Phone numbers in BelgiumProvisioned by Callstrike after approval
Belgium is workable for a voice phishing simulation and it is full of traps that are not where you would look for them: the recording rule everyone cites was repealed, the exception the regulator still describes was withdrawn in 2022, and the likeliest reason your campaign fails is not legal at all but a border rule that stops the calls arriving.
Phone numbers
Supplied by Callstrike
Local numbers in Belgium, after a one-time approval.
Running a simulation
Permitted
How you word the purpose decides whether you may name who failed.
Consent
Declined as a basis here
The regulator points to your authority under the employment contract instead.
Getting a phone number in Belgium
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Belgian numbers are not released from open inventory, so your workspace is cleared once and Callstrike then provisions a dedicated Belgian number against it. The clearance is register-based: the company's name, its enterprise number and its address, all evidenced from the commercial register, with the address inside the area the number's prefix covers.
Then the thing that decides whether the campaign works, and it has nothing to do with the clearance. A 2024 royal decree requires operators receiving inbound international calls to block every one presenting a Belgian number. A platform dialling Belgian staff from outside the country while showing a Belgian caller identity simply does not arrive. There is a derogation, and it is worth using rather than working around: it runs over a special interface under the originating operator's control, with an agreement listing the exact numbers it covers.
01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
03A dedicated number in Belgium is assigned to youCallstrike
04Build and launch the campaignYour team
What you provide
Accepted evidence, any one of
Business addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable where a local address is required.
Excerpt from the commercial register, Utility bill, Tax notice, Rent receipt, Title deed
Business registration number
Excerpt from the commercial register
Business name
Excerpt from the commercial register
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in Belgium?
The position in short, before your counsel reads the detail below.
Yes. The Belgian rule on unwanted communications lives in the economic law code, which states its own purpose as market practices and consumer protection, and every operative limb is tied to direct prospecting, direct marketing or advertising. An authorised test of your own staff is outside the chapter regardless of whether a person or a system is speaking, and you are not obliged to screen your own employees against the national opt-out list before calling them.
The basis is where Belgium diverges from its neighbours. The regulator declines to treat a worker's agreement as a lawful basis for electronic monitoring, on the ground that a person in a position of subordination cannot give it freely, and what it puts in its place is not the balancing ground that carries most of this portal but the employer's own right to exercise authority under the contract of employment. It frames that with three principles: a legitimate aim, control limited to what is strictly necessary, and informing the worker of the control and how it is carried out. The regulator also notes that its own basis has been criticised for imprecision, which is a reason to write the assessment carefully rather than to relax.
The single most consequential drafting decision on this page is how you word the purpose, because it changes what you may do with the results. The collective agreement on monitoring runs a closed list of four purposes and forks on them. Framed as protecting the security and proper technical functioning of your systems, you may go straight from an anomaly to the identity of the person responsible. Framed as testing compliance with your own rules on using the technology, you owe a published warning first, one free pass, and an interview with the person before any decision that affects them. Take that decision deliberately rather than discovering it afterwards.
Two things to hold in mind that most Belgian summaries miss. Recording should be treated as requiring everyone's authorisation: the criminal provision universally cited was repealed in September 2026, the telecoms rule the regulator actually relies on has no participant qualifier on its storage limb, and the business recording exception went in 2022 while the regulator's own page still describes it as live. And since September 2026 a harassment offence reaches a single act and is aggravated where committed by a person in authority over the victim, which is exactly the relationship a simulation runs in. Pretext design is a criminal question here, not only a human resources one.
What your company needs to do
6 items, in the order you will need them.
Word the purpose deliberately, and write it down onceBelgium-specificThe four permitted purposes are a closed list and the one you choose decides your procedure afterwards. Security and technical functioning gives you direct attribution of a result to a person. Compliance with your own acceptable-use rules costs you a published warning, a first anomaly that cannot be acted on, and an interview before any decision.
