analysis

What is the legal basis for AI-driven phishing simulation and human risk scoring under the GDPR?

Human risk management platforms profile employees: they send simulated attacks, record who failed, and calculate individual risk scores that drive automated targeting. Under the GDPR that is profiling of employee personal data, and it needs a legal basis under Article 6. In practice, only legitimate interest is available to most European employers — and legitimate interest requires that the processing actually be necessary to achieve the stated purpose. That is precisely the claim a growing body of peer-reviewed research now puts in question.

This page sets out the analysis as a security leader would need to present it to a data protection officer, and as a DPO would need to document it: what is being processed, which legal bases are realistically available, how the necessity and balancing tests interact with the efficacy evidence, and what the EU AI Act adds from 2 August 2026 onward.

Not legal advice

This article is general information for security and privacy professionals, published by CyberCoach, a vendor of an alternative approach. It is not legal advice, it does not create a lawyer–client relationship, and it does not account for your sector, your jurisdiction, your collective agreements or your facts. Data protection law is applied nationally and interpretation evolves. Obtain qualified local counsel before relying on any position described here, and treat our commercial interest as a reason to check our reasoning rather than to accept it.

The short answer

Simulated phishing with per-employee tracking is profiling within the meaning of Article 4(4) GDPR, because it evaluates aspects of a person's behavior and, in scored form, predicts their future reliability
Of the six Article 6 bases, only legitimate interest is realistically available to a private employer in most of Europe. Consent is generally invalid in employment; no law requires simulated phishing; and it is not necessary to perform an employment contract
Legitimate interest has three limbs: a legitimate purpose, necessity, and a balance that does not override employee rights. Necessity is the limb the efficacy research undermines directly
Four peer-reviewed studies covering roughly 36,000 employees report that deceptive simulation produced little or no durable improvement, and even suggest measurable harm
If a less intrusive method (such as CyberCoach) achieves the same purpose, necessity fails as a matter of established data protection reasoning — regardless of how normal the intrusive method has become in the market
Risk scores that trigger consequences without human involvement raise Article 22 questions, and AI systems used to evaluate employees fall in the EU AI Act's high-risk category

What is actually being processed?

Before the legal basis question can be answered, the processing has to be described. A modern human risk management platform typically holds, per named employee:

Identity and organizational data: name, work email, department, manager, location, role
Behavioral event data: which simulated messages were opened, clicked, replied to, reported or ignored, with timestamps
Derived scores: a per-person risk or susceptibility value, often trended over time and benchmarked against colleagues
Automated targeting decisions: which lure, difficulty or remedial training a person receives next, derived from their history
Threat telemetry linkage: in some products, whether the individual is externally targeted, drawn from live email security data
Management visibility: dashboards exposing individual results to line managers, HR, or both

Two features of that inventory matter legally. First, the data is generated by the employer's own deception rather than volunteered by the employee, so the employee is not a participant in the collection. Second, the output is an evaluative judgment about a person's competence, which is the kind of processing employees most reasonably object to and which sits closest to employment consequences.

Is simulated phishing with individual tracking "profiling"?

Article 4(4) GDPR defines profiling as any automated processing of personal data to evaluate personal aspects of a natural person, in particular to analyze or predict aspects such as performance at work, reliability or behavior. A platform that records how an employee responded to a simulated attack, converts it into a susceptibility score, and uses that score to predict how they will behave next is likely to meet that definition. 

Consequently, it is also how the platforms describe themselves: the product category renamed itself "human risk management" precisely because the value proposition is individual-level measurement and prediction. A DPIA that describes the same system as something less than profiling may be hard to reconcile with the vendor's own marketing claims. 

Note the consequence: profiling is lawful, but it raises the transparency bar (Articles 13–14 require meaningful information about the logic), it strengthens the employee's Article 21 right to object where legitimate interest is the basis, and it makes a data protection impact assessment likely under Article 35(3)(a) where the profiling is systematic and extensive and decisions follow from it.

The four candidate legal bases, one at a time

Article 6(1) offers six bases. Two — vital interests and public task — are not available to an ordinary private employer running an awareness program. That leaves four worth working through.

Consent — Article 6(1)(a)

Generally unavailable

Consent must be freely given. European regulators have taken the consistent position that an employee is rarely in a position to refuse an employer, because of the imbalance of power in the relationship. This argument is set out in the Article 29 Working Party's opinion on data processing at work and carried forward in the EDPB's consent guidelines. Consent that cannot be withdrawn without consequence is not consent.

