phishing

Are phishing simulations allowed in Switzerland?

AA
Aurum Avis Labs Author
8 min read

Are phishing simulations allowed in Switzerland?

Phishing simulations are allowed in Switzerland for most private employers if you tell staff beforehand, keep the purpose to practice, and keep individual clicks out of pay, bonuses and warnings. Advice built for a German works council, or for a US programme that ranks people by click rate, answers a different legal system. The Swiss anchors are Article 26 of Ordinance 3 to the Labour Act and Article 328b of the Code of Obligations. This is practical orientation for a company of about 20 to 250 people, not a legal opinion.

52%

Share of reports to BACS classified as fraud in the second half of 2025, in the BACS half-year report: 29,006 voluntary reports plus 145 from the reporting duty. Not our survey.

What Article 26 actually forbids

Article 26 paragraph 1 of Ordinance 3 forbids surveillance and control systems intended to monitor how employees behave at work. SECO’s commentary treats spot checks as part of that, not only a camera that runs all day. A clause in the employment contract does not switch the rule off. The commentary says a private agreement may not depart from it.

A technical system can still be lawful when it is needed for another reason, such as security or how the work is organised. Three things must then be true together: a clearly overriding other interest, proportionality, and employee involvement in planning, use and how long the data is kept.

Which side of that line a phishing simulation falls on depends on its purpose. If it exists mainly to score individuals, it is close to the ban. If it exists to practise whether suspicious mail gets reported, and you only look at aggregated figures, you are further away. The Federal Data Protection and Information Commissioner states that a system is forbidden when its exclusive or main aim is to monitor behaviour, and that people must be informed in advance when another justification exists. It points to Federal Supreme Court decision BGE 130 II 425. Whether a given product meets Article 26 is a case-by-case question, and we have not checked whether a cantonal court has ruled on a named simulation product.

Article 26 applies within the scope of the Labour Act, and that Act has exclusions. Check the Labour Act for your workplace; this page is not the scope note.

What you may do with click data

Article 328b of the Code of Obligations lets an employer process employee data only as far as it concerns suitability for the job or is required to perform the contract. The Data Protection Act applies for the rest. For an exercise, that means you announce the purpose and you stick to it afterwards.

Clicks you announced as training do not belong in the personnel file or in a pay review. Report by department, or aggregate far enough that a team of eight is not a list of names in disguise. Limit access to the people running the exercise. Set the retention period before you send anything, and keep it short.

A training page that asks for the real password creates a secret you then have to protect and delete. A page that stops the attempt and shows the reporting address does the teaching with less data. That is the smaller step when the aim is practice.

Why German and US playbooks miss

German pages on this query turn on works-council co-determination. Switzerland has no such body as a general rule. A collective agreement or a staff committee can still require its own steps. Read that text before the first exercise mail. If there is no such text, the involvement SECO describes is often a written note to everyone: that exercises will happen, why, who sees the figures, and how long they are kept.

US-style league tables of who clicked measure the person. That is the use this article tells you to leave out, even when the tool can produce the names.

Very small teams gain little from automated individual scores. If everyone can already tell who clicked, the chart is a name list whether or not the axis says so.

What to say before the first send

  1. The purpose in one sentence

    For example: we are checking whether suspicious mail reaches the internal reporting address.

  2. What clicks will not be used for

    No warning, no bonus, no entry in the personnel file.

  3. Where real mail goes

    The same address or channel you want people to use outside the exercise.

  4. Who sees the figures, and for how long

    Department, not names. Then delete them. Do not file them in HR.

Leave enough time between that note and the first fake message for the reporting path to become familiar. A note and a send on the same morning mostly measure surprise.

Who should skip the simulation

Skip it if you want names for performance reviews, or if you cannot inform people first. Skip it too if trust between management and the team is already thin: a fake message will be read as a trick, and the next real report may not come.

If a customer or an insurer only asks whether you train people, a documented live session with an attendance list and the topics covered is often enough. What a given insurer requires is in that insurer’s papers, not here.

A simulation is not a test of the firewall, and it is not permission to read private mail. If someone clicks on a real message, your incident steps apply. What staff and managers do first is in what to do if someone clicked a phishing link at work.

How this differs from a live session

A simulation shows behaviour on one day. A live session explains patterns, works through examples, and leaves room for questions about your tools and about payments. Many smaller firms do the session first, then decide whether an exercise would show something the session did not already settle.

Aurum runs security awareness in three parts: a look at the current situation, a live session of one to two hours, and a follow-up conversation a few weeks later. It takes place remotely or on site in Switzerland, with travel included, in German or English.

The session covers phishing, smishing, vishing, passwords, authentication and how to report an incident. Mapping to ISO/IEC 27001:2022 control A 6.3 or to NIST is available on request. The session does not certify the company.

A made-up example

A made-up example: a trading firm with 28 people in the Zurich area. After a fake invoice reached finance, the owner wants an exercise. HR writes to everyone: exercise messages will arrive, results stay by department, a click has no consequence for the person, and the internal reporting address is repeated. Two weeks later the tool runs. Three people click, see a short learning page and the same address. Management sees a chart by department, without names. Finance then sits in the live session and asks how to check a changed IBAN by phone.

The exercise did not replace the session. It showed that most people reported the message, and that finance still wanted clearer payment rules.

What to do first

Write the four points above before anyone switches a tool on. Agree them with HR and with whoever looks after IT. If the last session was more than a year ago, schedule that first. A structured session for Swiss SMEs is described on the security awareness page: recognising suspicious messages, reporting them, and the risks that show up in your roles.

Questions people ask

Common questions

Does German works-council law apply?

No. In Switzerland the relevant rules are Ordinance 3 and the Code of Obligations. A collective agreement or a staff committee can add steps. Those steps are in that text, not in German co-determination law.

Can the contract allow secret tests?

Not under SECO’s commentary on Article 26. A private agreement may not depart from that provision. Tell people first.

May HR see the names of people who clicked?

The tool often can. For an exercise you announced as training, the names do not belong in the personnel file or in a pay review. Limit access and report in aggregate.

May the training page ask for the password?

A page that stops and shows the reporting address does not need that secret. Ask for the real password only if you can explain why the smaller step is not enough, and if you protect the entry and delete it.

Is a session enough without a simulation?

Often yes, when the question is simply whether you train people and the team already talks about suspicious mail. A simulation earns its place when you want to test the reporting path and you can keep the rules above.

What if the message was real?

Then it is not an exercise. Follow your incident steps. What staff and managers do first is in the guide on clicking a phishing link at work.

phishing security awareness switzerland hr
AA

Written by

Aurum Avis Labs

Builds and ships at Aurum Avis Labs. Writes here about what we learn working with founders and SMEs in the DACH region.

Customize your cookie preferences. Essential cookies cannot be disabled as they are required for the website to function properly.

Essential Cookies

Required for basic website functionality, security, user authentication, and error tracking.

Always active

Analytics Cookies

Help us understand how visitors interact with our website to improve user experience. Includes Google Analytics and Microsoft Clarity session recordings.

Marketing Cookies

Used to track visitors across websites to display relevant and engaging advertisements.