Solve the border blocking before you plan the campaignBelgium-specificCalls arriving from outside Belgium with a Belgian caller identity are blocked at the international interface. The derogation exists for exactly this shape of service and it requires an agreement with the originating operator containing an exhaustive list of the numbers covered. Domestic origination avoids the question entirely.
Treat recording as needing everyone's authorisationBelgium-specificDo not reason from the criminal code, and do not rely on the call-centre exception the regulator's page still describes: it was repealed with effect from August 2022. Capturing outcomes rather than audio removes the question, which is the cleanest available answer while the regulator's own guidance is four years behind the statute.
Design the pretext against the new harassment offenceBelgium-specificA single act now suffices, the standard is what you ought to have known, and the penalty steps up where the person committing it holds authority over the victim. A bereavement, redundancy or medical pretext is where that bites. Put pretext review into the campaign approval rather than leaving it to whoever writes the script.
Inform the representatives, then inform people individuallyThe order is prescribed: the works council, or failing that the prevention committee, or failing that the union delegation, or failing that the workers. Then each worker individually when the system is installed, covering the control policy, the purposes, whether personal data are retained and where and for how long, and whether the control is permanent.
Schedule the evaluation, because it is the recurring dutyThe collective agreement requires a regular evaluation of the control systems installed, in the works council, the prevention committee or with the union delegation, so as to propose revisions. It is the only ongoing consultation obligation in the instrument, and it is the one programmes forget in year two.
The controls that do the work
How Callstrike is configured, and which provision in Belgium each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
The regulator's second principle is that control be limited to what is strictly necessary, and it applies that against a basis it has itself called imprecise, so the necessity argument carries more weight in Belgium than the basis does. A call that ends the instant an employee starts to give up a credential is strictly necessary by construction rather than by assertion: the exercise measures the behaviour and the credential is never acquired. It also keeps the collected data small enough that the individualisation fork is about a result rather than about a recording.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
This is where the new harassment offence and the collective agreement point the same way. The offence turns on deliberately disturbing a person's tranquillity where you ought to have known the effect, aggravated by your authority over them. A call that ends within seconds in a second voice explaining what happened, and vishing training in writing the same day, is a materially different act from one that leaves an employee frightened until a report circulates. Design that in rather than adding it later.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
The regulator declines a worker's agreement as the basis, so this is not that. Its third principle is informing the worker of any electronic control and of the way it is carried out, and it recommends the work rules as the vehicle while accepting a transparent policy, a contract clause or a collective agreement. A hashed copy of whichever instrument you already have, with a signed and timestamped attestation of the scope, is that information layer evidenced rather than asserted.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
In Belgium this is the route that gets a programme running while the border derogation is still being arranged. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after the module, and a call a person opens in their own browser presents no calling line identification at an international interface, so the decree that decides whether telephone calls arrive has nothing to attach to.
Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.
The regulator rejects consent, and names authority instead
Belgium enacted no employment-specific chapter when it implemented the GDPR. We counted the framework act through: the words for employer, worker and employment relationship appear nowhere in it, and its two references to an article 88 are self-references to its own article of that number rather than to the GDPR's employment provision. The space that other countries fill with a statute is filled in Belgium by collective labour agreements, which is why the consultation section below carries more weight here than almost anywhere else in this portal.
The regulator's position on consent is unusually blunt and worth having in its own words. It observes that the regime allowing an employer lawfully to access a worker's electronic communications is relatively constraining, that with the worker's consent access would certainly be possible under telecommunications legislation, but that the question arises whether a worker who is necessarily in a position of subordination can effectively give that consent freely. That is why, it says, it declines to regard consent given by the worker as a legal basis for electronic monitoring carried out by the employer.
What it puts in consent's place is not the legitimate interests ground that carries the weight elsewhere. It says the employer's legal right to exercise authority provides the solution: if the employer's power of control under the contract of employment can justify an interference with the worker's private life, that interference is strictly framed by a number of principles. The three it names are that the employer must pursue a legitimate aim, must limit the control to what is strictly necessary, and must inform the worker of any electronic control and of the manner in which it is carried out. It recommends distributing that information through the work rules, while accepting a transparent policy on information technology, a specific clause in the individual contract, or a collective agreement.
