What is the legal basis for AI-driven phishing simulation and human risk scoring under the GDPR?
Human risk management platforms profile employees: they send simulated attacks, record who failed, and calculate individual risk scores that drive automated targeting. Under the GDPR that is profiling of employee personal data, and it needs a legal basis under Article 6. In practice, only legitimate interest is available to most European employers — and legitimate interest requires that the processing actually be necessary to achieve the stated purpose. That is precisely the claim a growing body of peer-reviewed research now puts in question.
This page sets out the analysis as a security leader would need to present it to a data protection officer, and as a DPO would need to document it: what is being processed, which legal bases are realistically available, how the necessity and balancing tests interact with the efficacy evidence, and what the EU AI Act adds from 2 August 2026 onward.
This article is general information for security and privacy professionals, published by CyberCoach, a vendor of an alternative approach. It is not legal advice, it does not create a lawyer–client relationship, and it does not account for your sector, your jurisdiction, your collective agreements or your facts. Data protection law is applied nationally and interpretation evolves. Obtain qualified local counsel before relying on any position described here, and treat our commercial interest as a reason to check our reasoning rather than to accept it.
The short answer
What is actually being processed?
Before the legal basis question can be answered, the processing has to be described. A modern human risk management platform typically holds, per named employee:
Two features of that inventory matter legally. First, the data is generated by the employer's own deception rather than volunteered by the employee, so the employee is not a participant in the collection. Second, the output is an evaluative judgment about a person's competence, which is the kind of processing employees most reasonably object to and which sits closest to employment consequences.
Is simulated phishing with individual tracking "profiling"?
Article 4(4) GDPR defines profiling as any automated processing of personal data to evaluate personal aspects of a natural person, in particular to analyze or predict aspects such as performance at work, reliability or behavior. A platform that records how an employee responded to a simulated attack, converts it into a susceptibility score, and uses that score to predict how they will behave next is likely to meet that definition.
Consequently, it is also how the platforms describe themselves: the product category renamed itself "human risk management" precisely because the value proposition is individual-level measurement and prediction. A DPIA that describes the same system as something less than profiling may be hard to reconcile with the vendor's own marketing claims.
The four candidate legal bases, one at a time
Article 6(1) offers six bases. Two — vital interests and public task — are not available to an ordinary private employer running an awareness program. That leaves four worth working through.
Consent — Article 6(1)(a)
Consent must be freely given. European regulators have taken the consistent position that an employee is rarely in a position to refuse an employer, because of the imbalance of power in the relationship. This argument is set out in the Article 29 Working Party's opinion on data processing at work and carried forward in the EDPB's consent guidelines. Consent that cannot be withdrawn without consequence is not consent.
There is also a structural problem specific to deceptive simulation: informed consent to a specific test defeats the test. A program can be announced in general terms, but the moment participation is genuinely optional and genuinely refusable, the population you measure is no longer the population you wanted to protect.
Legal obligation — Article 6(1)(c)
This basis requires a legal obligation to carry out the specific processing. No European instrument requires employers to send deceptive messages to their own staff or to score them individually. NIS2 requires cyber hygiene practices and security training for management and employees; the frameworks organizations audit against — ISO/IEC 27001 Annex A 6.3, SOC 2, DORA — require awareness, education and training, and testing of controls. None of them prescribes deceptive simulation of individuals, and none requires retaining per-person failure records.
The distinction that matters in the file: an obligation to train is not an obligation to deceive and score. Evidence of completion satisfies an auditor. A susceptibility ranking is a choice the employer made, and must justify separately.
Performance of a contract — Article 6(1)(b)
This basis is read narrowly: the processing must be objectively necessary to deliver the contract. Guidance on Article 6(1)(b) has consistently emphasized that necessity here means objective necessity for the contract itself, rather than convenience for the controller. It may be difficult to argue that an employment contract requires the employer to test its employees by deception in order to pay them and provide work.
Legitimate interest — Article 6(1)(f)
In practice, this is the only realistic basis, and it is the one named in most vendor documentation and customer DPIAs. It is also the only one that requires the employer to keep proving something over time — which is why the accumulating efficacy evidence changes the picture rather than leaving it untouched.
One further note on Article 9: awareness programs are not intended to process special category data, but free-text responses, disability-related accessibility needs, or health-related lures can pull it in incidentally. This should also be considered in the DPIA.
Do national rules change the consent analysis?
