Something Inc.Schedule a free consultation
STRATEGY

That guessed email address is now personal data

Italy fined Lusha two million euros and ruled that an address a machine inferred from a name and a company domain is personal data. If your enrichment waterfall guesses, cold email GDPR exposure just moved upstream.

JBJosh BernsteinManaging Partner · AUG 14, 2026 · 10 MIN READ
2M
euro fine issued by Italy's Garante
JUL 14
date of the decision, announced July 27
5
GDPR articles cited in the finding
0
EU offices the company needed for jurisdiction to attach

Almost every outbound stack in the world does the same small thing. It cannot find a real address for a prospect, so it looks at the company's domain, looks at how other addresses there are formatted, and constructs one. First dot last at the domain. Nobody thinks of that as collecting data. It feels like arithmetic.

Italy's data protection authority thinks of it as collecting data. In a decision dated July 14 and announced July 27, the Garante fined the contact data provider Lusha two million euros, and among the findings was this: where the company lacked a verified address, its systems inferred one from a person's name and their employer's domain pattern, and those inferences were treated as personal data about a real individual. That single line is the part of cold email GDPR practice that most teams have never thought about.

Not the sending. The guessing.

That distinction is worth sitting with, because it relocates the risk. Most outbound compliance work has been designed around the moment a message leaves: consent language, opt-out mechanics, suppression lists, sending policy. All of that assumes the contact record itself was fine and the only question was what you did with it. This decision questions the record.

The decision, in plain terms

I am going to be careful here, because I am not a lawyer and you should not treat any of this as legal advice. What follows is what the decision reportedly says and what it plausibly means for how outbound teams buy and use data. Get your own counsel on your own facts.

The Garante cited five provisions: Article 5(1)(a) on lawfulness, fairness and transparency, Article 5(1)(c) on data minimisation, Article 6 on lawful basis, Article 12 on transparent communication with data subjects, and Article 25 on data protection by design and by default. The finding on lawful basis is the load-bearing one. The regulator did not accept legitimate interest as an adequate basis for the processing as it was carried out.

ARTICLE CITEDWHAT IT GOVERNSWHY IT LANDED HERE
5(1)(a)Lawfulness, fairness, transparencyPeople had no idea their details were in the database
5(1)(c)Data minimisationCollecting and inferring beyond what the purpose required
6Lawful basisLegitimate interest was found not to cover this processing
12Transparent communicationRights and information not made accessible to data subjects
25Protection by design and defaultInference was built into the product, not bolted on

The Article 25 point is quietly the sharpest. Data protection by design means the architecture is in scope, not just the policy. When address inference is a core product feature rather than an edge case, you cannot characterise it as an unfortunate side effect of a legitimate service.

WHAT THIS IS NOTThis is not a ruling that cold email is illegal, and it is not a ruling that B2B contact data cannot be sold. It is a ruling about how one company built and justified its dataset. The reasoning is what travels, not the outcome.

Why cold email GDPR exposure moved upstream

For years the compliance conversation in outbound has been about the send. Do you have a lawful basis for contacting this person. Is there an opt out. Is the message relevant to their professional role. All of that still matters.

This decision points a level earlier, at where the address came from. And it lands on the least defensible part of the pipeline, because a verified address at least represents something that existed. A pattern guess represents a hypothesis about a person, generated without their involvement, that becomes a record about them the moment it is stored.

Think about how that sounds in a complaint. Nobody gave you this address. Nobody published it. A machine assumed it, wrote it down next to my name and my employer, and sold it. The regulator agreed that the assumption is data about me.

1Your vendor's method is now your diligence problemVerified, sourced, and inferred are three different things sitting in the same CSV column. If your provider will not tell you the split, you cannot describe your own processing.
2Waterfall enrichment mixes the three by designThe whole point of a waterfall is to fall through to a guess when the good sources fail. Coverage rates north of ninety percent usually mean the last step is doing a lot of work.
3Legitimate interest needs the balancing test written downIt is not a checkbox. If you have never produced a documented assessment weighing your interest against the individual's rights, you do not have the basis you think you have.

None of this is exotic. It is the same discipline any serious cold email programme should already run on data provenance, applied with more teeth. The change is that the cost of getting it wrong now has a number attached.

The jurisdiction finding is the bigger one

Here is the part that should worry US vendors and their customers more than the fine itself, because a two million euro penalty is survivable for a funded company and a jurisdictional theory is not.

The Garante asserted jurisdiction under Article 3(2)(b), the provision covering the monitoring of behaviour of people in the Union. The reasoning: the company refreshed its dataset on a weekly cycle, and continuously re-checking whether a person's role, employer, and contact details have changed is monitoring their behaviour. No EU office required. No EU entity required. The refresh cadence was enough.

A weekly refresh is not a technical detail. It is the thing that turned a static list into ongoing observation, and observation is what the regulation attaches to.