The regulator flags the weakness in its own reasoning, which is rare enough to quote. Part of the case law, it says, considers that the employment contracts act is a sufficient legal basis because it contains provisions on the employer's power of authority and on the duty of mutual respect, and although that position has been criticised for its imprecision, it has been followed by the authority. A regulator telling you that its own basis is contested is a good reason to write the assessment down carefully rather than to relax.
One further exposure arrived on 1 September 2026 and it has nothing to do with data protection. The new criminal code creates a harassment offence consisting in deliberately disturbing a person's tranquillity, even where that occurs on a single occasion or results from a single act, where the person knew or ought to have known that the conduct would seriously affect the tranquillity of the person targeted. It is aggravated to the next penalty level where the offence is committed by a person in a position of authority or trust in relation to the victim. The provision it replaced required repeated nuisance over a telecommunications network. The new one needs one act, an objective ought-to-have-known standard, and it upgrades the penalty for precisely the relationship a simulation is run in. We are not saying any particular campaign meets it. We are saying that in Belgium the design of the pretext, and especially a bereavement, redundancy or medical pretext, is now a criminal question and not only a human resources one.
The famous article is dead, and it was the wrong one alive
Two things happened to Belgian call recording and most published answers have caught neither.
The first is that the criminal code everyone cites no longer exists. The Code pénal of 1867 was repealed with effect from 1 September 2026 by a concordance law of 3 March 2026, and its article 314bis went with it. The official consolidation does carry the repeal, on the 1867 code's own title line, which is exactly where a reader jumping straight to the article will not look. The successor provision reproduces the offence and keeps the crucial words: it is an offence deliberately, by means of any device, to intercept, take cognisance of or record communications not accessible to the public to which one is not a party, without the consent of all participants. A party to the call is still outside it. So the substance survived and the citation did not, and for months every competitor page will be citing a repealed provision.
The second is more important, because it changes the answer rather than the reference. The data protection authority's stated position is that recording electronic conversations, professional or private, is in principle prohibited, and that the prohibition it relies on is not in the criminal code at all. It is in the electronic communications act: unless authorised by all persons directly or indirectly concerned, nobody may intentionally take cognisance of the existence of information of any kind transmitted by electronic communication which is not intended for him personally, may intentionally identify the persons concerned by the transmission and its content, or may modify, delete, reveal, store or make any use whatsoever of the information or data obtained, whether intentionally or not.
Read the limbs against each other, because the difference is the whole point. The first limb carries a qualifier, information not intended for him personally, which a party to the call can argue its way out of. The limb about storing, or making any use whatsoever, carries no such qualifier and hangs off the same opening condition: unless authorised by all persons directly or indirectly concerned. That is why the regulator states the position as a prohibition in principle rather than as a one-party rule, and it is why a page that reads the criminal provision alone and concludes that a participant may record publishes the confident wrong answer.
Now the part that will catch a careful researcher. The regulator's own guidance page tells employers that an exception lets call centres monitoring service quality, and firms recording lawful commercial transactions to preserve evidence, listen to and even record conversations without the participants' consent. That exception was repealed with effect from 18 August 2022. Its history explains the stale page without excusing it: it was repealed in 2016, the Constitutional Court annulled that repeal in 2021, and a 2022 act repealed it again in terms. We counted the consolidated act through for the phrases the exception used and both return nothing. The exception is not moved, it is gone, and the surviving exceptions are for acts the law itself permits or requires, for checking that the network functions, for emergency services, for the regulator, for the ombudsman, for blocking unwanted communications and for operators fighting message fraud. None of them is an employer.
A second offence in the new criminal code is worth knowing because it survives lawful capture. Using a recording that was lawfully made, with fraudulent intent or intent to harm, is itself an offence. Recording lawfully is not a permanent licence over the audio.
