Why consent fails: the legal basis for attack simulations
Employee consent is frequently cited as the default legal basis for corporate security initiatives, yet in the context of attack simulations, relying on consent creates immediate regulatory vulnerability. European data protection authorities consistently evaluate consent through the lens of power dynamics between employer and employee. When an enterprise requests consent for security testing, the inherent subordination in the employment relationship prevents workers from exercising true freedom of choice without fear of implicit career repercussions.
The European Data Protection Board (EDPB) addressed this structural limitation in Guidelines 05/2020 on consent under Regulation 2016/679, which states that an imbalance of power makes it unlikely that an employee can freely refuse an employer's request to consent, so consent in employment settings is problematic as a legal basis. Furthermore, if an employee exercises their legal right to withdraw consent at any moment, the organization would be forced to exclude them from security evaluations, creating unmonitored blind spots across critical infrastructure.
To establish a resilient legal foundation, security leaders should rely on GDPR Article 6(1)(f), which allows processing that is necessary for the purposes of the legitimate interests pursued by the controller, provided those interests are not overridden by the interests or fundamental rights of the data subject. Safeguarding enterprise information technology systems against social engineering constitutes such a legitimate business interest. However, invoking Article 6(1)(f) requires executing and documenting a formal Legitimate Interest Assessment (LIA) prior to launching multi-channel campaigns.
- Purpose Test: Documenting the legal and operational necessity of protecting enterprise assets, intellectual property, and network security against AI-assisted social engineering threats.
- Necessity Test: Demonstrating that multi-channel attack simulations are necessary to build detection habits, as passive instruction or annual security reading cannot achieve defensive readiness.
- Balancing Test: Establishing that the organization's security interest outweighs individual privacy concerns by implementing default data minimization, group anonymization, and non-disciplinary frameworks.
Completing this three-part test before deployment ensures that security teams can execute continuous multi-channel simulations while maintaining strict alignment with European regulatory standards.
Data minimization: what personal data can you actually process?
GDPR Article 5(1)(c) establishes the core principle of data minimization, mandating that any personal data collected must be strictly proportional to the specific goal of the processing. In attack simulations, capturing employee responses is essential for evaluating organizational readiness, but logging sensitive operational data or user credentials violates these fundamental privacy boundaries.
To remain compliant, security systems should process only essential binary interaction metadata, such as email addresses, job roles, and timestamped actions like reporting or clicking. Under no circumstances should simulation platforms record or store actual credentials entered on simulated landing pages. Analyzing data across over 100,000 security simulations reveals that defensive readiness relies on measuring reporting behaviors rather than logging individual input contents.
Privacy concerns regarding artificial intelligence processing also require strict technical boundaries. Deploying interactive security training via the revel8 Platform ensures that customer data or simulation records are never used to train underlying AI models. All data processing occurs strictly within the customer's dedicated tenant, ensuring that organizational telemetry remains isolated and secure.
| Data Category | Permissible Processing Scope | Compliance Status |
|---|---|---|
| User Identifiers | Business email address, first/last name, job role | Permitted where limited to what is necessary (Art. 5(1)(c)) |
| Interaction Metadata | Timestamps of email receipt, clicks, and reporting actions | Permitted where limited to what is necessary (Art. 5(1)(c)) |
| Submitted Credentials | Actual passwords or sensitive form inputs entered by users | Strictly prohibited |
| AI Model Training | Exporting tenant logs to train public or vendor LLMs | Strictly prohibited |
Focusing strictly on interaction metadata fulfills data minimization requirements while shifting the organizational focus away from individual surveillance toward building a resilient human firewall.
The works council mandate: balancing security and privacy
In the DACH region, deploying technology capable of evaluating employee conduct triggers strict labor law requirements. Under Section 87(1) Number 6 of the German Works Constitution Act (Betriebsverfassungsgesetz, BetrVG), the works council (Betriebsrat) has a right of co-determination over the introduction and use of technical devices designed to monitor the behaviour or performance of employees.
Section 87(1) Number 6 is generally interpreted broadly, encompassing any software that collects individual interaction metrics. Attempting to deploy phishing simulations without prior works council approval risks legal injunctions, campaign halts, and severe institutional friction. Engaging employee representatives early in the architectural planning phase transforms compliance from an operational hurdle into a shared security objective.
In practice, the framework governing simulation tools is formalized through a binding works agreement (Betriebsvereinbarung). German employment law practice treats such an agreement as the standard instrument for settling co-determination on monitoring-capable software, defining the exact parameters of testing, the data processing boundaries, and the protection mechanisms for workers.
- Mandatory Non-Disciplinary Clause: An explicit prohibition against using simulation interaction records for performance reviews, disciplinary actions, or employment termination.
- Anonymized Reporting Standards: Structural requirements mandating group-level aggregation so that individual failure rates cannot be viewed by management or IT administrators.
- Transparency Protocols: Clear advance notices informing staff that multi-channel simulations are conducted periodically to strengthen organizational defenses.
Including an explicit non-disciplinary clause reassures workers that simulations are educational instruments rather than surveillance tools, safeguarding employee trust while maintaining legal validity under labor law.
