---
title: GDPR Legal Basis for Phishing Simulation and Risk Scoring
description: Phishing simulation with individual risk scores is profiling under GDPR. Recent peer-reviewed evidence is now challenging its legal basis.
image: https://www.cybercoach.com/hubfs/featured-image-legal.png
---

[![CyberCoach Full Logo with Bot Icon](https://www.cybercoach.com/hubfs/CyberCoach_Full_Logo_Black-2.svg)](https://www.cybercoach.com?hsLang=en)

- [English](https://www.cybercoach.com/legal-basis-phishing-simulation)
- [Suomi](https://www.cybercoach.com/fi/kalastelu)
- [Svenska](https://www.cybercoach.com/sv/phishing-training)

- PRODUCT
  
  ## CyberCoach at a glance
  
  An industry-changing platform built on peer-reviewed research: phishing, secure coding, and AI skills training, delivered directly in Teams, Slack, or the browser.
  
  
  
  ### [The Science Behind CyberCoach Why traditional phishing simulations don't work, according to peer-reviewed research from ETH Zurich.](https://www.cybercoach.com/science-behind-cybercoach?hsLang=en)
  
  
  
  ### [Is Phishing Simulation Legal Under GDPR? 9 steps GDPR requires before you phish your employees — and a new simulation approach that doesn't need any of them.](https://www.cybercoach.com/legal-basis-phishing-simulation)
  
  
  
  ### [Pricing Flexible plans, also monthly. ](https://www.cybercoach.com/pricing?hsLang=en)
  
  
  
  ### [Blog Latest insights into security awareness and what's new with CyberCoach.](https://blog.cybercoach.com?hsLang=en)
  
  
  
  ### [Customer Stories Read more about how CyberCoach has helped organizations across different industries modernize their approach to security and AI training. ](https://www.cybercoach.com/customer-stories?hsLang=en)
  
  
  
  ### [OT Security Training Targeted training for employees working with OT technology.](https://www.cybercoach.com/ot-security-training?hsLang=en)
- [AI TRAINING](https://www.cybercoach.com/ai-security-training?hsLang=en)
  
  ## [AI Training The most comprehensive role-based AI security and productivity training — built to help employees use AI effectively and safely, and keep your organization compliant with the EU AI Act.](https://www.cybercoach.com/ai-security-training?hsLang=en)
  
  
  
  ### [AI Security Training Why choose CyberCoach for your AI security training needs?](https://www.cybercoach.com/ai-security-training?hsLang=en)
  
  
  
  ### [EU AI Act Training Requirements: What You Actually Have To Do AI literacy training has been mandatory since February 2025.  ](https://www.cybercoach.com/eu-ai-act-training-requirements?hsLang=en)
- [FOR DEVELOPERS](https://www.cybercoach.com/secure-development-training-for-developers?hsLang=en)
  
  ## [For Developers Go beyond OWASP Top10 and offer hands-on interactive training for technical roles in secure coding and efficient use of AI. ](https://www.cybercoach.com/secure-development-training-for-developers?hsLang=en)
  
  
  
  ### [Secure Coding Skills Meet ISO/IEC 27001 or SOC 2 requirements for secure development practices with no-nonsense training for your developers and other technical roles, directly in Microsoft Teams or Slack chat. ](https://www.cybercoach.com/secure-development-training-for-developers?hsLang=en)
- [COMPANY](https://www.cybercoach.com/about-us?hsLang=en)
  
  ## [About us We're growing into the most diverse training platform company on the planet.](https://www.cybercoach.com/about-us?hsLang=en)
  
  
  
  ### [About Us Get to know our international team.](https://www.cybercoach.com/about-us?hsLang=en)
  
  
  
  ### [Contact Us Get in touch.](https://www.cybercoach.com/contact-us?hsLang=en)
  
  
  
  ### [Careers We are hiring.](https://www.cybercoach.com/careers?hsLang=en)
  
  
  
  ### [Partner with us Learn more about our partner program.](https://www.cybercoach.com/partnerships?hsLang=en)

- [English](https://www.cybercoach.com/legal-basis-phishing-simulation)
- [Suomi](https://www.cybercoach.com/fi/kalastelu)
- [Svenska](https://www.cybercoach.com/sv/phishing-training)

[FREE TRIAL](https://www.cybercoach.com/free-trial?hsLang=en) [GET A DEMO](https://meetings-eu1.hubspot.com/maria-bique/cybercoach-demo?uuid=88959d26-2ff7-4dd0-8ebd-dd43eb31443e)

 

 

 

 

 

 

 

analysis

# What is the legal basis for AI-driven phishing simulation and human risk scoring under the GDPR?

**Human risk management platforms profile employees: they send simulated attacks, record who failed, and calculate individual risk scores that drive automated targeting.** Under the GDPR that is profiling of employee personal data, and it needs a legal basis under Article 6. In practice, only legitimate interest is available to most European employers — and legitimate interest requires that the processing actually be necessary to achieve the stated purpose. That is precisely the claim a growing body of peer-reviewed research now puts in question.