If you do record, the regulator is specific about who must be told and when. The employer must inform workers of the existence of the recording, its purpose and the access and rectification rights, for example through the work rules, and the parties involved in the communication must be informed of the recording, its precise purposes and the storage period, before the recording. It stresses that this is not only about workers: other parties to the call must receive the information too.
One loose end, reported because it is real rather than because we can resolve it. The surviving exceptions provision still cross-refers to article 314bis of a criminal code that was repealed on 1 September 2026. Belgian consolidated law currently contains a live exception clause pointing at a dead provision, and the concordance law did not catch it.
Prospecting is the trigger, in every limb of the chapter
The Belgian rule on unwanted communications sits in the economic law code, and the code says what it is for in its own opening article: this book principally concerns the regulation of market practices and the protection of the consumer. Everything below follows from that framing.
The operative prohibition is that the use of automated calling systems without human intervention, and of fax machines, for the purposes of direct prospecting, is prohibited without the prior, free, specific and informed consent of the recipient. Other telephone communications for the purposes of direct marketing are permitted so long as the subscriber has not manifestly objected. Every limb is tied to direct prospecting, direct marketing or advertising, so an employer running an authorised test against its own staff is outside the chapter regardless of whether a person or a system is speaking.
The national opt-out list follows the same logic and is worth stating precisely, because the duty it creates is operational rather than passive. Any telephone call made for direct marketing reasons to a number on the do-not-call list is prohibited, and for any such call the caller must check beforehand whether the number is on the list. That pre-call screening duty is real, the burden of proving compliance rests on the person doing the marketing, and none of it reaches an internal security test. An employer is not obliged to screen its own staff against the list.
One provision is often quoted out of its scope and should not be. The code prohibits concealing the identity of the undertaking on whose behalf a communication is made, but expressly only when sending advertising by the techniques covered by the direct marketing paragraph. It is not a general rule that a caller may never hide who it is. The rule that does govern caller identity is in the telecoms act and is set out in the next section.
The European transparency duties reach Belgium directly, and they are Article 50 of the EU AI Act. Since 2 August 2026 a provider must design a system intended to interact directly with people so that those people are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person, and a deployer of a system generating or manipulating audio constituting a deep fake must disclose that the content is artificially generated. The information must be given in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. The only exceptions are for use authorised by law to detect, prevent, investigate or prosecute criminal offences, and for evidently artistic or satirical works.
A different article of the same Regulation should be read before a voice product ships an analytics feature. Inferring emotions of a natural person in the workplace is a prohibited practice, in force since 2 February 2025 and carrying up to thirty-five million euros or seven per cent of worldwide turnover, subject to a narrow exception for medical or safety reasons. The prohibition is gated by a definition confined to inference from biometric data, and the recitals put the mere detection of readily apparent expressions or of characteristics such as a raised voice outside it. Recording who disclosed a credential is nowhere near this. Scoring how stressed a named employee sounded is a definitional argument with a percentage of turnover attached.
Belgium has not designated its authorities under that Regulation. The Commission's own table shows a dash against Belgium, and the Belgian economy ministry's page, updated on 3 September 2026, says only that it handles the general coordination of implementation. We searched the official gazette for a designation instrument and found none, and Belgium did publish one for the Digital Services Act, so the absence is meaningful. What we will not say is that Belgium definitively has not designated: we will say that none is published, and that the duties bind either way.
Four instruments, and the one that stops you is at the border
Belgium has a statutory anti-spoofing rule, a numbering condition, a set of regulator guidelines and a blocking decree, and none of them is the clean rule people assume. Reading them as a chain is the only way to get the right answer.
The statute binds the caller and it turns on intent. It is prohibited to alter the calling line identification, or the sender of a text message, with the intention of causing harm to the called party or the recipient, or of deceiving them. Separately, the identification supplied with a numbering-based call must be transmitted unaltered to the called party and must comprise a valid telephone number that uniquely identifies the calling connection or person. Note what the statute does not say: it does not, in terms, require the caller to hold a right of use in the number. And note the word deceive, because deceiving the called party is exactly what a pretext call does. That is the sharpest sentence on this page.