There is also a structural problem specific to deceptive simulation: informed consent to a specific test defeats the test. A program can be announced in general terms, but the moment participation is genuinely optional and genuinely refusable, the population you measure is no longer the population you wanted to protect.

Legal obligation — Article 6(1)(c)

Not available

This basis requires a legal obligation to carry out the specific processing. No European instrument requires employers to send deceptive messages to their own staff or to score them individually. NIS2 requires cyber hygiene practices and security training for management and employees; the frameworks organizations audit against — ISO/IEC 27001 Annex A 6.3, SOC 2, DORA — require awareness, education and training, and testing of controls. None of them prescribes deceptive simulation of individuals, and none requires retaining per-person failure records.

The distinction that matters in the file: an obligation to train is not an obligation to deceive and score. Evidence of completion satisfies an auditor. A susceptibility ranking is a choice the employer made, and must justify separately.

Performance of a contract — Article 6(1)(b)

Not available

This basis is read narrowly: the processing must be objectively necessary to deliver the contract. Guidance on Article 6(1)(b) has consistently emphasized that necessity here means objective necessity for the contract itself, rather than convenience for the controller. It may be difficult to argue that an employment contract requires the employer to test its employees by deception in order to pay them and provide work. 

Legitimate interest — Article 6(1)(f)

The basis almost everyone relies on

In practice, this is the only realistic basis, and it is the one named in most vendor documentation and customer DPIAs. It is also the only one that requires the employer to keep proving something over time — which is why the accumulating efficacy evidence changes the picture rather than leaving it untouched.

One further note on Article 9: awareness programs are not intended to process special category data, but free-text responses, disability-related accessibility needs, or health-related lures can pull it in incidentally. This should also be considered in the DPIA. 

Article 88 GDPR allows member states to legislate for the employment context, and a handful appear to have addressed employee consent directly. The result is fragmentation that specialists themselves describe as contested, so the summaries below are offered as orientation for a conversation with counsel rather than as conclusions.

Germany — the clearest carve-out

Section 26(2) of the Federal Data Protection Act (BDSG) is generally read as permitting employee consent, and it goes further than a bare cross-reference by describing circumstances said to indicate that consent was freely given — commonly summarized as a legal or economic advantage for the employee, or employer and employee pursuing the same interest — with a written form requirement. One complication to raise with counsel: the CJEU’s 2023 judgment in C-34/21 found parts of Section 26 wanting against Article 88’s requirement for "more specific rules", and commentary appears divided on the precise consequences for subsection (2).

Denmark — often described as more permissive

Danish commentary is frequently cited for the proposition that the national act supplementing the GDPR leaves more room for employee consent than the European default. The plausible scope discussed in that commentary looks narrow: arrangements an employee can genuinely decline without detriment, closer in character to a voluntary benefit than to a mandatory security control. Whether a phishing simulation program could be designed to sit inside that space is a question for Danish counsel and Datatilsynet’s current practice.

Finland — reported as going the other way

Finnish provisions on privacy in working life are commonly described as making the necessity requirement for processing worker data something consent cannot displace, which would leave consent unavailable as a general basis regardless of how it is obtained. If Finland is in scope for your program, that reading is worth confirming early rather than late.

Portugal — reported as inverting the German logic

Portuguese law is discussed in commentary as excluding consent where the processing brings the employee an economic or legal advantage — close to the opposite of the factor Germany is understood to treat as evidence that consent was free. Two jurisdictions, apparently opposite tests, same regulation.

Most member states — no specific rule either way

The majority appear not to have legislated on employee consent specifically. That is not a prohibition: Article 6(1)(a) remains formally available. But without a national provision to point to, an employer is left arguing against EDPB and Article 29 Working Party guidance that treats employee consent as presumptively not freely given because of the power imbalance. Formally available and practically defensible are different things.

The design problem consent does not solve

Separate from the legal question, there is a structural one: informed consent to a specific deceptive test defeats the test, and a program employees can genuinely refuse will be refused first by the people whose exposure justified it. A consent-based design is also the least portable across borders, which matters for any multinational organization.

Everything in this section is a secondhand characterization of national law, including where we have named provisions, and national implementations are exactly where secondhand summaries fail. Nothing here should be treated as a determination about any jurisdiction. Local employment and data protection counsel should confirm the position for each country in scope before a program is designed around consent — and the fragmentation itself is a reason to prefer a design that does not depend on the answer.