This page sets out the analysis as a security leader would need to present it to a data protection officer, and as a DPO would need to document it: what is being processed, which legal bases are realistically available, how the necessity and balancing tests interact with the efficacy evidence, and what the EU AI Act adds from 2 August 2026 onward.

Not legal advice

This article is general information for security and privacy professionals, published by CyberCoach, a vendor of an alternative approach. It is not legal advice, it does not create a lawyer–client relationship, and it does not account for your sector, your jurisdiction, your collective agreements or your facts. Data protection law is applied nationally and interpretation evolves. Obtain qualified local counsel before relying on any position described here, and treat our commercial interest as an added reason to check our reasoning.

## The short answer

Simulated phishing with per-employee tracking is profiling within the meaning of Article 4(4) GDPR, because it evaluates aspects of a person's behavior and, in scored form, predicts their future reliability

Of the six Article 6 bases, only legitimate interest is realistically available to a private employer in most of Europe. Consent is generally invalid in employment; no law requires simulated phishing; and it is not necessary to perform an employment contract

Legitimate interest has three limbs: a legitimate purpose, necessity, and a balance that does not override employee rights. Necessity is the limb the efficacy research undermines directly

Four peer-reviewed studies covering roughly 36,000 employees report that deceptive simulation produced little or no durable improvement, and even suggest measurable harm

If a less intrusive method (such as CyberCoach) achieves the same purpose, necessity fails as a matter of established data protection reasoning — regardless of how normal the intrusive method has become in the market

Risk scores that trigger consequences without human involvement raise Article 22 questions, and AI systems used to evaluate employees fall in the EU AI Act's high-risk category

## What is actually being processed?

Before the legal basis question can be answered, the processing has to be described. A modern human risk management platform typically holds, per named employee:

Identity and organizational data: name, work email, department, manager, location, role

Behavioral event data: which simulated messages were opened, clicked, replied to, reported or ignored, with timestamps

Derived scores: a per-person risk or susceptibility value, often trended over time and benchmarked against colleagues

Automated targeting decisions: which lure, difficulty or remedial training a person receives next, derived from their history

Threat telemetry linkage: in some products, whether the individual is externally targeted, drawn from live email security data

Management visibility: dashboards exposing individual results to line managers, HR, or both

Two features of that inventory matter legally. First, the data is generated by the employer's own deception rather than volunteered by the employee, so the employee is not a participant in the collection. Second, the output is an evaluative judgment about a person's competence, which is the kind of processing employees most reasonably object to and which sits closest to employment consequences.

## Is simulated phishing with individual tracking "profiling"?

Article 4(4) GDPR defines profiling as any automated processing of personal data to evaluate personal aspects of a natural person, in particular to analyze or predict aspects such as performance at work, reliability or behavior. A platform that records how an employee responded to a simulated attack, converts it into a susceptibility score, and uses that score to predict how they will behave next is likely to meet that definition. 

Consequently, it is also how the platforms describe themselves: the product category renamed itself "human risk management" precisely because the value proposition is individual-level measurement and prediction. A DPIA that describes the same system as something less than profiling may be hard to reconcile with the vendor's own marketing claims. 

Note the consequence: profiling is lawful, but it raises the transparency bar (Articles 13–14 require meaningful information about the logic), it strengthens the employee's Article 21 right to object where legitimate interest is the basis, and it makes a data protection impact assessment likely under Article 35(3)(a) where the profiling is systematic and extensive and decisions follow from it.

## The four candidate legal bases, one at a time

Article 6(1) offers six bases. Two — vital interests and public task — are not available to an ordinary private employer running an awareness program. That leaves four worth working through.

### Consent — Article 6(1)(a)

Generally unavailable

Consent must be freely given. European regulators have taken the consistent position that an employee is rarely in a position to refuse an employer, because of the imbalance of power in the relationship. This argument is set out in the Article 29 Working Party's opinion on data processing at work and carried forward in the EDPB's consent guidelines. Consent that cannot be withdrawn without consequence is not consent.

There is also a structural problem specific to deceptive simulation: informed consent to a specific test defeats the test. A program can be announced in general terms, but the moment participation is genuinely optional and genuinely refusable, the population you measure is no longer the population you wanted to protect.

### Legal obligation — Article 6(1)(c)

Not available

This basis requires a legal obligation to carry out the specific processing. No European instrument requires employers to send deceptive messages to their own staff or to score them individually. NIS2 requires cyber hygiene practices and security training for management and employees; the frameworks organizations audit against — ISO/IEC 27001 Annex A 6.3, SOC 2, DORA — require awareness, education and training, and testing of controls. None of them prescribes deceptive simulation of individuals, and none requires retaining per-person failure records.

The distinction that matters in the file: an obligation to train is not an obligation to deceive and score. Evidence of completion satisfies an auditor. A susceptibility ranking is a choice the employer made, and must justify separately.

