therefore be considered subsumed within it. 160. Against this economic interest stands the fundamental right of the data subjects (the Contacts) not to be subjected to unjustified processing of their data beyond their control, the right not to suffer interference in their private lives, and the interest in not receiving commercial communications without prior consent or, in any case, being subjected to commercial practices that do not comply with the standards set forth by applicable regulations.

§

Given that some Contacts are also public officials or hold senior positions in the public administration, the interests of national security and the proper and impartial performance of public functions are also relevant. 161. As a general rule, the pursuit of an economic interest—even if, in the abstract, it is lawful and relevant—is not sufficient to justify a restriction on an individual’s fundamental rights, such as the right to data protection, as well as the other rights and interests mentioned, in the absence of specific conditions that make such a restriction reasonable. In this regard, the Company has not provided evidence of any weighing and balancing against the rights and interests of the Contacts but has merely inferred an individual’s interest in being contacted for a commercial purpose from the mere factual circumstance that the individual had created a profile on a digital platform with a more specific focus on the workplace and professional environment.

§

Consequently, and as previously stated in Opinion 6/2014 on the concept of legitimate interest, adopted on April 9, 2014, by the Art 29 Working Party, on page 31, if the interest pursued by the data controller is not “overriding,” it is more likely that the data subject’s interests and data subject rights will prevail over the data controller’s interest. 162. The Company has cited elements (such as the “credit”-based system that prevents the mass extraction of data from the database) that, rather than contributing to balancing the interests at stake in favor of the data controller, should be viewed as additional risk mitigation measures. 4, risk mitigation measures are not, in and of themselves, sufficient to allow the data controller’s or third parties’ interests to prevail over the data subject rights and interests; however, following a weighing of interests that has already been carried out, they may contribute to that end by strengthening the position of the data controller or third parties.

§

163. Given the absence of an effective balancing of the interests at stake, the Authority considers that Lusha failed to take into account relevant factors such as: the nature of the individuals involved (who are not always business owners but may also be public employees), the nature of the data processed (in particular, although contact details do not fall within special categories of personal data, they are nonetheless personal data that are generally confidential and not always made publicly available, especially when they expose direct contact information to others), the relationship between the parties involved, the reasonable expectations of the data subjects, and the legal and factual context in which the processing took place. 164. In particular, it is clear that no prior relationship exists between the Contacts and the Company. In the absence of a relationship between the parties involved in the processing, it seems possible—even in the abstract—to rule out the “reasonable expectation” regarding the processing referred to in Recital 47 of the Regulation.

§

165. It cannot be overlooked that the Court of Justice places particular emphasis on whether data subjects can reasonably expect such processing, as well as on the scope of the processing in question and its impact on the individual (in addition to the judgements already cited, see also the judgement of December 7, 2023, UF and AB v. Land Hessen, C‑26/22 and C‑64/22, ECLI:EU:C:2023:958, paragraph 80). The Court thus held that “the interests and fundamental rights of the data subject could, in particular, override the interest of the controller where personal data are processed in circumstances in which the data subjects cannot reasonably expect such processing” (Judgement of January 9, 2025, Mousse, C-394/23, ECLI:EU:C:2025:2, para. 50). 166. First, as also evidenced by the complaints and reports received by the Authority, the data subject may become aware of the existence of the processing and the availability of their data in a database not at the time they receive an initial marketing communication but only subsequently, that is, when they exercise their right of access under Article 15 of the Regulation and the sender informs them that they acquired the data on the Lusha platform.

§

167. Apart from these cases, which are based on the Authority’s experience, it is in any event inconceivable that the Contacts would have any expectation that their data present on digital platforms and other data held by third parties whom they cannot identify could be collected, processed, grouped into contact profiles, enriched with data from other sources, cross-referenced with other databases, and then constantly updated, for the purpose of making them available to an indefinite number of Customers. 168. Lusha appears to be well aware of this, at least when data is collected from sources other than the platforms to which the data subjects have subscribed. 14 state that: “In some cases, Lusha collects personal data from data subjects where they may not expect it. Lusha does not have an active relationship with data subjects, and the use cases for processing are not primarily for the benefit of the data subjects (rather, they are for the benefit of Lusha’s customers).

§

” 169. The Company decided to offset this lack of awareness and control on the part of data subjects by sending a privacy notice. Given that information and transparency requirements are general obligations applicable to all processing—and thus no particular diligence or exemplary compliance with the regulations can be attributed to the Company—the Company has prepared a Privacy Policy, published on its website, and a Personal Data Notice allegedly sent to each Contact. 170. 3, the Privacy Notice published on the website is entirely unsuitable for informing Contacts about the processing of their personal data. This policy could only become relevant after the Contact has been made aware, in some way, of the existence of the processing. 171. With regard to the Personal Data Notice, on the other hand, given that it must be understood as the necessary fulfillment of the obligation set forth in Art 14 of the Regulation rather than a mechanism to counterbalance the data subjects’ inability to foresee further processing of their data, the following issues are noted.

§

Lusha’s decision not to collect personal data—particularly contact information—directly from data subjects means that the Privacy Notice may be sent to an email address that the data subject may not check regularly, no longer use, or does not expect to receive important communications at. In any case, basic information security rules have long advised users not to interact with emails from unknown recipients. This is all the more true if such emails prompt the data subject to click on a link or perform a certain action; it is reasonable to assume that the data subject may view such a communication as a scam attempt and, therefore, choose to ignore it. 172. It should also be noted that Lusha cannot be certain that the contact information in its possession is accurate, since it relies solely on the fact that the same piece of data is cited at least twice in multiple sources. Such a frequency, slightly above one, may be the result of mere coincidence and does not provide adequate assurance of fairness.

§

Conversely, adopting a policy aimed at seeking a higher frequency in the identification of contact information could have avoided the risk of collecting and considering as reliable data that is obsolete and no longer in use by the data subject. This appears to be a limitation of the Data Controller’s business model, resulting from the decision not to collect data directly from data subjects, which falls within the risk that the Data Controller assumes and that should have been the subject of a specific analysis in the VIP. 173. Another factor that compromises the rights and interests of the Contacts—and which the Company has not adequately considered—is the data storage period established by the Company. 5) and in the Personal Data Policy under review (updated as of January 2023), Lusha states that it processes personal data for as long as necessary, unless the data subject updates their information or objects.

§

The specification of this retention period in a context where the Contact may remain unaware of the ongoing processing for a long time is a factor that accentuates the data subject’s dependence on the controller and which, therefore, does not allow for a balance to be struck in which the interests of the data controller or third parties prevail over the interests and rights of the data subjects. 174. The Company also identifies certain benefits and opportunities that Contacts may derive from the processing: for example, the possibility of being contacted by recruiters and receiving professional communications relevant to their interests. Given that even these circumstances are merely alleged by the Company but not demonstrated or supported in any way, it must be noted that these examples constitute, if anything, the very reasons why individuals sign up for job-oriented platforms. Thus, in the absence of any other concrete element or circumstance—which is currently not available in the record— these elements can only be used to infer the individual’s interest in registering on a platform and not also a reasonable expectation of receiving job offers or commercial communications outside the platform itself and within a context of processing that is beyond the individual’s control.

§

In addition to the fact that, in general, the presence of data online or on a digital platform does not automatically entail or always authorize third parties to reuse such data for purposes beyond those that led to its publication, it should be noted that contact information such as email addresses and, even less frequently, phone numbers, are accessible on platforms such as LinkedIn. In such cases, the Company has stated that it collects and supplements the missing data by obtaining it from other sources. Certainly in these cases—as the Company is also aware, having addressed the issue in the VIP—the data subject cannot reasonably foresee that their data will be subject to the processing in question. On the contrary, it is more likely to infer that the data subject has no interest in or is averse to receiving commercial communications, given that they have taken steps to ensure their contact information is not available on the platform.

§

176. Another significant factor is therefore the particular scope of data collection, in that Lusha does not limit itself to collecting data available on the LinkedIn or Salesforce platforms but supplements missing data through various sources, many of which are unknown to the Contacts and, therefore, beyond their control. com). These are all circumstances regarding which Contacts not only have no knowledge or expectation but also no real control or ability to stop the indiscriminate circulation of their personal data. 177. Furthermore, it must be noted that, with regard to the Contacts’ data extracted from Customers’ emails, we are faced with a disclosure of third party personal data by the Customers to the Company that appears to lack legality and is such as to render the disclosure unlawful (which may potentially give rise to independent accountability on the part of the Customers in other legal proceedings).

§

This is all the more true when one considers that communications between private individuals may be subject to specific protection under Art. 15 of the Constitution of the Italian Republic. 178. Furthermore, the facts and findings of the preliminary investigation refute the claim that the Company merely collected “publicly available” data online, insofar as it has been established that information such as email addresses and phone numbers—which are generally not publicly available—was supplemented and collected from other sources unknown to the data subjects. 179. The enormous volume of data collected by Lusha—from a wide variety of sources, particularly third parties—for the purpose of pursuing an economic interest, and in the absence of information sufficient to inform the data subjects, makes it unlikely, on the one hand, that such processing falls within the expectations of the data subjects (more precisely, the Contacts) and, on the other hand, is likely to have significant impacts on them, making them contactable by third parties for unforeseeable purposes (or at least outside the channels made available by the platform through which the data subject shared their data) and giving rise, when the data subjects become aware of the processing of their data, to a feeling of continuous monitoring and surveillance.

§

Therefore, with greater certainty, legitimate interest cannot be considered the appropriate legal basis for the collection of Contacts’ data from the Company’s Customers or from other sources not under the control of the data subjects. 180. This conclusion would also apply to the collection of data from partners or entities belonging to the Company’s group, which, from the outset, with regard to their processing, should be based on an adequate legal basis that legitimizes the disclosure of the data to Lusha (see Art. 130 of the Code). 181. ” In addition, the collection of data online (scraping) rather than directly from the data subjects affects the data subjects’ reasonable expectations (paragraph 94). 182. It is thus established that the processing of personal data has taken place which, although not falling within the special categories of personal data, is likely to expose the data subjects’ private lives to third parties; it has also been established that the Contacts were subject to the processing of their personal data in the absence of any prior relationship with the Company and without being able to reasonably expect that, without their consent, the Company would process their data to make it available to third parties.

§

All of this has had an unjustified impact on the legal rights of the Contacts. In addition to the annoyance of receiving unsolicited communications, as also documented by the reports and complaints received by the Authority, the possibility of Surveillance of their personal and professional lives cannot be ruled out, nor can the inability to control information pertaining to them and the infringement of the Contacts’ right not to be subjected to covert processing and/or interference with their confidentiality for the pursuit of the Company’s economic interest. 4. Measures to Mitigate the Impacts of Processing 183. If the outcome of the balancing test does not demonstrate that the interest pursued can prevail over the interests, the data subject rights and freedoms, the controller may still consider implementing mitigation or attenuation measures in order to create more favorable conditions for the data subject and thereby achieve a rebalancing of interests.

§

184. , and, even earlier, in the Art 29 Working Party’s “Opinion 6/2014 on the concept of legitimate interest,” dated April 9, 2014, p. , which referred to “additional safeguards”) specify, in para 57, that these mitigation measures must not be confused with the general obligations that the controller is required to adopt to ensure compliance with the GDPR regardless of the lawfulness basis adopted. In this sense, mitigation measures are safeguards that go beyond those required by the Regulation. 185. The Company has established certain mechanisms that can be equated with mitigation measures, namely: the adoption of a “credit”-based system that Customers must purchase to access data, in order to prevent the mass extraction of data from the database via free-text search; and, without prejudice to the right to object to processing at any time, the adoption of a voluntary seven-day cooling-off period for the data subject to opt out, in order to prevent the addition of data to the database from the outset.

§

186. With regard to the credit system that allows access only to a predetermined number of contact records rather than the entire database, even if this may be considered a good measure, the protection actually afforded to data subjects is, in practice, of little significance because it is contingent upon the financial means of the customers. In other words, nothing prevents customers from purchasing the credits necessary to obtain the amount of contact data they deem sufficient for their purposes—and, theoretically, all available data. Consequently, the level of protection that this measure affords data subjects is such that it does not result in a significant shift in the balance of the interests involved. 187. With regard to the voluntary cooling-off period granted to contacts, it should be noted that the opt-out is a right derived from the right to object that Art. 21 of the Regulation mandates in all cases where processing is based on the legal grounds set forth in Art.

§

6(1), subparagraphs (e) or (f) of the GDPR, granting the data subject 7 or 14 days to express their wish not to be included in the database cannot be considered an adequate safeguard due to certain factual elements that the Company has not adequately weighed. 188. As already noted, in fact, the Company sends the Privacy Notice to an email address that it cannot be certain is used or monitored by the data subject. When such an address is collected from other sources or otherwise reconstructed based on available information, it cannot be ruled out that the email address is not consistently monitored by the data subject. In any case, the data subject may not consider the communication to be reliable. Furthermore, even if the data subject does consider the communication to be reliable, 7 or 14 days may still not be sufficient—especially in the absence of additional reminders or notifications of the impending deadline— to: adequately research the Company’s identity, learn about the characteristics of the services offered, understand the consequences of the processing, as well as assess potential benefits, and, if necessary, express their objection.

§

Consequently, the Authority considers that a reflection period of 7 or 14 days—given the specific manner in which the processing was carried out—is excessively short and disproportionate to the scope of the processing and the potential impacts on the legal rights of the Contacts. 189. In conclusion, the Authority considers that the measures adopted by the Company to mitigate the impacts of the processing are not sufficient to warrant a reassessment of the balancing of interests in favor of the controller. 5. On the Specific Inadequacy of the Lawfulness Basis 190. In light of the foregoing, considering the context, the characteristics, and the manner in which the Company has, in practice, processed the personal data of the Contacts, as well as the nature of the rights and interests involved, the reliance on the lawfulness basis set forth in Art. Article 6, para 1, subparagraph (f) of the Regulation cannot be considered adequate.

§

This is because, to summarize the above: - making Contact data available for the pursuit of the economic interests of the Company and its Customers cannot be considered a “legitimate” interest within the meaning of Article 6(1)(f) GDPR, insofar as the law requires the prior consent of the contracting party or user as the legal basis for the transfer of personal data to third parties for independent commercial purposes; - The Company collects a vast amount of personal data from multiple sources, including some that cannot be considered public insofar as they are extracted from its Customers’ private interpersonal communications, or through integration with IT systems, or acquired from third parties. ” Furthermore, the Company collects data on public officials and individuals holding institutional roles who, as such, do not act to pursue independent professional interests and, therefore, are not necessary for the pursuit of the Company’s and its Customers’ interests.

