Home
Magazine
GDPR-compliant phishing training: rules and documentation
GDPR-compliant phishing training: rules and documentation

GDPR-compliant phishing training: rules and documentation

September 8, 2026
8 min read
Lana Kuzmina
Cyber Threat Analyst
lana

Effective AI-driven phishing simulations require navigating strict GDPR and works council regulations. Discover how to balance legitimate security interests with employee privacy, implement strict data minimization, and build an audit-ready compliance dossier.

Table of contents

Get started
with revel8

  • Employee consent is legally invalid for testing under EDPB Guidelines 05/2020; rely on a Legitimate Interest Assessment (LIA) instead.
  • German works councils hold co-determination rights under BetrVG Section 87(1) Number 6, requiring a strict works agreement.
  • Group-level anonymization (minimum size of five) protects employee privacy while still providing actionable risk metrics for CISOs.
  • Ethical simulations explicitly avoid sensitive personal triggers like fake bonuses, layoffs, or health emergencies to maintain trust.

Employee consent is frequently cited as the default legal basis for corporate security initiatives, yet in the context of attack simulations, relying on consent creates immediate regulatory vulnerability. European data protection authorities consistently evaluate consent through the lens of power dynamics between employer and employee. When an enterprise requests consent for security testing, the inherent subordination in the employment relationship prevents workers from exercising true freedom of choice without fear of implicit career repercussions.

The European Data Protection Board (EDPB) addressed this structural limitation in Guidelines 05/2020 on consent under Regulation 2016/679, which states that an imbalance of power makes it unlikely that an employee can freely refuse an employer's request to consent, so consent in employment settings is problematic as a legal basis. Furthermore, if an employee exercises their legal right to withdraw consent at any moment, the organization would be forced to exclude them from security evaluations, creating unmonitored blind spots across critical infrastructure.

To establish a resilient legal foundation, security leaders should rely on GDPR Article 6(1)(f), which allows processing that is necessary for the purposes of the legitimate interests pursued by the controller, provided those interests are not overridden by the interests or fundamental rights of the data subject. Safeguarding enterprise information technology systems against social engineering constitutes such a legitimate business interest. However, invoking Article 6(1)(f) requires executing and documenting a formal Legitimate Interest Assessment (LIA) prior to launching multi-channel campaigns.

  • Purpose Test: Documenting the legal and operational necessity of protecting enterprise assets, intellectual property, and network security against AI-assisted social engineering threats.
  • Necessity Test: Demonstrating that multi-channel attack simulations are necessary to build detection habits, as passive instruction or annual security reading cannot achieve defensive readiness.
  • Balancing Test: Establishing that the organization's security interest outweighs individual privacy concerns by implementing default data minimization, group anonymization, and non-disciplinary frameworks.

Completing this three-part test before deployment ensures that security teams can execute continuous multi-channel simulations while maintaining strict alignment with European regulatory standards.

Data minimization: what personal data can you actually process?

GDPR Article 5(1)(c) establishes the core principle of data minimization, mandating that any personal data collected must be strictly proportional to the specific goal of the processing. In attack simulations, capturing employee responses is essential for evaluating organizational readiness, but logging sensitive operational data or user credentials violates these fundamental privacy boundaries.

To remain compliant, security systems should process only essential binary interaction metadata, such as email addresses, job roles, and timestamped actions like reporting or clicking. Under no circumstances should simulation platforms record or store actual credentials entered on simulated landing pages. Analyzing data across over 100,000 security simulations reveals that defensive readiness relies on measuring reporting behaviors rather than logging individual input contents.

Privacy concerns regarding artificial intelligence processing also require strict technical boundaries. Deploying interactive security training via the revel8 Platform ensures that customer data or simulation records are never used to train underlying AI models. All data processing occurs strictly within the customer's dedicated tenant, ensuring that organizational telemetry remains isolated and secure.