### Performance of a contract — Article 6(1)(b)

Not available

This basis is read narrowly: the processing must be objectively necessary to deliver the contract. Guidance on Article 6(1)(b) has consistently emphasized that necessity here means objective necessity for the contract itself, rather than convenience for the controller. It may be difficult to argue that an employment contract requires the employer to test its employees by deception in order to pay them and provide work. 

### Legitimate interest — Article 6(1)(f)

The basis almost everyone relies on

In practice, this is the only realistic basis, and it is the one named in most vendor documentation and customer DPIAs. It is also the only one that requires the employer to keep proving something over time — which is why the accumulating efficacy evidence changes the picture.

One further note on Article 9: awareness programs are not intended to process special category data, but free-text responses, disability-related accessibility needs, or health-related lures can pull it in incidentally. This should also be considered in the DPIA. 

## Do national rules change the consent analysis?

Article 88 GDPR allows member states to legislate for the employment context, and a handful appear to have addressed employee consent directly. The result is fragmentation that specialists themselves describe as contested, so the summaries below are offered as orientation for a conversation with counsel rather than as conclusions.

### Germany — the clearest carve-out

Section 26(2) of the Federal Data Protection Act (BDSG) is generally read as permitting employee consent, and it goes further than a bare cross-reference by describing circumstances said to indicate that consent was freely given — commonly summarized as a legal or economic advantage for the employee, or employer and employee pursuing the same interest — with a written form requirement. One complication to raise with counsel: the CJEU’s 2023 judgment in C-34/21 found parts of Section 26 wanting against Article 88’s requirement for "more specific rules", and commentary appears divided on the precise consequences for subsection (2).

### Denmark — often described as more permissive

Danish commentary is frequently cited for the proposition that the national act supplementing the GDPR leaves more room for employee consent than the European default. The plausible scope discussed in that commentary looks narrow: arrangements an employee can genuinely decline without detriment, closer in character to a voluntary benefit than to a mandatory security control. Whether a phishing simulation program could be designed to sit inside that space is a question for Danish counsel and Datatilsynet’s current practice.

### Finland — reported as going the other way

Finnish provisions on privacy in working life are commonly described as making the necessity requirement for processing worker data something consent cannot displace, which would leave consent unavailable as a general basis regardless of how it is obtained. If Finland is in scope for your program, that reading is worth confirming early rather than late.

### Portugal — reported as inverting the German logic

Portuguese law is discussed in commentary as excluding consent where the processing brings the employee an economic or legal advantage — close to the opposite of the factor Germany is understood to treat as evidence that consent was free. Two jurisdictions, apparently opposite tests, same regulation.

### Most member states — no specific rule either way

The majority appear not to have legislated on employee consent specifically. That is not a prohibition: Article 6(1)(a) remains formally available. But without a national provision to point to, an employer is left arguing against EDPB and Article 29 Working Party guidance that treats employee consent as presumptively not freely given because of the power imbalance. Formally available and practically defensible are different things.

### The design problem consent does not solve

Separate from the legal question, there is a structural one: informed consent to a specific deceptive test defeats the test, and a program employees can genuinely refuse will be refused first by the people whose exposure justified it. A consent-based design is also the least portable across borders, which matters for any multinational organization.

Everything in this section is a secondhand characterization of national law, including where we have named provisions, and national implementations are exactly where secondhand summaries fail. Nothing here should be treated as a determination about any jurisdiction. Local employment and data protection counsel should confirm the position for each country in scope before a program is designed around consent — and the fragmentation itself is a reason to prefer a design that does not depend on the answer.

## The legitimate interest test, and where the evidence bites

Legitimate interest is a three-limb test, and all three must hold. The EDPB set out this structure in its Opinion 1/2024 on Article 6(1)(f), and the Court of Justice applied the same reasoning in *KNLTB* (C-621/22, October 2024): a controller's interest does not become lawful simply by being commercially real.

Limb 1 — a legitimate interest

### Usually satisfied

Protecting the organization against social engineering is a legitimate interest, and Recital 49 explicitly recognizes network and information security as one. This limb can be defensible. 

Limb 2 — necessity

### Where the efficacy research lands

Necessity asks two questions. Does this processing actually achieve the stated purpose? And is there a less intrusive way to achieve it? A negative answer to either is fatal to the basis, and both answers are empirical rather than legal.

This is the structural shift. For a decade, "we send simulated phishing and score employees because it reduces risk" was an untested but plausible assertion. It is now a contested empirical claim, and the controller is the party who has to evidence it. 

Limb 3 — balancing

### Weakened by the same evidence

Balancing weighs the interest against the rights, freedoms and reasonable expectations of the data subject, with the employment power imbalance counting against the employer. The heavier side of the scale is supposed to be the security benefit. If that benefit is small or unproven, the same intrusion has less to weigh against — and evidence of harm to trust and reporting behavior moves weight to the employee's side rather than merely removing it from the employer's.

A documentation point that follows directly: a legitimate interest assessment written in 2019 and never revisited may not suffice in 2026. The balancing test is a judgment about facts, and we are now starting to accumulate sufficient empirical and independent (not vendor published) data about the effectiveness of phishing simulations. 

