phishing simulationslegal aspectsdata protection

    September 3, 2026 · 6 min read · By Fensivo Team

    Phishing simulations on employees: is it legal in LATAM

    Leer en español

    The one-sentence answer: yes, it is legal, with conditions

    Yes, a company in LATAM can run simulated phishing attacks on its employees and measure how they react. This is not a gray area: it is a legitimate security practice, as long as it runs on data from the employment relationship, with a clear protective purpose, in proportion to the risk and communicated inside the internal policy. What turns a legal simulation into a problem is not the exercise itself, but carelessness: collecting more data than needed, exposing a person in front of their peers, or using the result to punish instead of to train. This piece frames the boundaries and points you back to reviewing each case with your legal and human resources teams.

    What data-protection law says about simulating and measuring

    Running phishing simulations by email is not a security whim. According to CISA, more than 90 percent of successful cyberattacks begin with a phishing email, so testing how the team reacts to that vector means measuring risk exactly where it enters. The catch is that the test processes the employee's personal data, and that is where the law has something to say.

    A simulation handles the person's email, how they react to the message and sometimes their role and department. In Colombia that processing falls under Ley 1581 of 2012, the personal-data protection law known as the Habeas Data regime, and its principles repeat with local variations across LATAM, where almost every country has its own data-protection law. The common thread is simple: processing a person's data needs a legitimate basis, an informed purpose and a limit. In the employment relationship, that basis is usually the company's legitimate interest in protecting its information, rather than a signature collected for each practice email.

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment

    Consent and communication: what to disclose without ruining the test

    Here comes the most common doubt: do you have to warn every employee that a simulation is coming? The practical answer is that you disclose the program, not the email. An internal policy stating that the company runs periodic security exercises, for what purpose and what happens with the results, meets the transparency requirement without revealing when each test lands. Announcing the exact message would ruin the measurement, because it would stop reflecting how the person behaves under real pressure and go back to measuring only what they already know.

    The right balance is total clarity about the rules of the game and zero hints about the specific play. That general notice usually lives in the security policy or the acceptable-use agreement the employee already signed. The human side of that notice, how to introduce simulations so the team does not feel trapped, we cover separately in how to introduce phishing simulations without punishment; this guide stays on the legal framing.

    Proportionality: measuring behavior without surveilling the person

    Proportionality is the line that separates a security program from a surveillance tool. Measuring whether a person clicked a practice email and offering them training in the moment is proportionate: the data serves the purpose of reducing risk and says nothing about their private life. Tracking their browsing, reading their real email or building a file to justify an employment decision is not. The minimization principle, present in data-protection laws across the region, requires collecting only what the stated purpose needs.

    A good program keeps the risk score and the response to the simulation, not a behavioral history that exceeds what security needs. It is worth remembering why the exercise runs at all: Cisco's 90-5-5 framework estimates that close to 90 percent of breaches involve a human factor, so the surface you need to measure is behavior in the face of deception, not the person's privacy. The control question is direct: does this data reduce risk, or does it only surveil the employee?

    What to agree with human resources and legal before you start

    Before sending the first simulation it helps to close three internal agreements. With legal, confirm the data-processing basis and that the internal policy already discloses the program's purpose. With human resources, define that the individual result does not feed disciplinary decisions or performance reviews, but training plans. And between the two, agree on who sees what: aggregate results serve to steer the program, while the per-person detail is limited to what remediation needs.

    This is the point where a well-intentioned simulation goes wrong, when data meant to train ends up in a file with a different purpose. Writing it down before you start prevents that drift. And it is worth spelling out: the above frames the boundaries, it does not replace review by your own legal and human resources teams, who know the contract, the internal policy and the law that applies in your country.

    How this becomes a test that validates learning

    There is one last condition that is as legal as it is technical: the simulation must help the person learn, not catch them out. Peer-reviewed evidence is clear that completing training does not on its own predict that someone will stop falling for a real attack (Ho et al., IEEE Symposium on Security and Privacy 2025; Lain et al., IEEE Symposium on Security and Privacy 2022). What proves behavior changed is testing it again weeks later, with a different message of the same type, and seeing whether the person no longer falls.

    That second attempt, the retest, turns measurement into verified learning and, along the way, strengthens the proportionality argument: the goal is not to record who failed, it is to confirm who is now prepared. A test that trains at the moment of failure and validates the change later is easier to defend, before an employee or an auditor, than one that only keeps a tally of clicks.

    At Fensivo we work on exactly that layer, within a human risk management (HRM) approach: we send phishing simulations by email personalized by role and behavior, we train the person at the moment they fall and we validate with a retest weeks later that the change held. What we do not do, to be clear, is give legal advice or manage each company's regulatory compliance: that is decided with each organization's legal and human resources teams. Our ground is preparing and measuring behavior under real pressure, within the framework each client defines, as shown in our use cases.

    Is your simulation program designed to train the people who fail, or only to record who fell?

    Sources and references

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment