Callstrike
Compliance

Voice phishing simulations in Croatia

Phone numbers in CroatiaProvisioned by Callstrike after approval

Croatia is the hardest country in this portal to run a pretext in, and neither reason is a data protection one. The communications act prohibits any false self-presentation by a caller, with no purpose or marketing qualifier attached, and the labour code puts the processing of worker data on the co-decision rung, so the works council agrees in advance rather than being consulted. Read both before choosing how to deliver a voice phishing simulation here.

Phone numbers

Supplied by Callstrike

Local numbers in Croatia, after a one-time approval.

Running a simulation

Permitted, but the pretext is the hard part

The constraint is on falsely presenting yourself as the caller, not on testing your own staff.

Consent

Not the ground, and not the gate

The works council's prior agreement is the gate. Employee agreement is neither.

Getting a phone number in Croatia

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Callstrike clears Croatia against your workspace and provisions the number, and the Croatian filing is unusually tidy because one document carries most of it. An excerpt from the court register evidences the company name, the company registration number and the business address, and the authorised representative named on it identifies themselves with a national identity card, a passport or a residence permit. The address has to sit inside the locality or region the number's own prefix covers, and a post office box is not accepted where a local address is required.

Croatia states the number rule positively rather than as a prohibition, which makes it easy to apply: the calling number must be visible, complete, correct and transmitted in its original form, and must not be altered or truncated. Correct and unaltered are not compatible with substituting a number you do not hold, and the right the act does give a caller is the right to withhold the number rather than to replace it. Then the border rule, in force since January 2024: operators managing international interfaces must block calls arriving from abroad bearing national geographic numbers save in exceptional and justified cases, and accept national mobile numbers only after verifying the user is roaming. We originate Croatian traffic inside Croatia for that reason.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Croatia is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Name of authorized representativeNational ID, Passport, Residence permit
Business nameExcerpt from the court register showing name of authorized representative
Business addressMust be within locality or region covered by the phone number’s prefix; a PO Box is not acceptable where a local address is required.Court register showing local address, Utility bill, Tax notice, Rent receipt, Title deed
Company registration numberExcerpt from court register showing company registration number

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Croatia?

The position in short, before your counsel reads the detail below.

Yes for testing your own workforce, and the marketing rule is not what stands in the way: the requirement for prior agreement to automated calling systems used without human intervention is scoped inside its own operative paragraph to direct promotion and sale, and an internal exercise promotes and sells nothing. The Croatian problem is a different article entirely, and it is the sharpest single provision in this portal.

In public communications networks, any false self-presentation by the caller is prohibited. Read the construction rather than the summary: there is no purpose element, no marketing element, no agreement gateway and no exception, and the prohibition is freestanding inside an article otherwise about malicious and harassing calls. No other country in this portal prohibits the pretext as such; elsewhere the constraint is on the number presented, or on the purpose, or on misusing a named individual's identity. A simulation whose whole design is a caller claiming to be someone else is, on the face of the words, inside it. The penalty is a misdemeanour one running to sixty-six thousand three hundred and sixty euro for a legal person, with the responsible person inside it separately liable, and either the communications regulator or the data protection authority may order the infringement to stop.

So the Croatian decision is about delivery rather than about paperwork, and it is better made at the start than defended later. A telephone campaign built on a claimed identity is the design that runs into that article, and how comfortable you are with that is a question for your own counsel rather than for us. The European transparency duty pushes the same way rather than the other: since August 2026 a deployer of a system generating audio constituting a deep fake must disclose that the content is artificially generated, at the latest at the first exposure, and the carve-out is confined to uses authorised by law for criminal law purposes, which an employer's own authorisation is not. Croatia gives you two independent reasons to disclose rather than one, and a module-led delivery is the shape that answers both.