The legitimate interest test, and where the evidence bites

Legitimate interest is a three-limb test, and all three must hold. The EDPB set out this structure in its Opinion 1/2024 on Article 6(1)(f), and the Court of Justice applied the same reasoning in KNLTB (C-621/22, October 2024): a controller's interest does not become lawful simply by being commercially real.

Limb 1 — a legitimate interest

Usually satisfied

Protecting the organization against social engineering is a legitimate interest, and Recital 49 explicitly recognizes network and information security as one. This limb can be defensible. 

Limb 2 — necessity

Where the efficacy research lands

Necessity asks two questions. Does this processing actually achieve the stated purpose? And is there a less intrusive way to achieve it? A negative answer to either is fatal to the basis, and both answers are empirical rather than legal.

This is the structural shift. For a decade, "we send simulated phishing and score employees because it reduces risk" was an untested but plausible assertion. It is now a contested empirical claim, and the controller is the party who has to evidence it. 

Limb 3 — balancing

Weakened by the same evidence

Balancing weighs the interest against the rights, freedoms and reasonable expectations of the data subject, with the employment power imbalance counting against the employer. The heavier side of the scale is supposed to be the security benefit. If that benefit is small or unproven, the same intrusion has less to weigh against — and evidence of harm to trust and reporting behavior moves weight to the employee's side rather than merely removing it from the employer's.

A documentation point that follows directly: a legitimate interest assessment written in 2019 and never revisited may not suffice in 2026. The balancing test is a judgment about facts, and we are now starting to accumulate sufficient empirical and independent (not vendor published) data about the effectiveness of phishing simulations. 

What does the peer-reviewed evidence say?
Four large studies published between 2022 and 2026, covering roughly 36,000 employees in real organizations, examine whether deceptive simulation delivers the protective benefit it is justified by. They are summarized here for the necessity analysis; each is described in full on the science behind CyberCoach.

14,733 employees · 15 months · IEEE Security & Privacy 2022

Employees who failed and were sent to training clicked more afterwards

Lain, Kostiainen and Capkun found that the embedded training page delivered on failure — the mechanism that justifies collecting failure data in the first place — was associated with worse subsequent behavior, not better. For a necessity analysis, this is the most damaging shape of result: it targets the specific processing operation rather than the general idea of awareness training.

4,554 employees · ACM CCS 2024

The nudge did the work, not the content — and mandatory retraining added nothing

Lain and colleagues found improvements attributable to the reminder that a program exists rather than to the training material delivered, and no measurable benefit from compelling repeat failures into further training. Both findings undercut the necessity of per-person failure records: if the effective ingredient is a general prompt, individual-level data is not needed to deliver it.

USENIX Security 2023

Documented costs to trust, culture and reporting

Brünken, Buckmann, Hielscher and Sasse catalogued the hidden costs of simulated phishing, including damage to the employee–employer relationship and to the willingness to report genuine incidents. Balancing-test relevance: a control that suppresses reporting costs both parties: it produces a security cost to the employer, as well as a privacy cost to the employee.

12,511 employees · ACM Web Conference 2026

Click rates tracked lure difficulty, not employee capability

Rozema and Davis found no meaningful improvement in detection ability from phishing simulations, with click rates only moving with how hard the lure was — 7% for easy lures, 15% for hard ones. This goes to the validity of the score itself: if the number mostly measures the difficulty of the test you chose, an employee ranking built from it is not measuring what the simulation platform intended to measure. A profile that does not measure what it claims to measure is difficult to defend as accurate under Article 5(1)(d), let alone as necessary.

Stated fairly: this literature is drawn from a limited number of organizations, and does not establish that all awareness training is ineffective — several of these authors are explicit that training itself has value. What it does establish is that the specific combination of deception, individual failure records and score-driven targeting can no longer be assumed to work. Necessity requires the controller to hold evidence, and the available independent evidence currently runs the other way.

Google has published its own position that it does not run surprise phishing tests against its staff, citing the damage to trust relative to the benefit. That is not authority, but it is evidence that a sophisticated security organization considers the deceptive simulations harmful and avoidable.

Do risk scores trigger Article 22?

Article 22 restricts decisions based solely on automated processing that produce legal effects or otherwise significantly affect a person. A score that generates the next simulated email is unlikely to reach that threshold. A score that automatically restricts a person's access, enrolls them in mandatory remedial training, flags them to HR, or feeds a performance conversation is a different matter — and the Court of Justice's judgment in SCHUFA (C-634/21) shows that producing the score can itself be the decision when a downstream actor predictably follows it.

The practical question for a DPO is not "does the vendor call it a decision" but "what happens to a person when their score goes up, and does a human meaningfully intervene before it happens?" 

