Skip to content

Lusha Fined €2 Million for Email Scraping

Lusha Fined €2 Million for Email Scraping

Italy’s data protection authority (GPDP) has fined B2B data platform Lusha €2 million after finding it unlawfully collected, generated and sold business email addresses and phone numbers. The regulator also ordered the company to stop processing unlawfully collected personal data relating to individuals in Italy and delete that data.

According to the GPDP, Lusha built its database by collecting business contact information from multiple sources, including public websites, social media profiles, third-party data brokers, browser extensions, customer integrations and community contributions. The platform then made the data available to paying subscribers for sales, marketing and other commercial purposes.

The regulator also found that Lusha generated some corporate email addresses by analysing common company email patterns, such as firstname.lastname@company.com, instead of obtaining the addresses directly from the individual.

During the investigation, Lusha argued that it notified affected individuals by email and gave them seven days to opt out before their details were added to the database. However, the GPDP said that period was too short because someone could easily miss the notification email and lose the opportunity to object before their information became available through the platform.

The authority also found that Lusha continuously updated and monitored professional information over time. That ongoing tracking meant the GDPR applied to the company’s activities, even though Lusha does not have an establishment in the European Union.

The GPDP concluded that these practices did not have a valid legal basis under the GDPR or Italy’s privacy laws. It rejected Lusha’s reliance on “legitimate interest,” saying the large-scale collection, enrichment and commercial distribution of contact information was not justified under that legal basis.

If you send cold email campaigns or buy contacts from third-party prospecting databases, then you should review where your contact data comes from. Consider asking your provider how email addresses were obtained, whether individuals were properly informed, and what legal basis supports the collection and sale of those records. You should also take note of the 5th paragraph about GDPR.

Here are the full details on the GPDP’s investigation and findings (long read ahead).

Also read about Italy’s Garante Email Tracking Pixel Rules

Read by 2,300+ Email Marketers

Join 2,300+ email marketers who receive daily updates on the latest email marketing news, AI-powered email innovations, industry trends, and more.


Categories: Category: Email Marketing News
Elvis M.

I have over 10 years of experience developing email marketing tools, having worked on a number of projects, including helping a bank with over 20 million customers run its email marketing. I also created an email-related WordPress plugin with over 30,000 installs and a self-hosted email marketing platform that was acquired. Most recently, I developed this Contact Exporter Google Workspace App. I am also a media and communication graduate and a certified journalist.

Email Elvis M.

Latest Posts