In 2026, the Italian Data Protection Authority sanctioned three Italian companies for using contacts purchased from Lusha and Apollo, and later sanctioned Lusha itself. Businesses purchasing B2B data must verify its origin and the lawfulness of the entire data supply chain: provider reputation, certifications and compliance claims are not enough. Bancomail documents the source, collection date, privacy notice and subsequent transfers for each record, making the data supply chain verifiable before purchase.
Lusha, Apollo and the Italian Data Protection Authority: Data Buyers Are Accountable for the Supply Chain

In January 2025, a small lead generation business purchased 2,500 contacts from Apollo, the US-based B2B contact platform, including names, email addresses, phone numbers and job titles. It paid $224. The contacts were used for email campaigns, with the source disclosed at the bottom of each message and an option to unsubscribe.
One recipient filed a complaint with the Italian Data Protection Authority: they had never registered with Apollo, and no one had informed them that their data was being processed.
Who pays? You might expect the answer to be Apollo, the company that collected and sold the data. Instead, the Authority sanctioned the buyer.
The buyer pays
The defence was one many companies might have used: Apollo stated that it was GDPR compliant, participated in the EU-US Data Privacy Framework and held ISO 27001 certification. What more could the buyer have done?
Quite a lot, according to the decision issued on 14 May 2026. A generic statement of compliance proves nothing. The EU-US Data Privacy Framework concerns transfers of personal data to the United States, while ISO 27001 concerns information security. Both are significant, but they address different issues. Neither tells you where a contact came from, whether the individual was informed, or whether that data could lawfully be used for the intended purpose.
Another point is worth noting: the Italian Data Protection Authority explicitly stated that, within those proceedings, it could not determine whether Apollo itself had collected the data lawfully. It did not need to. The party held accountable was the company that used the data.
The fine was €1,500, calibrated to the size of a sole proprietorship. It may sound modest, but the real cost lies elsewhere: a ban on processing the data, mandatory deletion and publication of the decision on the Authority’s website. The purchased list becomes unusable, campaigns stop, and the company’s name remains publicly associated with the decision.
Same day, different provider
The Apollo case was not an isolated one. On the same day, 14 May, the Authority concluded two almost identical proceedings against two companies that had obtained their contacts from Lusha.
The first had purchased approximately 300 contacts for email campaigns: €4,000. The second, a consulting company with a single employee, had collected 700 phone numbers and 400 email addresses using the Lusha plugin on LinkedIn, and had called a professional whose phone number was not even publicly visible on LinkedIn: €1,000. Both cases resulted in a ban on processing, deletion of the data and publication of the decision.
In those decisions, the Italian Data Protection Authority took a broader view. It highlighted the growth of platforms selling contact details without documenting how those contacts were collected or the legal basis on which they are transferred, alongside buyers who rely on the provider’s reputation or professional appearance. According to the Authority, supply-chain control is one of the most vulnerable points in marketing.
Translated from regulatory language: you are accountable for it.
Then it was the seller’s turn
In July, the Italian Data Protection Authority turned directly to Lusha Systems: a €2 million fine, a ban on processing the data of individuals in Italy and an order to delete the data. According to the Authority, the contact details offered for sale included those of senior institutional figures, public administration officials, law-enforcement personnel and members of the judiciary. An enterprise-grade way of getting noticed by exactly the wrong people.
The Authority raised three main issues. Provenance: data had also been collected through social-media scraping and purchases from other data brokers, creating a supply chain that downstream users could not reconstruct. Use: rather than a one-off collection, profiles were continuously updated over time, an activity the Authority described as monitoring or tracking. Transparency: individuals had ended up in a database without knowing it and discovered this only when they began receiving calls and emails. The complaints included the two cases from May.
For accuracy: the decision against Lusha is currently suspended. On 8 September, the Court of Rome issued an interim order and the proceedings challenging the decision are still pending. The final outcome concerning the seller has therefore not yet been determined. The May decisions concerning the buyers remain in place.
Public does not mean free to use
In 2015, I wrote an article arguing that when a company makes an email address public, even on a billboard beside a motorway, it does so to be contacted: to receive enquiries, but also potentially to receive relevant business proposals. I still believe that.
A professional’s mobile number obtained through a plugin from a profile where they had not even published it is another matter. So is a continuously updated profile that follows a person from one job to the next.
What matters is how the data became public, who made it public and for what purpose. And if the company selling it to you cannot answer those questions, the problem becomes yours.
The questions to ask before paying
Following the investigation, the Apollo buyer introduced a preventive supplier verification process covering registered office, EU representative, privacy notices and consent. The Lusha case adds the questions that were missing: where does the data come from, is it monitored over time, and how can someone leave the database if they no longer want to be included?
We have asked ourselves these questions. Here are our answers.
Where is the provider based?
In Genoa, Italy. Bancomail S.p.A. has been operating since 2001 and is directly subject to the GDPR and to the Italian Data Protection Authority, without intermediaries.
Does it have a representative in the European Union?
We do not need one because we are established in the EU. We also have an appointed Data Protection Officer, who can be contacted at [email protected].
Where does the data come from?
From validated public sources, with the provenance chain documented for every record: source, collection date, privacy notice provided and transfers made. We explain the process in detail in our article on the documented lifecycle of each individual data record.
Is the data tracked over time?
We verify it periodically: we check whether an email address exists and remains active, not where a person works from one job to the next. That is the difference between maintaining data and tracking an individual.
Have the data subjects been informed?
Yes. We provide privacy information to contacts included in our database and maintain records of those notices.
How can someone leave the database?
Through our internal opt-out register: anyone who asks to be removed is removed and is not reintroduced during a subsequent update.
What about consent?
We guarantee the collection and transfer of the data up to the point of delivery. How the data is subsequently used, and through which channel, is determined by the recipient as an independent data controller. The rules applicable to different channels are explained in our Permission Marketing guidelines.
This applies to every provider, including us: if the answer is just a “GDPR compliant” badge, that is not much. If the answer is documented, then there is something you can actually assess.
Companies and professionals: the difference
Our database consists predominantly of companies, but it also includes contact details that can be attributed to natural persons acting in a professional capacity, such as doctors and independent professionals. For these records, the chain remains the same: validated public source, documented provenance, privacy information provided and internal opt-out register. No profiles built by combining social-network data with information from other brokers, and no tracking of an individual’s career over time.
We tell buyers how to start correctly: by providing the information required under Article 14 of the GDPR before any promotional communication, identifying Bancomail as the source and giving recipients the choice to remain, specify what they wish to be contacted about, or opt out. Introduce yourself before you sell. It works better than any clever subject line.
And when we transfer a database, we transfer it outright: the customer becomes the data controller and identifies Bancomail as the source in its own privacy notice. Our name therefore appears in the inboxes of the people to whom the data relates. That is the opposite of a database whose existence people discover only when their phone rings.
We have documented the rest in our GDPR Compliance documentation and Database Policy.
A famous provider is not a shield. A documented data supply chain is where due diligence starts.







