Callstrike
Compliance

Voice phishing simulations in Cyprus

Phone numbers in CyprusProvisioned by Callstrike after approval

Cyprus permits an authorised voice phishing simulation against your own workforce, and Callstrike clears the country and assigns the number. Two Cypriot facts have no counterpart elsewhere in this portal: everyone on a call must have agreed in advance before it may be recorded, and failing to carry out a required impact assessment is itself a criminal offence, with liability landing on your most senior executive.

Phone numbers

Supplied by Callstrike

Local numbers in Cyprus, after a one-time approval.

Running a simulation

Permitted, and the assessment is not optional

Skipping the impact assessment is a criminal offence here, not an administrative one.

Consent

Your evidence of notice

The regulator's employment directive wants purpose, manner, duration and technical detail in advance.

Getting a phone number in Cyprus

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Callstrike clears Cyprus against your workspace and provisions the number, and the Cypriot filing is built around a single document doing several jobs. Your business registration evidences the company name, the registration number and the address, and the authorised representative named on it identifies themselves with a government-issued document, a passport or a residence permit. The address has to sit inside the locality or region the number's prefix covers, and a post office box is not accepted where a local address is required.

On which number you may then present, Cyprus is the one page in this portal where the honest answer is that we could not find a rule. The electronic communications act governs only the right to withhold identification and the tracing of malicious calls; the 2023 numbering decision covers assignment, categories and fees and says nothing about what identity may be shown. That is an absence of sourced prohibition and not a permission, and it has a practical consequence worth acting on: where your carrier tells you it cannot do something in Cyprus, ask which instrument that comes from, and treat its own terms of service as the operative constraint until somebody produces one.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Cyprus is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Business nameBusiness registration showing showing authorized representative name
Business registration numberBusiness registration
Authorized representative nameGovernment-issued ID, Passport, Residence permit
Business addressMust be within locality or region covered by the phone number’s prefix; a PO Box is not acceptable where a local address is required.Business registration showing local address, Utility bill, Tax notice, Rent receipt, Title deed

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Cyprus?

The position in short, before your counsel reads the detail below.

Yes. The Cypriot transposition of the European rule on unsolicited communications is scoped by purpose throughout: automatic calling and communication systems used without human intervention, fax machines and electronic mail are permitted for the purposes of direct commercial promotion only where the subscriber has agreed in advance, and a further subsection repeats the gate for unsolicited calls made for that same purpose. An authorised internal test promotes nothing commercially and sits outside both. One detail is the reverse of the usual assumption: the prohibition on disguising or concealing the sender's identity is confined to electronic mail, with no voice analogue in the article at all.

Then read the recording rule before you design anything, because Cyprus is the strictest jurisdiction in this portal by a wide margin and the statute leaves little room. Interception is defined to include recording, and deliberately intercepting the content of a private communication carries up to ten years or a hundred thousand euro or both. The exception is where party status would normally save you, and here it does the opposite: prior express approval is required from the person making the communication and from the person intended to receive it, and a further subsection removes all doubt by requiring it from all of them. Being on the call is simply not the question.

There is one opening in the drafting and it is the whole of the practical answer, so be exact about how far it goes. The statutory word is prior, and nothing in the text requires the approval to be specific to a particular call. A documented, prior, express approval covering recording, given in advance and covering every party, is on the face of the words capable of satisfying the exception. That is a reading of the statutory language rather than a position anyone has published, and a Cypriot programme that intends to record should have it reviewed locally before the first campaign rather than after it. The safer path is the one most Cypriot programmes should take, which is not to record.

The last Cypriot fact changes who inside your business has to read the file. The implementing act makes a controller who does not carry out a required impact assessment guilty of an offence carrying up to three years or thirty thousand euro or both, and fixes liability on the person designated as the undertaking's most senior executive body. Whether one is required comes from the Commissioner's list, which catches an exercise like this on three limbs: systematic monitoring, with a worked example of a company monitoring employees' talk time on the telephone; employees named as vulnerable data subjects; and the use of new technological solutions. That list describes itself as indicative and carries a 2018 date, which is worth knowing and is not a reason to economise when the penalty for guessing wrong is a criminal one.

What your company needs to do

6 items, in the order you will need them.

