Short answer: yes - running phishing simulations on staff is legal in Australia, and it is standard practice in Australian businesses and MSP-managed client environments. But it is not a lawless free-for-all. Two states regulate how employers may monitor employee computer use, and a poorly run simulation programme can fall squarely inside those rules. The difference between a defensible programme and a risky one is mostly paperwork: notice, policy and a no-blame culture.
TL;DR
- Phishing simulations are legal in Australia; no law prohibits testing employees with simulated phishing.
- NSW (Workplace Surveillance Act 2005) and the ACT (Workplace Privacy Act 2011) regulate computer surveillance of employees at work - simulated phishing emails are computer-based monitoring, so they sit in scope.
- Both acts require written notice to employees before surveillance starts - 14 days under each act - and the ACT adds a consultation requirement.
- The practical fix is universal: notify every employee, put simulations in the security policy, and apply the programme nationally even though only NSW and ACT mandate it.
- Covert testing is the trap: NSW allows it only with a court-issued covert surveillance authority.
Why this matters
The question comes up for a good reason: a phishing simulation is, technically, an employer sending deceptive emails to employees to observe how they respond. In most Australian workplaces that is ordinary computer use monitoring - lawful, but covered by the employer's duty to be transparent about surveillance. In NSW and the ACT, that transparency is a statutory requirement, and getting it wrong is not a reputational problem; it can make the surveillance itself unlawful.
MSPs carry a second layer of this: when you run simulations for a client, the client is the employer doing the monitoring. Your programme needs to survive the client's legal review in the strictest state they have staff in, not the average one.
Who this is for
MSPs running security awareness programmes for Australian clients, and internal IT, HR and people teams launching simulations for the first time. This is general information, not legal advice - for a binding answer, the client's employment lawyer reads the current acts.
The two acts that matter
Australia has no single national workplace surveillance statute. The most comprehensive regulation of workplace surveillance sits in two jurisdictions:
- New South Wales - the Workplace Surveillance Act 2005 (NSW). It covers optical, computer and tracking surveillance of employees at work. Computer surveillance - which is what a phishing simulation and its click-tracking are - is unlawful unless the employer has given notice in accordance with the act. The standard form is 14 days' written notice before the surveillance begins, and the notice must set out details such as the kind of equipment used and when the surveillance takes place. The act also prohibits surveillance in change rooms, toilets and shower facilities, and surveillance of employees outside work.
- The ACT - the Workplace Privacy Act 2011 (ACT). A parallel regime covering optical, tracking and data surveillance devices. Employers must give 14 days' written notice to affected workers before covered surveillance starts, and the act requires the employer to consult with employees in good faith before introducing the surveillance.
Everywhere else in Australia there is no dedicated workplace surveillance act, but employers are not in a legal vacuum: general privacy obligations under the Privacy Act 1988 (Cth) apply to the personal information collected, and the fair-work and work-health-and-safety frameworks still expect proportionate, communicated monitoring.
What this means for phishing simulations
A simulation programme does several things the acts care about:
- It sends computer-generated messages to employees at work - the deceptive email is the surveillance instrument.
- It tracks computer use: opens, clicks, credential entries and report actions are recorded per employee.
- It collects personal information - who clicked, when, how they scored - which then sits in a reporting system.
Under the NSW and ACT regimes, all of that is in scope the moment it happens without notice. With notice, policy and a defined programme, it is ordinary, lawful monitoring. The statutes effectively encode the best practice any security team should adopt anyway: tell people testing happens, say what is measured, and write it down.
The five-point compliance checklist
- Notify every employee before the first simulation. A written notice of at least 14 days before the programme starts covers the NSW and ACT requirements, and it costs nothing. State that simulated phishing will be used, that clicks and reports are recorded, and what the data is used for.
- Put it in the policy. The notice should point at the security or IT acceptable-use policy, which states that the company runs ongoing phishing simulations as part of its security programme. Policy coverage makes the ongoing cadence lawful without a fresh notice each campaign.
- Consult - especially for ACT staff. The ACT act requires good-faith consultation before surveillance is introduced. A staff announcement, an FAQ, and a channel for questions satisfy the spirit; document that it happened.