§

However, with regard to the interest in preventing or avoiding fraud, the Company has not demonstrated that it cannot achieve the same interest through less intrusive processing methods; - given the nature of the interests and rights being balanced, the absence of any relationship between the Company and the Contacts, the fact that it cannot be argued that the data subjects could have had reasonable expectations of being subject to the processing described, as well as the limited effectiveness of the measures to mitigate the impacts of the processing, it has not been demonstrated that the pursuit of the data controller’s or third parties’ interests outweighs the interests or fundamental rights and freedoms of the data subjects. 191. Ultimately, the service offered by the Company—in this specific case, in a manner that does not comply with the law—mirrors that already offered by other digital service providers, with the difference that the latter base their activities on the processing of data provided directly by the data subjects and grant them greater control over their own data.

§

Only with regard to such digital service providers is it plausible to argue that data subjects aim to establish business relationships and/or may expect to receive job offers through the channels and in the manner made available by the platform, or to use the platform itself to verify the information in their possession for anti-fraud purposes. 192. The Authority therefore confirms and establishes a violation of Article 5(1)(c) of the Regulation with regard to the principle of data minimization, as well as a violation of Articles 5(1)(a) and 6 of the Regulation to the extent that, in violation of the principles of lawfulness, fairness, and transparency, the basis of lawfulness referred to in Art. 6(1)(f) of the Regulation cannot be considered, in this specific case, an adequate legal basis. 193. Finally, the Authority has decided to dismiss the alleged violation of Article 7 of the Regulation and Article 129 of the Code.

§

6. Processing of Data Relating to Public Figures and Compliance with the Principles of Data Protection by Design and by Default 194. With regard to the collection of data on public figures, the Company acknowledged and justified the collection due to a technical shortcoming in the exclusion algorithm, which was unable to filter out particularly specific job titles. 195. The Company has, however, justified the processing on the basis of: the absence of a specific obligation under the Regulation to adopt measures preventing the collection of data on public figures; as well as the necessity of processing such data. According to the Company, all of this must take into account the fact that public figures have a lower expectation of confidentiality than other data subjects. 196. First, it should be clarified that no individual is, in general and in the abstract, subject to a limitation of the rights to respect for private and family life and to data protection set forth in Articles 7 and 8 of the Charter of Fundamental Rights of the EU.

§

If anything, pursuant to Article 52 of the same Charter, the Regulation allows, on a case-by-case basis, for the right to data protection to be restricted to the extent that such restriction is proportionate to the purpose of achieving objectives of general interest or other rights. 197. In this context, the case law and guidelines cited by the Company all refer to the so-called “right to be forgotten,” as established beginning with the Court of Justice’s first judgement of May 13, 2014, Costeja, C-131/12. It is abundantly clear that this reference is not appropriate to the case under consideration here, insofar as, in the context of applying the right to be forgotten, the notoriety or public relevance of the individual involved in the publication and/or republication of information and facts pertaining to them is only one of the elements in the balancing of multiple fundamental rights: the individual’s right to confidentiality and/or data protection of personal data, on the one hand, and the right to report news and the public interest in being informed about events of particular significance and current relevance, on the other.

§

Furthermore, the possibility of providing for exemptions or exceptions to personal data protection rules to “reconcile” this right with the right to freedom of expression and information is expressly provided for in Art. 85 of the Regulation. Therefore, only when rights of equal standing to the data protection are present—and, in particular, only if the right to report news is exercised in compliance with sector-specific regulations and within the limits defined by constitutional and supreme court case law—may the confidentiality of an individual be restricted to the extent and for the duration necessary to satisfy the public interest. 198. None of the conditions specific to the right to be forgotten apply to the case under review. Furthermore, no public or legally relevant interest in accessing the contact information of public officials for the purposes described above has been identified or demonstrated by the Company.

§

199. Given that the Authority does not agree with the argument that only a small number of profiles of public figures were available in the Lusha database, the economic interest pursued by the Company negates the need to collect and make available to Customers information on such individuals, who, by their very nature, do not pursue independent business interests. Therefore, in the absence of any other justification for the collection of such data—which, in any case, was not provided by the Company—the Authority reiterates that the collection of such data is not necessary to pursue the Company’s own business purposes or those of its customers. 200. ). 201. , filters, domain blocking, and periodic checks) should be considered measures voluntarily adopted as a matter of prudence and in the absence of a specific obligation under the Regulation. Given that the GDPR is a “general” regulatory act—and thus could not have imposed specific prohibitions on processing or particular security obligations—the lack of necessity for processing data from public entities stems precisely from the purpose pursued by the controller and the methods identified by the controller.

§

We are therefore not dealing with a “voluntary guarantee” or a “broken promise” on the part of the data controller, but rather with measures that Lusha adopted—albeit in an ineffective manner—based on the obligations arising from the principles known to it: those set forth in the combined provisions of Articles 5(1)(c), 24, 25, and 32 of the Regulation. 202. The investigation conducted and the documentation on file show that, although the Company clearly defined the risk of collecting data from public figures, it did not equip itself with effective tools to exclude such information. This demonstrated the absence of technical and organizational measures aimed at implementing the principles of personal data protection set forth in Article 25 of the Regulation (data protection by design and by default). 203. The Authority confirms and establishes the violation of the aforementioned principles and, therefore, of the provisions set forth in Articles 5(1)(c) and 25 of the Regulation.

§

5. CONCLUSIONS 204. In light of the assessments set forth above, the allegations raised in the notice initiating the proceedings pursuant to Art 166 of the Code are partially confirmed, since the statements made during the preliminary investigation and the defenses raised were not sufficient to fully rebut the findings made by the Office; furthermore, none of the cases provided for in Art. 11 of the Data Protection Authority’s Regulation No. 1/2019 apply. 205. Such conduct is attributable to the Data Controller, at least on the grounds of negligence, to the extent that it has been demonstrated—and in some cases documented in the VIP—that Lusha was aware of the relevant regulations (to the point of applying them spontaneously) as well as the risks associated with its processing activities. Despite its knowledge of the regulations, the Company only formally—and in any case, in a deficient manner—balanced its economic interests against the data subject rights, and failed to adequately apply the rules and principles designed to safeguard the data subject rights and control.

§

Therefore, the Authority considers that the Company could well have avoided the errors it committed by exercising due diligence. In this regard, according to case law, the good faith referred to in Article 3 of Law No. 689/1981 serves as a ground for exclusion of administrative accountability only if it is established that the offender did everything possible to comply with the legal requirement, such that no blame can be attributed to them. In this regard, see Civil Cassation, Section II, November 29, 2023, No. 33121, which holds that simple negligence is sufficient to establish the subjective element of the offense, whereas an error regarding the lawfulness of the conduct (“good faith”) may serve to exclude administrative accountability only when it is unavoidable; for this purpose, a positive factor—external to the offender—must exist that is capable of leading the offender to believe in the aforementioned lawfulness, in addition to the condition that the perpetrator has done everything possible to comply with the law and that no blame can be attributed to him, such that the error was blameless—that is, not preventable through ordinary diligence (see, among others, Civil Cassation, Section II, June 11, 2007, No.

§

13610). 206. Therefore, the Authority finds that the conduct of the Data Controller regarding the processing of Contact data was unlawful, in violation of the following provisions: a) Article 5(1)(a) and (c); and Article 6 of the Regulation, for having carried out processing in violation of the principles of lawfulness, fairness, and transparency, as well as data minimisation, and for having based the processing on an inadequate legal basis. Since such processing, which is still ongoing, must be considered to have been carried out from the outset without a valid basis of lawfulness, it is necessary to prohibit the processing of personal data of Contacts located in Italian territory and, consequently, to order the erasure of the data of Contacts located in Italian territory. It is also necessary to impose a monetary penalty under the terms set forth below; b) Articles 5(1)(a) and 12 of the Regulation, with reference to the violation of the principle of transparency and its corollaries, as described above.

§

For this violation as well, it is necessary to impose a financial penalty under the terms set forth below; c) Articles 5(1)(c) and 25 of the Regulation, as the Data Controller failed to implement adequate technical and organizational measures to prevent the collection of data from public entities. Since the Data Controller has stated that it has deleted such data and ceased processing it, it is not necessary to impose a corrective measure, but only a monetary penalty under the terms set forth below. 207. The Authority, however, orders the dismissal of the alleged violations referred to in Articles 7; 13(1)(a) and (c); and 14 of the Regulation and Article 129 of the Code. 6. INJUNCTION ORDER 208. Pursuant to Article 58(2)(i) of the Regulation and Article 166 of the Code, the Data Protection Authority has the power to impose an administrative fine pursuant to Article 83 of the Regulation by issuing an injunction order.

§

” 209. Given that the violation of the aforementioned provisions occurred as a result of a single act—that is, in relation to the same processing operation or interconnected processing operations—Art 83, para 3, of the Regulation applies, pursuant to which the total amount of the administrative fine shall not exceed the amount specified for the most serious violation. Given that, in the present case, the most serious violations are subject to the penalty provided for in Article 83, para 5, of the Regulation, the amount of the administrative fine shall be set at a maximum of 20,000,000 euros or, for enterprises, up to 4% of the total worldwide annual turnover of the preceding fiscal year, whichever is higher. 210. To determine the maximum amount of the fine, reference must be made to the enterprise’s turnover, as defined in Articles 101 and 102 of the TFEU, as clarified in Recital 150 of the Regulation.

§

Since the documentation on file shows that Lusha Systems Inc. is wholly owned by Lusha Systems Ltd. (the latter is also expressly designated as a joint controller in the “Privacy Notice on the Processing of Personal Data” updated in May 2026), the turnover indicated in the consolidated financial statements of Lusha Systems Ltd. 2). Consequently, the maximum statutory fine in the present case is set at 20,000,000 euros. 211. The amount of the administrative fine must be determined based on the circumstances of each individual case, taking due account of the factors set forth in Article 83(2) of the Regulation: - the gravity of the violations (Articles 83(2)(a) and 83(para) of the GDPR), taking into account the subject matter and purposes of the processing, which are attributable to commercial activities; the fact that the violations concerned failure to comply with the basic principles of the relevant legislation; such as determining the lawfulness of the processing, as well as the high number of Italian contacts or data subjects involved in the unlawful processing (in the order of XX) and the fact that the unlawful collection of data is structural in nature rather than isolated; - as an aggravating factor, the negligent nature of the Data Controller’s conduct (Art.

§

83(2)(b) of the GDPR); - as a mitigating factor, the fact that the Data Controller has not previously been a recipient of a corrective or punitive measure by the Data Protection Authority (Art. 83(2)(e) of the GDPR); - the fact that the processing did not involve special categories of personal data or data relating to criminal convictions and offenses (Article 83(2)(g) of the GDPR); - as a further mitigating factor, the cooperation demonstrated with the supervisory authority to remedy the breach and limit its potential negative effects, as well as the general cooperation during the investigation, as evidenced by the Company’s active participation in the proceedings, including through the appointment of an Italian law firm (Art. 83(2)(f) of the GDPR); - adherence to certification mechanisms (Art. 83(2)(j) of the GDPR); - as a further mitigating factor, the data on revenue and the degree of competition in the relevant market (Art.

§

83(2)(k) of the GDPR). 212. Based on the totality of the factors set forth above and the principles of effectiveness, proportionality, and deterrence provided for in Art. 00 (two million/00), equal to 10% of the maximum penalty. 2. Additional Sanction 213. In the case at hand, it is deemed that the ancillary sanction of publishing this injunction order on the Data Protection Authority’s website, as provided for in Article 166, paragraph 7, of the Code and Article 16 of the Data Protection Authority’s Regulation No. 1/2019, should also be applied, given the particular gravity of the violations and the particularly reprehensible nature of the conduct, as well as—and above all—the fact that the processing carried out by the Company, particularly as a result of the methods used to collect Contact data, is likely to have effects and repercussions on subsequent processing of personal data carried out by its Clients.

§

NOW THEREFORE, THE DATA PROTECTION AUTHORITY 214. , represented by its pro tempore legal representative, with registered office in Boston, MA 02199, USA, in its capacity as controller, for violating Articles 5(1)(a) and (c); 6; 12; and 25 of the Regulation, as set forth in the reasoning below, and: a) pursuant to Article 58(2)(f) of the Regulation, prohibits any further processing of the data of data subjects located in Italian territory that was collected without an adequate legal basis; b) pursuant to Article 58(2)(g) of the Regulation, orders the erasure of the data of data subjects located in Italian territory that were collected without an adequate legal basis; c) pursuant to Article 58(1)(a) of the Regulation and Article 157 of the Code, requires the company to notify the Authority, within 60 days of the notification of this order, confirmation of compliance with the measures imposed in subparagraphs (a) and (b) above.

§

ORDERS 215. 00 (two million/00) euros as an administrative fine for the violations set forth in the grounds. ORDERS 216. 00 euros (two million/00), in accordance with the procedures set forth in the annex, within 30 days of the service of this order, failing which the necessary enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. 217. It is hereby noted that, pursuant to Article 166, paragraph 8, of the Code, within the time limit set forth in Article 10, paragraph 3, of Legislative Decree No. 150 of 2011 for filing an appeal, the offender may settle the dispute by: a) by complying with the Data Protection Authority’s requirements; b) by paying an amount equal to half of the imposed penalty. IT IS HEREBY ORDERED 218. the publication of this order, pursuant to Articles 154-bis, paragraph 3, of the Code and Article 37 of the Data Protection Authority’s Regulation No.

§

1/2019, as well as the imposition of the ancillary penalty of publishing the injunction order on the Data Protection Authority’s website, as provided for in Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No. 1/2019; 219. and, pursuant to Article 17 of the Data Protection Authority’s Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58(2) of the Regulation in the Authority’s internal register provided for in Article 57(1)(u) of the Regulation. 220. Pursuant to Article 78 of the Regulation, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this decision may be filed with the ordinary courts, by filing an appeal with the ordinary court of the jurisdiction specified in the same Art 10, under penalty of inadmissibility, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad.

§

Rome, July 14, 2026 THE PRESIDENT Stanzione THE RAPPORTEUR Stanzione THE SECRETARY GENERAL Montuori [Web Doc. No. 10275035] Decision of July 14, 2026 Register of Decisions No. 542 of July 14, 2026 THE DATA PROTECTION AUTHORITY AT today’s meeting, attended by Prof. Pasquale Stanzione, Chair; Prof. Ginevra Cerrina Feroni, Vice Chair; Dr. Agostino Ghiglia, Member; and Dr. Luigi Montuori, Secretary General; HAVING REGARD TO Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter the “Regulation” or “GDPR”); HAVING REGARD TO the Code on Data Protection (Legislative Decree No. 196 of June 30, 2003, hereinafter the “Code”); HAVING REGARD TO the documentation on file; HAVING REGARD TO the observations submitted by the Secretary General pursuant to Article 15 of the Data Protection Authority’s Regulation No.