Related exposure worth naming: every per-employee record is disclosable in a subject access request, and derived scores are included. Employees have the right to know their susceptibility ranking, the logic behind it, and who saw it. 

What does the EU AI Act add?

The AI Act operates alongside the GDPR, not instead of it, and two parts are directly relevant to AI-driven awareness platforms.

Employment as a high-risk use case

Annex III classifies AI systems intended to be used to monitor or evaluate the behavior or performance of workers as high risk. Whether a susceptibility-scoring engine falls inside that classification is a question of its intended purpose, and it is one your vendor should be able to answer in writing.

The compliance deadline for standalone Annex III high-risk obligations was deferred by Regulation (EU) 2026/1744 (the Digital Omnibus on AI), from 2 August 2026 to 2 December 2027. Two things did not move: Article 50 transparency duties and the Article 4 AI-literacy obligation remain on their original schedule, and the Article 5 prohibition on workplace emotion inference has applied since February 2025.

Prohibited practices

Article 5 prohibits inferring emotions in the workplace, and prohibits social scoring leading to detrimental treatment in unrelated contexts. Standard awareness platforms are not designed to do either. The point of naming these is that as vendors add engagement, sentiment and behavioral-nudge features, the boundary is worth watching — and asking about — rather than assumed.

There is a compounding effect here that security leaders should see clearly. A control whose necessity is contested under the GDPR, whose accuracy is questioned by the research, and which may sit in the AI Act's high-risk category, carries three separate documentation burdens. An approach that delivers personalized and effective hands-on training but never profiles individuals carries none of them.

Works councils and national employment law

Article 88 lets member states legislate specifically for the employment context, and several have. The result is that GDPR compliance is necessary but not sufficient.

In Germany, technical systems capable of monitoring employee performance or behavior typically require works council co-determination under the Works Constitution Act — a veto point independent of your legal basis
In the Netherlands, France and the Nordics, employee representative consultation obligations and national DPA guidance on workplace monitoring apply alongside the GDPR analysis

What to document, whichever approach you choose

This list is deliberately neutral. An organization that works through it and decides to continue with deceptive simulation is in a far stronger position than one that never asked.

1. A current legitimate interest assessment, dated within the last twelve months, that engages with the published efficacy evidence rather than ignoring it.
2. A documented alternatives analysis: which less intrusive methods were considered, and on what evidence they were rejected as inadequate.
3. A DPIA where one is required for employee monitoring, profiling and/or automated decision-making.
4. Transparency materials that state plainly that simulated attacks will be sent, what is recorded per person, who can see it, and for how long — shared proactively before the program starts, not after a complaint.
5. A defined retention period for individual failure records and derived scores, with deletion actually implemented.
6. A stated position on Article 21 objections: what happens when an employee objects to being profiled, and who decides.
7. An Article 22 analysis of every automated consequence attached to a score, and a record of where human review sits.
8. A written answer from your vendor on whether its system is high risk under Annex III of the AI Act, and what deployer obligations follow for you.
9. Evidence of works council or employee representative engagement where national law requires it, completed before deployment.

The design question underneath the legal one

Almost every obligation above exists because the program creates a per-employee performance record. Remove that record and the analysis simplifies dramatically: no profiling, no balancing test to lose, no susceptibility score to disclose in a subject access request, no Article 22 question, no argument with a works council about a monitoring system.

Compliance evidence does not require it either. Auditors ask whether required training was completed, and completion records answer that. The individual failure data is collected for measurement, and this type of measurement is the what recent research questions.

Our position, stated as an interest and not as a neutral finding: CyberCoach is built without individual scoring — learning is anonymous, only successful completion is recorded per person, and the platform can run on pseudonymous Microsoft identifiers so that no personal data reaches us at all. The research behind that design is documented. We think that is the better answer to the necessity question. You should test that claim against your own facts and your own counsel, exactly as you would test any vendor's legal reasoning about its own product.

Frequently asked questions

Is simulated phishing legal in the EU?

There is no prohibition on simulated phishing as such, and it has not been ruled unlawful. What the GDPR requires is a valid legal basis for processing the employee personal data it generates, together with transparency, a proportionate design, a defined retention period and — where national law requires — employee representative involvement. The realistic basis for a private employer is legitimate interest under Article 6(1)(f), which must be documented and kept current.

Can an employer rely on employee consent for phishing simulations?