Article 88 GDPR allows member states to legislate for the employment context, and a handful appear to have addressed employee consent directly. The result is fragmentation that specialists themselves describe as contested, so the summaries below are offered as orientation for a conversation with counsel rather than as conclusions.
Germany — the clearest carve-out
Section 26(2) of the Federal Data Protection Act (BDSG) is generally read as permitting employee consent, and it goes further than a bare cross-reference by describing circumstances said to indicate that consent was freely given — commonly summarized as a legal or economic advantage for the employee, or employer and employee pursuing the same interest — with a written form requirement. One complication to raise with counsel: the CJEU’s 2023 judgment in C-34/21 found parts of Section 26 wanting against Article 88’s requirement for "more specific rules", and commentary appears divided on the precise consequences for subsection (2).
Denmark — often described as more permissive
Danish commentary is frequently cited for the proposition that the national act supplementing the GDPR leaves more room for employee consent than the European default. The plausible scope discussed in that commentary looks narrow: arrangements an employee can genuinely decline without detriment, closer in character to a voluntary benefit than to a mandatory security control. Whether a phishing simulation program could be designed to sit inside that space is a question for Danish counsel and Datatilsynet’s current practice.
Finland — reported as going the other way
Finnish provisions on privacy in working life are commonly described as making the necessity requirement for processing worker data something consent cannot displace, which would leave consent unavailable as a general basis regardless of how it is obtained. If Finland is in scope for your program, that reading is worth confirming early rather than late.
Portugal — reported as inverting the German logic
Portuguese law is discussed in commentary as excluding consent where the processing brings the employee an economic or legal advantage — close to the opposite of the factor Germany is understood to treat as evidence that consent was free. Two jurisdictions, apparently opposite tests, same regulation.
Most member states — no specific rule either way
The majority appear not to have legislated on employee consent specifically. That is not a prohibition: Article 6(1)(a) remains formally available. But without a national provision to point to, an employer is left arguing against EDPB and Article 29 Working Party guidance that treats employee consent as presumptively not freely given because of the power imbalance. Formally available and practically defensible are different things.
The design problem consent does not solve
Separate from the legal question, there is a structural one: informed consent to a specific deceptive test defeats the test, and a program employees can genuinely refuse will be refused first by the people whose exposure justified it. A consent-based design is also the least portable across borders, which matters for any multinational organization.
The legitimate interest test, and where the evidence bites
Legitimate interest is a three-limb test, and all three must hold. The EDPB set out this structure in its Opinion 1/2024 on Article 6(1)(f), and the Court of Justice applied the same reasoning in KNLTB (C-621/22, October 2024): a controller's interest does not become lawful simply by being commercially real.
Usually satisfied
Protecting the organization against social engineering is a legitimate interest, and Recital 49 explicitly recognizes network and information security as one. This limb can be defensible.
Where the efficacy research lands
Necessity asks two questions. Does this processing actually achieve the stated purpose? And is there a less intrusive way to achieve it? A negative answer to either is fatal to the basis, and both answers are empirical rather than legal.
This is the structural shift. For a decade, "we send simulated phishing and score employees because it reduces risk" was an untested but plausible assertion. It is now a contested empirical claim, and the controller is the party who has to evidence it.
Weakened by the same evidence
Balancing weighs the interest against the rights, freedoms and reasonable expectations of the data subject, with the employment power imbalance counting against the employer. The heavier side of the scale is supposed to be the security benefit. If that benefit is small or unproven, the same intrusion has less to weigh against — and evidence of harm to trust and reporting behavior moves weight to the employee's side rather than merely removing it from the employer's.
A documentation point that follows directly: a legitimate interest assessment written in 2019 and never revisited may not suffice in 2026. The balancing test is a judgment about facts, and we are now starting to accumulate sufficient empirical and independent (not vendor published) data about the effectiveness of phishing simulations.
What does the peer-reviewed evidence say?
Four large studies published between 2022 and 2026, covering roughly 36,000 employees in real organizations, examine whether deceptive simulation delivers the protective benefit it is justified by. They are summarized here for the necessity analysis; each is described in full on the science behind CyberCoach.
Employees who failed and were sent to training clicked more afterwards
Lain, Kostiainen and Capkun found that the embedded training page delivered on failure — the mechanism that justifies collecting failure data in the first place — was associated with worse subsequent behavior, not better. For a necessity analysis, this is the most damaging shape of result: it targets the specific processing operation rather than the general idea of awareness training.