§

1/2000, adopted by resolution of June 28, 2000; RAPPORTEUR: Prof. Pasquale Stanzione; 1. 1. Origin of the investigation 1. In light of several news articles reporting that the telephone numbers of the most senior officials of the Italian Republic were present on the Lusha platform, in April 2025 the Office initiated a preliminary investigation into the company Lusha Systems Inc. (hereinafter “Lusha,” the “Company,” or the “Data Controller”), represented by its pro tempore legal representative, with registered office in Boston, MA 02199, USA, a wholly-owned subsidiary of Lusha Systems Ltd. 2. Subsequently, the Data Protection Authority received a complaint and a report from data subjects who, after receiving unsolicited advertising messages and calls from third-party companies and upon requesting clarification regarding the source of their contact information, discovered that their data was available on the Lusha platform without their consent to such processing.

§

2. The Authority’s Request for Information and the Company’s Response 3. On April 7, 2025 (Ref. No. 47069 of the same date), the Office issued a request for information to Lusha and another company, headquartered in Germany, which Lusha had designated as its EU contact point, a request for information pursuant to Article 157 of the Code, asking them to provide details on the number of Italian data subjects in their database (hereinafter also referred to as the “B2B database”), the sources from which the data was obtained, and information on the processing operations carried out. The Data Protection Impact Assessment (DPIA) and the Legitimate Interest Assessment (LIA) were also requested. 4. The Company submitted its response on May 29, 2025 (Ref. No. 78434 of May 30, 2025), after obtaining an extension until May 30, 2025 (Ref. No. 53505 of April 17, 2025). 5. The Company first stated that it did not consider itself subject to the Regulation or the Code, as it does not have an establishment in the EU; therefore, the additional criteria set forth in Article 3(2) of the Regulation would not apply.

§

It also declared that it was not required to appoint a representative. The Company designated a contact point in Germany solely to be easily accessible to individuals and authorities in the EU and the United Kingdom; furthermore, although not required to do so, it voluntarily applied the provisions of the Regulation to comply with international and European standards. 6. The Company has also stated the following: - According to its own nomenclature, “Customers” (or “Clienti”) are defined as Users who have registered for the service and can access the data contained in the B2B contact database. In contrast, there are “Contacts,” meaning those whose data is collected and made available in the database regardless of whether or not they are also Customers of the Company; - that it acts as the data controller for: the processing of data related to visits to its website; the collection and processing of data related to joining the Lusha group, the Facebook fan page, or the LinkedIn page; the collection and processing of data related to company profiles whose data is accessible via the platform; - to process information relating to approximately XX Italian data subjects, including individuals who do not use the platform (Contacts), who would, however, be informed via the sending of a specific privacy notice containing the provisions of Art.

§

, phone number, email, location, or occupation); - to exclude from the database the data of Contacts who hold public office or who are otherwise considered public figures; - to limit data collection to: names, email addresses, and phone numbers, as well as a Contact’s professional title, tenure, role, and location; - to ensure the accuracy and correctness of the data by verifying multiple sources, cross-checking data, and updating the data weekly, which entails erasure or correction of data deemed inaccurate. 7. With regard to the sources of personal data collection, the Company has identified the following: publicly available information on the Internet, such as public social media profiles, as well as from professional blogs and forums; entities specializing in the provision of information from which Lusha purchases or licenses data; from its own “Community Program,” which involves the collection of data from Program members to the extent that they consent to sharing information; and through an email generation algorithm.

§

8. Finally, with regard to the legal bases, Lusha conducted a Legitimate Interest Assessment (LIA) within the VIP, concluding that the processing of Contact data and the related communication to Customers meets the requirements of legitimate interest. 2. INITIATION OF PROCEEDINGS FOR THE ADOPTION OF CORRECTIVE AND SANCTIONARY MEASURES 9. Based on the evidence gathered during the activities described above, by notice dated August 6, 2025 (Ref. No. 109501), served pursuant to Article 166, paragraph 5, of the Code, the Office initiated proceedings for the adoption of the measures referred to in Article 58(2) of the Regulation against the Company as the controller. 10. Having noted the Company’s lack of an establishment in the Union and given that the collection and processing of personal data of European citizens was undisputed, the Office considered that Lusha also offered its service to natural persons established in the EU.

§

11. Since it could not be ruled out that the individuals accessing the platform are also, and above all, natural persons whose data are thus subject to processing and, therefore, are to be considered “data subjects,” the Office concluded that Lusha offered its services to European data subjects and met the criterion set forth in Article 3(2)(a) of the Regulation. 12. The documentation on file also showed that the Company did not merely collect contact data from multiple sources but reorganized it into a “Company Contact Profile” that was unique and identifiable, in order to make the data contained in the database easily retrievable using various filters; furthermore, it enriched the data to ensure its completeness and constantly updated it to provide up-to-date information. In particular, both the data enrichment and updating activities (for example, to verify whether the person still held a certain job position or had changed positions or workplaces), including through “cross-checks,” appeared to involve monitoring the Contact’s job position over time to the extent that it constituted monitoring of their conduct.

§

13. The Office therefore concluded that the Company was monitoring the work-related behavior of the Contacts—a practice necessary to assess the personal/work-related positions held by them over time—which could constitute monitoring of the data subjects’ behavior pursuant to Art 3, para 2, subparagraph (b) of the Regulation. 2. Compliance with the Principles of Lawfulness and Data Minimisation 14. ) and, for most of the purposes pursued, states that it processes such data to pursue its legitimate interest. The Office has limited its investigation to the processing of “Contacts” data. 15. With regard to Contacts, Lusha has stated that it processes the data typically contained on business cards or in the “signature block” of emails: name, professional title, role, years of experience, email address, phone number, and the country where the individual works. 16. Nevertheless, additional data is collected through other channels such as: - the “Community Program”: community members share data from their professional corporate network, such as email headers and signature blocks, client names, company names, professional titles, work phone numbers, and email addresses.

§

com); - corporate social media profiles when a User uses the Lusha browser extension while on LinkedIn. 17. The “Privacy Notice” published online did not identify a specific legal basis for the collection of Contact data but referred to legitimate interest as the legal basis for ensuring the lawfulness of allowing Customers to access the database, and thus, technically, to allow the disclosure of Contact data to Customers. Only in the VIP (§5) sent in response to the Office’s request for information was it clarified that the legal basis for the collection of Contact data was legitimate interest. 18. The enormous volume of data collected—from diverse sources and third parties—for the purpose of carrying out processing that, on the one hand, is difficult for data subjects to foresee or expect and, on the other hand, is likely to have significant impacts on them—making them contactable by third parties for unforeseeable purposes—raised doubts about the adequacy of the legitimate interest as a legal basis.

§

19. In addition, Article 129 of the Code requires the consent of contracting parties for the inclusion of their data in paper or electronic directories available to the public and for the use of such data for the purposes of sending advertising or direct sales material or for conducting market research or commercial communication; and Article 130 of the Code, in summary, requires the consent of Users and contracting parties for the sending of advertising or direct sales material or for the conduct of market research or commercial communications. 20. In the case of particularly extensive and intrusive processing based on a vast amount of data—and likely to have a significant impact on unsuspecting data subjects—the Office took issue with the Company for failing to justify in any way the use of legitimate interest as a legal basis or to demonstrate the lawful origin of the data. 21. Finally, with regard to information and the right to object, the Office noted that allowing data subjects such a short period to exercise their right to opt out (7 days from the date the notice was sent via email) created the risk that the data subject might fail to object due to circumstances beyond their control.

§

22. ” 23. With regard to the data contained in the calendars of Community Program members, meeting titles, participants and their email addresses, as well as email account data, the Office found that this information was unnecessary. Such collection was therefore, in theory, capable of constituting a violation of the principle of data minimization referred to in Article 5(1)(c) of the Regulation. In light of the foregoing, the Office found that, with regard to the collection and processing of Contact data, the Company had not identified any valid legal basis for lawfulness, since, under the circumstances and in the manner described above, reliance on legitimate interest did not appear to constitute an adequate legal basis for lawfulness. This constitutes a possible violation of the principles of lawfulness and fairness set forth in Article 5(1)(a) and (c) of the Regulation, as well as Articles 6 and 7 of the Regulation.

§

These violations were compounded by a violation of Article 129 of the Code. 3. Compliance with the Principles of Transparency 25. The privacy notice published on the Company’s website, which at the time of the investigation was last updated on February 5, 2025, did not clarify the lawfulness of the collection of Contact data or who the Company’s representative in the EU was. These omissions were, in theory, capable of violating the principles of fairness and transparency, as well as the requirement to provide adequate information to data subjects, as set forth in Articles 5(1)(a); 12; and 13(para 1)(a) and (c) of the Regulation. 4. Information to the Applicants 26. Although the Company stated that it provided the privacy notice to all Contacts, the Authority received reports and complaints (in particular, case files nos. 459328 and 465278, made available to the Company and resolved, respectively, by decisions nos.

§

349 (web doc. No. 10262105) and 350 (web doc. No. 10262367) of May 14, 2026), in which the collection and processing of data by Lusha without any notification to the relevant individuals was complained of. This omission, too, was theoretically capable of constituting a possible violation of the principles of fairness and transparency, as well as the obligation to provide adequate information to data subjects, as set forth in Articles 5(1)(a) and 14 of the Regulation. 5. Data Relating to Public and Institutional Figures 27. The preliminary investigation revealed that the platform contained, by way of example only, the contact information of the following individuals: the President of the Italian Republic, Sergio Mattarella; the Deputy Prime Minister and Minister, Antonio Tajani; Minister Guido Crosetto—all expressly identified by their institutional titles—as well as former Minister and later Vice-President of the European Commission, Raffaele Fitto; Member of Parliament Chiara Appendino and Senator Stefano Patuanelli; Commissioners Elisa Giomi and Massimiliano Capitanio of the Communications Regulatory Authority; as well as Saverio Valentino, a member of the Italian Competition and Market Authority.

§

Furthermore, among the various contacts found in the database were German Chancellor Friedrich Merz and former Chancellor Angela Merkel. 28. These circumstances appear to indicate that the Company was unable to exclude information that it itself deemed it should not process. This demonstrated the absence of technical and organizational measures aimed at implementing the data protection principles set forth in Art. 25 of the Regulation, as well as a violation of the principle of data minimisation to the extent that the Company collected and stored information that it itself deemed irrelevant. Such conduct thus constitutes a possible violation of Articles 5(1)(c) and 25 of the Regulation. 3. EXERCISE OF THE RIGHT OF DEFENSE BY THE DATA CONTROLLER 29. The Company, exercising its right of defense, submitted its “defensive arguments and observations” on October 6, 2025 (Ref. No. 132076 of October 7, 2025) and requested a hearing.

§

30. Lusha first clarified that, with regard to Contacts, it collects the data typically contained in business cards that Customers use to carry out sales, marketing, and recruiting activities, committing to comply with applicable regulations. 31. 1. Inapplicability of the Regulation 32. According to the Company, its processing activities do not meet the requirements of Article 3(2) of the Regulation; in support of this, it cited the French supervisory authority, the Commission Nationale de l’Informatique et des Libertés (hereinafter “CNIL”), in its decision of December 20, 2022 (SAN-2022-024), and the Luxembourg supervisory authority, the Commission Nationale pour la Protection des Données (or “CNPD”), based on an email dated June 9, 2022. 33. Both the CNPD’s decision and the CNIL’s decision reportedly concern the same processing activities under review. Therefore, given these precedents that have recognized the non-applicability of the Regulation, the Company concluded that: “the Data Protection Authority should give due weight to their decisions and not deviate from them without justification,” failing which it would violate the principle of: loyal cooperation under Art.

§

4(3) TEU; consistent and uniform application of EU law, as set forth in Recital 10 and Chapter VII of the GDPR; and legal certainty and consistent interpretation of EU law. 1. Inapplicability of Art 3(2)(a) of the GDPR 34. More specifically, with regard to the criterion set forth in Article 3(2)(a) of the Regulation, Lusha argued that it does not offer goods or services to natural persons in the EU. On the contrary, its services are designed, offered, and provided solely to legal entities for professional use, not to natural persons for private use. 35. According to the Company, pursuant to that provision: - the applicability of the GDPR must be assessed with reference to specific processing activities; - since the provision refers to the offering of goods or services to “data subjects”—that is, natural persons as defined in Article 4(1) GDPR, the Regulation does not apply where processing is limited to the offering of goods or services to corporations, partnerships, or other legal entities; - the mere presence, in a database, of personal data relating to Union residents is not sufficient to determine the applicability of the GDPR; rather, the controller must explicitly address or demonstrate a clear intention to offer goods or services to data subjects; - The GDPR applies only when the data being processed concerns the data subjects themselves (“the aforementioned data subjects”) to whom the provision of goods or services is offered.

§

36. As can be seen from the website, the “Terms and Conditions,” and the “Privacy Policy” (updated on February 5, 2025), Lusha’s services are designed for enterprises. It is clear that the actual registration on the platform is carried out by a natural person acting as a representative of the legal entity, and whoever accepts the contractual terms declares that they are acting as a member of an organization. 37. Lusha considers the GDPR a “golden standard” in the field of data protection and, for this reason, adopts its principles and concepts; however, this does not imply that the Regulation applies to or binds the Company. 38. Furthermore, contrary to the Office’s contention, Lusha has adopted a series of measures to prevent natural persons from accessing its services. , the individual registering on behalf of the legal entity) is required to provide a professional email address. , Gmail, Yahoo, Hotmail, …) are not accepted; - Through the “Know Your Business” (KYB) program, Lusha uses external verification tools and databases to ensure that potential customers are registered and operate within a recognized legal system; 39.

§

According to the Company, the notice initiating the sanctioning proceedings does not cite any provision requiring the submission of documents—such as a power of attorney—to certify the legal entity status of the Clients. 40. Furthermore, even if, in isolated cases, individual professionals manage to register and be accepted as Clients, this does not alter the B2B nature of the services offered and does not justify the applicability of Art 3(2)(a) of the GDPR. 41. In any case, according to Lusha, the Regulation would not apply because the recipients of its service (the Clients) are not the data subjects whose data is being processed (the Contacts). 2. Inapplicability of Art 3(2)(b) of the GDPR 42. With regard to the criterion set forth in Art. 3(2)(b) of the Regulation, Lusha argued that the contested processing does not involve Tracking Contacts, nor profiling, nor behavioral analysis capable of falling under the concept of monitoring identified in Recital 24 of the Regulation and in the European Data Protection Board (EDPB) Guidelines No.