There is a negative finding worth recording alongside it. The provision listing the articles that carry the act's fifty to one hundred thousand euro fine does not include the caller identification article. The prohibition is not backed by that penalty, and we did not establish which enforcement route replaces it.
The numbering decree binds your operator rather than you. The holder of numbering capacity must ensure that the number presented to the called party is the same as the number allocated to the calling line, unless the holder proves that this is not technically feasible, and numbers may only be assigned to users out of capacity properly allocated. The technical-infeasibility escape is real and is why this is not the clean rule either.
The intuitive rule, that the caller must be able to show a right of use in the number it presents, exists in Belgium in exactly one place: the regulator's caller identification guidelines, which require operators to permit a presentation number only where the end user can demonstrate a right of use and an agreement exists about that use, require operators to act without delay when they become aware of users presenting numbers without a right of use, and require regular revalidation. Those guidelines describe themselves as recommendations, they date from December 2020, and they were written in anticipation of a statutory spoofing ban that has since arrived and has not caused them to be reissued. Treat them as the operator's working practice, not as the current legal framework.
The rule most likely to decide whether your campaign works at all is none of those. A 2024 royal decree requires operators receiving inbound international calls on their international network interfaces to block every call using a Belgian geographic or non-geographic number as the calling line identification, along with calls that do not conform to the relevant international recommendation and calls presenting short numbers. A platform dialling Belgian staff from outside Belgium while presenting a Belgian number simply does not arrive.
The decree does provide the route through, and a serious deployment should use it. Cloud-based teleconference, customer assistance and telephone direct marketing services using Belgian geographic numbers may be permitted by way of derogation, provided they are carried over a special interface where call routing is entirely under the control of the originating operator, and provided in the case of customer assistance and marketing services that the calls and numbers are wholly under the control of and allocated to an undertaking established in Belgium. The derogation requires an agreement with the caller's operator containing an exhaustive list of the numbers it covers. The regulator adds that the decree does not reach text traffic, voice calls placed from within Belgium, calls presenting foreign numbers, or calls received while the called person is roaming abroad.
Two closing points. Belgium has no do-not-originate list, whatever is widely reported: the regulator said in May 2025 that it will not introduce one for the time being, and the enabling provision remains unexercised for telephony. There is a separate voluntary blacklist limited to certain bank numbers and to inbound international traffic, which is not the same thing. And freephone, premium rate and short numbers can never be presented as a calling line identity, because no call originates from them.
Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.
How you word the purpose decides what you may do afterwards
Belgium puts its monitoring rules in a collective labour agreement rather than a statute, and that agreement contains something no other country in this portal has: a fork where the purpose you write down determines the procedure you owe afterwards.
Start with the purposes, because the list is closed. Control of networked electronic communication data is authorised only where one or more of four purposes is pursued: preventing unlawful or defamatory acts, acts contrary to public decency or acts capable of harming another's dignity; protecting the confidential economic, commercial and financial interests of the undertaking and combating practices contrary to them; the security or proper technical functioning of the undertaking's networked information systems, including the control of associated costs and the physical protection of installations; and good-faith compliance with the principles and rules for using networked technologies laid down in the undertaking. The employer must define the purpose clearly and explicitly.
Now the fork. Attributing collected data to an identified or identifiable worker is what the agreement calls individualisation, and it comes in two procedures according to the purpose. Where the purpose is one of the first three, individualisation is direct: on spotting an anomaly the employer may go straight from aggregate data to the identity of the person responsible. Where the purpose is the fourth, compliance with the firm's own rules on using the technology, individualisation is permitted only after a prior information phase whose object is to make the existence of the anomaly known to the workers in a certain and comprehensible way and to warn them that a further anomaly of the same kind will be individualised. On that route the worker to whom an anomaly can be attributed must then be invited to an interview before any decision or evaluation liable to affect them individually.
