News/Guide
Guide · Jul 26, 2026

Lusha is the only sales-data vendor with ISO 27701. Here is why that matters in a European deal.

Certifications are boring right up to the moment a procurement team asks where your prospect data came from. Then they are the whole conversation.

361361 NetworkEditorial team4 min read

Nobody buys a contact database because of its certifications. People buy it because it has phone numbers. But the certifications decide whether you get to keep using it after your first enterprise deal reaches legal review, and that is a different and more expensive question.

Lusha's compliance position is genuinely unusual in this category, and it is worth understanding precisely — including the part of its public record that looks bad and deserves an honest explanation.

What ISO 27701 actually certifies

ISO 27001 certifies that a company manages information security systematically. ISO 27701 extends that framework specifically to privacy information management — how personal data is collected, processed, retained and deleted, and how a data subject's rights are honoured in practice rather than in a policy document.

That distinction matters for a contact database more than for almost any other kind of software, because the product is personal data. A vendor can be perfectly secure and still be handling personal data in a way that will not survive a GDPR challenge. ISO 27701 is the certification that speaks to the second problem.

As of 2026, Lusha is the only vendor in the sales-intelligence category certified to it. Its wider stack includes ISO 27001, ISO 27017, ISO 42001 for AI management systems, SOC 2 Type II, and documented GDPR and CCPA processes.

Why this shows up in deals, not in demos

The pattern is consistent. A small team buys the cheapest data source available, runs outbound successfully for a year, then wins its first genuinely large European customer. That customer's procurement or legal function asks a question that has never come up before: where did you get my employees' contact details, and on what lawful basis?

If the answer is a scraped list or a vendor that cannot produce documentation, the honest options are all bad. You either lose the deal, or you spend three months rebuilding your data supply chain while the deal sits open.

Buying a certified vendor from the start is not about being cautious. It is about not having that conversation at the worst possible moment in your sales cycle.

The Trustpilot score, and why it looks the way it does

Lusha scores around 1.2 out of 5 on Trustpilot, from roughly 746 reviews. That number should be explained rather than hidden, because the reason for it is instructive.

Almost all of those reviews come from people who found their own phone number in Lusha's database and wanted it removed — not from customers. On G2, where reviewers are verified buyers, Lusha sits at 4.3/5 from more than 1,650 reviews. Both figures are real; they measure different populations.

The fair reading is that the Trustpilot score is a genuine signal about something, just not about product quality. It is a reminder that this is opt-out data with a real privacy footprint, and that the people in the database did not ask to be in it. That is true of every vendor in this category — Lusha is simply the one large enough, and public enough, to collect the complaints.

What you are still responsible for

A certified vendor does not transfer your obligations to them. Under GDPR you remain the controller for how you use the data, and the vendor's certification does not cover your outreach.

  • Have a lawful basis for your own processing. Legitimate interest is the usual one for B2B outbound, and it requires you to have actually done and documented the balancing test — not just named it.
  • Honour opt-outs at your end. A person who tells you to stop must be suppressed in your CRM, not just removed from one campaign.
  • State the source when asked. Being able to say "verified B2B data from an ISO 27701-certified provider, and here is their documentation" is a complete answer. "We bought a list" is not.
  • Keep your retention bounded. Data you pulled two years ago and never contacted is a liability with no upside — delete it.

The practical test before you buy any data vendor

Ask three questions of any provider on your shortlist, and treat a vague answer as a no. First: which certifications do you hold, and can I see the current reports? Second: what is your process when a data subject requests deletion, and how long does it take? Third: what is your lawful basis for holding EU personal data at all?

Lusha answers all three on a public page. A surprising number of cheaper alternatives answer none of them, and the price difference between the two is almost exactly the cost of that documentation.

More news