What does the peer-reviewed evidence say?  
Four large studies published between 2022 and 2026, covering roughly 36,000 employees in real organizations, examine whether deceptive simulation delivers the protective benefit it is justified by. They are summarized here for the necessity analysis; each is described in full on [the science behind CyberCoach](https://www.cybercoach.com/science-behind-cybercoach?hsLang=en).

14,733 employees · 15 months · IEEE Security & Privacy 2022

### Employees who failed and were sent to training clicked more afterwards

Lain, Kostiainen and Capkun found that the embedded training page delivered on failure — the mechanism that justifies collecting failure data in the first place — was associated with worse subsequent behavior, not better. For a necessity analysis, this is the most damaging shape of result: it targets the specific processing operation rather than the general idea of awareness training.

4,554 employees · ACM CCS 2024

### The nudge did the work, not the content — and mandatory retraining added nothing

Lain and colleagues found improvements attributable to the reminder that a program exists rather than to the training material delivered, and no measurable benefit from compelling repeat failures into further training. Both findings undercut the necessity of per-person failure records: if the effective ingredient is a general prompt, individual-level data is not needed to deliver it.

USENIX Security 2023

### Documented costs to trust, culture and reporting

Brünken, Buckmann, Hielscher and Sasse catalogued the hidden costs of simulated phishing, including damage to the employee–employer relationship and to the willingness to report genuine incidents. Balancing-test relevance: a control that suppresses reporting costs both parties: it produces a security cost to the employer, as well as a privacy cost to the employee.

12,511 employees · ACM Web Conference 2026

### Click rates tracked lure difficulty, not employee capability

Rozema and Davis found no meaningful improvement in detection ability from phishing simulations, with click rates only moving with how hard the lure was — 7% for easy lures, 15% for hard ones. This goes to the validity of the score itself: if the number mostly measures the difficulty of the test you chose, an employee ranking built from it is not measuring what the simulation platform intended to measure. A profile that does not measure what it claims to measure is difficult to defend as accurate under Article 5(1)(d), let alone as necessary.

Stated fairly: this literature is drawn from a limited number of organizations, and does not establish that all awareness training is ineffective — several of these authors are explicit that training itself has value. What it does establish is that the specific combination of deception, individual failure records and score-driven targeting can no longer be assumed to work. Necessity requires the controller to hold evidence, and the available independent evidence currently runs the other way.

Google has published its own position that it does not run surprise phishing tests against its staff, citing the damage to trust relative to the benefit. That is not authority, but it is evidence that a sophisticated security organization considers the deceptive simulations harmful and avoidable.

## Do risk scores trigger Article 22?

Article 22 restricts decisions based solely on automated processing that produce legal effects or otherwise significantly affect a person. A score that generates the next simulated email is unlikely to reach that threshold. A score that automatically restricts a person's access, enrolls them in mandatory remedial training, flags them to HR, or feeds a performance conversation is a different matter — and the Court of Justice's judgment in *SCHUFA* (C-634/21) shows that producing the score can itself be the decision when a downstream actor predictably follows it.

The practical question for a DPO is not "does the vendor call it a decision" but "what happens to a person when their score goes up, and does a human meaningfully intervene before it happens?" 

Related exposure worth naming: every per-employee record is disclosable in a subject access request, and derived scores are included. Employees have the right to know their susceptibility ranking, the logic behind it, and who saw it. 

## What does the EU AI Act add?

The AI Act operates alongside the GDPR, not instead of it, and two parts are directly relevant to AI-driven awareness platforms.

### Employment as a high-risk use case

Annex III classifies AI systems intended to be used to monitor or evaluate the behavior or performance of workers as high risk. Whether a susceptibility-scoring engine falls inside that classification is a question of its intended purpose, and it is one your vendor should be able to answer in writing.

The compliance deadline for standalone Annex III high-risk obligations was deferred by Regulation (EU) 2026/1744 (the Digital Omnibus on AI), from 2 August 2026 to 2 December 2027. Two things did **not** move: Article 50 transparency duties and the Article 4 AI-literacy obligation remain on their original schedule, and the Article 5 prohibition on workplace emotion inference has applied since February 2025.

### Prohibited practices

Article 5 prohibits inferring emotions in the workplace, and prohibits social scoring leading to detrimental treatment in unrelated contexts. Standard awareness platforms are not designed to do either. The point of naming these is that as vendors add engagement, sentiment and behavioral-nudge features, the boundary is worth watching — and asking about — rather than assumed.

There is a compounding effect here that security leaders should see clearly. A control whose necessity is contested under the GDPR, whose accuracy is questioned by the research, and which may sit in the AI Act's high-risk category, carries three separate documentation burdens. An approach that delivers personalized and effective hands-on training but never profiles individuals carries none of them.

## Works councils and national employment law

Article 88 lets member states legislate specifically for the employment context, and several have. The result is that GDPR compliance is necessary but not sufficient.