§

3/2018 on the territorial scope of the GDPR. 43. The Company concluded that it is not sufficient for the data of data subjects to be processed—even over an extended period of time—for the Regulation to apply; rather, the processing must involve profiling and behavioral analysis. 44. Therefore, according to Lusha, Article 3(2)(b) of the Regulation would not apply to the processing of Contacts’ data for the following reasons: - Absence of behavioral analysis: The Company processes only personal data such as name, email address, phone number, job title, role, and location. Such data neither reflects nor reveals behaviors, habits, or preferences and is not subject to any “subsequent behavioral analysis”; - Absence of monitoring: According to the Company, “monitoring” involves tracking the online or offline behavior of data subjects, for example, by recording Internet browsing activity or through video surveillance in public or private spaces.

§

This therefore constitutes “systematic and intrusive processing of personal data,” which Lusha does not carry out because it limits itself to processing professional contact information for the purpose of ensuring its accuracy; - Data accuracy: Measures aimed at ensuring the accuracy of the information available in the database do not fall under the concept of monitoring but serve the sole purpose of ensuring data accuracy pursuant to Art. 5(1)(d) of the GDPR and are functional to the protection of the Contacts; - Absence of profiling: Lusha does not engage in profiling within the meaning of Article 4(4) of the Regulation, insofar as it neither “evaluates” the Contacts nor “analyzes” or “predict” aspects pertaining to their professional, economic, health, or personal lives, but is limited to providing accurate professional contact information. 2. Inapplicability of the Privacy Code 45. The inapplicability of the Regulation would entail the inapplicability of the Code as a complementary and supplementary act, operating within the limits of Art.

3 of the GDPR

§

With Legislative Decree No. 101 of August 10, 2018, the legislature repealed the provisions of the Code that were incompatible with the GDPR and, in particular, Art. 5, which extended the application of Italian law to data controllers established outside the Union. 3. Transparency and Information Regarding the Legal Basis and the EU Representative 46. As of February 5, 2025 (the date of the update to the Privacy Policy or “Privacy Notice”), Lusha would already have been transparent regarding the legal basis for data collection and with respect to its representative. 47. As for the legal basis, contact data is not collected directly from the data subjects; therefore, Article 13 of the GDPR does not apply. Furthermore, although not required to do so, Lusha has nonetheless published notices (namely the “Privacy Notice” and the “Personal Information Notice,” the latter updated in January 2023) which, “if read correctly and in context” (p.

§

4, defense arguments), ensure that Contacts are adequately informed about the legitimate interest, including the related data collection process. In any case, the Personal Data Notice also complies with the requirements of Art 14 and was sent to each Contact prior to the inclusion of their data in the database. 48. 1 of the Privacy Policy clarifies that the purpose of “enriching, updating, cross-checking, and validating Lusha’s B2B database” is based on legitimate interest. This statement makes it clear that Lusha collects and processes Contacts’ data to create and maintain its database. Furthermore, other sections of the Privacy Notice refer to the “collection” of data. 49. Second, the Personal Information Notice clarifies that Contact data is collected for the purpose of inclusion in the database based on legitimate interest and informs data subjects of their right to opt out, as well as other options and rights available to them.

§

50. ” 51. Finally, with regard to the complaints and reports received by the Authority, the Company stated that it had sent the Privacy Notice to the respective data subjects, indicating the dates of dispatch and the corresponding timestamps. 4. Validity of the Legitimate Interest 52. With regard to the legal basis for the processing of Contacts’ data, the Company cited the Judgement of the Court of Justice of the European Union of December 7, 2023, SCHUFA Holding AG, C-26/22 and C-64/22, para. 83, insofar as it demonstrates the possibility of basing processing on legitimate interests even when data are collected indirectly, that is, when collection takes place through third parties. 53. The Data Protection Authority itself has previously acknowledged that the development of B2B activities based on legitimate interest is compatible with the regulatory framework provided that it is accompanied by adequate safeguards (for example, transparency and the option to opt out).

§

In particular, the Company cited the decisions of February 22, 2018, January 15, 2020 [9256486], [8080493], and April 29, 2025 [10145986]. 54. Similarly, in Opinion 28/2024 on legitimate interest in the context of artificial intelligence models, the EDPB reportedly reiterated that this legal basis is admissible even when information about data subjects is collected from public sources or third parties and made available to customers, provided that this is supported by a thorough balancing of interests and appropriate safeguards. 55. ” 56. Lusha’s primary interest lies in its economic interest in providing reliable services to its Customers, in particular by ensuring that they have access to accurate and up-to-date professional contact information in order to prevent fraud and to establish meaningful and effective business interactions with other enterprises and their representatives. 57.

§

The Company has thus emphasized that the concept of legitimate interest must be understood broadly, also encompassing the legitimate interests of its Customers, which include: - Protection against identity theft, impersonation, and online fraud. By providing validated and up-to-date information derived from public sources, community contributions, and reliable partnerships, Lusha enables customers to verify and authenticate the consistency between the professional attributes declared by an individual and the data that actually corresponds to them; - Business development, marketing, and recruitment. Through access to up-to-date contact information, organizations can identify and connect with potential clients, qualified candidates, and strategic decision-makers. 58. With regard to the requirement that processing be necessary for the pursuit of legitimate interests, the Company has reiterated that it processes only limited, clearly defined categories of data of a professional nature (such as name, contact information, job title, and position).

§

This data must necessarily be enriched, verified, and updated. 59. The Company decided to avoid collecting data directly from data subjects, deeming this approach “structurally incomplete,” as it would have excluded a large portion of professional contacts and would have been of little help for anti-fraud and identity theft prevention purposes. 60. With regard to balancing the fundamental rights and freedoms of data subjects, the Company has chosen to prevent the ability to conduct free and extensive searches on its database to avoid massive data extraction or misuse of the platform. Instead, it has adopted a “credit”-based system that Customers must purchase and use to access the data; this is intended to encourage targeted and contextualized searches, thereby limiting overall access to Contact data. 61. , financial information); that the processing does not affect the private lives of Contacts because Lusha has no direct relationship with them and the processing relates to professional data, which is often already publicly available; 62.

§

, on LinkedIn)—falls within the reasonable expectations of the data subjects. 63. The Company has also identified certain professional opportunities and benefits that the processing provides for Contacts, namely: the possibility of being contacted by recruiters regarding job openings; the receipt of relevant commercial communications; and more targeted and efficient professional communication. 64. Finally, the Company has adopted additional measures to mitigate risks, namely the implementation of a voluntary seven-day cooling-off period for the data subject to opt out; while the right to object remains at any time, even beyond this period, this serves as a voluntary safeguard allowing those who request it to prevent their data from being added to the database from the outset. 65. With regard to the Community Program, the Company has determined that the data collected in this manner is necessary, as this program serves to ensure and improve the accuracy of the database.

§

Only in this way can the database be kept up-to-date and accurate, in accordance with Art 5(1)(d) of the GDPR (and, at the same time, to the benefit of balancing legitimate interests under Art 6(1)(f) of the GDPR). 66. The Company further specified, with regard to the data contained in the calendars of Community members, that it offers—separately—a calendar feature for Community members. This would constitute an independent processing operation (“Lusha Over Calendar”) that integrates with Users’ calendars (Google/Outlook) to facilitate more effective meetings. 5. Inapplicability of Title X of the Privacy Code 67. With reference to Articles 129 and 130 of the Code, the Company stated that it is not an “electronic communications provider” but rather operates as an online platform that provides access to commercial data. Article 129 of the Code would not apply in any case because the Company does not produce, manage, or market public subscriber directories, and its database cannot be equated with the universal subscriber directories provided for in Art.

§

” 68. Similarly, Art 130 of the Code would not apply insofar as the Company does not send marketing communications; rather, these are carried out by its customers, who assume full accountability for compliance with applicable regulations. 6. Compliance with the Principles of Data Protection by Design and by Default 69. ” 70. In the absence of a “specific” obligation under the Regulation, the adoption of safeguards beyond those provided for by the legislation cannot be transformed into an obligation whose violation would entail accountability and sanctions. Furthermore, the Authority confuses the Company’s voluntary decision, made as a precautionary measure, with a non-existent admission that the excluded data are not necessary. The Authority has not demonstrated why the possible residual presence of professional data pertaining to government officials would constitute unlawful processing.

§

On the contrary, according to the Company, the processing of such data also falls within the scope of the communication purposes. 71. Citing European case law and guidelines on the right to be forgotten, the Company asserted that public figures have a lower expectation of privacy than other data subjects. 72. In any case, to exclude the contact information of public officials from the database, Lusha has for years been implementing voluntary measures and advanced technologies, such as specific filters, domain suppression, and periodic checks. 73. The residual presence of a small number of profiles, identified in the complaints, was caused by a technical flaw in the exclusion algorithm, which failed to detect particularly specific job titles. ) from its database. 7. Additional Voluntary Measures 74. To demonstrate its willingness to cooperate in ensuring full compliance with the regulations, Lusha reported that it had adopted the following new measures: - updating the World Map of Direct Marketing Regulations for Italy, to provide customers with clearer information on Italian direct marketing regulations; - initiated the process of integrating the Public Opt-Out Registry into the corresponding feature within Lusha; - strengthened the customer registration process by introducing additional verifications (requirement to provide the company name and registered office, and a checkbox declaration confirming authorization to act on behalf of the represented company); - Update of the Privacy Policy and Personal Data Notices to further clarify the use of legitimate interest and resend the updated Personal Data Notice to Italian contacts in Italian; - Extension, effective October 2025, of the cooling-off period from 7 to 14 days granted to new Contacts to exercise their right to opt out; - Gradual phase-out and blocking of access to the Community Program in Italy; - Strengthening of measures to exclude data relating to public officials and similar figures, including the removal of any remaining profiles linked to the public sector in Italy and the introduction of: (i) a weekly AI-based scan of official institutional websites to identify and eliminate any matching names in the database; and (ii) quarterly audits conducted by a third-party consultant to ensure continuous monitoring and ongoing improvement of the measures implemented.

§

8. Mitigating Circumstances 75. With regard to the nature, severity, and duration of the violation, the Company has: - contested the characterization of its processing as “particularly extensive and intrusive,” since the data being processed consists solely of basic professional identifiers, which are normally made available by the professionals themselves in work contexts. Lusha does not process the categories of data referred to in Articles 9 and 10 of the GDPR; - argued that the professional context mitigates the severity; - specified that Lusha’s service is structurally different from an “open” or “public” directory; - argued that no actual harm to the data subjects has been identified; - stated that the violation is characterized by “low offensiveness” insofar as the objections relate to matters of interpretation and the effectiveness of voluntary safeguards that exceed the legal minimum.

§

76. Furthermore, Lusha has always acted in good faith, and any violation cannot be attributed to either willful misconduct or negligence; it has also cooperated with the Authority by strengthening the Company’s compliance. 77. The Company has also certified its entire legal and compliance team through CIPP (Certified Information Privacy Professional) certifications, and its data processing activities are subject to independent audits conducted by third parties based on various certifications. 78. Finally, the Company described its revenue as “modest,” “limited,” and with “negative margins,” while also emphasizing that it is not a dominant player in its target market and continues to invest in compliance without deriving any profit from it. 9. The Company’s Hearing and Subsequent Communication 79. On February 11, 2026, the Company’s hearing took place at the Authority’s headquarters, during which the Company first confirmed that it had adopted certain measures to address the allegations.

§

In particular, it clarified that it had: - completely removed all remaining contacts attributable to Italian public entities and institutions from the database, as well as updated and strengthened the exclusion system to also include the public administration, law enforcement agencies, and judicial authorities; - completed the process of resending the Personal Data Notices “to all contacts, including those residing in Italy (numbering over XX for Italy), an operation concluded on January 29, 2026”; - updated its Terms and Conditions; - discontinued and blocked access to the Community Program for Customers who register via Italian IP addresses or for individuals associated with domains linked to Italian organizations; 80. With regard to the applicability of the Regulation pursuant to Art 3, para 2, subparagraph (a), the Company argued that what matters for jurisdictional purposes is the intention to offer its services to natural persons established in the EU.

§

In this specific case, Lusha’s intention is to offer its services only to companies and organizations as a B2B service. What must therefore be demonstrated is not the User’s intention to act as a legal entity but Lusha’s intention to target other companies rather than private individuals. ). 81. it). This is because the Company does not intend to offer its services to entities with their own accounts, such as freelancers and sole proprietorships, and their access to the service would constitute a violation of the terms of service because the User cannot act as an individual. 82. Following the Authority’s investigation, the Company introduced additional measures, such as requiring users to enter the company name, the legal name, and a checkbox to declare that they are acting on behalf of the company. Furthermore, the email address provided is now cross-checked against those contained in a database of companies, corporations, and external suppliers maintained by the Company.

§

Information such as the company’s tax identification number or VAT number, an invoice, or a power of attorney is not required. 83. With regard to the monitoring criterion set forth in Art. 3, para. 2, subparagraph b), of the Regulation, the Company highlighted the similarities between the Data Protection Authority’s investigation and the one previously conducted by the CNIL. Following its investigation, the CNIL reportedly concluded that: “there was no monitoring, as there is no profiling activity within the meaning of the Regulation. Lusha records changes in the employment status of the individuals in its database, but this does not constitute profiling; it is merely an update of the data. The fact that someone changes jobs—and consequently Lusha updates the job title in the database—does not constitute profiling to the extent that it does not lead to an understanding of behavioral preferences.

§

” Furthermore, the Company specified that: “To update the contacts in the database, it must check them all periodically and consistently. ” 84. With regard to the legal basis for processing, the Company confirmed that it relies on legitimate interest pursuant to Art. 6(1)(f) of the Regulation both for the collection of Contact data and for its disclosure to third parties for the purposes of those third parties. Furthermore, data subjects have a legitimate expectation of being contacted by companies and professionals, as they are the ones who have made their information public. 85. On this issue, after the Office noted that Users’ contact information (phone number and email address) is not available on their LinkedIn profiles (which the Company identified as the primary source of data), the Company stated that: “If a person signs up for LinkedIn, it means they want to present themselves as a professional in the job market.

§

[…] As for data not available on LinkedIn—specifically email addresses—these can be inferred using an algorithm, which then attempts to send a privacy notice, or obtained from other sources. ’” 86. Finally, in a communication dated February 18, 2026 (Ref. No. 26323), the Company provided a written account of the clarifications offered during the hearing regarding the proceedings involving Lusha before the CNIL. On that occasion, while acknowledging “the full autonomy and decision-making authority of this Authority, as well as the lack of formally binding effect of the CNIL’s decision,” the Company reiterated that: with regard to Art. 3(2)(a) of the GDPR, the CNIL had acknowledged that Lusha’s offering of goods and services is directed exclusively at Customers; with regard to the criterion set forth in Article 3(2)(b) of the GDPR, however, the CNIL concluded that Lusha’s processing activities do not constitute tracking, profiling, or monitoring of the behavior of data subjects.