Anonymized reporting: how to measure risk without surveillance
Measuring organizational human risk without conducting individual surveillance requires robust structural anonymization. To satisfy both executive oversight needs and works council mandates, security metrics must focus on collective behavioral trends rather than personal tracking.
Default group-level reporting anonymization enforces a strict technical minimum group size of five employees. If an organizational unit contains fewer than five members, the reporting platform automatically aggregates data into a higher-level department. Cryptographic hash functions prevent IT administrators from deanonymizing individual user actions, ensuring that reporting remains purely statistical.
For instance, enterprise deployments like Alexander Bürkle demonstrate how aggregated metrics enable management to track organizational resilience effectively without compromising individual privacy. Security executives should track key performance indicators that highlight positive defensive engagement rather than penalizing isolated mistakes.
| Metric Name | Measurement Focus | Privacy Control Mechanism |
|---|---|---|
| Reporting Rate | Percentage of simulated threats actively reported by staff | Aggregated group metric (min. size 5) |
| Interaction Rate | Percentage of risky clicks or interactions over time | Anonymized group trends |
| Ignore Rate | Percentage of threats ignored without active reporting | Departmental percentage distribution |
| Human Firewall Index | Overall organizational risk posture score | Composite enterprise benchmark |
Emphasizing the reporting rate as the primary security metric encourages proactive threat detection and establishes a transparent security culture built on trust.
Mandatory documentation: proving compliance to your auditor
When supervisory authorities or external auditors inspect an organization's security awareness program, verbal assurances are insufficient. GDPR Article 5(2) makes the controller "responsible for, and be able to demonstrate compliance with" the processing principles, the accountability principle. In practice, that means Chief Information Security Officers need a comprehensive compliance dossier evidencing lawful data processing and stringent technical security controls.
Under GDPR Article 30, controllers are obligated to document their data workflows in a formal record of processing activities, mapping out why data is used, whose data is involved, retention schedules, and the overarching security safeguards in place. Furthermore, Article 28 dictates that when engaging an external vendor, an organization must establish a binding data processing agreement that enforces stringent technical controls, manages the use of sub-processors, and guarantees full audit rights.
Sovereign data residency represents a critical pillar of European compliance. The revel8 Platform is hosted on STACKIT infrastructure in Germany, ensuring that all processing occurs strictly within European jurisdiction. Mandatory obligations under the German BSI Act implementation of NIS2 awareness training require audit-proof logs of every simulation and training action. Organizations aligning with European data sovereignty can source infrastructure via the STACKIT Marketplace to simplify procurement and compliance verification.
- Legitimate Interest Assessment (LIA): Documented balancing test establishing legal justification under GDPR Article 6(1)(f).
- Records of Processing Activities (ROPA): Formal Article 30 registry detailing processing purposes, data categories, and retention periods.
- Article 28 Data Processing Agreement: Vendor agreement detailing TOMs, sub-processor lists, and European cloud hosting commitments.
- Audit-Ready Simulation Logs: Cryptographically secured logs proving compliance with NIS-2, DORA, and ISO 27001 requirements.
Maintaining this documentation dossier guarantees that security leaders can successfully clear regulatory audits while demonstrating proactive risk management.
Ethical boundaries: which social engineering lures cross the line?
While simulations must reflect realistic attack vectors, ethical boundaries dictate scenario design. Manipulative or emotionally distressing lures destroy workforce trust, trigger severe backlash from works councils, and jeopardize the legitimate interest legal basis under GDPR.
Threat scenarios targeting personal financial anxieties, employee terminations, salary adjustments, or health emergencies cross ethical boundaries. Experiencing deceptive lures centered on personal distress causes psychological harm and resentment among staff. When employees feel manipulated by internal security teams, reporting rates plummet and legal challenges multiply.
Instead of emotional manipulation, security teams should deploy realistic business scenarios enriched with open-source intelligence (OSINT) data, such as vendor payment updates, IT system verifications, or multi-channel meeting invites. Grounding scenarios in everyday professional contexts creates authentic learning moments without violating ethical standards.
| Category | Permissible Business Scenarios | Prohibited Manipulative Triggers |
|---|---|---|
| Operational Lures | Fake IT password resets, shared document alerts | Fake termination notices or performance warnings |
| Financial Context | Vendor invoice updates, expense portal checks | Fake bonus announcements or pay cut notifications |
| External Threat Vectors | Multi-channel SMS, voice, and messenger alerts | Personal health updates or emergency notifications |
Respecting ethical boundaries ensures that social engineering assessments strengthen organizational habits without damaging internal workplace culture.
Building a compliant security awareness program in 2026 requires balancing aggressive threat defense with strict adherence to European data privacy laws and labor co-determination mandates. By anchoring campaigns in legitimate interest, enforcing default group anonymization, and maintaining audit-ready documentation, CISOs can transform human risk management into a defensible strategic asset. To evaluate how your organization can deploy audit-ready, multi-channel simulations that meet strict DACH works council requirements, contact our security team to review our DPA templates and compliance framework.

.avif)