A vishing simulation can be described honestly either way. Framed as security it sits in the third purpose and the employer may name who failed. Framed as testing compliance with the firm's own acceptable-use rules it sits in the fourth, and the employer owes a published warning, one free pass, and an interview before acting on the result. That is a drafting decision with legal consequences, and it should be taken deliberately rather than discovered afterwards.
The transparency machinery is a list you can work through. The employer that wishes to install a control system informs the works council or, failing that, the committee for prevention and protection at work or, failing that, the union delegation or, failing that, the workers. It informs the workers concerned individually when the system is installed, in information that must be effective, comprehensible and kept up to date, in a medium the employer chooses. The mandatory content is prescribed: the control policy and the prerogatives of the employer and of the supervising staff, the purposes pursued, whether personal data are retained and if so where and for how long, and whether the control is permanent. The individual layer adds the rules on using the tool including limits on functional use, the workers' rights, duties and any prohibitions, and the sanctions provided in the work rules for a breach.
There is one recurring duty, and it is the only consultation-shaped obligation in the agreement: an evaluation of the installed control systems must be carried out regularly, as the case may be within the works council, the prevention committee or with the union delegation, so as to make proposals for revising them in the light of technological developments.
Nowhere in any of this is a veto. The works council's statutory mission is to give its opinion and formulate suggestions or objections on any measure that might alter work organisation, working conditions or the undertaking's output, and to draw up and amend the work rules; the prevention committee's is to research and propose. The work-rules limb is the strongest of them and is the reason the regulator treats the work rules as the natural home for a monitoring policy. But no Belgian instrument makes employer monitoring conditional on the representatives agreeing.
Two neighbouring agreements are worth knowing so you can rule them out with a reason rather than by silence. The one on new technologies imposes a genuine written information and concertation duty at least three months before implementation, but only in undertakings averaging fifty or more workers and only where an investment in a new technology has important collective consequences, defined as affecting at least fifty per cent and at least ten workers of a given occupational category. A simulation is very unlikely to clear that bar, though a standing enterprise-wide platform will get the question asked. The agreement on workplace surveillance by cameras is about cameras and reaches a telephone call on no reading.
Finally, an honest limit on all of the above. The agreement's own scope definition reads differently in its two official languages: the French text speaks of networked electronic communication data throughout, the Dutch of on-line communication data. A voice call is unambiguously networked; whether it is on-line is a different question, and every worked example in the agreement is email or web browsing. The text does not settle whether it reaches a telephone call, and we are not going to settle it for you.
Everything says train, and the only framework naming it says email
Belgium transposed the European network and information security directive by a law of 26 April 2024, in force on 18 October 2024 and since amended once. Among the risk-management measures it requires are basic cyber hygiene practices and cybersecurity training. Nothing in it names phishing, vishing or social engineering, and nothing requires a simulation.
One transposition detail matters if you are citing chapter and verse. The Directive's governance article has a second sentence requiring entities to offer similar training to their employees on a regular basis. The Belgian governance article stops after the management-body sentence: directors approve the measures, supervise implementation, bear responsibility for breach and follow training themselves. Belgium put the employee half in the risk-management article instead. That is a defensible choice, but an employee-training duty cited to the Belgian equivalent of the governance article is cited to the wrong provision.
We also counted the act through for the national cybersecurity framework everyone associates with Belgium, and it is not named in the act at all. The statute routes everything through the national cybersecurity authority rather than through a named framework, which the authority's own reference is mentioned in more than a hundred times. We could not retrieve the framework's own text, which is served behind a block that refused every request, so nothing here is asserted about its content.
For financial entities the European digital operational resilience Regulation applies directly and it is emphatic about training and silent about technique. It requires financial entities to develop information and communications technology security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes, applicable to all employees and to senior management, at a complexity commensurate with their functions, extending to third-party providers where appropriate. Its menu of test types runs from vulnerability assessments and scans through gap analyses and scenario-based tests to penetration testing, and threat-led penetration tests must be carried out at least every three years on live production systems. We counted the Regulation through: social engineering and phishing each return nothing. It does not mandate a vishing simulation and does not name the technique.