§

4. THE AUTHORITY’S ASSESSMENTS 87. Following the preliminary investigation, and having assessed the arguments put forward by the Company—to which the declarant responds pursuant to Art. 168 of the Code—the Authority considers that these arguments are only partially sufficient to exclude the Company’s accountability. 1. Operation of the Service Offered 88. The service offered by the Company consists of making the information contained in its database available to Customers—in exchange for payment of a monthly, annual, or customized subscription fee, and subject to a limited period of free use. 89. This information is organized into a “Business Contact Card” (“Business Contact Card”) for each individual Contact, which is updated weekly and contains data relating to a specific natural person, including the following information: name, email address, phone number, professional title, years of service, role, and location.

§

This information constitutes personal data pursuant to Article 4(1) of the Regulation. 90. The business model is centered on making the personal data of Contacts available to Customers. ) or through automatic suggestions using recommendation algorithms based on interests inferred from the Clients. 91. With regard to such processing and as acknowledged by the Company in its response of May 29, 2025, the Authority considers that Lusha qualifies as the controller pursuant to Article 4, paragraph 7, of the Regulation, since it is Lusha that determines the purpose (making the data available) and the means of processing (the various methods comprising the processes of collection, merging, enrichment, updating, and making the data available and/or excluding it from the database). In turn, Customers may use the data obtained in this manner for their own purposes, in their capacity as independent controllers.

§

92. The main sources of data collection are LinkedIn and Salesforce, as well as blogs, websites, and professional forums. In addition, the Company obtains contact data from its customers who agree to the contractual terms of the Community Program, as well as through the integration of the Lusha API with other customer services and CRMs (for example, Gmail, Outlook, and Outreach). 2 of the Privacy Notice on file states: “By connecting your email account as an Integration, Lusha may scan and/or extract business contact details from your inbox and may use them to improve its services”) and through the use of “Lusha integrations,” such as Lusha browser extensions or other software that enables data collection while the customer who has installed such extensions is browsing online. 93. Finally, any missing information is reconstructed through various processing operations. dominio). Once an email address is generated, an attempt is made to send a privacy notice.

§

As for phone numbers, these are purchased from other “vendors” or partners who collaborate with the Company and who are primarily based in the United States. 2. On the Applicability of the Regulation 94. As a preliminary matter, it is necessary to address the applicability of Regulation (EU) 2016/679 to the processing of data of data subjects located in the EU carried out by a controller (or processor) not established in the Union. In doing so, it is appropriate to set aside assessments made by other entities and, in particular, the aforementioned precedents established by the authorities in Luxembourg and France. 95. Given that the Data Protection Authority holds the assessments made by its European counterparts in the highest regard—with whom, as is well known, maintains constant relations and exchanges within the framework of the cooperation and consistency mechanism described in Chapter VII of the Regulation, in accordance with European law and outside the aforementioned cooperation and consistency mechanism, the Data Protection Authority is not bound by their assessments and is not legally subject to any prior rulings.

§

This circumstance is also acknowledged by the Company in its communication of February 18, 2026, in which it filed a clarification note regarding the statements made during the hearing. 96. More specifically, with regard to the email from the Luxembourg authority, the Data Protection Authority notes that, since it concerns a specific case, the email can only be considered a communication between third parties unrelated to the Data Protection Authority and therefore, if applicable, is binding only among the parties involved. This document, which, moreover, has not been published, must be considered to have no legal effect erga omnes and is not binding on other European supervisory authorities. 97. With regard to Decision SAN-2022-024 of December 20, 2022, issued by the French supervisory authority (“CNIL”), regardless of the specific case under analysis, this ruling is also the result of an assessment of the specific factual case submitted to that authority and is likewise not binding on the Data Protection Authority or other supervisory authorities.

§

As can also be inferred from Recital 143 of the Regulation, this decision, too, produces legal effects only with respect to the parties to the lawsuit. Given that, in general, the EU legal system has entrusted the Court of Justice, through the preliminary ruling procedure provided for in Art. 267 of the TFEU, with the fundamental function of ensuring the uniformity of European law, which entails the obligation to apply EU law consistently and uniformly, the Data Protection Authority’s compliance with the principle of sincere cooperation set forth in Art. 4(3) of the TEU must be assessed in light of the cooperation procedures provided for in Chapter VII of the Regulation. Since the Company does not have an establishment within the territory of a Member State, the aforementioned cooperation procedure does not apply and, therefore, there is no violation of the principle of sincere cooperation on the part of the Data Protection Authority vis-à-vis other European supervisory authorities (see EDPB Guidelines 3/2018, p.

§

14). 99. Similarly, outside the aforementioned cooperation procedures—which, with regard to personal data protection legislation, entrust the EDPB with the task of ensuring the consistent application of the GDPR (see Court of Justice, February 10, 2026, WhatsApp Ireland v. EDPB, C-97/23 P, para. 103), the Authority considers that the requirement set forth in Recital 10 of the Regulation—aimed at ensuring an equivalent level of protection of rights and freedoms in all Member States—does not, in and of itself, preclude a supervisory authority from deviating from the prior assessments of another authority. On the contrary, pursuant to Article 57(1) of the Regulation, each supervisory authority is competent to carry out the tasks and exercise the powers conferred upon it under that Regulation within the territory of its Member State. 1. The criterion of offering goods or services to data subjects in the EU referred to in Art.

§

3(2)(a) of the GDPR 100. With regard to the criterion set forth in Art. 3(2)(a) of the Regulation, Lusha argued that its services are designed, offered, and provided solely to legal entities for professional use, not to natural persons for private use. 101. The documentation on file shows that the Company’s stated interest and intention to offer its services only to legal entities is not matched by an organizational structure or the adoption of appropriate mechanisms and measures sufficient to prevent natural persons from accessing its services. While it is undisputed that the Company’s intent must and can be assessed—and thus also demonstrated—based on the actions it has taken to move from an abstract concept to a concrete operational model (see Recital 23 of the GDPR), and thus the Company should have adequately implemented and concretized its intentions, it is precisely from an analysis of the practical outcome of its approach that it becomes clear the Company was unable to guarantee and demonstrate that it dealt only with legal entities and not also with natural persons.

§

102. In particular, unlike other operators in B2B markets—who, in order to limit the provision of their services solely to legal entities or, in any case, to individuals acting in an enterprise capacity, take care to request elements that unambiguously indicate enterprise activity (such as a VAT number or proof of authority to represent or a power of attorney), the Company has not implemented adequate measures. 103. That said, although it is not considered proven that the Company’s services are offered only to legal entities and not also to individuals who could theoretically be classified as “data subjects,” it is acknowledged that, based in part on EDPB Guidelines 3/2018, the application of the criterion set forth in Art. 3(2)(a) of the GDPR would result in the Regulation’s applicability to the processing of “Customers’” personal data. 104. Therefore, while the argument that the Regulation does not apply to the processing of personal data carried out by the Company cannot generally be accepted—since there remain processing activities that, as explained, may fall within the scope of the Regulation— the Authority acknowledges that the criterion set forth in Art.

§

3(2)(a) of the GDPR cannot also cover the processing of data pertaining to Contacts, to which this investigation is limited. 2. The criterion of monitoring the behavior of data subjects referred to in Art. 3(2)(b) of the GDPR 105. ” 106. This criterion is clarified in Recital 24 of the Regulation, which states: “The processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union should also be subject to this Regulation where it relates to the monitoring of the behavior of such data subjects, to the extent that such behavior takes place within the Union. ” 107. According to the settled case law of the Court of Justice, for the purposes of a uniform interpretation of Union law, account must be taken not only of its literal wording but also of the context in which it is set and the objectives pursued by the legislation of which it forms part (judgments of December 18, 2025, Storstockholms Lokaltrafik, C-422/24, para.

§

28; August 1, 2025, Alace and Canpelli, C-758/24 and C-759/24, EU:C:2025:591, para. 91; November 28, 2024, Másdi, C-169/23, EU:C:2024:988, para. 39; December 7, 2023, UF and AB v. Land Hessen, C‑26/22 and C‑64/22, ECLI:EU:C:2023:958, para. 48). Furthermore, the objective of the GDPR is to ensure a high level of protection of the fundamental rights and freedoms of natural persons, in particular their right to privacy, with regard to the processing of personal data, as enshrined in Art. 8, para 1, of the Charter of Fundamental Rights of the EU and Art 16(1) TFEU (judgments of February 27, 2025, Dun & Bradstreet Austria, C-203/22, EU:C:2025:117, para. 51; October 4, 2024, C-446/21, Schrems v. , EU:C:2024:834, para. 45, and the case law cited therein). 108. ” 109. ” In this regard, the Court of Justice has held that the provisions of EU law must be interpreted and applied uniformly in light of the versions in force in all the languages of the Union and, in the event of a discrepancy, the provision in question must be interpreted in light of the general scheme and purpose of the legislation of which it forms part (see judgements of December 18, 2025, Storstockholms Lokaltrafik, C-422/24, ECLI:EU:C:2025:980, para.

§

31; February 13, 2025, Verbraucherzentrale Berlin, C-612/23, EU:C:2025:82, para. 31, and the case law cited therein). 110. According to Recital 24, monitoring or tracking occurs when the data subject is “tracked on the internet” (in English) or “suivies sur internet” (in French) and, in particular, when such tracking serves to make decisions concerning the data subject or, alternatively (the Recital uses the disjunctive “or”), to analyze or even predict: the data subject’s preferences, behaviors, and personal views. 111. These objectives may also be achieved through processing expressly defined in Recital 24 as “possible” and “subsequent” to Tracking that has already taken place, namely the use of profiling pursuant to Art 4(4) of the Regulation. It follows from this that profiling is not a sine qua non condition for the tracking of natural persons on the internet (and, therefore, their monitoring or control) but rather a merely “potential” form of processing which, if present, certainly contributes to strengthening and making Tracking more efficient, as well as increasing the level of risk involved, but whose absence does not affect the ability to track the behavior of natural persons.

§

112. That “internet tracking,” as a form characteristic of the “monitoring” of data subjects’ behavior, is a distinct activity from profiling in a technical sense can also be inferred from a reading of Recital 30 of the Regulation and, consequently, from the legislation on tracking systems. 113. , cookies). ” In this sense, creating profiles does not mean engaging in profiling activities but rather compiling a “static” list of attributes relating to a natural person. This can be inferred from the provisions regarding cookies and other tracking tools (among others, with reference to the Data Protection Authority, see: Guidelines on Cookies and Other Tracking Tools, June 10, 2021, web doc. no. 9677876; Guidelines on the Use of Tracking Pixels in Email Communications, April 17, 2026, web doc. no. 10241943). The operation of cookies and other tracking tools, such as pixels, allows for the “tracking” of a user’s activity but does not, instantly and simultaneously with that same action, enable profiling—that is, carrying out evaluative and/or predictive activities regarding the individual.

§

Profiling is therefore a subsequent activity carried out using the information obtained from prior tracking. 114. It follows that “internet Tracking,” which involves “monitoring the behavior of data subjects,” can certainly serve as a basis for a “subsequent” and “potential” profiling activity of the data subject but remains, in any case, a distinct processing operation that logically precedes profiling and is, in theory, also useful for other processing operations that do not involve profiling. As stated in the “Cookie Guidelines” of June 10, 2021: “Cookies can therefore perform important and varied functions, including session tracking, storing information on specific configurations regarding users accessing the server, facilitating the use of online content, etc. […]. ” 115. That the concepts of monitoring and profiling refer to ontologically autonomous and distinct activities can also be inferred, pursuant to Art.

§

01) and endorsed by the EDPB, in the section listing the criteria indicative of a high risk. ” Similarly, the Data Protection Authority, in Annex 1 to Decision No. 467 of October 11, 2018, web doc. No. 9058979, has also distinguished profiling from the observation, monitoring, or control of data subjects. Finally, one may cite Article 37(1)(c) of the GDPR, which considers “the regular and systematic monitoring of data subjects on a large scale”—and not profiling—as an activity that triggers the obligation to appoint a data protection officer. 116. Furthermore, in Guidelines 3/2018, the EDPB, while reiterating that “the monitoring of the behavior of data subjects located in the Union could therefore encompass a wide range of activities,” proposes a non-exhaustive list of processing operations that may constitute relevant monitoring within the meaning of Art. 3(2)(b) of the Regulation. Among these, the following are the ones that most closely resemble the processing carried out by the Company: geolocation, particularly for marketing purposes; and monitoring or regular reporting on an individual’s health status.

§

On page 17, the EDPB then provides an example of monitoring that does not necessarily require profiling: “By processing the data subject’s location data to deliver targeted advertising based on that location, the processing activities also involve monitoring the behavior of natural persons in the Union. S. ” 117. It must therefore be concluded that, in order for the monitoring or Tracking of data subjects’ behavior to be covered, it is necessary to demonstrate the “Tracking” of natural persons on the internet; it is not necessary to demonstrate the presence of profiling relevant under Art 4(4) of the Regulation or behavioral analysis. 118. ” 119. In this specific case, the Company carries out various processing operations on the Contacts’ data: from collection to organization and combination with other information, up to the enrichment and constant updating of such data, which enable it to analyze the employment status (as a subcategory of a personal characteristic) of several hundred thousand individuals and/or to make a decision about whether to make the data available (or exclude it, as will be seen in the case of public officials) from its database.

§

Furthermore, based on the information available in the case file, it appears that the Company constantly updates, at least on a weekly basis, the unique “contact profiles” for each individual listed in the database. In doing so, even in the absence of profiling activities relevant under Article 4(4) of the Regulation, the Company continues over time to “track online” the personal circumstances of the Contacts, supplementing its prior decision regarding the data subjects—resulting from the monitoring activity—with the additional purpose of analyzing changes in their personal and professional circumstances. 120. Therefore, contrary to the Company’s assertion, the Authority considers that monitoring the behavior of data subjects does not require profiling or behavioral analysis in the technical sense, but rather the collection of information—or traces thereof—relating to the behavior and personal circumstances of data subjects within the Union, in order to make decisions concerning them with regard to their employment.

§

Lusha carries out all of these activities through the creation and subsequent ongoing updating of “contact profiles” that are unique to each individual. 121. The fact that updating the employment status of Contacts is also carried out as a measure aimed at ensuring the accuracy of the information in accordance with the principle of accuracy under Art. 5(1)(d) of the GDPR, does not preclude the actual monitoring of the data subjects’ behavior. 122. The Authority therefore considers that, first and foremost, tracking a natural person’s position, job title, location, or other element related to their employment for the purpose of evaluating their inclusion in a database (and, consequently, determining whether or not to make their data available to third parties), as well as, subsequently, monitoring the presence, modification, or erasure of the aforementioned data relating to work activity in order to analyze any changes, on a continuous and constant basis over time, is consistent not only with the letter but also with the rationale of the monitoring criterion set forth in Art.

§

3, para 2, subparagraph b), of the Regulation, and provides the basis for protecting natural persons under EU law on an equal footing worldwide for all enterprises operating in EU markets. 123. It must therefore be considered proven that the Regulation applies to the processing of Contact data carried out by the Company, in its capacity as controller, pursuant to Art 3, para 2, subparagraph b), of the Regulation. 3. Applicability of the Code 124. The applicability of the Regulation to the processing operations under investigation also entails the applicability of the Code. 3. Transparency Regarding the Legal Basis and the EU Representative 125. The principle of transparency under Article 5(1)(a) of the Regulation, as set forth in the information obligations referred to in Articles 12 et seq. of the same Regulation, requires the controller to provide data subjects— “in a concise, transparent, intelligible, and easily accessible form, using clear and plain language”—the information necessary to describe the processing operations.

§

In particular, this information must include the identity and contact details of the data controller and, where the data controller is not established in the EU, of its representative, as well as the processing purposes and the relevant legal bases. 126. The Company argued that both the Privacy Notice and the Personal Information Policy, “when read correctly and in context,” made it possible to identify legitimate interest as the legal basis. 127. 1, legitimate interest is frequently cited as the legal basis. Nevertheless, no reference is made to data collection, which was, in fact, the subject of the Office’s objection. Furthermore, while acknowledging that the data collection operation may be considered implicit in subsequent processing activities, in the absence of a specific indication of data collection, supported by the relevant legal basis, the data subject is deprived of information essential to a proper understanding of the processing and is therefore unable to fully exercise the rights granted to them by law.

§

Furthermore, specifying the data collection activity helps determine the source from which the data was obtained, including for the purpose of assessing the scope of application of Articles 13 or 14 of the Regulation. 128. With regard to the Privacy Notice, it should be noted at the outset that this document is not easily accessible on the Company’s website. The legal documentation is not present on the home page but is available only by clicking on the “Resources” menu item and then on “About” to open the corresponding page, which contains several hyperlinks at the bottom (see also the screenshot provided by the Company, Exh. 6, defenses and observations). Among these, in the “Legal” column, there are links to certain documents such as the Terms and Conditions, the Privacy Notice, and the Cookie Policy, but not to the aforementioned Personal Data Policy (“Personal Information Policy”).

§

Thus, while it takes at least three clicks to access the Privacy Policy, it is not possible to access the Policy on personal data due to the absence of the corresponding link. The only easy way to access this latter document turned out to be through a search engine query—a process that necessarily requires prior knowledge of the document’s online existence. The Office itself became aware of this document because the Company submitted it along with its defense arguments. That said, the much more concise context and the indication of the sources from which the data was collected make it possible to infer the legal basis for data collection, which is also stated here as legitimate interest. 129. As a result of the foregoing, the Company’s defenses may be considered to partially resolve the allegations raised, to the extent that information regarding the lawfulness of the data collection is in any case available to the data subjects.

§

However, the manner in which the information was provided overall does not appear to be in line with the criteria established by Art. 12(1) of the Regulation. Precisely the fact that the relevant information was not available on the home page, as well as the need to pay particular attention when reading multiple documents in English—and thus not in the language of the Contacts’ nationality—prevents the information provided from being characterized as concise, transparent, intelligible, simple, clear, or easily accessible. 130. With regard to the representative pursuant to Article 27 of the Regulation, the Authority takes note of the changed approach demonstrated by the Company. In its response to the Office’s request for information, the Company had argued that it was not required to appoint its own representative in the EU and that it had identified a mere contact point in Germany. Similarly, the Privacy Policy referred to that entity as a “contact point” in the EU.

§

However, when exercising its right of defense, the Company asserted that it had appointed its own representative and that the Privacy Notice expressly referred to the status provided for in Art. 27 of the Regulation. 131. The Authority agrees with the Company’s most recent position in considering the designated contact point to be its representative in the Union. 132. In conclusion, the Authority orders the dismissal of the specific violation of Article 13(1)(a) and (c) of the Regulation but confirms the violation of Articles 5(1)(a); and 12 of the Regulation with regard to the principle of transparency and its corollaries. 4. Regarding Information Provided to Contacts 133. With regard to the report (file no. 459328) and the complaint (file no. 465278) received, the Authority took issue with the Company’s failure to provide any information to the data subjects in their capacity as Contacts.

§

134. The Company claimed that it had sent the Personal Data Notice and provided a text file containing a string with various values, including the data subjects’ email addresses, and a “timestamp” as proof of the date the notice was sent. Although there were no mechanisms in place to guarantee the authenticity and non-repudiation of the file, and although the Company did not provide conclusive evidence regarding the direct origin of the text file from its information systems or its direct connection to the specifically requested compliance, the Authority does not have sufficient evidence to confirm the alleged violation. Consequently, the allegation regarding the possible violation of the principle of fairness and transparency, as well as the obligation to provide information to data subjects, as set forth in Articles 5(1)(a) and 14 of the Regulation, is hereby dismissed. 5. On the Lawfulness of the Processing of Contacts’ Data 135.

§

With regard to the Contacts, Lusha stated that it collects and processes only the name, email address, phone number, professional title, years of experience, role, and location in order to make this information available to its Clients and for anti-fraud purposes, based on its own legitimate interest and that of its Clients. ” 136. As a preliminary matter, we confirm what was already stated in our objection regarding the Legitimate Interest Assessment (“LIA”). This document, which consists entirely of the few lines comprising Section 5 of the impact assessment, contains no elements useful for supporting the Company’s decision to rely on legitimate interest as the legal basis for processing Contact data. The LIA, as prepared in such a generic manner and with unsubstantiated assertions, merely states that the processing is necessary and proportionate. Furthermore, there is no assessment whatsoever regarding the balancing of interests with the rights of the data subjects.

§

These shortcomings are such that the LIA must be considered entirely omitted, and not merely incomplete. 137. During the preliminary investigation, in support of its reliance on the legitimate interest, the Company cited the case law of the Court of Justice and that of other supervisory authorities, including the Italian Data Protection Authority. The Authority does not intend to disregard these precedents, which, on the contrary, contain elements useful for analyzing the specific case at hand, nor does it intend to deny the abstract possibility of relying on legitimate interest as a basis for lawfulness. However, the possibility of relying on this legal basis must be assessed on a case-by-case basis and must comply with the conditions set forth in Art. 6(1)(f) of the Regulation. 138. , C-252/21, EU:C:2023:537, para. 106, and the case law cited therein. In this regard, see also the “Guidelines 1/2024 on the processing of personal data based on Article 6(1)(f) of the GDPR,” ver.

§

3, also cited by the Company itself). The data controller must therefore demonstrate that it has satisfied three cumulative conditions, namely: that it has pursued a legitimate interest; processing only the data necessary to pursue that interest; and, finally, that the interests or fundamental rights and freedoms of the data subjects do not override the legitimate interest pursued by the controller (the so-called “balancing test”). Compliance with these conditions will be examined in the following subsections. 1. The Condition of Lawfulness of the Pursued Interest 139. The pursuit of specific interests by a data controller may be considered legitimate to the extent that it is not prohibited by law. In other words, to be “legitimate,” the interest pursued must first and foremost be lawful. 140. With specific reference to direct marketing, although this is a fully lawful activity—constituting the exercise of freedom of enterprise and the right to economic initiative under Art.

§

41 of the Constitution—it remains a regulated activity under both national and European law. The general principles governing advertising require that it always be transparent and recognizable as such, as well as fair and not misleading. When such activity involves the processing of personal data, consumer protection regulations are supplemented by those governing the proper processing of personal data. In addition to the general provisions of the Regulation, Art 13 of Directive 2002/58/EC and Art 130 of the Code (which transposes it into Italian law) apply, requiring the prior consent of the contracting party or user for the sending of commercial communications. , Articles 26(3) and 28(2) of EU Regulation 2022/2065). 141. Although the Office did not allege that the Company had violated Article 130 of the Code—since it is not the entity sending advertising material—the regulatory framework summarized above makes it clear that, with regard to direct marketing, both national and European legislation share the same rationale: the need for an activity that is lawful but nonetheless potentially impactful on the freedom and autonomy of data subjects to be carried out under their control.

§

142. It should also be noted that, according to the Authority’s established case law, the disclosure of personal data to third parties for the purpose of conducting commercial and/or advertising activities in the interest of third parties must, in any case, be based from the outset on valid consent from the data subject, and it is the responsibility of those who create a contact database, drawing from various sources, to verify the lawful origin of the data and, therefore, to exercise effective control over the acquired lists to ascertain the possibility of lawfully transferring the contacts thus collected (among others, decision “Realmaps” of January 16, 2025, No. 11, web doc. No. 10110241. 3, web doc. No. 2542348). 143. Furthermore, as early as the “Guidelines on Promotional Activities and Combating Spam” of July 4, 2013, the Data Protection Authority had clarified that, in the absence of consent from the contracting party or User, promotional communications may not be sent, even if the data is derived from public records, directories, websites, or documents known or knowable to anyone.

§

It follows that, whether data is acquired directly from Users and/or data subjects or indirectly through scraping, the use of algorithms, or the purchase of data from third parties, the Company should have taken steps to obtain consent covering the purpose of disclosing data to third parties for their commercial purposes. 144. ” 145. ” 146. Conversely—with regard to the fulfillment of the first condition of the “three-part test” identified by the Court of Justice, as summarized in paragraph 138 of this decision—the Authority considers, in the present case, the processing of data for anti-fraud purposes to be, in principle, legitimate. 147. ” 148. The same considerations set forth above with regard to the Company’s interest can be applied to the pursuit of interests for the benefit of Lusha’s customers. 2. The Condition of Strict Necessity of the Processing 149. With regard to the second condition, concerning the necessity of the processing, it requires verifying that the pursuit of the interest cannot reasonably be achieved just as effectively by other means that are less detrimental to the fundamental rights of the data subjects, in particular the rights to respect for private life and to data protection guaranteed by Articles 7 and 8 of the Charter of Fundamental Rights of the EU.

§

150. The condition regarding the necessity of the processing must also be examined in conjunction with the principle of data minimisation enshrined in Art. , C-252/21, ECLI:EU:C:2023:537, paragraphs 108 and 109, and the case law cited therein. See also the EDPB’s “Guidelines 1/2024 on the processing of personal data based on Article 6(1)(f) of the GDPR,” dated October 8, 2024, paragraph 29). Furthermore, based on Recital 47 of the GDPR, which refers to the “strict necessity” of the processing in relation to the interest pursued, according to the Court’s case law, the concept of necessity must be interpreted in a manner that fully reflects the objectives of data protection law. , C-252/21, ECLI:EU:C:2023:537, paras. 99, 102). 151. For the purpose of creating a unique “Company Contact Profile,” the Company stated that it needed to collect personal data such as name, email address, phone number, professional title, years of service, role, and location.

§

152. However, the documentation on file shows that the Company also collected other data from various sources: from its own customers as part of the Community Program or through integrations with other services, such as information related to “CRM databases”—including information from third parties—email headers and subject lines, information on scheduled meetings (meeting participants, meeting description, subject, date, and time of the meeting), as well as browsing data. With regard to this information, there is no clear demonstration of a strict necessity in relation to the purpose of providing customers with a summary sheet of an individual’s contact information. On the contrary, the collection of such information appears excessive and is not justified by the Company. The Company has not provided any basis for assessing the proportionality and necessity of collecting such data but has merely announced the termination of the Community Program in Italy.

§

153. Anticipating what will be discussed in greater detail below, the findings of the preliminary investigation also indicate that the Company collected data relating to public officials and other public office holders—including those in senior positions—in order to make such data available to customers for commercial purposes. It must be noted, however, that those working in the public administration do not pursue business purposes; therefore, there are no valid and lawful reasons—nor has the Company provided any evidence to that effect—why a business entity should obtain the data of individual officials for marketing or commercial purposes. This applies all the more to senior officials in the public administration and/or constitutional bodies. Consequently, the Authority considers that the Company has not provided adequate justification for making information regarding individuals working in the public sector available to customers for a commercial purpose or for the pursuit of its own economic interests.

§

On the contrary, in the summary table of risks associated with the processing, included at the end of the VIP, Lusha acknowledges that the processing of such data is unnecessary. 154. With regard to anti-fraud processing, the Company has stated that the interest in preventing fraud consists in protecting against identity theft and impersonation by providing Customers with validated and up-to-date information to verify and authenticate the consistency between the professional attributes declared by a natural person and those obtained by Lusha. In other words, this interest is achieved by making information regarding a natural person available to the requester. This is therefore a method that results in the permanent transfer of a set of personal data to a third party, as well as a volume of information that may even exceed what is necessary. 155. Conversely, with regard to the specific case at hand and limited to the circumstances under analysis here, the Authority considers that the pursuit of an anti-fraud interest could be achieved just as effectively by avoiding the permanent transfer of all available information relating to a particular individual.

§

). Therefore, rather than providing customers with all information about the individual, the customer could have been asked to enter the information in their possession so that the platform could verify (or not) whether there was a match with the person stated to be the subject of the search. 156. The Authority considers that—with regard to the fulfillment of the second condition of the “three-part test” identified by the Court of Justice, as referred to in para 138—in violation of the principle of data minimization set forth in Article 5(1)(c) of the Regulation, the Company collected data that was excessive and unnecessary for the purpose of making the data available to Customers. Consequently, the criterion of strict necessity of the processing for the pursuit of the legitimate interest is not considered to have been met. 157. In particular, the criterion of strict necessity of the processing is not satisfied even with regard to anti-fraud processing, insofar as the Company has not demonstrated that this interest could not reasonably be achieved just as effectively by means less detrimental to the fundamental data subject rights.