The nudge did the work, not the content — and mandatory retraining added nothing
Lain and colleagues found improvements attributable to the reminder that a program exists rather than to the training material delivered, and no measurable benefit from compelling repeat failures into further training. Both findings undercut the necessity of per-person failure records: if the effective ingredient is a general prompt, individual-level data is not needed to deliver it.
Documented costs to trust, culture and reporting
Brünken, Buckmann, Hielscher and Sasse catalogued the hidden costs of simulated phishing, including damage to the employee–employer relationship and to the willingness to report genuine incidents. Balancing-test relevance: a control that suppresses reporting costs both parties: it produces a security cost to the employer, as well as a privacy cost to the employee.
Click rates tracked lure difficulty, not employee capability
Rozema and Davis found no meaningful improvement in detection ability from phishing simulations, with click rates only moving with how hard the lure was — 7% for easy lures, 15% for hard ones. This goes to the validity of the score itself: if the number mostly measures the difficulty of the test you chose, an employee ranking built from it is not measuring what the simulation platform intended to measure. A profile that does not measure what it claims to measure is difficult to defend as accurate under Article 5(1)(d), let alone as necessary.
Google has published its own position that it does not run surprise phishing tests against its staff, citing the damage to trust relative to the benefit. That is not authority, but it is evidence that a sophisticated security organization considers the deceptive simulations harmful and avoidable.
Do risk scores trigger Article 22?
Article 22 restricts decisions based solely on automated processing that produce legal effects or otherwise significantly affect a person. A score that generates the next simulated email is unlikely to reach that threshold. A score that automatically restricts a person's access, enrolls them in mandatory remedial training, flags them to HR, or feeds a performance conversation is a different matter — and the Court of Justice's judgment in SCHUFA (C-634/21) shows that producing the score can itself be the decision when a downstream actor predictably follows it.
The practical question for a DPO is not "does the vendor call it a decision" but "what happens to a person when their score goes up, and does a human meaningfully intervene before it happens?"
What does the EU AI Act add?
The AI Act operates alongside the GDPR, not instead of it, and two parts are directly relevant to AI-driven awareness platforms.
Employment as a high-risk use case
Annex III classifies AI systems intended to be used to monitor or evaluate the behavior or performance of workers as high risk. Whether a susceptibility-scoring engine falls inside that classification is a question of its intended purpose, and it is one your vendor should be able to answer in writing.
The compliance deadline for standalone Annex III high-risk obligations was deferred by Regulation (EU) 2026/1744 (the Digital Omnibus on AI), from 2 August 2026 to 2 December 2027. Two things did not move: Article 50 transparency duties and the Article 4 AI-literacy obligation remain on their original schedule, and the Article 5 prohibition on workplace emotion inference has applied since February 2025.
Prohibited practices
Article 5 prohibits inferring emotions in the workplace, and prohibits social scoring leading to detrimental treatment in unrelated contexts. Standard awareness platforms are not designed to do either. The point of naming these is that as vendors add engagement, sentiment and behavioral-nudge features, the boundary is worth watching — and asking about — rather than assumed.
There is a compounding effect here that security leaders should see clearly. A control whose necessity is contested under the GDPR, whose accuracy is questioned by the research, and which may sit in the AI Act's high-risk category, carries three separate documentation burdens. An approach that delivers personalized and effective hands-on training but never profiles individuals carries none of them.
Works councils and national employment law
Article 88 lets member states legislate specifically for the employment context, and several have. The result is that GDPR compliance is necessary but not sufficient.
What to document, whichever approach you choose
This list is deliberately neutral. An organization that works through it and decides to continue with deceptive simulation is in a far stronger position than one that never asked.
The design question underneath the legal one
Almost every obligation above exists because the program creates a per-employee performance record. Remove that record and the analysis simplifies dramatically: no profiling, no balancing test to lose, no susceptibility score to disclose in a subject access request, no Article 22 question, no argument with a works council about a monitoring system.
Compliance evidence does not require it either. Auditors ask whether required training was completed, and completion records answer that. The individual failure data is collected for measurement, and this type of measurement is the what recent research questions.
Frequently asked questions
Is simulated phishing legal in the EU?
There is no prohibition on simulated phishing as such, and it has not been ruled unlawful. What the GDPR requires is a valid legal basis for processing the employee personal data it generates, together with transparency, a proportionate design, a defined retention period and — where national law requires — employee representative involvement. The realistic basis for a private employer is legitimate interest under Article 6(1)(f), which must be documented and kept current.
