RSS Amplifier

Own Your Data · Aug 26, 2026

Lusha vs. the GDPR: your data is a commodity

0
Sign in to vote or save

Marco Parisi · Own Your Data

The article on Cyberinsider confirms that Lusha has collected massive amounts of Italian personal data, cross-referencing it from public sources and reselling it to third parties for aggressive marketing. The fine comes after years of this activity, during which thousands of people only discovered they were in the database after receiving unwanted calls. But the fine is a belated act of redress: the damage has already been done, and privacy has been irreversibly violated.

The GDPR guarantees powerful rights: access, rectification, erasure, and objection. But there’s a fundamental problem: to exercise these rights, you first need to know who is processing your data.

Here’s the vicious cycle:

  • What the GDPR provides: Broad and binding rights for data controllers.

  • What individuals can do: Request access, object, and have data erased.

  • The real problem: How can you request the erasure of data you don’t even know exists?

  • What data brokers do: They operate in the shadows, aggregating data from fragmented sources and creating profiles without any direct relationship with the data subjects.

Data brokers like Lusha exploit this very information asymmetry. They collect data from LinkedIn, public records, and social media, and supplement it with information from other sources. They create massive databases that include names, email addresses, phone numbers, and job titles. Then they sell them to the highest bidder. The average citizen doesn’t even know these databases exist, let alone how to exercise their rights against entities they don’t know. Authorities can intervene, as the Italian Data Protection Authority has done, but such action is always reactive, not preventive. It comes after the damage has been done.

We need collective action, aggressive enforcement by authorities, and above all, a paradigm shift:

Moving from a system where consent is an assumption to be proven, to one where consent is irrefutable digital evidence required before any use.

This is where the fundamental contrast between the current model and Meishi’s vision comes into play. While Lusha represents the extreme form of the predatory data brokerage model, Meishi proposes a radically different approach: total control over one’s own data through cryptographic proof. Meishi does not ask for permission; it does not rely on the fictitious consent implied by incomprehensible terms of service. It operates on opposite principles:

  • Individual sovereignty: Data belongs exclusively to the user, not to the platforms.

  • Absolute transparency: You know exactly who has access to your data and why.

  • Active control: You can revoke access at any time.

  • Privacy-by-design architecture: Privacy isn’t an afterthought – it’s the foundation.

In a situation like the one created by Lusha, the current model fails because there is no central registry of consent. With Meishi, that data would never have been used legally without an explicit authorization link. The key difference lies not in the impossibility of data collection, but in the indisputable proof of illegality. In a system based on explicit and verifiable consent, if a third party uses data without having received that specific consent (and therefore without the link), there is incontrovertible proof: the absence of the authorization record.

This absence transforms the use of the data from a “gray area” to a proven violation; there is no “presumed consent.” There is no need to wait for authorities to interpret the law years later; the illegality is inherent in the absence of the link. This allows for the creation of an ecosystem in which all actors operating outside this explicit consent system are automatically outside the law. It is indeed a reactive measure upon discovery, but the proactive element lies in the initial control: explicit consent, the possibility of immediate revocation, and a level of control that prevents one’s data from traveling freely across the network far more effectively than is the case today, because every legitimate use requires a key that only the user possesses.

The fine imposed on Lusha is significant, but it is insufficient. It demonstrates that the authorities can take action, but it does not solve the structural problem: as long as there is a market for personal data collected without genuine consent, there will always be new companies like Lusha ready to emerge.

The real solution lies not in retroactive regulation, but in structural prevention. We need an ecosystem in which:

  1. Data cannot be used without proof of explicit and verifiable authorization.

  2. Users have practical tools to monitor and control every instance of use.

  3. The consequences for violations are immediate and based on digital evidence, not legal interpretations.

  4. There are real alternatives that give power back to individuals.

Meishi represents this alternative. It’s not just another app; it’s a declaration of digital independence.

In a world where data brokers turn our existence into a commodity, choosing Meishi means refusing to be treated as products for sale. Data sovereignty isn’t dead. It’s just waiting for us to stop trusting systems that betray us and start building ones that truly protect us.

The concept of Data Sovereignty in the Meishi Manifesto is missing here. If access to our data is restricted for commercial, regulatory, power, or security reasons, are we owners or just renters of our own lives? Data Sovereignty isn’t a gift – it’s a right we build ourselves. While you wait for the next post, I ask you:

Who do you want to control your data?

  1. 5–7 Big Tech companies

  2. 200+ governments

  3. You

Choose wisely!

✊❤️🔒
Own Your Data
Marco Parisi

No posts

Read the original on ownyourdatamp.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.