In Germany, technical systems capable of monitoring employee performance or behavior typically require works council co-determination under the Works Constitution Act — a veto point independent of your legal basis

In the Netherlands, France and the Nordics, employee representative consultation obligations and national DPA guidance on workplace monitoring apply alongside the GDPR analysis

## What to document, whichever approach you choose

This list is deliberately neutral. An organization that works through it and decides to continue with deceptive simulation is in a far stronger position than one that never asked.

**1.** A current legitimate interest assessment, dated within the last twelve months, that engages with the published efficacy evidence rather than ignoring it.

**2.** A documented alternatives analysis: which less intrusive methods were considered, and on what evidence they were rejected as inadequate.

**3.** A DPIA where one is required for employee monitoring, profiling and/or automated decision-making.

**4.** Transparency materials that state plainly that simulated attacks will be sent, what is recorded per person, who can see it, and for how long — shared proactively before the program starts, not after a complaint.

**5.** A defined retention period for individual failure records and derived scores, with deletion actually implemented.

**6.** A stated position on Article 21 objections: what happens when an employee objects to being profiled, and who decides.

**7.** An Article 22 analysis of every automated consequence attached to a score, and a record of where human review sits.

**8.** A written answer from your vendor on whether its system is high risk under Annex III of the AI Act, and what deployer obligations follow for you.

**9.** Evidence of works council or employee representative engagement where national law requires it, completed before deployment.

## The design question underneath the legal one

Almost every obligation above exists because the program creates a per-employee performance record. Remove that record and the analysis simplifies dramatically: no profiling, no balancing test to lose, no susceptibility score to disclose in a subject access request, no Article 22 question, no argument with a works council about a monitoring system.

Compliance evidence does not require it either. Auditors ask whether required training was completed, and completion records answer that. The individual failure data is collected for measurement, and this type of measurement is the what recent research questions.

**Our position, stated as an interest and not as a neutral finding:** CyberCoach is built without individual scoring — learning is anonymous, only successful completion is recorded per person, and the platform can run on pseudonymous Microsoft identifiers so that no personal data reaches us at all. [The research behind that design](https://www.cybercoach.com/science-behind-cybercoach?hsLang=en) is documented. We think that is the better answer to the necessity question. You should test that claim against your own facts and your own counsel, exactly as you would test any vendor's legal reasoning about its own product.

## Frequently asked questions

### Is simulated phishing legal in the EU?

There is no prohibition on simulated phishing as such, and it has not been ruled unlawful. What the GDPR requires is a valid legal basis for processing the employee personal data it generates, together with transparency, a proportionate design, a defined retention period and — where national law requires — employee representative involvement. The realistic basis for a private employer is legitimate interest under Article 6(1)(f), which must be documented and kept current.

### Can an employer rely on employee consent for phishing simulations?

Generally not. European regulators treat employee consent as rarely freely given because of the imbalance of power in the employment relationship, and consent that cannot be refused without consequence is invalid. Certain countries like Denmark have national supplementing legislation that is understood to be more permissive, but the plausible scope is narrow — genuinely voluntary arrangements an employee can decline without detriment. 

### Are per-employee phishing risk scores profiling under the GDPR?

Yes, on the ordinary reading of Article 4(4). A score derived from automated evaluation of an employee's behavior, used to predict their future reliability and to target them with further processing, is profiling. That triggers heightened transparency duties, an Article 21 right to object where legitimate interest is the basis, and a likely DPIA obligation.

### Does research showing simulations are ineffective affect the legal basis?

It can, because necessity and balancing are factual judgments rather than fixed legal conclusions. Necessity requires that the processing actually achieve its purpose and that no less intrusive means would do. Where independent peer-reviewed studies report little or no durable benefit, and documented costs to trust and incident reporting, a controller relying on legitimate interest carries a heavier evidential burden than it did when the benefit was simply assumed.

### Does ISO 27001, SOC 2, NIS2 or DORA require phishing simulations?

These frameworks require awareness, education and training, and testing of security controls; none prescribes deceptive simulation of named individuals, and none requires retaining per-person failure records. An obligation to train is not an obligation to deceive and score.

### Does the EU AI Act apply to security awareness platforms?

It may. Annex III treats AI systems intended to monitor or evaluate the behavior or performance of workers as high risk. The compliance deadline for that category was pushed from 2 August 2026 to 2 December 2027 by the Digital Omnibus on AI (Regulation (EU) 2026/1744) — but Article 50 transparency duties and the Article 4 AI-literacy obligation were not deferred, and classification itself doesn't wait: a multi-year contract signed today will still be live when the new deadline arrives. Whether a particular susceptibility-scoring engine falls inside Annex III depends on its intended purpose; deployers should get a written position from the provider now, since deployer duties — human oversight and worker transparency — attach to the buyer regardless of when enforcement starts.

### Can employees request their phishing simulation results?

Yes. Individual results and derived risk scores are personal data, so they fall within the Article 15 right of access, alongside information about the purposes, recipients and retention period and, where profiling is involved, meaningful information about the logic. Employees may also object under Article 21 where the basis is legitimate interest.