Data CategoryPermissible Processing ScopeCompliance Status
User IdentifiersBusiness email address, first/last name, job rolePermitted where limited to what is necessary (Art. 5(1)(c))
Interaction MetadataTimestamps of email receipt, clicks, and reporting actionsPermitted where limited to what is necessary (Art. 5(1)(c))
Submitted CredentialsActual passwords or sensitive form inputs entered by usersStrictly prohibited
AI Model TrainingExporting tenant logs to train public or vendor LLMsStrictly prohibited

Focusing strictly on interaction metadata fulfills data minimization requirements while shifting the organizational focus away from individual surveillance toward building a resilient human firewall.

The works council mandate: balancing security and privacy

In the DACH region, deploying technology capable of evaluating employee conduct triggers strict labor law requirements. Under Section 87(1) Number 6 of the German Works Constitution Act (Betriebsverfassungsgesetz, BetrVG), the works council (Betriebsrat) has a right of co-determination over the introduction and use of technical devices designed to monitor the behaviour or performance of employees.

Section 87(1) Number 6 is generally interpreted broadly, encompassing any software that collects individual interaction metrics. Attempting to deploy phishing simulations without prior works council approval risks legal injunctions, campaign halts, and severe institutional friction. Engaging employee representatives early in the architectural planning phase transforms compliance from an operational hurdle into a shared security objective.

In practice, the framework governing simulation tools is formalized through a binding works agreement (Betriebsvereinbarung). German employment law practice treats such an agreement as the standard instrument for settling co-determination on monitoring-capable software, defining the exact parameters of testing, the data processing boundaries, and the protection mechanisms for workers.

  • Mandatory Non-Disciplinary Clause: An explicit prohibition against using simulation interaction records for performance reviews, disciplinary actions, or employment termination.
  • Anonymized Reporting Standards: Structural requirements mandating group-level aggregation so that individual failure rates cannot be viewed by management or IT administrators.
  • Transparency Protocols: Clear advance notices informing staff that multi-channel simulations are conducted periodically to strengthen organizational defenses.

Including an explicit non-disciplinary clause reassures workers that simulations are educational instruments rather than surveillance tools, safeguarding employee trust while maintaining legal validity under labor law.

Anonymized reporting: how to measure risk without surveillance

Measuring organizational human risk without conducting individual surveillance requires robust structural anonymization. To satisfy both executive oversight needs and works council mandates, security metrics must focus on collective behavioral trends rather than personal tracking.

Default group-level reporting anonymization enforces a strict technical minimum group size of five employees. If an organizational unit contains fewer than five members, the reporting platform automatically aggregates data into a higher-level department. Cryptographic hash functions prevent IT administrators from deanonymizing individual user actions, ensuring that reporting remains purely statistical.

For instance, enterprise deployments like Alexander Bürkle demonstrate how aggregated metrics enable management to track organizational resilience effectively without compromising individual privacy. Security executives should track key performance indicators that highlight positive defensive engagement rather than penalizing isolated mistakes.

Metric NameMeasurement FocusPrivacy Control Mechanism
Reporting RatePercentage of simulated threats actively reported by staffAggregated group metric (min. size 5)
Interaction RatePercentage of risky clicks or interactions over timeAnonymized group trends
Ignore RatePercentage of threats ignored without active reportingDepartmental percentage distribution
Human Firewall IndexOverall organizational risk posture scoreComposite enterprise benchmark

Emphasizing the reporting rate as the primary security metric encourages proactive threat detection and establishes a transparent security culture built on trust.

Mandatory documentation: proving compliance to your auditor

When supervisory authorities or external auditors inspect an organization's security awareness program, verbal assurances are insufficient. GDPR Article 5(2) makes the controller "responsible for, and be able to demonstrate compliance with" the processing principles, the accountability principle. In practice, that means Chief Information Security Officers need a comprehensive compliance dossier evidencing lawful data processing and stringent technical security controls.

Under GDPR Article 30, controllers are obligated to document their data workflows in a formal record of processing activities, mapping out why data is used, whose data is involved, retention schedules, and the overarching security safeguards in place. Furthermore, Article 28 dictates that when engaging an external vendor, an organization must establish a binding data processing agreement that enforces stringent technical controls, manages the use of sub-processors, and guarantees full audit rights.

Sovereign data residency represents a critical pillar of European compliance. The revel8 Platform is hosted on STACKIT infrastructure in Germany, ensuring that all processing occurs strictly within European jurisdiction. Mandatory obligations under the German BSI Act implementation of NIS2 awareness training require audit-proof logs of every simulation and training action. Organizations aligning with European data sovereignty can source infrastructure via the STACKIT Marketplace to simplify procurement and compliance verification.