The employment side is a genuine gate and it is workable if you plan for it. The labour code has three separately headed rungs, information, consultation and co-decision, and the collection, processing, use and delivery of worker data sits on the top one: you may adopt the decision only with the works council's prior agreement. The mechanics soften it. Silence for eight days counts as agreement, a refusal has to be reasoned in writing, and you may ask a court or an arbitral tribunal within fifteen days to substitute the agreement, with the first-instance court obliged to decide within thirty. It is a veto with a defined route around it. A council is not automatic, arising at twenty workers and only where staff elect one; where none exists a trade union commissioner assumes its rights, and where there is neither, the requirement has no addressee at all.

What your company needs to do

6 items, in the order you will need them.

  • Decide how you deliver before you design the pretextCroatia-specificCroatia prohibits any false self-presentation by a caller in public networks, with no purpose qualifier and no exception. That makes the delivery channel the first decision rather than the last one, and it is the one place in this portal where the module-led route is the answer to a domestic prohibition rather than a convenience.
  • Get the works council's prior agreement, and start the eight days earlyCroatia-specificWorker data processing is a co-decision matter, not a consultation one. Put the request in writing with the purpose, the categories, who sees the results and how long they are kept. Silence for eight days is agreement; a reasoned refusal can be taken to a court to substitute within fifteen days. Where there is no council, the trade union commissioner stands in its place.
  • Name the data categories in your rules of work, in advanceCroatia-specificWhere collecting worker data is necessary, the code requires you to determine in advance, in the rules of work, which data you will collect, process, use or deliver to third parties and for what purpose. An employer of twenty or more has to adopt and publish those rules anyway, so the vehicle exists: the question is whether what a simulation generates is named in it.
  • Appoint the supervisor the labour code requires above twenty workersCroatia-specificThis is not the data protection officer of the European Regulation. It is a separate labour-law post, defined by the workers' confidence in the holder, authorised alongside you to supervise whether worker data are handled lawfully, and failing to appoint one is a named offence. Its appointment sits on the same co-decision rung as the processing itself.
  • Take the recording question to Croatian counselThe offence covers unauthorised sound recording of another's non-publicly spoken words, and the qualifier that lets a participant out is attached to the eavesdropping limb only. That is deliberately unresolved here, because settling it needs Croatian case law. Using or passing on such a recording is separately punished at the same level, so a lawful capture licenses nothing downstream.
  • Do not let anyone tell you Croatian law requires thisCroatia is the only country in our coverage whose regulation names phishing simulation, and it grades that sub-measure voluntary at the basic, medium and advanced levels alike. What is binding at all three is the neighbouring sub-measure on regular cyber-hygiene training for every employee. Buy this because it works, not because a vendor quoted an annex at you.

The controls that do the work

How Callstrike is configured, and which provision in Croatia each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

Croatia has a second offence sitting beside the recording one, reaching whoever collects, processes or uses personal data contrary to the conditions laid down by law, and the conditions in question are the labour code ones about naming categories in advance. The call ends the instant an employee begins to give up a credential, so the credential is never collected at all and never has to appear in the categories you named. It is also what makes the works council request a short document rather than a negotiation.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The council's agreement is a real gate, and what the conversation is actually about is what the exercise does to the people inside it. A second voice that breaks character the moment the call ends, with vishing training in writing the same day and an undertaking that results never reach anybody's disciplinary record, is a term you can offer inside the eight-day window rather than a promise about your intentions.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

The regulator has said twice, in 2022 and again in 2024, that dependence in the employment relationship means a worker cannot refuse without fear of detriment, and that providing for monitoring in the rules of work and then taking agreement for it would satisfy the legitimacy condition only formally. So this is not the ground and it is not the gate. What it produces is the dated evidence of notice, or a hashed copy of the rules of work and the council's agreement with a signed attestation of the scope they cover.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

In Croatia this is the answer to the domestic prohibition rather than a fallback from it, which is true nowhere else in this portal. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module. The prohibition is written about a caller falsely presenting themselves in a public communications network, and a session a learner opens in their own browser has neither a caller presenting an identity nor a public communications network for it to happen in.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

The rules that bite are in the labour code, not the privacy act

Croatia's data protection implementing act is thinner on employment than most readers expect. It has no general provision about employee data at all. Two articles touch employees: one permits processing employees' biometric data for recording working time and for entry to and exit from official premises, subject to explicit consent, and one governs video surveillance of work premises, requiring advance information to employees and prohibiting cameras in rest, hygiene and changing rooms. Both are specific and neither has an audio or telephony analogue.