  • Decide not to record, or get the prior approval before you doCyprus-specificEvery party to the call must have given prior express approval, and the ceiling is ten years or a hundred thousand euro. The only opening is that the statute says prior rather than call-specific. If you intend to rely on that, have it reviewed in Cyprus first; if you do not need the audio, the question disappears.
  • Put the impact assessment in front of your most senior executiveCyprus-specificFailing to carry one out is a criminal offence here and the act fixes liability on the person designated as the undertaking's most senior executive body. That makes this a document somebody signs rather than a file somebody keeps, and the same provision reaches the record of processing activities.
  • Answer the regulator's four-part notice, in advanceCyprus-specificThe Commissioner's employment directive says covert monitoring is prohibited and requires employees to be told, before it begins, the purpose, the manner, the duration and the technical characteristics. Our reading is that a programme-level notice given in advance supplies all four without disclosing which call is which. No Cypriot source confirms that, so do not present it internally as blessed.
  • Know that the directive rests on a repealed act, and treat it as live anywayCyprus-specificIt is built on the 2001 data protection law, which the 2018 implementing act repealed, and the Commissioner still publishes it and re-uploaded it in September 2025. So it is the regulator's stated position rather than law in force. Both halves are true, and in any conversation with that regulator the first half is the one that will be quoted at you.
  • Do not expect the works council to be a gateThe Cypriot information and consultation regime applies at thirty employees and upwards, defines consultation as an exchange of views, and owes you nothing stronger than a reasoned reply to an opinion. There is no provision making a measure ineffective for want of employee-side agreement, so the veto some neighbours have has no Cypriot analogue.
  • Ask your carrier which instrument its restriction comes fromNo Cypriot rule prohibiting a caller from presenting a number it does not hold could be sourced, and that is reported as an absence rather than as a permission. In practice the operative constraint on what identity you may present is your provider's own terms, so settle it there and record what you were told.

The controls that do the work

How Callstrike is configured, and which provision in Cyprus each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

The impact assessment is a criminal matter in Cyprus and it is the document your most senior executive is personally exposed on, so what actually goes into it is the whole question. The call ends the instant an employee begins to give up a credential, so the credential is never spoken into the system and never stored, and the assessment describes an exercise that measures susceptibility without acquiring the thing the pretext asked for. That is a materially shorter document to sign.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The Commissioner's directive tells you to avoid continuous monitoring and to choose the least intrusive means, and it sets that against employees who were not told which call was which. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is the least intrusive version of the same measurement, and it is the answer to a regulator whose starting position is that covert monitoring is prohibited.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Two distinct jobs here, and Cyprus is the country where they come apart most clearly. It produces the advance notice the employment directive asks for, carrying the purpose, the manner, the duration and the technical characteristics, dated before the campaign. And where a programme does intend to record, the documented prior approval the recording statute requires from every party is exactly the artefact this produces and timestamps. Neither makes the criminal provision go away, and this page does not suggest it does.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

In Cyprus this is the route that avoids the two questions the page could not close. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module. The learner opts in knowing what it is, so the prior-approval problem takes a different shape entirely, and there is no Cypriot number and no presented calling identity for the unsourced numbering questions to arise about.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

An impact assessment you can be prosecuted for skipping

Cyprus did not use the European opening clause for employment-specific rules, and the negative is worth showing rather than asserting. The implementing act's second part covers processing by the courts and parliament, publication of judgments, and processing on the basis of a decision of the council of ministers. Searching the whole act for the Greek words for employee, employer and employment relationship returns nothing; every apparent hit is inside the word for processing itself. So the basis for a simulation is the ordinary European one with nothing national layered on top.

What Cyprus adds instead is unique in this cluster and it is criminal. The act provides that a controller who does not carry out an impact assessment, in breach of the European requirement or of the national article, commits a criminal offence, as does a controller or processor who does not keep the record of processing activities. The penalty is imprisonment not exceeding three years, or a fine not exceeding thirty thousand euro, or both. And a further subsection fixes liability on the person designated as the undertaking's most senior executive body.

That converts the documentation question from a compliance matter into a personal exposure, and it changes who inside a Cypriot business needs to have read the file. We have not found this construction anywhere else in the portal.