### Can security awareness training be delivered without processing personal data?

Largely, yes. CyberCoach allows learner-led personalization choices that are not stored or connected to users during anonymous learning interactions and only records successful completion, sothere is no per-person performance record to disclose or defend. Deployment on pseudonymous identifiers such as Microsoft UUIDs further minimizes personal data processing, while the customer's own authorized administrators retain the reports needed for compliance reporting. 

Full disclaimer, sources and review

Published by CyberCoach, which sells a security awareness platform that does not profile individual employees. We have a commercial interest in the conclusions above and have tried to state the counter-arguments accordingly. Nothing here is legal advice or a legal opinion, no lawyer–client relationship arises from reading it, and it does not address your jurisdiction, sector, collective agreements or facts. Legislation, national implementing law, regulatory guidance and case law change; provisions and dates should be checked against current official sources. Obtain qualified local counsel before acting.

Primary sources referred to: Regulation (EU) 2016/679 (Articles 4(4), 5, 6, 9, 13–15, 21, 22, 35, 88 and Recital 49); Regulation (EU) 2024/1689 (AI Act, Article 5 and Annex III); Regulation (EU) 2026/1744 (Digital Omnibus on AI), amending Regulation (EU) 2024/1689; Directive (EU) 2022/2555 (NIS2); EDPB Opinion 1/2024 on legitimate interest; Article 29 Working Party Opinion 2/2017 on data processing at work; CJEU C-621/22 (*KNLTB*) and C-634/21 (*SCHUFA*); the Danish Data Protection Act supplementing the GDPR. Research: Lain, Kostiainen and Capkun, IEEE Security & Privacy 2022; Lain, Jost, Matetic, Kostiainen and Capkun, ACM CCS 2024; Brünken, Buckmann, Hielscher and Sasse, USENIX Security 2023; Rozema and Davis, ACM Web Conference 2026; Google Security Blog, 2024.

Published 26 August 2026

Reviewed quarterly

Corrections: [info@cybercoach.com](mailto:info@cybercoach.com)

## Read the research before the sales pitch

Every study cited above is summarized, with its limitations, on the science page, including the findings that complicate our own argument.

# Get Started Free

No credit card needed.

[Sounds good!](https://www.cybercoach.com/free-trial?hsLang=en)

[![phishy_badge_cybercoach](https://www.cybercoach.com/hubfs/phishy_badge_cybercoach.svg)](https://blog.cybercoach.com/phishing-training-makes-employees-more-prone-to-be-phished?hsLang=en)

## Phishing Training Makes Employees More Prone to be Phished

An entire phishing simulation industry has emerged to combat the dangers of phishing attacks...

[LEARN MORE](https://blog.cybercoach.com/phishing-training-makes-employees-more-prone-to-be-phished?hsLang=en)

![cybercoach_logo_white.svg.2023_03_15_16_58_04.0](https://www.cybercoach.com/hubfs/cybercoach_logo_white.svg.2023_03_15_16_58_04.0.svg)

### Product

- [For Developers](https://www.cybercoach.com/secure-development-training-for-developers?hsLang=en)
- [AI Security](https://www.cybercoach.com/ai-security-training?hsLang=en)
- [Manage Subscription](https://billing.stripe.com/p/login/28o4jRclF4gab1C6oo)
- [FAQ](https://www.cybercoach.com/faq?hsLang=en)

### Connect

- [Partner Program](https://www.cybercoach.com/partnerships?hsLang=en)
- [Careers](https://www.cybercoach.com/careers?hsLang=en)
- [For Media](https://www.cybercoach.com/media?hsLang=en)
- [Contact Us](https://www.cybercoach.com/contact-us?hsLang=en)

### Legal

- [Privacy](https://www.cybercoach.com/cybercoach-website-privacy?hsLang=en)
- [General Terms](https://www.cybercoach.com/general-terms?hsLang=en)

### Company

- [About Us](https://www.cybercoach.com/about-us?hsLang=en)
- [Blog](https://blog.cybercoach.com?hsLang=en)
- [ESG Policy](https://www.cybercoach.com/esg-policy?hsLang=en)