What does the work is the labour code. Workers' personal data may be collected, processed, used and delivered to third parties only if that is laid down by that or another act, or if it is necessary for the exercise of rights and obligations arising from the employment relationship. And then the requirement that turns a Croatian programme into a document: where such collection is necessary, the employer must determine in advance, in its rules of work, which data it will collect, process, use or deliver to third parties for that purpose.

In advance, and in the rules of work. An employer of twenty or more workers must adopt and publish those rules anyway, so above that threshold the vehicle already exists and the question is whether the categories a simulation generates are named in it.

The same article adds an appointment nobody expects. An employer employing at least twenty workers must appoint a person who must enjoy the workers' confidence and who, besides the employer, is authorised to supervise whether personal data are collected, processed, used and delivered to third parties in accordance with the law. That is not the data protection officer of the Regulation; it is a separate labour-law post, it is defined by the workers' confidence in the holder, and failing to appoint one is a named offence under the Act.

The regulator's position on consent is consistent and repeated. Given the dependence arising from the employer and employee relationship, it says, it is not likely that a data subject can refuse consent without fear or real risk of detrimental effects, and for most workplace processing the lawful basis cannot and should not be the employee's consent; processing rests instead on the employment contract and on the employer's legal obligations under specific statutes. It published that in 2022 and again in 2024.

On monitoring specifically its published position is older and narrower than people assume, and we are going to label it. It dates from 2019 and it addresses business email, not voice. Within that scope it sets out six principles, necessity, purpose, transparency, legitimacy, proportionality, and accuracy with retention, and it says two things that matter here. Monitoring of electronic communications without the employee's knowledge is contrary to data protection rules, and both employees and external addressees must be informed of any monitoring introduced. And providing for monitoring in the rules of work and taking consent for it would satisfy the legitimacy condition only formally, because in an employment relationship seeking consent would be a mere form and its absence could put employees in an unequal position.

One limb carries the qualifier and the other does not

The Croatian offence is drafted in two limbs joined by or, and the difference between them is the whole question.

Whoever without authorisation makes a sound recording of another's non-publicly spoken words, or whoever by special devices without authorisation eavesdrops on another's non-publicly spoken words which are not intended for him, is punished by imprisonment of up to three years.

Notice where the qualifier sits. The words which are not intended for him come at the end of the second limb, after eavesdrops. They do not appear in the recording limb. As the text is published, the recording limb is qualified only by without authorisation and by non-publicly spoken. That is the opposite arrangement from most European provisions, where the qualifier that lets a participant out is attached to both.

We are not going to resolve whether a party to a call is inside that limb, because the answer turns on the scope of the words without authorisation and that requires Croatian case law or doctrine. The official gazette publishes statutes and constitutional court decisions, not criminal judgments of the supreme court, and the data protection authority has published nothing on call recording. A Croatian programme that intends to record should take this specific point to Croatian counsel rather than assume the European default.

Three further features of the provision matter operationally. Using such a recording or making it available to a third person is separately punished with the same penalty, so a lawfully made recording carries no free licence to circulate it. There is a statutory exclusion where the acts were done in the public interest or in another interest outweighing the recorded person's privacy interest, which is the provision an employer would have to argue within. And the recordings and the devices used are seized on conviction.

One correction, because it is repeated everywhere. The offence is prosecuted on the injured party's motion, which is a public prosecution triggered by the victim. It is not a private charge. The same Code uses the phrase for private charge elsewhere, in the offences against honour and reputation, so the drafting distinction is deliberate.

A second offence sits alongside it and is easier to trip. Whoever, contrary to the conditions laid down by law, collects, processes or uses personal data of natural persons commits an offence carrying up to a year, rising to three years where the data are taken out of Croatia for further processing, published, otherwise made available to another, or where the act obtains significant pecuniary gain or causes significant damage. Contrary to the conditions laid down by law is doing a lot of work there, and the conditions in question include the labour code requirements set out above.

