Home
Magazine
Smishing simulation on BYOD devices: what's legally permitted
Smishing simulation on BYOD devices: what's legally permitted

Smishing simulation on BYOD devices: what's legally permitted

August 27, 2026
7 min read
Lana Kuzmina
Cyber Threat Analyst
lana

Attackers increasingly target personal smartphones via SMS to bypass corporate email filters. Discover how to run legally compliant smishing simulations on BYOD devices by navigating GDPR legitimate interest and German Works Council requirements.

Table of contents

Get started
with revel8

  • Under the GDPR, employee consent is rarely valid; simulations must rely on legitimate interest with a documented balancing test.
  • Smishing simulations trigger co-determination under Section 87(1) No. 6 BetrVG, requiring a formal works agreement in Germany.
  • Ethical execution requires avoiding deceptive, employee-sensitive lures like fake bonuses or fake terminations.
  • Privacy is enforced technically via localized German data hosting and default group-level reporting anonymization.

Why do BYOD smishing simulations create privacy concerns?

Bring Your Own Device (BYOD) policies have expanded the enterprise attack surface across European organizations. Mobile messaging apps and SMS bypass traditional corporate network perimeters and secure email gateways, landing directly in the undefended inbox of personal smartphones. Threat actors leverage open-source intelligence (OSINT) to craft highly targeted SMS phishing (smishing) messages that mimic internal IT notifications, authentication requests, or cloud service alerts.

According to guidance from NIST SP 1800-22 on mobile device security, managing cybersecurity risks on personal devices requires balancing organizational resource access against individual user privacy protections. On personal smartphones, corporate IT security controls lack full device visibility. When security teams attempt to evaluate mobile threat resilience through simulated smishing campaigns, they immediately encounter legal friction regarding employee personal data processing on non-corporate hardware.

Vector DomainCorporate EmailBYOD Mobile Messaging
Perimeter DefenseFiltered by secure email gatewaysDirect delivery bypassing email controls
Device ControlFull corporate endpoint monitoringPrivately owned personal hardware
Privacy BoundaryWork-only asset and networkPersonal messages mixed with corporate traffic

This operational friction creates a dilemma for security executives. Establishing clear legal and privacy boundaries between personal phone usage and corporate threat testing is essential before expanding attack simulations across mobile channels.

When structuring mobile security simulations under the General Data Protection Regulation (GDPR), selecting the correct legal basis is critical. Organizations frequently consider requesting employee consent under Article 6(1)(a). However, European data protection authorities consistently maintain that freely given consent is virtually impossible in employment relationships due to the structural power imbalance between employer and worker. The EDPB guidelines on consent treat valid employee consent as an exceptional case, only possible where refusal carries no adverse consequences. German practice guidance is equally blunt: the works council's co-determination right is mandatory and cannot be circumvented by an internal policy or by employee consent, so consent adds paperwork without adding legal certainty. Announcing a campaign in advance also removes the unannounced conditions that make the test diagnostically useful.

Instead, security leaders must ground mobile attack simulations on legitimate interest under Article 6(1)(f) of the GDPR, the basis that permits processing necessary for the legitimate interests of the controller where employee rights do not override them. Relying on legitimate interest requires documenting a formal Legitimate Interest Assessment (LIA). This three-part test proves the processing purpose, establishes necessity for organizational defense, and conducts a strict balancing test against the fundamental privacy rights of employees.

Legal BasisConsent (Art. 6(1)(a))Legitimate Interest (Art. 6(1)(f))
VoluntarinessFlawed in employment contextRooted in organizational security obligations
Simulation ValidityDestroys surprise factorPreserves authentic threat conditions
Compliance BasisCan be withdrawn at any timeRequires documented Legitimate Interest Assessment

To maintain a valid legitimate interest claim, organizations must strictly enforce data minimization. The GDPR storage limitation principle means personal data may not be kept in identifiable form longer than the stated purpose requires, which in practice means collecting only interaction events (open, click, data entry, report) and holding them identifiably for a short operational window (commonly 30 to 90 days) before aggregating or anonymizing them for long-term trend reporting. Aligning simulation programs with mandatory obligations like NIS2 awareness training further reinforces the necessity argument.

When is German Works Council (BetrVG) approval required?

In Germany and regions operating under co-determination frameworks, technical systems that measure or evaluate employee behavior fall under strict statutory oversight. Under Section 87(1) No. 6 of the German Works Constitution Act (Betriebsverfassungsgesetz - BetrVG), the works council (Betriebsrat) holds mandatory co-determination rights regarding any technical device designed to monitor employee behavior or performance.

Because smishing simulations log, per recipient, who opens a message, who clicks the link, who enters credentials and who reports it, the underlying simulation platform qualifies as a technical monitoring system. Settled German Federal Labour Court case law asks only whether a system is objectively suitable for monitoring, so co-determination is triggered even if individual results are never evaluated. Where a works council exists and the simulation is introduced without involving it, the measure is unlawful and the data already collected counts as unlawfully obtained, and the council can block the rollout until an agreement is reached. Attempting to bypass the works council creates immediate legal liabilities and severe trust breakdown across the organization.

  • Formal Works Agreement: A binding Betriebsvereinbarung signed prior to deployment defining platform scope and data processing rules.
  • No Individual Monitoring: Strict contractual prohibitions on using simulation click rates for individual performance appraisals or disciplinary measures.
  • Group-Level Reporting: Aggregation of performance metrics to ensure individual responses remain completely anonymous to management and IT administrators.
  • Technical Transparency: Complete technical documentation provided to employee representatives detailing data flows, storage locations, and sub-processors.