© 2026 CyberCoach   
All rights reserved

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.cybercoach.com/#organization",
  "@type" : "Organization",
  "foundingDate" : "2019",
  "legalName" : "Cult Security",
  "logo" : "https://www.cybercoach.com/hubfs/CyberCoach_Full_Logo_Black-2.svg",
  "name" : "CyberCoach",
  "sameAs" : [ "https://www.linkedin.com/company/cult-security", "https://x.com/cybercoachUS", "https://www.instagram.com/cybercoachus/", "https://www.youtube.com/@CyberCoachOfficial" ],
  "url" : "https://www.cybercoach.com/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.cybercoach.com/#software",
  "@type" : "SoftwareApplication",
  "applicationCategory" : "BusinessApplication",
  "applicationSubCategory" : "Security awareness and AI skills training",
  "availableLanguage" : [ "English", "Spanish", "Portuguese (Brazil)", "Portuguese (Portugal)", "French", "Dutch", "German", "Swedish", "Finnish" ],
  "description" : "CyberCoach is a role-based security awareness, privacy and AI skills training platform that runs as a conversational app inside Microsoft Teams, Slack or a web browser. Employees practice AI skills and responding to social engineering in short, psychologically safe scenario-based sessions. Learning is anonymous while successful completions are recorded per user so the organization can evidence training completion for compliance. CyberCoach can also run on pseudonymous identifiers such as Slack or Microsoft UUIDs, with no personal data shared with CyberCoach.",
  "featureList" : [ "Conversational phishing and social engineering challenges", "Role-based training programs for technical and non-technical roles", "AI security and AI use training", "Secure coding training for developers", "OT security training", "Custom content creation", "Compliance assessments (ISO/IEC 27001, GDPR, AI compliance)", "Anonymous learning with per-user completion records for compliance", "Optional pseudonymous deployment using Slack or Microsoft UUIDs" ],
  "name" : "CyberCoach",
  "offers" : [ {
    "@type" : "Offer",
    "description" : "Cover the basics.",
    "name" : "Starter",
    "price" : "49",
    "priceCurrency" : "EUR"
  }, {
    "@type" : "Offer",
    "description" : "Broad topic coverage, custom content, hosted kick-off.",
    "name" : "Advanced",
    "price" : "159",
    "priceCurrency" : "EUR"
  }, {
    "@type" : "Offer",
    "description" : "Full coverage, 24/7 AI chat, compliance assessments, hosted kick-off.",
    "name" : "Complete",
    "price" : "179",
    "priceCurrency" : "EUR"
  } ],
  "operatingSystem" : "Microsoft Teams, Slack, Web browser, iOS, Android",
  "publisher" : {
    "@id" : "https://www.cybercoach.com/#organization"
  },
  "url" : "https://www.cybercoach.com/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.cybercoach.com/#faq",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "CyberCoach is a security awareness, privacy and AI skills training platform that runs inside Microsoft Teams, Slack or a web browser. Employees practice role-based skills such as responding to social engineering, ethical and productive use of AI and even secure coding skills in short conversational scenarios. Learning is anonymous, while successful completions are stored so the organization can evidence training completion for compliance frameworks such as ISO/IEC 27001 and SOC 2."
    },
    "name" : "What is CyberCoach?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes, but not by sending deceptive emails to employees. CyberCoach uses conversational phishing challenges in which employees practice recognizing and responding to social engineering scenarios in Teams, Slack or the browser. Peer-reviewed research, including Lain et al. (ETH Zurich, 2022 and 2024), finds that traditional email-based simulated phishing does not reduce risk and can increase misplaced trust in the inbox."
    },
    "name" : "Does CyberCoach do phishing tests?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "No. Learning is anonymous: how an employee answered a training scenario is never visible to managers or administrators. What is recorded is successful completion, so the organization can evidence who has completed required training for compliance purposes. This is privacy by design: the sensitive part of the interaction stays private, and only the completion fact is retained."
    },
    "name" : "Are individual employee answers visible to managers?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. CyberCoach can be deployed using pseudonymous identifiers, such as Slack or Microsoft UUIDs, so no personal data is shared with CyberCoach. Compliance reporting still works: the mapping between a UUID and a real person is resolved only for authenticated and authorized administrators within the customer's own organization."
    },
    "name" : "Can CyberCoach be used without sharing personal data?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "CyberCoach supports security awareness and secure development training requirements under ISO/IEC 27001 and SOC 2, and includes assessments covering ISO 27001, GDPR and AI compliance on the Complete plan."
    },
    "name" : "Which compliance requirements does CyberCoach support?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "CyberCoach is available in English, Spanish, Portuguese (Brazil), Portuguese (Portugal), Polish, French, Dutch, German, Swedish, Norwegian, Danish and Finnish, with more languages in development."
    },
    "name" : "Which languages does CyberCoach support?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Plans start at 49 EUR per month for Starter, 159 EUR per month for Advanced and 179 EUR per month for Complete, available monthly or yearly, including through the Microsoft Azure Marketplace."
    },
    "name" : "How much does CyberCoach cost?"
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.cybercoach.com/legal-basis-phishing-simulation#article",
  "@type" : "Article",
  "about" : [ {
    "@type" : "Thing",
    "name" : "General Data Protection Regulation"
  }, {
    "@type" : "Thing",
    "name" : "Employee profiling"
  }, {
    "@type" : "Thing",
    "name" : "Legitimate interest"
  }, {
    "@type" : "Thing",
    "name" : "Security awareness training"
  }, {
    "@type" : "Thing",
    "name" : "EU AI Act"
  } ],
  "author" : {
    "@type" : "Organization",
    "name" : "CyberCoach",
    "url" : "https://www.cybercoach.com/"
  },
  "citation" : [ {
    "@type" : "CreativeWork",
    "author" : "Lain, Kostiainen, Capkun",
    "datePublished" : "2022",