Read that against how modern contact platforms market themselves. Always current. Continuously verified. Job change alerts. Real-time updates. Every one of those phrases describes a refresh cycle, and the refresh cycle is precisely what the regulator pointed at. The feature list is the exposure.

VENDOR CLAIMWHAT IT DESCRIBESHOW THE REASONING READS IT
Continuously verified dataA recurring re-check of each recordOngoing monitoring of the individual
Job change alertsDetecting a change in employmentTracking a person across employers
Weekly or daily refreshA crawl and update cadenceThe cadence that grounded jurisdiction
Ninety percent plus coverageHigh fill rate on contact fieldsLikely heavy reliance on inference

If you are a US company buying from a US vendor and sending to European prospects, the comfortable assumption has been that distance provides insulation. This decision says the vendor's insulation is thinner than assumed, and it says nothing reassuring about yours. We looked at a related pattern when a German court ruling put liability on AI-generated statements, and the shape is the same: European regulators are attaching consequences to systems built elsewhere, on the basis of who the system touches.

What the pattern guess actually is

Worth being concrete about the mechanic, because a lot of people running outbound have genuinely never looked at it. It happens inside a vendor's infrastructure, it takes milliseconds, and it arrives in your sequencer looking identical to a verified address. There is no field in most exports that tells you which is which, which is itself part of the problem.

The inference step, stated plainly● LIVE
Known: person name, employer, employer domain
Known: the domain's dominant address format, learned from
other addresses observed at that domain
 
Output: a constructed address for a person who never
published one
 
Stored: as a contact record, attached to their name,
title and employer, and sold or licensed onward
 
Not done: verification with the individual, notification,
or any opportunity to object before storage

Written out like that, the finding stops being surprising. The output is a record about an identifiable person, generated and retained without their knowledge. That is squarely the kind of thing the regulation was written about, and the fact that the arithmetic is simple has never been a defence.

There is a fair objection to all of this, and it deserves a hearing rather than a dismissal. Business contact details are, in most of the world, treated as low-sensitivity information. A work address is not a medical record. The whole professional economy runs on people being reachable at work, and a rule that made B2B contact impossible would be a strange rule.

The counter, and I think it is the stronger one, is that the objection defends publication and the ruling addresses construction. If someone puts their work address on a conference page, a company directory, or their own site, they made a choice to be reachable. When a system invents an address they never published, no choice was made by anyone except the vendor. Those are different situations wearing the same label, and collapsing them is how the industry ended up here.

Cold email GDPR housekeeping that is worth doing

You do not need a legal project to make meaningful progress here, and waiting for one is how nothing gets done for a year. Four things, none of which require anyone's permission, all of which improve your outbound performance independently of any regulatory question. Cleaner provenance means fewer bounces, and fewer bounces means better inbox placement, so this is not a cost centre pretending to be a virtue.

DILIGENCE
Ask every vendor for the provenance splitWhat share of records are verified, sourced from a public disclosure, or inferred. A vendor that will not answer has answered.
DATA
Segment EU contacts and treat them separatelyDifferent basis, different retention, different suppression. Blending them into one global list is how a single complaint becomes a whole-database problem.
RECORD
Write the balancing test downOne page: your interest, the individual's reasonable expectations, the safeguards, the opt out. Written and dated beats remembered.
OPERATIONS
Make opt out instant and permanentAcross every sender, every domain, every sequencer. Channel-level suppression that does not propagate is the failure regulators keep penalising.

The fourth is where most stacks break, and it has nothing to do with this decision specifically. Multi-domain, multi-sender outbound architecture is exactly the design where a suppression fails to reach every send path. That risk got worse this summer when complaint feeds stopped disclosing who complained, because a complaint you cannot resolve to a person is a suppression you cannot execute.

The honest risk read

I do not think this ruling ends B2B contact data, and anyone telling you it does is selling something. One regulator, one company, one set of facts, and there is an appeal path. Enforcement against buyers rather than sellers is still rare.

But the direction is not ambiguous, and it has not been for a while. The reasoning that inference creates personal data and that a refresh cadence creates jurisdiction is portable to every vendor in the category. Somebody will test it again.

So the useful posture is not panic and it is not denial. It is knowing where your data came from. That is a question you can answer this month, and the teams who can answer it will be fine in a way the teams who cannot will not. If you want the commercial version of the same argument, we ran the numbers on what outbound actually costs when you audit it honestly, and provenance turns out to be one of the cheapest line items to fix.

Source: Italy's Garante decision of July 14, 2026, announced July 27, 2026, reported by emailexpert on August 6, 2026 (coverage). Nothing here is legal advice.

See where you are cited today

A free snapshot audit of your rankings and AI citations before we ever talk.

JB
Josh BernsteinMANAGING PARTNER, SOMETHING INC.

Josh leads work at the intersection of SEO and generative engines at Something Inc., helping B2B brands get ranked and cited across every major AI engine.

Free consultation

Let us be the last SEO agency you ever work with

A 30 minute call and a free audit of your SEO and GEO position. You keep the findings either way.