  • Legitimate Interest Assessment (LIA): Documented balancing test establishing legal justification under GDPR Article 6(1)(f).
  • Records of Processing Activities (ROPA): Formal Article 30 registry detailing processing purposes, data categories, and retention periods.
  • Article 28 Data Processing Agreement: Vendor agreement detailing TOMs, sub-processor lists, and European cloud hosting commitments.
  • Audit-Ready Simulation Logs: Cryptographically secured logs proving compliance with NIS-2, DORA, and ISO 27001 requirements.

Maintaining this documentation dossier guarantees that security leaders can successfully clear regulatory audits while demonstrating proactive risk management.

Ethical boundaries: which social engineering lures cross the line?

While simulations must reflect realistic attack vectors, ethical boundaries dictate scenario design. Manipulative or emotionally distressing lures destroy workforce trust, trigger severe backlash from works councils, and jeopardize the legitimate interest legal basis under GDPR.

Threat scenarios targeting personal financial anxieties, employee terminations, salary adjustments, or health emergencies cross ethical boundaries. Experiencing deceptive lures centered on personal distress causes psychological harm and resentment among staff. When employees feel manipulated by internal security teams, reporting rates plummet and legal challenges multiply.

Instead of emotional manipulation, security teams should deploy realistic business scenarios enriched with open-source intelligence (OSINT) data, such as vendor payment updates, IT system verifications, or multi-channel meeting invites. Grounding scenarios in everyday professional contexts creates authentic learning moments without violating ethical standards.

CategoryPermissible Business ScenariosProhibited Manipulative Triggers
Operational LuresFake IT password resets, shared document alertsFake termination notices or performance warnings
Financial ContextVendor invoice updates, expense portal checksFake bonus announcements or pay cut notifications
External Threat VectorsMulti-channel SMS, voice, and messenger alertsPersonal health updates or emergency notifications

Respecting ethical boundaries ensures that social engineering assessments strengthen organizational habits without damaging internal workplace culture.

Building a compliant security awareness program in 2026 requires balancing aggressive threat defense with strict adherence to European data privacy laws and labor co-determination mandates. By anchoring campaigns in legitimate interest, enforcing default group anonymization, and maintaining audit-ready documentation, CISOs can transform human risk management into a defensible strategic asset. To evaluate how your organization can deploy audit-ready, multi-channel simulations that meet strict DACH works council requirements, contact our security team to review our DPA templates and compliance framework.

FAQ

Do we need employee consent to run a phishing simulation?

No. Under GDPR, employee consent is generally considered invalid due to the power imbalance in the employment relationship (as clarified by EDPB Guidelines 05/2020). Instead, organizations should rely on Article 6(1)(f) Legitimate Interest and document a formal balancing test (LIA) before launching simulations.

How does the German Works Constitution Act affect phishing simulations?

Under BetrVG Section 87(1) Number 6, any technical device capable of monitoring employee behavior triggers mandatory co-determination. This requires a formal works agreement (Betriebsvereinbarung) that strictly prohibits the use of simulation data for performance evaluations or disciplinary measures.

What data should we log during a social engineering simulation?

Adhere to the GDPR principle of data minimization by collecting only basic interaction metrics: whether the employee opened the message, clicked a link, or reported the threat. Never log or store the actual passwords or sensitive credentials entered during a simulated attack.

How can we report on simulation results without violating privacy?

Implement group-level reporting to anonymize the data. By aggregating metrics into teams or departments with a minimum group size of five, organizations can track engagement trends and vulnerability rates without exposing the individual performance of specific employees.

Which phishing lures are considered unethical or non-compliant?

Avoid using emotionally manipulative or highly sensitive topics, such as fake bonuses, termination notices, payroll changes, or personal health crises. These scenarios cross ethical boundaries, damage employee trust, and can invalidate the legal justification of your legitimate interest assessment.

Sources

Related Articles

White abstract curved shape with jagged edges on a black background.

Ready to defend against
AI-powered attacks?