- Collect only what the programme needs. Per-user click and report data is the point of the programme. Do not extend tracking into keystrokes, screenshots or personal devices, and keep the reporting window no longer than the programme requires.
- Use the data for training, not punishment. The notice and policy should say the results drive coaching. Beyond the legal framing, this is also the design choice that makes simulations work: staff who fear punishment hide clicks, and hidden clicks are unreported compromises.
What NOT to do
- No covert simulations. Covert surveillance in NSW requires a covert surveillance authority issued by a court - the practical standard no awareness programme meets. Unannounced is fine; unannounced-to-everyone-forever is not.
- No targeting personal devices or personal time. The NSW act prohibits surveillance of employees outside work. Simulate to work addresses on the work programme.
- No deceptive consequences beyond the simulation. A simulated phish is a test; following it with real disciplinary deception - fake HR investigations, punitive gotcha pages with staged consequences - invites both legal and cultural blowback.
- No public shaming. Leaderboards that celebrate reporters, yes. Wall-of-shame pages naming clickers, no. The first builds reporting culture; the second destroys it and makes the monitoring disproportionate to its stated purpose.
- Do not collect what you will not use. If your human risk reporting aggregates risk rather than naming individual clickers, say so in the notice - it reassures staff and narrows the data use.
How to announce a programme
One email, one page, done in 200 words:
- What is happening: from [date], we will run ongoing simulated phishing emails as part of our security programme.
- What is measured: opens, clicks and reports are recorded to measure our resilience and target training.
- How it is used: results guide training and coaching. Simulations are a learning tool, not a performance measure.
- What staff should do: report anything suspicious - including the simulations. Reporting is the behaviour we celebrate.
- Where the policy lives, and who to ask.
Send it 14 days before the first campaign, keep it in the policy, and reference it in onboarding for new starters - who should also see the notice on day one, not after their first simulation.
Common mistakes
- State-by-state thinking. Only NSW and ACT mandate notice, but the programme is one programme. Apply the notice and policy nationally - it is simpler and covers every jurisdiction.
- Contract-only coverage. A line buried in the employment contract is weaker than a policy staff have actually seen. Do both.
- One-time notice for a changed programme. If the programme changes materially - new channels, new data uses - re-notify.
- Forgetting new hires. The notice covers the programme; onboarding should reference it, and the annual policy acknowledgment should include it.
What to do next
Legal cover is the floor, not the goal. The programme that justifies itself is one with a real curriculum - security awareness training on a monthly cadence - and simulations that measure whether the training landed, run through phishing simulations with a no-blame reporting culture on top. If the business case needs a risk picture first, a gap assessment shows where the human layer is exposed before anyone spends a dollar.
FAQ
Is it legal to phish your own employees in Australia?
Yes, with notice. No Australian law prohibits phishing simulations. NSW and the ACT regulate the computer surveillance involved, and both require written notice before it starts - 14 days under each act - with the ACT also requiring consultation.
Do we need consent from each employee?
No. The NSW and ACT regimes run on notice, not consent: give the required written notice, cover the programme in policy, and consult in the ACT. Consent frameworks from GDPR-style thinking are not what the Australian acts require.
What about other states - Victoria, Queensland, Western Australia?
They have no dedicated workplace surveillance act covering computer monitoring the way NSW and ACT do, but general privacy and employment obligations still apply. Notifying staff and covering simulations in policy satisfies all of them and keeps the programme uniform.
Can we run simulations without telling staff when they will be tested?
Yes - the notice covers the programme, not the schedule. Nobody needs to know which Tuesday the next simulation lands.
Can we discipline staff who click?
You can manage performance, but the smarter design choice is not to. Punishing clicks suppresses reporting, and reporting is the behaviour that protects everyone else. State in the notice that results drive coaching, and reward fast reporting instead.
Do the rules change for remote staff?
No. The notice and policy apply nationally; staff working from home in NSW or the ACT get the same written notice as anyone in the office. Nothing about distributed teams weakens the notice requirement.
One last thing
Check that the simulation reporting you buy aggregates risk instead of naming individual clickers in every export. It reassures staff, keeps the data use proportionate to the stated purpose, and makes the notice easier to write.