Skip to main content

The lawful basis for testing your own staff

A phishing simulation produces personal data about identifiable employees. DPDP s.4(1) gives two grounds for processing it, s.7(i) is the employment ground, and s.8 governs the dataset on either.

By Abhinav Awasthi
August 31, 20267 min read

An organisation that measures how its workforce responds to a simulated phishing message creates a record about identifiable people: who was sent the message, who opened it, who clicked, who submitted credentials, and at what time. That record is personal data. Processing it needs a ground under the Digital Personal Data Protection Act, 2023.

The Act supplies one. Section 4(1) permits the processing of personal data for a lawful purpose either on the consent of the Data Principal or for a certain legitimate use. Section 7 sets out the legitimate uses, and clause (i) is the employment ground. That is the basis on which an employer runs a simulation against its own staff and records who clicked.

The rest follows from where each obligation sits in the Act. The notice provision is drawn to the consent route. The security and erasure obligations in section 8 apply to the dataset either way.

Why the dataset exists

The obligation to measure and the obligations over what measurement produces come from different instruments, and they bind the same programme.

The Reserve Bank's Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026, issued 31 July 2026, require a commercial bank to "evaluate the awareness level of employees periodically" (Commercial Banks, ¶202; ¶201 for Payments Banks and Small Finance Banks, ¶197 for Credit Information Companies). For NBFCs the construction is different: ¶36 requires a "formal mechanism to measure and track the effectiveness of such training through periodic assessments or testing", together with an "up-to-date repository of the training and awareness status of all users".

SEBI states it at GV.RM Guidelines item 1(e), page 87 of the Cybersecurity and Cyber Resilience Framework, Version 1.0 of 20 August 2024: "REs shall periodically assess level of employee cybersecurity awareness, for e.g., through phishing test success rate, etc." The applicability on that page is "All REs except small-size, self-certification REs (Mandatory)." SEBI requires periodic assessment of awareness, and names phishing test success rate as an example of how.

Each obligation is discharged by producing evidence, and evidence about employees is data about employees. A programme on a quarterly cadence produces it again every quarter.

Section 4(1), and the employment ground

Section 4(1) gives two limbs: personal data may be processed for a lawful purpose for which the Data Principal has given consent, or for a certain legitimate use. Section 7 is headed "Certain legitimate uses". Clause (i) reads:

"for the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee."

Read the clause against what a simulation measures. Phishing is the delivery mechanism for credential theft, and credential theft is the route to the loss of the categories the clause names outright: trade secrets, intellectual property, classified information. A campaign that measures whether staff surrender credentials to a crafted message is processing for purposes related to safeguarding the employer from loss or liability, and the people it processes are Data Principals who are employees. The words of the clause and the purpose of the exercise line up.

Two limits arrive with the ground rather than after it. The processing runs to the employment purpose, so the fields collected are the ones the agreed metrics require. And the population is the employer's own staff: CERT-In's Comprehensive Cyber Security Audit Policy Guidelines, CISG-2025-02, reach the same boundary at §15.2.2(iii), which limits social engineering and process testing to the group of employees explicitly included within the agreed audit scope.

Where the notice obligation sits

Section 5(1) states the notice a Data Fiduciary gives with, or before, a request for consent under section 6. The provision is written to the consent request: it sets out what a Data Principal is told in order to give the consent that section 6 defines.

A simulation programme stands on section 7(i), which is the second limb of section 4(1). Its ground is the employment legitimate use, and the section 5(1) notice provision addresses the consent route.

That distinction is what makes an unannounced exercise coherent with the Act, and it is the one most often lost when the Act is read in summary. Summaries describe a single consent-and-notice pipeline and place every processing activity inside it. Section 4(1) has two limbs, and section 7(i) is in the second.

What applies on either limb is section 8.

Section 8 over the click dataset

Section 8 sets out the general obligations of a Data Fiduciary, and two of them govern the dataset a campaign produces.

Section 8(5) requires reasonable security safeguards to prevent a personal data breach. The click dataset is a list of named employees who, on a stated day, were deceived by a message. Wherever it lives during the campaign — the testing infrastructure, an analyst's export, the reporting pack, a mailbox — it lives under that obligation, and a programme should be able to say where the dataset is at each stage and who can reach it.

