Italy’s data protection authority (GPDP) has fined B2B data platform Lusha €2 million after finding it unlawfully collected, generated and sold business email addresses and phone numbers. The regulator also ordered the company to stop processing unlawfully collected personal data relating to individuals in Italy and delete that data.
According to the GPDP, Lusha built its database by collecting business contact information from multiple sources, including public websites, social media profiles, third-party data brokers, browser extensions, customer integrations and community contributions. The platform then made the data available to paying subscribers for sales, marketing and other commercial purposes.
The regulator also found that Lusha generated some corporate email addresses by analysing common company email patterns, such as firstname.lastname@company.com, instead of obtaining the addresses directly from the individual.
During the investigation, Lusha argued that it notified affected individuals by email and gave them seven days to opt out before their details were added to the database. However, the GPDP said that period was too short because someone could easily miss the notification email and lose the opportunity to object before their information became available through the platform.
The authority also found that Lusha continuously updated and monitored professional information over time. That ongoing tracking meant the GDPR applied to the company’s activities, even though Lusha does not have an establishment in the European Union.
The GPDP concluded that these practices did not have a valid legal basis under the GDPR or Italy’s privacy laws. It rejected Lusha’s reliance on “legitimate interest,” saying the large-scale collection, enrichment and commercial distribution of contact information was not justified under that legal basis.
If you send cold email campaigns or buy contacts from third-party prospecting databases, then you should review where your contact data comes from. Consider asking your provider how email addresses were obtained, whether individuals were properly informed, and what legal basis supports the collection and sale of those records. You should also take note of the 5th paragraph about GDPR.
Here are the full details on the GPDP’s investigation and findings (long read ahead).
Also read about Italy’s Garante Email Tracking Pixel Rules
