Voice phishing simulations in Cyprus
Cyprus permits an authorised voice phishing simulation against your own workforce, and Callstrike clears the country and assigns the number. Two Cypriot facts have no counterpart elsewhere in this portal: everyone on a call must have agreed in advance before it may be recorded, and failing to carry out a required impact assessment is itself a criminal offence, with liability landing on your most senior executive.
Phone numbers
Supplied by Callstrike
Local numbers in Cyprus, after a one-time approval.
Running a simulation
Permitted, and the assessment is not optional
Skipping the impact assessment is a criminal offence here, not an administrative one.
Consent
Your evidence of notice
The regulator's employment directive wants purpose, manner, duration and technical detail in advance.
Getting a phone number in Cyprus
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Callstrike clears Cyprus against your workspace and provisions the number, and the Cypriot filing is built around a single document doing several jobs. Your business registration evidences the company name, the registration number and the address, and the authorised representative named on it identifies themselves with a government-issued document, a passport or a residence permit. The address has to sit inside the locality or region the number's prefix covers, and a post office box is not accepted where a local address is required.
On which number you may then present, Cyprus is the one page in this portal where the honest answer is that we could not find a rule. The electronic communications act governs only the right to withhold identification and the tracing of malicious calls; the 2023 numbering decision covers assignment, categories and fees and says nothing about what identity may be shown. That is an absence of sourced prohibition and not a permission, and it has a practical consequence worth acting on: where your carrier tells you it cannot do something in Cyprus, ask which instrument that comes from, and treat its own terms of service as the operative constraint until somebody produces one.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Cyprus is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Business name | Business registration showing showing authorized representative name |
| Business registration number | Business registration |
| Authorized representative name | Government-issued ID, Passport, Residence permit |
| Business addressMust be within locality or region covered by the phone number’s prefix; a PO Box is not acceptable where a local address is required. | Business registration showing local address, Utility bill, Tax notice, Rent receipt, Title deed |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in Cyprus?
The position in short, before your counsel reads the detail below.
Yes. The Cypriot transposition of the European rule on unsolicited communications is scoped by purpose throughout: automatic calling and communication systems used without human intervention, fax machines and electronic mail are permitted for the purposes of direct commercial promotion only where the subscriber has agreed in advance, and a further subsection repeats the gate for unsolicited calls made for that same purpose. An authorised internal test promotes nothing commercially and sits outside both. One detail is the reverse of the usual assumption: the prohibition on disguising or concealing the sender's identity is confined to electronic mail, with no voice analogue in the article at all.
Then read the recording rule before you design anything, because Cyprus is the strictest jurisdiction in this portal by a wide margin and the statute leaves little room. Interception is defined to include recording, and deliberately intercepting the content of a private communication carries up to ten years or a hundred thousand euro or both. The exception is where party status would normally save you, and here it does the opposite: prior express approval is required from the person making the communication and from the person intended to receive it, and a further subsection removes all doubt by requiring it from all of them. Being on the call is simply not the question.
There is one opening in the drafting and it is the whole of the practical answer, so be exact about how far it goes. The statutory word is prior, and nothing in the text requires the approval to be specific to a particular call. A documented, prior, express approval covering recording, given in advance and covering every party, is on the face of the words capable of satisfying the exception. That is a reading of the statutory language rather than a position anyone has published, and a Cypriot programme that intends to record should have it reviewed locally before the first campaign rather than after it. The safer path is the one most Cypriot programmes should take, which is not to record.
The last Cypriot fact changes who inside your business has to read the file. The implementing act makes a controller who does not carry out a required impact assessment guilty of an offence carrying up to three years or thirty thousand euro or both, and fixes liability on the person designated as the undertaking's most senior executive body. Whether one is required comes from the Commissioner's list, which catches an exercise like this on three limbs: systematic monitoring, with a worked example of a company monitoring employees' talk time on the telephone; employees named as vulnerable data subjects; and the use of new technological solutions. That list describes itself as indicative and carries a 2018 date, which is worth knowing and is not a reason to economise when the penalty for guessing wrong is a criminal one.
What your company needs to do
6 items, in the order you will need them.
- Decide not to record, or get the prior approval before you doCyprus-specificEvery party to the call must have given prior express approval, and the ceiling is ten years or a hundred thousand euro. The only opening is that the statute says prior rather than call-specific. If you intend to rely on that, have it reviewed in Cyprus first; if you do not need the audio, the question disappears.
- Put the impact assessment in front of your most senior executiveCyprus-specificFailing to carry one out is a criminal offence here and the act fixes liability on the person designated as the undertaking's most senior executive body. That makes this a document somebody signs rather than a file somebody keeps, and the same provision reaches the record of processing activities.
- Answer the regulator's four-part notice, in advanceCyprus-specificThe Commissioner's employment directive says covert monitoring is prohibited and requires employees to be told, before it begins, the purpose, the manner, the duration and the technical characteristics. Our reading is that a programme-level notice given in advance supplies all four without disclosing which call is which. No Cypriot source confirms that, so do not present it internally as blessed.
- Know that the directive rests on a repealed act, and treat it as live anywayCyprus-specificIt is built on the 2001 data protection law, which the 2018 implementing act repealed, and the Commissioner still publishes it and re-uploaded it in September 2025. So it is the regulator's stated position rather than law in force. Both halves are true, and in any conversation with that regulator the first half is the one that will be quoted at you.
- Do not expect the works council to be a gateThe Cypriot information and consultation regime applies at thirty employees and upwards, defines consultation as an exchange of views, and owes you nothing stronger than a reasoned reply to an opinion. There is no provision making a measure ineffective for want of employee-side agreement, so the veto some neighbours have has no Cypriot analogue.
- Ask your carrier which instrument its restriction comes fromNo Cypriot rule prohibiting a caller from presenting a number it does not hold could be sourced, and that is reported as an absence rather than as a permission. In practice the operative constraint on what identity you may present is your provider's own terms, so settle it there and record what you were told.
The controls that do the work
How Callstrike is configured, and which provision in Cyprus each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
The impact assessment is a criminal matter in Cyprus and it is the document your most senior executive is personally exposed on, so what actually goes into it is the whole question. The call ends the instant an employee begins to give up a credential, so the credential is never spoken into the system and never stored, and the assessment describes an exercise that measures susceptibility without acquiring the thing the pretext asked for. That is a materially shorter document to sign.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The Commissioner's directive tells you to avoid continuous monitoring and to choose the least intrusive means, and it sets that against employees who were not told which call was which. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is the least intrusive version of the same measurement, and it is the answer to a regulator whose starting position is that covert monitoring is prohibited.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Two distinct jobs here, and Cyprus is the country where they come apart most clearly. It produces the advance notice the employment directive asks for, carrying the purpose, the manner, the duration and the technical characteristics, dated before the campaign. And where a programme does intend to record, the documented prior approval the recording statute requires from every party is exactly the artefact this produces and timestamps. Neither makes the criminal provision go away, and this page does not suggest it does.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
In Cyprus this is the route that avoids the two questions the page could not close. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module. The learner opts in knowing what it is, so the prior-approval problem takes a different shape entirely, and there is no Cypriot number and no presented calling identity for the unsourced numbering questions to arise about.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.