Is it legal to run phishing simulations on staff in Australia?

Yes - phishing simulations are legal in Australia. What NSW and ACT workplace surveillance laws require: 14 days' notice, consultation in the ACT, and a no-blame programme design.

Short answer: yes - running phishing simulations on staff is legal in Australia, and it is standard practice in Australian businesses and MSP-managed client environments. But it is not a lawless free-for-all. Two states regulate how employers may monitor employee computer use, and a poorly run simulation programme can fall squarely inside those rules. The difference between a defensible programme and a risky one is mostly paperwork: notice, policy and a no-blame culture.

TL;DR

Why this matters

The question comes up for a good reason: a phishing simulation is, technically, an employer sending deceptive emails to employees to observe how they respond. In most Australian workplaces that is ordinary computer use monitoring - lawful, but covered by the employer's duty to be transparent about surveillance. In NSW and the ACT, that transparency is a statutory requirement, and getting it wrong is not a reputational problem; it can make the surveillance itself unlawful.

MSPs carry a second layer of this: when you run simulations for a client, the client is the employer doing the monitoring. Your programme needs to survive the client's legal review in the strictest state they have staff in, not the average one.

Who this is for

MSPs running security awareness programmes for Australian clients, and internal IT, HR and people teams launching simulations for the first time. This is general information, not legal advice - for a binding answer, the client's employment lawyer reads the current acts.

The two acts that matter

Australia has no single national workplace surveillance statute. The most comprehensive regulation of workplace surveillance sits in two jurisdictions:

Everywhere else in Australia there is no dedicated workplace surveillance act, but employers are not in a legal vacuum: general privacy obligations under the Privacy Act 1988 (Cth) apply to the personal information collected, and the fair-work and work-health-and-safety frameworks still expect proportionate, communicated monitoring.

What this means for phishing simulations

A simulation programme does several things the acts care about:

Under the NSW and ACT regimes, all of that is in scope the moment it happens without notice. With notice, policy and a defined programme, it is ordinary, lawful monitoring. The statutes effectively encode the best practice any security team should adopt anyway: tell people testing happens, say what is measured, and write it down.

The five-point compliance checklist

  1. Notify every employee before the first simulation. A written notice of at least 14 days before the programme starts covers the NSW and ACT requirements, and it costs nothing. State that simulated phishing will be used, that clicks and reports are recorded, and what the data is used for.
  2. Put it in the policy. The notice should point at the security or IT acceptable-use policy, which states that the company runs ongoing phishing simulations as part of its security programme. Policy coverage makes the ongoing cadence lawful without a fresh notice each campaign.
  3. Consult - especially for ACT staff. The ACT act requires good-faith consultation before surveillance is introduced. A staff announcement, an FAQ, and a channel for questions satisfy the spirit; document that it happened.
  4. Collect only what the programme needs. Per-user click and report data is the point of the programme. Do not extend tracking into keystrokes, screenshots or personal devices, and keep the reporting window no longer than the programme requires.
  5. Use the data for training, not punishment. The notice and policy should say the results drive coaching. Beyond the legal framing, this is also the design choice that makes simulations work: staff who fear punishment hide clicks, and hidden clicks are unreported compromises.

What NOT to do

How to announce a programme

One email, one page, done in 200 words:

Send it 14 days before the first campaign, keep it in the policy, and reference it in onboarding for new starters - who should also see the notice on day one, not after their first simulation.

Common mistakes

What to do next

Legal cover is the floor, not the goal. The programme that justifies itself is one with a real curriculum - security awareness training on a monthly cadence - and simulations that measure whether the training landed, run through phishing simulations with a no-blame reporting culture on top. If the business case needs a risk picture first, a gap assessment shows where the human layer is exposed before anyone spends a dollar.

FAQ

Is it legal to phish your own employees in Australia?

Yes, with notice. No Australian law prohibits phishing simulations. NSW and the ACT regulate the computer surveillance involved, and both require written notice before it starts - 14 days under each act - with the ACT also requiring consultation.

Do we need consent from each employee?

No. The NSW and ACT regimes run on notice, not consent: give the required written notice, cover the programme in policy, and consult in the ACT. Consent frameworks from GDPR-style thinking are not what the Australian acts require.

What about other states - Victoria, Queensland, Western Australia?

They have no dedicated workplace surveillance act covering computer monitoring the way NSW and ACT do, but general privacy and employment obligations still apply. Notifying staff and covering simulations in policy satisfies all of them and keeps the programme uniform.

Can we run simulations without telling staff when they will be tested?

Yes - the notice covers the programme, not the schedule. Nobody needs to know which Tuesday the next simulation lands.

Can we discipline staff who click?

You can manage performance, but the smarter design choice is not to. Punishing clicks suppresses reporting, and reporting is the behaviour that protects everyone else. State in the notice that results drive coaching, and reward fast reporting instead.

Do the rules change for remote staff?

No. The notice and policy apply nationally; staff working from home in NSW or the ACT get the same written notice as anyone in the office. Nothing about distributed teams weakens the notice requirement.

One last thing

Check that the simulation reporting you buy aggregates risk instead of naming individual clickers in every export. It reassures staff, keeps the data use proportionate to the stated purpose, and makes the notice easier to write.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.