A ban on pretending to be someone else, with no purpose attached

This is the most important paragraph on the Croatian page, and it is not a data protection rule.

The communications act provides that in public communications networks any false self-presentation by the caller, or by the sender of text or multimedia messages, is prohibited. Read the construction: any false presentation is prohibited. There is no purpose element, no marketing element, no consent gateway and no exception. It sits in an article headed malicious or harassing calls, whose remaining paragraphs impose tracing duties on operators, but the prohibition itself is freestanding.

No other country in our coverage prohibits the pretext as such. Elsewhere the constraint is on the number presented, or on marketing purposes, or on identity misuse of a named individual. Croatia prohibits falsely presenting yourself as the caller, full stop, and a simulation whose whole design is a caller claiming to be someone else is on the face of the words inside it.

The penalty is a misdemeanour one and it is real: from six thousand six hundred and thirty to sixty-six thousand three hundred and sixty euros for a legal person, from six hundred and sixty to six thousand six hundred and thirty for the responsible person within it, and from two hundred and sixty to two thousand six hundred and fifty for a natural person, with higher bands where the offence was committed for gain. Either the regulator or the data protection authority may order the cessation of infringements, ex officio or on request.

By contrast the marketing rule is conventionally purpose-scoped. The use of automated calling and communication systems without human intervention, fax machines or electronic mail including text and multimedia messages, for the purpose of direct promotion and sale, is permitted only with the end user's prior consent. That qualifier sits inside the operative paragraph and governs the whole list of channels, and a further paragraph disapplies the rule to communications directed at legal persons. An internal security test promotes and sells nothing, so the marketing article is not the Croatian problem. The false self-presentation article is.

The European transparency duty applies here directly, and it is Article 50 of the EU AI Act rather than anything Croatian. Since 2 August 2026 a provider must design a system intended to interact directly with people so those people are informed they are dealing with an AI system, and a deployer of a system generating or manipulating audio constituting a deep fake must disclose that the content is artificially generated, at the latest at the first interaction or exposure. The carve-out is confined to uses authorised by law for criminal law purposes and to evidently artistic work. Read together with the domestic prohibition above, a Croatian campaign has two independent reasons to disclose rather than one.

The same Regulation has prohibited using AI systems to infer emotions of a natural person in the workplace since 2 February 2025, outside a narrow medical or safety exception, at up to thirty-five million euros or seven per cent of worldwide turnover. Its gate is a definition confined to inference from biometric data, and the recitals put readily apparent expressions and a raised voice outside it. Recording who disclosed something is unaffected; scoring how a named person sounded is not the same activity.

Correct, complete, and in its original form

Croatia states the number rule positively rather than as a prohibition, which makes it unusually easy to apply.

The regulator's ordinance provides that the calling number must be visible, complete, correct and transmitted in its original form, and that it must not be altered or truncated. Correct and unaltered are not compatible with substituting a number you do not hold.

The act's own caller identification article grants a right that is often confused with the one people want. An operator offering calling line identification must let the calling user prevent presentation of the number, simply and free of charge, per call or for all calls, and must let the called party prevent presentation of incoming numbers. That is a right to withhold. It is not a right to substitute, and the two should not be run together.

Then the border rule, which decides whether the campaign connects at all. For the purpose of preventing spoofing of the calling number, operators who manage international network interfaces, who directly manage incoming international voice traffic, or who terminate calls, must block calls that do not conform to the relevant international recommendation, and must block calls arriving from abroad bearing national geographic numbers save in exceptional and justified cases. Calls bearing national mobile numbers are accepted only after the operators verify and confirm that the end user is roaming. That ordinance has been in force since 1 January 2024.

So a platform dialling Croatian staff from outside Croatia while presenting a Croatian landline number is squarely inside the class of traffic operators are instructed to block. Originate domestically, on a number the chain can verify.