Can an employer rely on employee consent for phishing simulations?
Generally not. European regulators treat employee consent as rarely freely given because of the imbalance of power in the employment relationship, and consent that cannot be refused without consequence is invalid. Certain countries like Denmark have national supplementing legislation that is understood to be more permissive, but the plausible scope is narrow — genuinely voluntary arrangements an employee can decline without detriment.
Are per-employee phishing risk scores profiling under the GDPR?
Yes, on the ordinary reading of Article 4(4). A score derived from automated evaluation of an employee's behavior, used to predict their future reliability and to target them with further processing, is profiling. That triggers heightened transparency duties, an Article 21 right to object where legitimate interest is the basis, and a likely DPIA obligation.
Does research showing simulations are ineffective affect the legal basis?
It can, because necessity and balancing are factual judgments rather than fixed legal conclusions. Necessity requires that the processing actually achieve its purpose and that no less intrusive means would do. Where independent peer-reviewed studies report little or no durable benefit, and documented costs to trust and incident reporting, a controller relying on legitimate interest carries a heavier evidential burden than it did when the benefit was simply assumed.
Does ISO 27001, SOC 2, NIS2 or DORA require phishing simulations?
These frameworks require awareness, education and training, and testing of security controls; none prescribes deceptive simulation of named individuals, and none requires retaining per-person failure records. An obligation to train is not an obligation to deceive and score.
Does the EU AI Act apply to security awareness platforms?
It may. Annex III treats AI systems intended to monitor or evaluate the behavior or performance of workers as high risk. The compliance deadline for that category was pushed from 2 August 2026 to 2 December 2027 by the Digital Omnibus on AI (Regulation (EU) 2026/1744) — but Article 50 transparency duties and the Article 4 AI-literacy obligation were not deferred, and classification itself doesn't wait: a multi-year contract signed today will still be live when the new deadline arrives. Whether a particular susceptibility-scoring engine falls inside Annex III depends on its intended purpose; deployers should get a written position from the provider now, since deployer duties — human oversight and worker transparency — attach to the buyer regardless of when enforcement starts.
Can employees request their phishing simulation results?
Yes. Individual results and derived risk scores are personal data, so they fall within the Article 15 right of access, alongside information about the purposes, recipients and retention period and, where profiling is involved, meaningful information about the logic. Employees may also object under Article 21 where the basis is legitimate interest.
Can security awareness training be delivered without processing personal data?
Largely, yes. CyberCoach allows learner-led personalization choices that are not stored or connected to users during anonymous learning interactions and only records successful completion, sothere is no per-person performance record to disclose or defend. Deployment on pseudonymous identifiers such as Microsoft UUIDs further minimizes personal data processing, while the customer's own authorized administrators retain the reports needed for compliance reporting.
Published by CyberCoach, which sells a security awareness platform that does not profile individual employees. We have a commercial interest in the conclusions above and have tried to state the counter-arguments accordingly. Nothing here is legal advice or a legal opinion, no lawyer–client relationship arises from reading it, and it does not address your jurisdiction, sector, collective agreements or facts. Legislation, national implementing law, regulatory guidance and case law change; provisions and dates should be checked against current official sources. Obtain qualified local counsel before acting.
Primary sources referred to: Regulation (EU) 2016/679 (Articles 4(4), 5, 6, 9, 13–15, 21, 22, 35, 88 and Recital 49); Regulation (EU) 2024/1689 (AI Act, Article 5 and Annex III); Regulation (EU) 2026/1744 (Digital Omnibus on AI), amending Regulation (EU) 2024/1689; Directive (EU) 2022/2555 (NIS2); EDPB Opinion 1/2024 on legitimate interest; Article 29 Working Party Opinion 2/2017 on data processing at work; CJEU C-621/22 (KNLTB) and C-634/21 (SCHUFA); the Danish Data Protection Act supplementing the GDPR. Research: Lain, Kostiainen and Capkun, IEEE Security & Privacy 2022; Lain, Jost, Matetic, Kostiainen and Capkun, ACM CCS 2024; Brünken, Buckmann, Hielscher and Sasse, USENIX Security 2023; Rozema and Davis, ACM Web Conference 2026; Google Security Blog, 2024.
Read the research before the sales pitch
Every study cited above is summarized, with its limitations, on the science page, including the findings that complicate our own argument.
Phishing Training Makes Employees More Prone to be Phished
An entire phishing simulation industry has emerged to combat the dangers of phishing attacks...