§

158. , C-252/21, ECLI:EU:C:2023:537, para. , C-597/19, EU:C:2021:492, paragraph 111, and the case law cited therein). 159. In this specific case, the Company pursues an economic interest in providing a service that is profitable for itself: providing access to Contact Data to enable Customers to reuse such data for their own commercial purposes or to prevent fraud. In this sense, the interest pursued for the benefit of Customers is also commercial in nature but dependent on the Company’s interest and available only within the limits and under the conditions imposed by the Company. Unlike in other cases, the Customers’ interest is not distinct or independent from that of the data controller and may therefore be considered subsumed within it. 160. Against this economic interest stands the fundamental right of the data subjects (the Contacts) not to be subjected to unjustified processing of their data beyond their control, the right not to suffer interference in their private lives, and the interest in not receiving commercial communications without prior consent or, in any case, being subjected to commercial practices that do not comply with the standards set forth by applicable regulations.

§

Given that some Contacts are also public officials or hold senior positions in the public administration, the interests of national security and the proper and impartial performance of public functions are also relevant. 161. As a general rule, the pursuit of an economic interest—even if, in the abstract, it is lawful and relevant—is not sufficient to justify a restriction on fundamental individual rights, such as the right to personal data protection, as well as the other rights and interests mentioned, in the absence of specific conditions that make such a restriction reasonable. In this regard, the Company has not provided evidence of any weighing and balancing against the rights and interests of the Contacts but has merely inferred a person’s interest in being contacted for a commercial purpose from the mere factual circumstance that the person had created a profile on a digital platform with a more specific focus on the workplace and professional environment.

§

Consequently, and as previously stated in Opinion 6/2014 on the concept of legitimate interest, adopted on April 9, 2014, by the Art 29 Working Party, on page 31, if the interest pursued by the data controller is not “overriding,” it is more likely that the data subject’s interests and data subject rights will prevail over the data controller’s interest. 162. The Company has cited elements (such as the “credit”-based system that prevents the mass extraction of data from the database) that, rather than contributing to balancing the interests at stake in favor of the data controller, should be viewed as additional risk mitigation measures. 4, risk mitigation measures are not, in and of themselves, sufficient to allow the data controller’s or third parties’ interests to prevail over the data subject rights and interests; however, following a weighing of interests that has already been carried out, they may contribute to that end by strengthening the position of the data controller or third parties.

§

163. Given the absence of an effective balancing of the interests at stake, the Authority considers that Lusha failed to take into account relevant factors such as: the nature of the individuals involved (who are not always business owners but may also be public employees), the nature of the data processed (in particular, although contact information does not fall within the special categories of data, it is nonetheless personal data that is generally confidential and not always made publicly available, especially when it exposes direct contact information to others), the relationship between the parties involved, the reasonable expectations of the data subjects, and the legal and factual context in which the processing took place. 164. In particular, it is clear that no prior relationship exists between the Contacts and the Company. In the absence of a relationship between the parties involved in the processing, it seems possible—even in the abstract—to rule out the “reasonable expectation” regarding the processing referred to in Recital 47 of the Regulation.

§

165. It cannot be overlooked that the Court of Justice places particular emphasis on whether data subjects can reasonably expect such processing, as well as on the scope of the processing in question and its impact on the individual (in addition to the judgements already cited, see also the judgement of December 7, 2023, UF and AB v. Land Hessen, C‑26/22 and C‑64/22, ECLI:EU:C:2023:958, paragraph 80). The Court thus held that “the interests and data subject rights could, in particular, override the interest of the controller where personal data are processed in circumstances in which the data subjects cannot reasonably expect such processing” (Judgement of January 9, 2025, Mousse, C-394/23, ECLI:EU:C:2025:2, para. 50). 166. First, as also evidenced by the complaints and reports received by the Authority, the data subject may become aware of the existence of the processing and the availability of their data in a database not at the time they receive an initial marketing communication but only later, namely when they exercise their right of access under Article 15 of the Regulation and the sender informs them that they obtained the data from the Lusha platform.

§

167. Apart from these cases, which are based on the Authority’s experience, it is in any event inconceivable that the Contacts would have any expectation that their data present on digital platforms and other data held by third parties whom they cannot identify could be collected, processed, grouped into contact profiles, enriched with data from other sources, cross-referenced with other databases, and then constantly updated, for the purpose of making them available to an indefinite number of Customers. 168. Lusha appears to be well aware of this, at least when data is collected from sources other than the platforms to which the data subjects have subscribed. 14 state that: “In some cases, Lusha collects personal data from data subjects where they may not expect it. Lusha does not have an active relationship with data subjects, and the use cases for processing are not primarily for the benefit of the data subjects (rather, they are for the benefit of Lusha’s customers).

§

” 169. The Company decided to offset this lack of awareness and control on the part of data subjects by sending a privacy notice. Given that information and transparency requirements are general obligations applicable to all processing—and thus no particular diligence or exemplary compliance with the regulations can be attributed to the Company—the Company has prepared a Privacy Policy, published on its website, and a Personal Data Notice allegedly sent to each Contact. 170. 3, the Privacy Notice published on the website is entirely unsuitable for informing Contacts about the processing of their data. This policy could only become relevant after the Contact has been made aware, in some way, of the existence of the processing. 171. With regard to the Personal Data Policy, on the other hand, given that it must be understood as the necessary fulfillment of the obligation set forth in Art. 14 of the Regulation rather than a mechanism to counterbalance the data subjects’ inability to foresee further processing of their data, the following issues are noted.

§

Lusha’s decision not to collect personal data directly from data subjects—particularly contact information—means that the Privacy Notice may be sent to an email address that the data subject may not check regularly, no longer use, or does not expect to receive important communications at. In any case, basic information security rules have long advised users not to interact with emails from unknown recipients. This is all the more true if such emails prompt the data subject to click on a link or perform a certain action; it is reasonable to assume that the data subject may view such a communication as a scam attempt and, therefore, choose to ignore it. 172. It should also be noted that Lusha cannot be certain that the contact information in its possession is accurate, since it relies solely on the fact that the same piece of data is cited at least twice in multiple sources. Such a frequency, slightly above one, may be the result of mere coincidence and does not provide adequate assurance of fairness.

§

Conversely, adopting a policy aimed at seeking a higher frequency in the identification of contact information could have avoided the risk of collecting and considering as reliable data that is obsolete and no longer in use by the data subject. This appears to be a limitation of the Data Controller’s business model, resulting from the decision not to collect data directly from data subjects, which falls within the risk that the Data Controller assumes and that should have been the subject of a specific analysis in the VIP. 173. Another factor that compromises the rights and interests of the Contacts—and which the Company has not adequately considered—is the data storage period established by the Company. 5) and in the Personal Data Policy under review (updated as of January 2023), Lusha states that it processes personal data for as long as necessary, unless the data subject updates their information or objects.

§

The specification of this storage period in a context where the Contact may remain unaware of the ongoing processing for a long time is a factor that accentuates the data subject’s dependence on the controller and, therefore, does not allow for a balance to be struck in which the interests of the data controller or third parties prevail over the interests and rights of the data subjects. 174. The Company also identifies certain benefits and opportunities that Contacts may derive from the processing: for example, the possibility of being contacted by recruiters and receiving professional communications relevant to their interests. Given that even these circumstances are merely alleged by the Company but not demonstrated or supported in any way, it must be noted that these examples constitute, if anything, the very reasons why individuals sign up for job-oriented platforms. Thus, in the absence of any other concrete element or circumstance—which is currently not available in the record— these elements can only be used to infer the individual’s interest in registering on a platform and not also a reasonable expectation of receiving job offers or commercial communications outside the platform itself and within a context of processing that is beyond the individual’s control.

§

In addition to the fact that, in general, the presence of data online or on a digital platform does not automatically entail or always authorize third parties to reuse such data for purposes beyond those that led to its publication, it should be noted that contact information such as email addresses and, even less frequently, phone numbers, are accessible on platforms such as LinkedIn. In such cases, the Company has stated that it collects and supplements the missing data by obtaining it from other sources. Certainly in these cases—as the Company is also aware, having addressed the issue in the VIP—the data subject cannot reasonably foresee that their data will be subject to the processing in question. On the contrary, it is more likely to infer that the data subject has no interest in or is averse to receiving commercial communications, given that they have taken steps to ensure their contact information is not available on the platform.

§

176. Another relevant factor is therefore the particular scope of the data collection, insofar as Lusha does not limit itself to collecting data available on the LinkedIn or Salesforce platforms but supplements missing data through various sources, many of which are unknown to the Contacts and, therefore, beyond their control. com). These are all circumstances regarding which Contacts not only have no knowledge or expectation but also no real control or ability to stop the indiscriminate circulation of their personal data. 177. Furthermore, it cannot be overlooked that, with regard to the Contacts’ data extracted from Customers’ emails, we are faced with a disclosure of third party personal data by the Customers to the Company that appears to lack legality and is such as to render the disclosure unlawful (which may potentially give rise to independent accountability on the part of the Customers in other legal proceedings).

§

This is all the more true when one considers that communications between private individuals may be subject to specific protection under Article 15 of the Constitution of the Italian Republic. 178. Furthermore, the facts and findings of the preliminary investigation refute the claim that the Company merely collected “publicly available” data online, insofar as it has been established that information such as email addresses and phone numbers—which are generally not publicly available—was supplemented and collected from other sources unknown to the data subjects. 179. The enormous volume of data collected by Lusha—from a wide variety of sources, particularly third parties—for the purpose of pursuing an economic interest, and in the absence of information sufficient to inform the data subjects, makes it unlikely, on the one hand, that such processing falls within the expectations of the data subjects (more precisely, the Contacts) and, on the other hand, is likely to have significant impacts on them, making them contactable by third parties for unforeseeable purposes (or at least outside the channels made available by the platform through which the data subject shared their data) and giving rise, when the data subjects become aware of the processing of their data, to a feeling of continuous monitoring and surveillance.

§

Therefore, with greater certainty, legitimate interest cannot be considered the appropriate legal basis for the collection of Contacts’ data from the Company’s Customers or from other sources not under the control of the data subjects. 180. This conclusion would also apply to the collection of data from partners or entities belonging to the Company’s group, which, from the outset, with regard to their processing, should be based on an adequate legal basis that legitimizes the disclosure of the data to Lusha (see Art. 130 of the Code). 181. ” In addition, the collection of data online (scraping) rather than directly from the data subjects affects the data subjects’ reasonable expectations (paragraph 94). 182. It is thus established that the processing of personal data has taken place which, although not falling within the special categories of personal data, is likely to expose the data subjects’ private lives to third parties; it has also been established that the Contacts were subject to the processing of their personal data in the absence of any prior relationship with the Company and without being able to reasonably expect that, without their consent, the Company would process their data to make it available to third parties.

§

All of this has had an unjustified impact on the legal rights of the Contacts. In addition to the annoyance of receiving unsolicited communications, as also documented by the reports and complaints received by the Authority, the possibility of Surveillance of their personal and professional lives cannot be ruled out, nor can the inability to control information pertaining to them and the violation of the Contacts’ right not to be subjected to covert processing and/or interference with their confidentiality for the pursuit of the Company’s economic interests. 4. Measures to Mitigate the Impacts of Processing 183. If the outcome of the balancing test does not demonstrate that the interest pursued can outweigh the interests, the data subject rights and freedoms, the controller may still consider implementing mitigation or attenuation measures in order to create more favorable conditions for the data subject and thereby achieve a rebalancing of interests.

§

184. , and, prior to that, in the Art 29 Working Party’s “Opinion 6/2014 on the concept of legitimate interest,” dated April 9, 2014, p. , which referred to “additional safeguards”) specify, in para 57, that these mitigation measures must not be confused with the general obligations that the controller is required to adopt to ensure compliance with the GDPR regardless of the lawfulness basis adopted. In this sense, mitigation measures are safeguards that go beyond those required by the Regulation. 185. The Company has established certain mechanisms that can be equated with mitigation measures, namely: the adoption of a “credit”-based system that Customers must purchase to access data, in order to prevent the mass extraction of data from the database via free-text search; and, without prejudice to the right to object to processing at any time, the adoption of a voluntary seven-day cooling-off period for the data subject to opt out, in order to prevent the addition of data to the database from the outset.

§

186. With regard to the credit system that allows access only to a predetermined number of contact records rather than the entire database, even if this may be considered a good measure, the protection actually afforded to data subjects is, in practice, of little significance because it is contingent upon the financial resources of the customers. In other words, nothing prevents customers from purchasing the credits necessary to obtain the amount of contact data they deem sufficient for their purposes—and, theoretically, all available data. Consequently, the level of protection that this measure affords data subjects is such that it does not result in a significant shift in the balance of the interests involved. 187. With regard to the voluntary cooling-off period granted to contacts, it should be noted that the opt-out is a right derived from the right to object that Article 21 of the Regulation mandates in all cases where processing is based on the grounds of lawfulness set forth in Article 6(1), subparagraphs (e) or (f) of the GDPR, granting the data subject 7 or 14 days to express their wish not to be included in the database cannot be considered an adequate safeguard due to certain factual elements that the Company has not adequately weighed.

§

188. As already noted, in fact, the Company sends the Privacy Notice to an email address that it cannot be certain is used or monitored by the data subject. When such an address is collected from other sources or otherwise reconstructed based on available information, it cannot be ruled out that the email address is not consistently monitored by the data subject. In any case, the data subject may not consider the communication to be reliable. Furthermore, even if the data subject does consider the communication to be reliable, 7 or 14 days may still not be sufficient—especially in the absence of additional reminders or notifications regarding the impending deadline— to: adequately research the Company’s identity, learn about the characteristics of the services offered, understand the consequences of the processing, as well as assess potential benefits, and, if necessary, express their objection.

§

Consequently, the Authority considers that a reflection period of 7 or 14 days—given the specific manner in which the processing was carried out—is excessively short and disproportionate to the scope of the processing and the potential impacts on the legal rights of the Contacts. 189. In conclusion, the Authority considers that the measures adopted by the Company to mitigate the impacts of the processing are not sufficient to warrant a reassessment of the balancing of interests in favor of the controller. 5. On the Actual Inadequacy of the Lawfulness Basis 190. In light of the foregoing, given the context, the characteristics, and the manner in which the Company has, in practice, processed the personal data of the Contacts, as well as the nature of the rights and interests involved, the reliance on the legal basis set forth in Art. 6(1)(f) of the Regulation cannot be considered adequate.

§

This is because, to summarize the above: - making the Contacts’ data available for the pursuit of the economic interests of the Company and its Customers cannot be considered a “legitimate” interest within the meaning of Article 6(1)(f) of GDPR, insofar as the law requires the prior consent of the contracting party or user as the legal basis for the transfer of personal data to third parties for independent commercial purposes; - The Company collects a vast amount of personal data from multiple sources, including some that cannot be considered public insofar as they are extracted from its Customers’ private interpersonal communications, or through integration with IT systems, or acquired from third parties. ” Furthermore, the Company collects data on public officials and individuals holding institutional roles who, as such, do not act to pursue independent professional interests and, therefore, are not necessary for the pursuit of the Company’s and its Customers’ interests.