One honest limit. The numbering conditions in the act are addressed to operators, who must use assigned numbers in accordance with the plans and exclusively for the purposes stated in their assignment request, and may pass numbers to end users only under the regulator's ordinance. Because that last provision expressly contemplates onward assignment to end users, an ordinary business presenting a number its carrier gave it is not caught by anything there. The prohibition that does reach a caller is the false self-presentation one described in the previous section, not a numbering-rights provision.

What the country matrix holds for Croatia

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Employee data sits on the top rung, and the top rung is agreement

The Croatian labour code distinguishes three regimes for worker participation, and it gives each its own heading: the duty to inform, the duty to consult before adopting a decision, and co-decision. Most monitoring questions in Europe land on the second rung. In Croatia the processing of worker data lands on the third.

The employer may adopt a decision on the collection, processing, use and delivery to third parties of data on a worker only with the prior agreement of the works council. The same article puts the appointment of the person who supervises that processing on the same footing. The consultation list in the preceding article, which covers the rules of work, employment and dismissal policy, transfer of undertaking, health and safety measures, new technology and changes in work organisation, holiday plans, working-time schedules, night work and collective redundancy, does not include personal data at all. The drafters put it one rung higher on purpose.

The mechanics are workable and worth planning around rather than fearing. If the works council does not declare itself within eight days, it is deemed to agree. If it withholds agreement, the withholding must be reasoned in writing, and the employer may within fifteen days of service ask a court or an arbitral tribunal to substitute the agreement, with the first-instance court obliged to decide within thirty days. So it is a veto with a defined route around it, not an absolute one.

A works council is not automatic. The right to participate in decision-making arises with an employer of at least twenty workers, and the council is elected at free and direct elections by secret ballot, on the initiative of a trade union or of at least twenty per cent of the workers. Many Croatian employers above the threshold have none.

Where none exists, the trade union commissioner assumes all the rights and obligations of the works council under the Act, with one exception about appointing a workers' representative to a company body. A union may appoint a commissioner where it has at least five employees with that employer, and must notify the employer in writing. Where there is neither a council nor a union, the Act designates no substitute and the prior agreement requirement has no addressee. The rules of work obligations and the supervisor appointment continue to bind regardless.

One sanction is worth knowing because it is unusually blunt. A decision of the employer adopted contrary to the consultation obligation is null and void. That provision sits on the consultation rung, and adopting a co-decision matter without the required agreement is separately a named offence.

The Croatian file, then, is specific: the categories of data named in advance in the rules of work, the appointment of a supervisor who enjoys the workers' confidence above twenty employees, and the works council's prior agreement to the processing itself, obtained or deemed, before the campaign runs.

The one regulation that names it says you need not do it

Croatia transposed the European network and information security directive in February 2024, and its risk-management measures include basic cyber-hygiene practices and cybersecurity training. A separate article makes the persons responsible for managing those measures obliged both to attend appropriate training themselves and to enable the entity's employees to attend it.

The penalties are the serious end of the European range. An essential entity faces from ten thousand euros to ten million euros, or from half a per cent to two per cent of total worldwide annual turnover, whichever is higher, including where the persons responsible fail to ensure that appropriate training is carried out. Important entities face five thousand to seven million, or 0.2 to 1.4 per cent. The responsible natural persons are separately fined.

We counted the act through and it names nothing about our activity: no occurrence of simulation, phishing or identity theft. Its single mention of testing is about national cyber exercises testing communication mechanisms.

The implementing regulation is where Croatia becomes unique in this portal, and it cuts the opposite way from how a vendor would quote it. Its annex of measures contains a sub-measure requiring the entity to implement social engineering testing, identity theft simulations, in terms phishing simulations, and awareness-raising programmes, and it says these activities must be regular and must cover all employees in order to identify vulnerabilities and educate personnel in recognising and responding to them.

Then the applicability table grades it. The regulation marks each sub-measure A where implementation is binding, B where it is binding under stated conditions, and C where it is voluntary. The social engineering and phishing simulation sub-measure is graded C at the basic level, C at the medium level and C at the advanced level. Sub-measures marked C are recommended for implementation depending on the results of the entity's own risk assessment.