    "isPartOf" : "IEEE Symposium on Security and Privacy",
    "name" : "Phishing in Organizations: Findings from a Large-Scale and Long-Term Study"
  }, {
    "@type" : "CreativeWork",
    "author" : "Lain, Jost, Matetic, Kostiainen, Capkun",
    "datePublished" : "2024",
    "isPartOf" : "ACM Conference on Computer and Communications Security",
    "name" : "Content, Nudges and Incentives: A Study on the Effectiveness and Perception of Embedded Phishing Training"
  }, {
    "@type" : "CreativeWork",
    "author" : "Brunken, Buckmann, Hielscher, Sasse",
    "datePublished" : "2023",
    "isPartOf" : "USENIX Security Symposium",
    "name" : "To Simulate or Not to Simulate: Hidden Costs of Simulated Phishing"
  } ],
  "dateModified" : "2026-08-26",
  "datePublished" : "2026-08-26",
  "description" : "Human risk management platforms profile employees under Article 4(4) GDPR. Only legitimate interest is realistically available to most European employers, and its necessity limb is directly challenged by recent peer-reviewed evidence on the efficacy of deceptive phishing simulation.",
  "disambiguatingDescription" : "General information for security and privacy professionals. Not legal advice.",
  "headline" : "What is the legal basis for AI-driven phishing simulation and human risk scoring under the GDPR?",
  "inLanguage" : "en",
  "publisher" : {
    "@id" : "https://www.cybercoach.com/#organization"
  },
  "url" : "https://www.cybercoach.com/legal-basis-phishing-simulation"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.cybercoach.com/legal-basis-phishing-simulation#faq",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "There is no prohibition on simulated phishing as such and it has not been ruled unlawful. The GDPR requires a valid legal basis for the employee personal data it generates, together with transparency, proportionate design, a defined retention period and, where national law requires, employee representative involvement. For a private employer the realistic basis is legitimate interest under Article 6(1)(f), which must be documented and kept current. This is general information, not legal advice."
    },
    "name" : "Is simulated phishing legal in the EU?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Usually it is a difficult basis to rely on. EDPB and Article 29 Working Party guidance treats employee consent as presumptively not freely given because of the imbalance of power in the employment relationship, and consent that cannot be refused without consequence would not qualify. A few member states appear to have legislated specifically: Germany's Federal Data Protection Act Section 26(2) is generally read as permitting employee consent under stated conditions, and Danish commentary describes the Danish position as more permissive than the default, while Finnish and Portuguese provisions are reported as narrowing or excluding it. Most member states have no specific rule either way. These are secondhand characterizations offered for orientation only, and local counsel should confirm the position for each country in scope."
    },
    "name" : "Can an employer rely on employee consent for phishing simulations?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes, on the ordinary reading of Article 4(4) GDPR. A score derived from automated evaluation of an employee's behavior, used to predict future reliability and to target them with further processing, is profiling. That triggers heightened transparency duties under Articles 13 and 14, an Article 21 right to object where legitimate interest is the basis, and a likely data protection impact assessment obligation under Article 35."
    },
    "name" : "Are per-employee phishing risk scores profiling under the GDPR?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "It can, because necessity and balancing under Article 6(1)(f) are factual judgments rather than fixed legal conclusions. Necessity requires that the processing actually achieve its purpose and that no less intrusive means would suffice. Where independent peer-reviewed studies report little or no durable benefit and documented costs to trust and incident reporting, a controller relying on legitimate interest carries a heavier evidential burden than when the benefit was assumed."
    },
    "name" : "Does research showing phishing simulations are ineffective affect the legal basis?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "No. These frameworks require awareness, education and training, and testing of security controls. None prescribes deceptive simulation of named individuals and none requires retaining per-person failure records. An obligation to train is not an obligation to deceive and score, which is why Article 6(1)(c) legal obligation does not carry this processing."
    },
    "name" : "Do ISO 27001, SOC 2, NIS2 or DORA require phishing simulations?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "It may. Annex III of Regulation (EU) 2024/1689 treats AI systems intended to monitor or evaluate the behavior or performance of workers as high risk, and obligations for those systems became applicable on 2 August 2026. Whether a particular susceptibility-scoring engine falls inside that classification depends on its intended purpose, so deployers should obtain a written position from the provider, since deployer duties including human oversight and worker information can follow."
    },
    "name" : "Does the EU AI Act apply to security awareness platforms?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. Individual results and derived risk scores are personal data and fall within the Article 15 right of access, alongside information about purposes, recipients and retention and, where profiling is involved, meaningful information about the logic. Employees may also object under Article 21 where the basis is legitimate interest."
    },
    "name" : "Can employees request their phishing simulation results?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Largely yes. If learning interactions are anonymous and only successful completion is recorded, there is no per-person performance record to justify, disclose or defend. Deployment on pseudonymous identifiers such as Microsoft UUIDs can mean the vendor never receives personal data, while the customer's own authenticated and authorized administrators retain the mapping needed for compliance reporting."
    },
    "name" : "Can security awareness training be delivered without processing personal data?"
  } ]
}
```