§

However, with regard to the interest in preventing or avoiding fraud, the Company has not demonstrated that it cannot achieve the same interest through less intrusive processing methods; - given the nature of the interests and rights being balanced, the absence of any relationship between the Company and the Contacts, the fact that it cannot be argued that the data subjects could have had reasonable expectations of being subject to the processing described, as well as the limited effectiveness of the measures to mitigate the impacts of the processing, it has not been demonstrated that the pursuit of the data controller’s or third parties’ interests outweighs the interests or fundamental rights and freedoms of the data subjects. 191. Ultimately, the service offered by the Company—in this specific case, in a manner that does not comply with the law—mirrors that already offered by other digital service providers, with the difference that the latter base their activities on the processing of data provided directly by the data subjects and grant them greater control over their own data.

§

Only with regard to such digital service providers is it plausible to argue that data subjects aim to establish business relationships and/or can expect to receive job offers through the channels and by the means made available by the platform, or to use the platform itself to verify the information in their possession for anti-fraud purposes. 192. The Authority therefore confirms and establishes a violation of Article 5(1)(c) of the Regulation with regard to the principle of data minimization, as well as a violation of Articles 5(1)(a) and 6 of the Regulation to the extent that, in violation of the principles of lawfulness, fairness, and transparency, the basis of lawfulness referred to in Art. 6(1)(f) of the Regulation cannot be considered, in this specific case, an adequate legal basis. 193. Finally, the Authority has decided to dismiss the alleged violation of Article 7 of the Regulation and Article 129 of the Code.

§

6. Processing of Data Relating to Public Figures and Compliance with the Principles of Data Protection by Design and by Default 194. With regard to the collection of data on public figures, the Company acknowledged and justified the collection due to a technical flaw in the exclusion algorithm, which was unable to filter out particularly specific job titles. 195. The Company has, however, justified the processing on the basis of: the absence of a specific obligation under the Regulation to adopt measures preventing the collection of data on public figures; as well as the necessity of processing such data. According to the Company, all of this must take into account the fact that public figures have a lower expectation of confidentiality than other data subjects. 196. First, it should be clarified that no individual is, in general and in the abstract, subject to a limitation of the rights to respect for private and family life and to data protection set forth in Articles 7 and 8 of the Charter of Fundamental Rights of the EU.

§

If anything, pursuant to Article 52 of the same Charter, the Regulation allows, on a case-by-case basis, for the right to data protection to be restricted to the extent that such restriction is proportionate to the purpose of pursuing objectives of general interest or other rights. 197. In this context, the case law and guidelines cited by the Company all refer to the so-called “right to be forgotten,” as established beginning with the Court of Justice’s first judgement of May 13, 2014, Costeja, C-131/12. It is abundantly clear that this reference is not appropriate to the case at hand, insofar as, in the context of applying the right to be forgotten, the notoriety or public relevance of the individual involved in the publication and/or republication of information and facts pertaining to them is only one of the elements in the balancing of multiple fundamental rights: the individual’s right to confidentiality and/or data protection, on the one hand, and the right to report news and the public interest in being informed about events of particular significance and current relevance, on the other.

§

Furthermore, the possibility of providing for exemptions or exceptions to personal data protection rules to “reconcile” this right with the right to freedom of expression and information is expressly provided for in Art. 85 of the Regulation. Therefore, only when rights of equal standing to data protection are present—and, in particular, only if the right to report news is exercised in compliance with sector-specific regulations and within the limits defined by constitutional and supreme court case law—may an individual’s confidentiality be restricted to the extent and for the duration necessary to satisfy the public interest. 198. None of the conditions specific to the right to be forgotten apply to the case under review. Furthermore, no public or legally relevant interest in obtaining the contact information of public officials for the purposes described above has been identified or demonstrated by the Company.

§

199. Given that the Authority does not agree with the argument that only a small number of profiles of public figures were available in the Lusha database, the economic interest pursued by the Company negates the need to collect and make available to Customers information on such individuals, who, by their very nature, do not pursue independent business interests. Therefore, in the absence of any other justification for the collection of such data—which, in any case, was not provided by the Company—the Authority reiterates that the collection of such data is not necessary to pursue the Company’s own business purposes or those of its customers. 200. ). 201. , filters, domain blocking, and periodic checks) should be considered measures voluntarily adopted as a matter of prudence and in the absence of a specific obligation under the Regulation. Given that the GDPR is a “general” regulatory act—and thus could not have imposed specific prohibitions on processing or particular security obligations—the lack of necessity for processing data from public entities stems precisely from the purpose pursued by the data controller and the methods identified by the controller.

§

We are therefore not dealing with a “voluntary assurance” or a “broken promise” on the part of the data controller, but rather with measures that Lusha adopted—albeit in an ineffective manner—based on the obligations arising from the principles known to it: those set forth in the combined provisions of Articles 5(1)(c), 24, 25, and 32 of the Regulation. 202. The investigation conducted and the documentation on file show that, although the Company clearly defined the risk of collecting data from public figures, it did not implement effective measures to exclude such information. This demonstrated the absence of technical and organizational measures aimed at implementing the principles of personal data protection set forth in Art. 25 of the Regulation (data protection by design and by default). 203. The Authority confirms and establishes the violation of the aforementioned principles and, therefore, of the provisions set forth in Articles 5(1)(c) and 25 of the Regulation.

§

5. CONCLUSIONS 204. In light of the assessments set forth above, the allegations set forth in the notice initiating the proceedings pursuant to Art 166 of the Code are partially confirmed, since the statements made during the preliminary investigation and the defenses raised were not sufficient to fully rebut the findings made by the Office; furthermore, none of the cases provided for in Art. 11 of the Data Protection Authority’s Regulation No. 1/2019 apply. 205. Such conduct is attributable to the Data Controller, at least on the grounds of negligence, to the extent that it has been demonstrated—and in some cases documented in the VIP—that Lusha was aware of the relevant regulations (to the point of applying them spontaneously) as well as the risks associated with its processing activities. Despite its knowledge of the regulations, the Company only formally—and in any case, in a deficient manner—balanced its economic interests against the data subject rights, and failed to adequately apply the rules and principles designed to safeguard the data subject rights and control.

§

Therefore, the Authority considers that the Company could well have avoided the errors it committed by exercising ordinary diligence. In this regard, according to case law, the good faith referred to in Article 3 of Law No. 689/1981 serves as a ground for excluding administrative accountability only if it is established that the offender did everything possible to comply with the legal requirement, such that no blame can be attributed to them. In this regard, see Civil Cassation, Section II, November 29, 2023, No. 33121, which holds that simple negligence is sufficient to establish the subjective element of the offense, whereas an error regarding the lawfulness of the conduct (“good faith”) may serve to exclude administrative accountability only when it is unavoidable; for this purpose, a positive factor—external to the offender—must exist that is capable of leading the offender to believe in the aforementioned lawfulness, in addition to the condition that the perpetrator has done everything possible to comply with the law and that no blame can be attributed to him, such that the error was blameless—that is, not preventable through ordinary diligence (see, among others, Civil Cassation, Section II, June 11, 2007, No.

§

13610). 206. Therefore, the Authority finds that the conduct of the Data Controller in relation to the processing of Contact data was unlawful, in violation of the following provisions: a) Article 5(1)(a) and (c); and Article 6 of the Regulation, for having carried out processing in violation of the principles of lawfulness, fairness, and transparency, as well as data minimisation, and for having based the processing on an inadequate legal basis. Since such processing, which is still ongoing, must be considered to have been carried out from the outset without a valid basis of lawfulness, it is necessary to prohibit the processing of the personal data of Contacts located in Italy and, consequently, to order the erasure of the data of Contacts located in Italy. It is also necessary to impose a monetary penalty under the terms set forth below; b) Articles 5(1)(a) and 12 of the Regulation, with reference to the violation of the principle of transparency and its corollaries, as described above.

§

For this violation as well, it is necessary to impose a financial penalty under the terms set forth below; c) Articles 5(1)(c) and 25 of the Regulation, as the Data Controller failed to implement adequate technical and organizational measures to prevent the collection of data from public entities. Since the Data Controller has stated that it has deleted such data and ceased processing it, it is not necessary to impose a corrective measure, but only a monetary penalty under the terms set forth below. 207. The Authority, however, orders the dismissal of the alleged violations referred to in Articles 7; 13(1)(a) and (c); and 14 of the Regulation and Article 129 of the Code. 6. INJUNCTION ORDER 208. Pursuant to Article 58(2)(i) of the Regulation and Article 166 of the Code, the Data Protection Authority has the power to impose an administrative fine pursuant to Article 83 of the Regulation by issuing an injunction order.

§

” 209. Given that the violation of the aforementioned provisions occurred as a result of a single act—that is, in connection with the same processing operation or related processing operations—Art 83, para 3, of the Regulation applies, pursuant to which the total amount of the administrative fine shall not exceed the amount specified for the most serious violation. Given that, in the present case, the most serious violations are subject to the penalty provided for in Article 83, para 5, of the Regulation, the amount of the administrative fine shall be set at a maximum of 20,000,000 euros or, for enterprises, up to 4% of the total annual worldwide turnover of the preceding fiscal year, whichever is higher. 210. To determine the maximum amount of the administrative fine, reference must be made to the enterprise’s turnover, as defined in Articles 101 and 102 of the TFEU, as clarified in Recital 150 of the Regulation.

§

Since the documentation on file shows that Lusha Systems Inc. is wholly owned by Lusha Systems Ltd. (the latter is also expressly designated as a joint controller in the “Privacy Notice on the Processing of Personal Data” updated in May 2026), the turnover indicated in the consolidated financial statements of Lusha Systems Ltd. 2). Consequently, the maximum statutory fine in the present case is set at 20,000,000 euros. 211. The amount of the administrative fine must be determined based on the circumstances of each individual case, taking due account of the factors set forth in Art. 83(2) of the Regulation: - the gravity of the violations (Articles 83(2)(a) and 83(para) of the GDPR), taking into account the subject matter and purposes of the processing, which are attributable to commercial activities; the fact that the violations concerned non-compliance with the basic principles of the relevant legislation; such as determining the lawfulness of the processing, as well as the high number of Italian contacts or data subjects involved in the unlawful processing (in the order of XX) and the fact that the unlawful collection of data is structural in nature rather than isolated; - as an aggravating factor, the negligent nature of the Data Controller’s conduct (Art.

§

83(2)(b) of the GDPR); - as a mitigating factor, the fact that the Data Controller has not previously been a recipient of a corrective or punitive measure by the Data Protection Authority (Art. 83(2)(e) of the GDPR); - the fact that the processing did not involve special categories of personal data or data relating to criminal convictions and offenses (Article 83(2)(g) of the GDPR); - as a further mitigating factor, the cooperation demonstrated with the supervisory authority to remedy the breach and limit its potential negative effects, as well as the general cooperation during the investigation, as evidenced by the Company’s active participation in the proceedings, including through the appointment of an Italian law firm (Art. 83(2)(f) of the GDPR); - adherence to certification mechanisms (Art. 83(2)(j) of the GDPR); - as a further mitigating factor, data on revenue and the degree of competition in the relevant market (Art.

§

83(2)(k) of the GDPR). 212. Based on all of the above factors and the principles of effectiveness, proportionality, and deterrence set forth in Art. 00 (two million/00), equal to 10% of the maximum penalty. 2. Additional Sanction 213. In the case at hand, it is deemed that the ancillary sanction of publishing this injunction order on the Data Protection Authority’s website, as provided for in Art. 166, paragraph 7, of the Code and Art. 16 of the Data Protection Authority’s Regulation No. 1/2019, should also be applied, given the particular gravity of the violations and the particularly reprehensible nature of the conduct, as well as—and above all—the fact that the processing carried out by the Company, particularly as a result of the methods used to collect Contact data, is likely to have effects and repercussions on subsequent processing of personal data carried out by its Clients. NOW THEREFORE, THE DATA PROTECTION AUTHORITY 214.

§

, represented by its pro tempore representative, with registered office in Boston, MA 02199, USA, in its capacity as controller, for violating Articles 5(1)(a) and (c); 6; 12; and 25 of the Regulation, as set forth in the reasoning below, and: a) pursuant to Article 58(2)(f) of the Regulation, prohibits any further processing of the data of data subjects located in Italian territory that was collected without an adequate legal basis; b) pursuant to Article 58(2)(g) of the Regulation, orders the erasure of the data of data subjects located in Italian territory that were collected without an adequate legal basis; c) pursuant to Article 58(1)(a) of the Regulation and Article 157 of the Code, requires the company to notify the Authority, within 60 days of the notification of this order, confirmation of compliance with the measures imposed in subparagraphs (a) and (b) above. ORDERS 215. 00 (two million/00) euros as an administrative fine for the violations set forth in the grounds.

§

ORDERS 216. 00 euros (two million/00), in accordance with the procedures set forth in the annex, within 30 days of the service of this order, failing which the relevant enforcement measures will be taken pursuant to Art. 27 of Law No. 689/1981. It is hereby noted that, pursuant to Article 166, paragraph 8, of the Code, within the time limit set forth in Article 10, paragraph 3, of Legislative Decree No. 150 of 2011 for filing an appeal, the offender may settle the dispute: a) by complying with the Data Protection Authority’s requirements; b) by paying an amount equal to half of the imposed penalty. IT IS HEREBY ORDERED 218. the publication of this order, pursuant to Articles 154-bis, paragraph 3, of the Code and Article 37 of the Data Protection Authority’s Regulation No. 1/2019, as well as the imposition of the ancillary penalty of publishing the injunction order on the Data Protection Authority’s website, as provided for in Article 166, paragraph 7, of the Code and Article 16, paragraph 1, of the Data Protection Authority’s Regulation No.

§

1/2019; 219. and, pursuant to Article 17 of the Data Protection Authority’s Regulation No. 1/2019, the recording of the violations and the measures adopted in accordance with Article 58(2) of the Regulation in the Authority’s internal register provided for in Article 57(1)(u) of the Regulation. 220. Pursuant to Article 78 of the Regulation, as well as Article 152 of the Code and Article 10 of Legislative Decree No. 150 of September 1, 2011, an appeal against this decision may be filed with the ordinary courts, by filing an appeal with the ordinary court of the jurisdiction specified in the aforementioned Art 10, under penalty of inadmissibility, within thirty days from the date of notification of the decision, or within sixty days if the appellant resides abroad. Rome, July 14, 2026 THE PRESIDENT Stanzione THE RAPPORTEUR Stanzione THE SECRETARY GENERAL Montuori