Engaging the works council early in the planning process establishes shared accountability for organizational cyber resilience while ensuring full compliance with BetrVG §87(1) No. 6.

What makes a smishing works agreement ethical?

A robust works agreement establishes operational parameters for mobile security testing while enforcing ethical boundaries that protect participating employees. The foundational requirement is strict purpose limitation: simulation metrics must exist solely to evaluate organizational risk and trigger targeted microtraining in the flow of work, never for employee discipline. German practice guidance is explicit that results serve security awareness rather than performance or behavior control, and that no employment law consequences may follow from an individual click.

Ethical guardrails are equally critical when selecting attack lures. The UK NCSC warns that phishing simulations erode trust between employees and security, and that because nobody can spot every phishing message, punishing people for clicking on emails you sent yourself starts to resemble entrapment, which is why it tells organizations to always check with HR before running a simulation. Lures built on sensitive financial or personnel topics amplify that damage. Deploying deceptive lures of this kind undermines the legitimate interest balancing test under GDPR Article 6(1)(f) and risks immediate labor disputes.

  • Prohibited HR Lures: Scenarios referencing fake bonuses, salary adjustments, layoffs, or performance reviews.
  • Prohibited Personal Topics: Lures themed around family emergencies, medical notifications, or legal actions.
  • Approved Scenario Themes: Simulations modeled on routine IT notifications, common software updates, or standard vendor communications.
  • Immediate Learning Moments: Instant transition from a simulation interaction to non-punitive educational feedback.

Formalizing these ethical boundaries in the works agreement safeguards employee dignity while preserving the legal validity of mobile threat testing.

How should BYOD policies be updated for mobile testing?

GDPR Article 13 requires controllers, at the time personal data are obtained, to tell data subjects the purposes of the processing and its legal basis, and where that basis is Article 6(1)(f), the legitimate interests being pursued. Organizations must therefore integrate mobile security testing explicitly into official BYOD policies. Employees utilizing personal devices for work tasks must be informed that multi-channel threat simulations are part of the enterprise security framework. This notice must clarify that testing extends across SMS, voice phishing, and mobile messaging channels.

German practice guidance frames transparency as informing the workforce in advance, in plain language, about the purpose, process and evaluation of simulations. That duty is satisfied by an upfront notice rather than by publishing campaign schedules or message templates, which would compromise authentic testing conditions. BYOD policy documentation must therefore articulate what interaction data is gathered and how personal content on the phone remains untouched.

  1. Define Vector Scope: Formally document that security testing encompasses email, SMS, voice, and messenger vectors.
  2. Specify Data Boundaries: Detail that only interaction events and timestamps are processed, never personal text messages or personal apps.
  3. Outline Privacy Rights: Inform employees of their rights under GDPR and identify the contact point for data protection queries.
  4. State Educational Goals: Reiterate that mobile testing aims to build workforce habits rather than monitor individuals.

Clear BYOD policy guidelines eliminate ambiguity, providing employees with complete clarity on how personal devices are shielded during corporate threat testing.

How can sovereign infrastructure ensure secure smishing simulations?

Executing legally compliant smishing simulations on BYOD devices requires privacy guardrails embedded directly into platform architecture. The Awareness Playlist automates continuous, multi-channel attack simulations across SMS, email, voice, and messenger, combining real-world OSINT context with strict technical privacy protections.

Privacy protections are enforced natively through group-level reporting anonymization, requiring a minimum group size of five recipients to make individual behavioral tracking impossible. German works council practice expects exactly this pattern: click rates reported only in aggregate, per department, scenario or over time, and never by name. Building that aggregation into the platform removes the need for manual data handling after each campaign. All customer data remains within the customer tenant and is never used to train underlying AI models.

To guarantee sovereign data compliance, all simulation infrastructure is hosted on European cloud infrastructure via STACKIT in Germany, available on the STACKIT Marketplace. This infrastructure ensures compliance with GDPR, NIS-2, DORA, and ISO 27001 mandates while guaranteeing local data residency.

FAQ

Why is employee consent not recommended for smishing simulations?

Under the GDPR, consent within an employment relationship is generally invalid because the power imbalance means it is not freely given. Instead, organizations should base their simulations on legitimate interest (Article 6(1)(f)) and document this with a balancing test.

Do smishing simulations require Works Council approval in Germany?

Yes. Under Section 87(1) No. 6 of the Works Constitution Act (BetrVG), any technical device capable of monitoring employee behavior triggers co-determination. A formal works agreement (Betriebsvereinbarung) is mandatory before launching.

What must be included in a works agreement for simulations?

A legally sound works agreement must explicitly prohibit using simulation results for personnel measures or disciplinary actions. It should also mandate data minimization, define strict retention periods, and require group-level anonymization for management reporting.

How does BYOD complicate security awareness training?

Simulating attacks on private mobile numbers requires strict boundary-setting in internal BYOD policies to ensure security testing does not infringe on personal privacy.

Which lures are considered unethical in smishing simulations?

Organizations must avoid employee-sensitive triggers that cause disproportionate distress or undermine dignity. This includes deceptive lures related to fake bonuses, fake terminations, or personal health issues, which can invalidate legitimate interest.

How does revel8 protect employee privacy during simulations?

The revel8 platform ensures privacy by enforcing default group-level reporting anonymization with a minimum group size of five. Furthermore, sovereign data residency is guaranteed, as the platform is hosted entirely on STACKIT in Germany.

Sources

Related Articles

White abstract curved shape with jagged edges on a black background.

Ready to defend against
AI-powered attacks?