Whether the assessment is required at all is answered by the Commissioner's published list, which catches a simulation on three limbs. Systematic monitoring is one, and its worked example is a company that systematically monitors its employees' activities, their workstation, their internet activity and their talk time on the telephone. Employees are expressly listed as vulnerable data subjects, together with any case where an unequal relationship between the data subject's position and the controller is established. And the use or application of new technological or organisational solutions is a third.

We should be precise about the status of that list, given what the offence above carries. It describes itself as indicative, and the Commissioner's own page says an assessment is recommended rather than required, so it is not a strict blacklist of the kind the Regulation contemplates. It also carries a last-updated date of August 2018. Our reading is that three overlapping indicative limbs plus a criminal penalty for getting the answer wrong is not a place to economise, and we would rather say that than pretend the list is binding.

Every party must have agreed in advance, and the ceiling is ten years

This is the block that decides whether a Cypriot programme records at all, and the statute is unusually explicit, so there is little room for interpretation.

The act defines interception to mean the acoustic or other capture of the content of any private communication by means of any device or apparatus, and says in terms that it includes listening, magnetic recording or any other form of recording. It then makes it an offence deliberately to intercept the content of any private communication, punishable by imprisonment not exceeding ten years or a fine not exceeding one hundred thousand euro or both.

The exception is where party status would normally save you, and here it does the opposite. It requires prior express approval for the interception from the person making the communication and from the person who received or is intended to receive it. A further subsection removes all doubt, providing that the prior express approval must be obtained from all the persons making the communication and from all the persons intended to receive it.

So being a party to the call is not the question in Cyprus. Everyone on it must have agreed, and this is the strictest recording rule in the portal by a wide margin.

There is one opening in the drafting and it is the whole of the practical answer, so we will be exact about how far it goes. The statutory word is prior, and nothing in the text requires the approval to be specific to a particular call. A documented, prior, express approval covering recording, obtained from the employee in advance and covering every party to the call, is on the face of the words capable of satisfying the exception. That is our reading of the statutory language rather than a position anyone has published, and a Cypriot programme that intends to record should have it reviewed locally before the first campaign rather than after it.

One constitutional note we are recording without resolving. The constitution protects the secrecy of correspondence and other communication and permits interference only in an exhaustively enumerated set of cases, which covers prisoners and two categories of court order and does not include agreement. The better textual reading is that recording with every party's approval is not an interference with the right at all, rather than an unlisted exception to it. We found no Supreme Court authority either way and are not going to assert one.

Commercial promotion is the gate, and email gets a rule voice does not

The Cypriot transposition of the European rule on unsolicited communications sits in the electronic communications and postal services regulation act, and it is scoped by purpose throughout.

The use of automatic calling and communication systems without human intervention, fax machines or electronic mail for the purposes of direct commercial promotion is permitted only in the case of subscribers or users who have given their agreement in advance. A further subsection repeats the same gate for everything outside those cases, prohibiting unsolicited calls made for the purpose of direct commercial promotion without agreement. An authorised internal security test promotes nothing commercially and sits outside both.

There is a detail worth carrying because it is the reverse of the natural assumption. The act does prohibit the practice of sending messages that disguise or conceal the identity of the sender, and it confines that prohibition to electronic mail. There is no voice analogue anywhere in the article.

Enforcement sits with the data protection commissioner rather than with the telecoms regulator, which is worth knowing when working out who would ask the questions. And there is no statutory definition of direct commercial promotion in the act, so the boundary of the scoping is undefined even though the scoping itself is clear.

On the European transparency rule, Article 50 of the AI Act has applied since 2 August 2026 and reaches Cyprus directly. A provider must design a system built to interact with people so the person is informed they are dealing with an AI system, and a deployer of a system generating or manipulating audio constituting a deep fake must disclose that the content is artificially generated, in both cases at the latest at the time of the first interaction or exposure. An employer running the exercise is the deployer. The carve-outs are for use authorised by law to detect, prevent, investigate or prosecute criminal offences, and for evidently artistic works, and an employer's own authorisation is not authorisation by law.

We could not establish that Cyprus has designated a national authority for that article. We checked the Commission's published lists, one of which returns nothing and one of which carries no Cypriot entry, and the deputy ministry responsible, whose only artificial intelligence item is a public consultation on a national strategy rather than a designation. So we record the position as not established rather than as nobody having been designated.