Section 8(7)(a) requires erasure "as soon as it is reasonable to assume that the specified purpose is no longer being served". That is a retention rule with an event trigger rather than a calendar date, and it is the rule that governs the list of names.

The specified purpose of a simulation is to evaluate the awareness of a population. The identified layer of the dataset serves that purpose while results are being collected, deduplicated, checked for delivery failures and analysed into cohorts. Once the statistics exist, the purpose is being served by the statistics.

One analysis argues for holding identifiers beyond that point: repeat exposure, meaning whether the same individuals respond across successive campaigns. It is a real measurement question, and the answer is to name it as a purpose at commissioning, with the window it needs, rather than let a dataset persist because nobody fixed the point at which it stops.

A programme carries this in a form a single exercise does not. Every campaign in a series inherits the same retention decision, so one decision, taken once and written down, governs the whole clock.

Two instruments, one disposal

CISG-2025-02, Version 1.0 of 25 July 2025, §15.2.2(iii), pp. 55–56:

"Social engineering and process testing should be conducted in a controlled and ethical manner. When targeting general staff (e.g., untrained or non-security personnel), such testing must utilize anonymized or statistical techniques—ensuring no individual is personally identified or penalized. The purpose is to evaluate overall awareness and the effectiveness of security processes, not to single out individuals."

§4 of the guidelines applies them to CERT-In empanelled auditing organisations, so §15.2.2(iii) binds the auditor conducting the test.

The two instruments arrive at the same disposal from opposite directions. Section 8(7)(a) fixes the point at which the identified layer stops being needed. §15.2.2(iii) fixes the form of the output: anonymised or statistical techniques, with the stated purpose being overall awareness rather than singling out individuals. A click rate by department, a time-to-click distribution and a report rate carry the evidence a regulator asks for, and they carry it in a form that survives the erasure obligation intact.

The convergence settles as a rule what would otherwise be argued as a preference: the output of a measurement programme is a population statistic, and the roster of names is working data on its way to becoming one.

The provisions in one view

ProvisionWhat it governs
DPDP s.4(1)The two limbs on which personal data may be processed for a lawful purpose: consent, or a certain legitimate use
DPDP s.7(i)The employment legitimate use, including purposes related to safeguarding the employer from loss or liability
DPDP s.5(1)The notice given with or before a request for consent under s.6
DPDP s.8(5)Reasonable security safeguards over the dataset, to prevent a personal data breach
DPDP s.8(7)(a)Erasure once it is reasonable to assume the specified purpose is no longer being served
CISG-2025-02 §13.2.7(ii), p. 50Specific written permissions from the auditee organisation before process testing or social engineering
CISG-2025-02 §15.2.2(iii), pp. 55–56Anonymised or statistical techniques for general staff; target population limited to the agreed employee groups

What the authorisation should record

CISG-2025-02 §13.2.7(ii), p. 50, requires that "Specific written permissions must be obtained" from the auditee organisation before tests involving process testing or social engineering. That document is where the data questions belong as well, because it is signed before anything is collected.

  1. The ground: that the processing stands on section 7(i) as a legitimate use, and the employment purpose it serves.
  2. The fields: what is captured per recipient, which should be the minimum the agreed metrics need.
  3. The population: the employee groups explicitly within the agreed scope, per §15.2.2(iii).
  4. The custody of the dataset at each stage of the campaign, and the safeguards over it under section 8(5).
  5. The erasure point for the identified layer, expressed as an event, under section 8(7)(a) — and, where repeat-exposure analysis is wanted, the purpose and window that support holding identifiers longer.
  6. The form of the output: population and cohort statistics, with no individual personally identified or penalised.

An organisation that can answer those six before the first campaign can run the fourth and the twelfth on the same terms. That is what a measurement programme on a regulatory clock needs and a single exercise does not: one decision about lawful basis, custody and retention, taken once, carried across a multi-year series and legible to an auditor at any point in it.

About the author

Abhinav Awasthi

Lead — VAPT & Security Assessments

Leads Security Brigade's VAPT delivery team, having progressed from Security Consultant to Team Lead. Has executed advanced penetration tests across BFSI, fintech, QSR, and telecom — including ICICI Bank, Domino's, and Jubilant FoodWorks.