The Belgian threat-led testing framework is the closest any of this comes to the activity, and it is careful about its own status. Its national implementation guide states that executing such a test is not mandatory unless a regulation specifically says otherwise, that some institutions participate voluntarily while others are or will be tested as a mandatory requirement under the European Regulation, and that the central bank team operates neither in a supervision nor in an oversight capacity but as a catalyst.
What the framework does give you is a documentation template. The confirmed rules of engagement must record the tactics, techniques and procedures allowed and not allowed in the attack, the ethical boundaries for social engineering, and how the privacy of the parties involved will be safeguarded. Social engineering otherwise appears only in an optional physical breach scenario that the control team may exclude.
And a negative that deserves to be stated because the temptation to imply otherwise is strong. We counted both of the central bank's published documents through for the word voice and found it in neither. Every occurrence of the suffix in both is phishing, and the worked scenario describes launching spear-phishing campaigns against carefully selected employees to evaluate susceptibility and measure the effectiveness of email filtering and awareness training. The framework names phishing, describes it as email, and never mentions voice phishing. No Belgian regime we could source mandates a vishing simulation, and this page will not imply that one does.
Paste into Claude, Harvey or your firm's tool to pressure-test the position above.
You are advising on an authorised internal security exercise in BELGIUM. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. Workers are informed in advance under the work rules.
Verify or correct each proposition below against primary Belgian sources:
1. ⚠ Code penal 1867 art. 314bis was REPEALED with effect from 1 September 2026 by the concordance law of 3 March 2026; the successor is new Code penal art. 342, which keeps the participant carve-out.
2. ⚠ For recording, art. 124 LCE governs and its limb 4 hangs off a chapeau requiring authorisation from ALL persons directly or indirectly concerned, with no 'not intended for him personally' qualifier. Confirm this displaces the participant analysis.
3. ⚠ Art. 125 §2 LCE (the call-centre exception) was repealed with effect from 18 August 2022, after a 2016 repeal annulled by the Constitutional Court in 2021. The APD's own guidance page still describes it as live.
4. CDE arts VI.110 to VI.113 are tied to direct prospecting, marketing or advertising in every limb, so an internal test is outside the chapter and outside the DNC pre-screening duty.
5. CCT 81's four purposes are closed, and individualisation under the fourth requires a prior information phase and an interview. ⚠ Its scope reads 'en reseau' in French and 'on-line' in Dutch; both are official. Does it reach a telephone call?
6. Code penal arts 237 and 238 (harassment, live 1 September 2026) reach a single act and are aggravated for a person in authority over the victim.
7. The AR of 12 May 2024 requires blocking of inbound international calls presenting Belgian CLI; describe the derogation conditions precisely.
Flag anything that has changed since September 2026.
Common questions
May a party to the call record it in Belgium?
The criminal provision still exempts a participant, but the regulator says recording is prohibited in principle under the telecoms act, which requires authorisation from all persons directly or indirectly concerned and has no participant qualifier on its storage limb. Treat Belgium as an all-parties country.
Is the call-centre recording exception still available?
No. It was repealed with effect from 18 August 2022, after an earlier repeal that the Constitutional Court annulled in 2021. The data protection authority's own guidance page still describes it as live, which is the single most dangerous stale statement we found anywhere in this portal.
Can the works council block the campaign?
No. Its role is to give an opinion and to draw up the work rules, and the collective agreement on monitoring requires information rather than agreement, plus a regular evaluation of the systems installed. No Belgian instrument makes employer monitoring conditional on worker representatives consenting.
Why might our Belgian calls never connect?
Because a 2024 royal decree makes operators block every inbound international call presenting a Belgian number. Dialling Belgian staff from outside Belgium with a Belgian caller identity fails at the border unless a special-interface agreement listing your exact numbers is in place with the originating operator.
Elsewhere in Western Europe
The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.