This is a permanent edition. It carries the briefing exactly as published on this date and does not change.
Italian Garante fines Lusha EUR 2 million for unlawful data processing and sale of personal data
Fine: EUR 2 million
The Italian Garante has fined data broker Lusha EUR 2 million for monitoring and selling the personal data of a large number of individuals without a lawful basis. The authority found that Lusha collected personal data, including professional contact details, from various sources and made it available for commercial purposes. The decision confirms the Garante's focus on large scale data brokerage, and the penalty reflects failures of transparency and lawful basis under the GDPR rather than a security incident.
A data broker operating in the EU collects professional contact details from publicly available sources and sells them to third parties for marketing purposes. The Garante privacy issues a significant fine against a similar entity for unlawful processing and sale of personal data. What is the most critical compliance aspect this data broker must immediately review to mitigate similar enforcement risks?
The adequacy of their data security measures to prevent breaches.
The transparency of their privacy policy regarding data collection sources.
The existence of a valid lawful basis, such as consent or legitimate interest, for both collection and sale of data.
The geographic location of their data storage servers to ensure data residency.
Ransomware groups are now routinely using EDR kill techniques to disable endpoint detection and response tools before initiating encryption. This advanced tactic, once specialized, has become standard practice among leading ransomware threats, as detailed in Halcyon's Q2 2026 Ransomware Evolution Report. The Gentlemen, a prominent ransomware group, is noted for systematically incorporating EDR or antivirus shutdown into their attack chains.
A data leak at the Tribeca Film Festival has exposed personal information belonging to A-list directors, actors, and celebrities. This incident highlights the risks associated with data held by event organizers and the potential for high-profile individuals to be affected by breaches. The exposure of sensitive data could lead to various privacy and security concerns for those impacted.
The ICO has updated its website with data on cyber investigations, distinguishing between incidents reviewed and full investigations leading to potential regulatory action. Additionally, the ICO detailed its robust approach to recovering fines, including pursuing formal recovery actions and exercising creditor rights in insolvency cases. This transparency provides insight into the ICO's enforcement processes and its commitment to ensuring compliance.
Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.