Generally not. European regulators treat employee consent as rarely freely given because of the imbalance of power in the employment relationship, and consent that cannot be refused without consequence is invalid. Certain countries like Denmark have national supplementing legislation that is understood to be more permissive, but the plausible scope is narrow — genuinely voluntary arrangements an employee can decline without detriment. 

Are per-employee phishing risk scores profiling under the GDPR?

Yes, on the ordinary reading of Article 4(4). A score derived from automated evaluation of an employee's behavior, used to predict their future reliability and to target them with further processing, is profiling. That triggers heightened transparency duties, an Article 21 right to object where legitimate interest is the basis, and a likely DPIA obligation.

Does research showing simulations are ineffective affect the legal basis?

It can, because necessity and balancing are factual judgments rather than fixed legal conclusions. Necessity requires that the processing actually achieve its purpose and that no less intrusive means would do. Where independent peer-reviewed studies report little or no durable benefit, and documented costs to trust and incident reporting, a controller relying on legitimate interest carries a heavier evidential burden than it did when the benefit was simply assumed.

Does ISO 27001, SOC 2, NIS2 or DORA require phishing simulations?

These frameworks require awareness, education and training, and testing of security controls; none prescribes deceptive simulation of named individuals, and none requires retaining per-person failure records. An obligation to train is not an obligation to deceive and score.

Does the EU AI Act apply to security awareness platforms?

It may. Annex III treats AI systems intended to monitor or evaluate the behavior or performance of workers as high risk. The compliance deadline for that category was pushed from 2 August 2026 to 2 December 2027 by the Digital Omnibus on AI (Regulation (EU) 2026/1744) — but Article 50 transparency duties and the Article 4 AI-literacy obligation were not deferred, and classification itself doesn't wait: a multi-year contract signed today will still be live when the new deadline arrives. Whether a particular susceptibility-scoring engine falls inside Annex III depends on its intended purpose; deployers should get a written position from the provider now, since deployer duties — human oversight and worker transparency — attach to the buyer regardless of when enforcement starts.

Can employees request their phishing simulation results?

Yes. Individual results and derived risk scores are personal data, so they fall within the Article 15 right of access, alongside information about the purposes, recipients and retention period and, where profiling is involved, meaningful information about the logic. Employees may also object under Article 21 where the basis is legitimate interest.

Can security awareness training be delivered without processing personal data?

Largely, yes. CyberCoach allows learner-led personalization choices that are not stored or connected to users during anonymous learning interactions and only records successful completion, sothere is no per-person performance record to disclose or defend. Deployment on pseudonymous identifiers such as Microsoft UUIDs further minimizes personal data processing, while the customer's own authorized administrators retain the reports needed for compliance reporting. 

Full disclaimer, sources and review

Published by CyberCoach, which sells a security awareness platform that does not profile individual employees. We have a commercial interest in the conclusions above and have tried to state the counter-arguments accordingly. Nothing here is legal advice or a legal opinion, no lawyer–client relationship arises from reading it, and it does not address your jurisdiction, sector, collective agreements or facts. Legislation, national implementing law, regulatory guidance and case law change; provisions and dates should be checked against current official sources. Obtain qualified local counsel before acting.

Primary sources referred to: Regulation (EU) 2016/679 (Articles 4(4), 5, 6, 9, 13–15, 21, 22, 35, 88 and Recital 49); Regulation (EU) 2024/1689 (AI Act, Article 5 and Annex III); Regulation (EU) 2026/1744 (Digital Omnibus on AI), amending Regulation (EU) 2024/1689; Directive (EU) 2022/2555 (NIS2); EDPB Opinion 1/2024 on legitimate interest; Article 29 Working Party Opinion 2/2017 on data processing at work; CJEU C-621/22 (KNLTB) and C-634/21 (SCHUFA); the Danish Data Protection Act supplementing the GDPR. Research: Lain, Kostiainen and Capkun, IEEE Security & Privacy 2022; Lain, Jost, Matetic, Kostiainen and Capkun, ACM CCS 2024; Brünken, Buckmann, Hielscher and Sasse, USENIX Security 2023; Rozema and Davis, ACM Web Conference 2026; Google Security Blog, 2024.

Published 26 August 2026
Reviewed quarterly
Corrections: info@cybercoach.com

Read the research before the sales pitch

Every study cited above is summarized, with its limitations, on the science page, including the findings that complicate our own argument.

Get Started Free

No credit card needed.
phishy_badge_cybercoach

Phishing Training Makes Employees More Prone to be Phished

An entire phishing simulation industry has emerged to combat the dangers of phishing attacks...

LEARN MORE