So the only instrument in this entire portal that names phishing simulation by name is also the one that says it is voluntary at every level. What is binding, graded A at all three levels, is the neighbouring sub-measure requiring regular training on basic cyber-hygiene practices and awareness of risks and threats for all employees, immediately after a person enters employment and regularly thereafter. And nothing in the regulation mentions voice: the sub-measure names identity theft in the form of phishing and the broader category of social engineering testing, and stops there.

For financial entities the European digital operational resilience Regulation applies directly from 17 January 2025 and the national central bank is a designated competent authority. That Regulation requires compulsory awareness and resilience training modules for all staff and senior management, and threat-led penetration testing of live production systems for identified entities, and it names neither phishing nor social engineering anywhere in its text.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in CROATIA. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance at the programme level.

Verify or correct each proposition below against primary Croatian sources, and tell me whether a telephone pretext can lawfully be run here at all:

1. ⚠⚠ ZEK čl. 48(1) prohibits «SVAKO lažno predstavljanje pozivatelja» in public communications networks, with NO purpose, marketing or consent qualifier, penalised under čl. 171(1) t. 15. Assess whether an authorised internal simulation using an invented persona is inside it, and whether any exception, practice or HAKOM position exists.
2. ⚠ Zakon o radu čl. 151 st. 1 t. 7 puts collecting, processing, using and delivering worker data on the SUODLUČIVANJE rung: prior agreement of the works council. Confirm the eight-day deemed agreement, the reasoned refusal, and the fifteen-day route to a court to substitute it.
3. Zakon o radu čl. 29 requires the data categories to be determined IN ADVANCE in the pravilnik o radu, and requires a supervisor enjoying the workers' confidence at 20+ workers.
4. Where there is no works council, the sindikalni povjerenik assumes its rights; where there is neither, čl. 151 has no addressee. Confirm.
5. ⚠ KZ čl. 143: the «koji nisu njemu namijenjene» qualifier attaches to the EAVESDROPPING limb only, so the recording limb is qualified by «neovlašteno» alone. Supply Croatian case law or doctrine on whether a participant is inside it. Note the offence is prosecuted PO PRIJEDLOGU, not by private charge.
6. ZEK's marketing rule is scoped to «izravne promidžbe i prodaje» inside the operative paragraph, so an internal test is outside it.
7. Pravilnik čl. 76 requires the calling number to be visible, complete, correct and unaltered, and requires blocking of inbound international calls bearing national geographic numbers.
8. Uredba o kibernetičkoj sigurnosti Prilog II mjera 4.11 (social engineering and phishing simulation) is graded C, voluntary, at all three levels, while 4.4 is A.

Flag anything that has changed since September 2026, and identify any obligation in our own kolektivni ugovor that this analysis omits.

Common questions

Is the pretext itself lawful in Croatia?
That is the hard question here. The communications act prohibits any false self-presentation by a caller in public networks, with no purpose, marketing or consent qualifier, at up to sixty-six thousand three hundred and sixty euros for a company. No other country in our coverage prohibits the pretext as such.
Does the works council have to agree, or only be consulted?
Agree. Croatian labour law puts the collection, processing, use and delivery of worker data on the co-decision rung, above consultation. Silence for eight days counts as agreement, a refusal must be reasoned in writing, and the employer may ask a court to substitute the agreement within fifteen days.
Does Croatian law require phishing simulations?
No, and Croatia is the only country in our coverage where a regulation names them. The cybersecurity regulation's sub-measure on social engineering testing and phishing simulation is graded voluntary at every level, while the neighbouring sub-measure on regular cyber-hygiene training for all employees is binding.
May we record the call in Croatia?
Unresolved, deliberately. The offence covers unauthorised sound recording of another's non-publicly spoken words, and the qualifier that would let a participant out is attached only to the eavesdropping limb. There is a statutory exclusion for an overriding interest. Take this point to Croatian counsel.

Elsewhere in Southern Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.