KS-CYBER_

Insights / Law

Phishing simulations and the GDPR — may you test your own employees?

Updated: August 2026 · about 5 min read

You may, and it is a practice recommended by cybersecurity authorities. But a simulation processes employees' personal data, so it needs a legal basis, a privacy notice and limits that should not be crossed. What follows is a practical checklist — not legal advice.

The legal basis: not consent, but legitimate interest

Intuition suggests asking employees for consent. That is wrong for two reasons. First, in the employer–employee relationship consent is often treated as not freely given, because of the imbalance between the parties. Second, if an employee had to consent to a specific test, it would stop being a test.

The right basis is the controller's legitimate interest (Art. 6(1)(f) GDPR) — protecting the organisation's systems and data from attack. It is worth documenting this with a balancing test showing that the company's interest outweighs the intrusion into the employee's privacy, and that the intrusion itself is minimal.

The duty to inform — give notice, but not the date

Employees have to know that the organisation runs phishing simulations. They do not have to know when or in what form. The standard is a clause in the security policy or the work rules plus an announcement when the programme is introduced — stating the purpose, the legal basis, the scope of data collected and how long it is kept.

A practical test. If employees would feel deceived once the rules of the programme were disclosed, the programme is badly designed. The goal is learning, not catching people out.

Limits not worth crossing

  • No scenarios that attack people's dignity — fake bonuses, redundancy notices, medical results or family matters cause real harm and destroy trust in the security team.
  • No disciplinary consequences for a single click — a simulation measures the organisation's exposure, it does not build a dismissal list. Punishment turns the programme into a surveillance tool, and that changes the proportionality assessment too.
  • No collecting passwords — the test page should not store a typed password in any usable form. The fact that credentials were submitted is enough.
  • No indefinite retention — keep individual results only for as long as remediation needs, then retain aggregate data only.

What about works councils and trade unions

Where a company has trade unions or a works council, informing them about the programme before it starts is sensible regardless of whether a provision requires it. A simulation discovered by accident tends to be read as covert monitoring and can trigger a dispute that one meeting would have avoided.

A minimum checklist before the first campaign

  • A clause in the security policy stating that simulations are run.
  • A privacy notice with purpose, basis and retention.
  • A balancing test documented in writing.
  • A decision that there are no sanctions, communicated openly — it raises incident reporting.
  • A defined retention period for individual data.
  • A remediation path — whoever clicks gets training, not a reprimand.

Simulations with remediation built in

A campaign ends by assigning training to the people who clicked, and the board-level report shows aggregate data rather than a list of names to answer for. Tell us how many employees the campaign would cover — we will send back the scope, a privacy notice and a balancing test ready to sign.

How we run campaigns

Prefer to talk now: +48 535 740 973 · kontakt@ks-cyber.pl