One further provision of that Regulation should be read before any analytics feature is built, and its scope is wider than the phrase people quote. It prohibits AI systems used to infer emotions of a natural person in the workplace and in education institutions, with an exception only for uses intended for medical or safety reasons, and it has applied since 2 February 2025 at up to thirty-five million euros or seven per cent of worldwide turnover. The workplace limb is what reaches an employer's exercise. Whether a given feature is inside turns on the definition of an emotion recognition system, which is confined to inference from biometric data, so measuring whether someone complied is outside it while scoring how they sounded while complying is the contested case.

We could not find a Cypriot rule, and we are not inventing one

This is the thinnest block on the Cypriot page and we would rather say so than fill it.

What is established is what the law covers. The electronic communications act's provision on the presentation and restriction of calling and connected line identification is the European privacy rule, and it is entirely about the right to prevent the function: the calling user must be able, by simple means and free of charge, to block it. The neighbouring article deals with overriding that block for tracing malicious calls and for emergency services. Neither imposes a duty of accuracy on the caller.

We then read the current numbering instrument in full, the regulatory decision on numbering of December 2023, and searched it for the Greek words for identification, misleading and misuse. All three return nothing. It governs the procedure for assigning numbers, the fees and the categories, not what identity may be presented on a call.

So no Cypriot rule prohibiting a caller from presenting a number it does not hold a right of use in could be sourced. We are not asserting that no such rule exists, and we are certainly not asserting that presenting someone else's number is therefore fine. If your carrier tells you it cannot do something, ask which instrument that comes from, and treat its own terms of service as the operative constraint until you have one.

What the country matrix holds for Cyprus

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Four words from the regulator, resting on a repealed act

The Commissioner has published a directive on the processing of personal data in employment relations, and one sentence in it is more adverse to this activity than anything in the Cypriot statute book: covert monitoring is prohibited.

The same paragraph sets out what an employer must do in every case. It must inform employees, before the monitoring begins, of the purpose, the manner, the duration and the technical characteristics of the monitoring. It says continuous monitoring at the workplace is to be avoided, and that the employer must choose the least intrusive means of monitoring.

Now the part that has to be said in the same breath, because leaving it out would be the kind of half-truth this portal exists to replace. That directive is built on the 2001 data protection law, and the 2018 implementing act expressly repealed the 2001 laws. The Commissioner nonetheless still publishes it and re-uploaded it to the government portal in September 2025. So it is the regulator's stated position, carrying real weight in any conversation with that regulator, and it is not law in force. Both of those are true and a page that gave you only one would mislead you.

How the prohibition and a simulation sit together is our reading and we will label it as such. The requirement is advance information about the purpose, manner, duration and technical characteristics of the monitoring, and a programme-level notice given in advance supplies all four without disclosing which call is which. Nothing in any Cypriot primary source addresses simulations, so this is not a regulator-blessed reading and you should not present it internally as one.

On consultation the answer is simpler and negative. The Cypriot transposition of the European information and consultation directive applies to undertakings employing at least thirty employees. It defines consultation as the exchange of views and establishment of dialogue, and information as the transmission of data so that representatives may take cognisance of the matter and examine it. Its strongest outcome duty is that representatives can meet the employer and receive a reasoned reply to any opinion they express, with consultation conducted with a view to reaching agreement on decisions within the employer's competence. There is no provision making a measure ineffective for want of employee-side agreement, so the works-council veto some neighbouring countries have has no Cypriot analogue.

One genuine timing duty does exist: the employer must ensure that information and consultation take place before it reaches any decisions affecting employees. Whether a simulation is even a subject on which consultation is owed is unresolved, since the duty attaches to decisions capable of bringing about substantial changes in work organisation or in contracts of employment. A one-off awareness exercise plainly is not. A standing, per-employee-scored programme wired into a disciplinary process is arguable, and no Cypriot source settles it.

One amending law, and term counts that settle the mandate question

Cyprus notified a single measure transposing the European network and information security directive, and it is an amending law rather than a new statute: the law amending the security of networks and information systems law, published in the official gazette on 25 April 2025, against a transposition deadline of 17 October 2024.

Whether any of that requires this technique is answerable by counting, which is more useful than paraphrasing. Across the directive's full text, voice phishing appears zero times and simulation appears zero times. Phishing and social engineering appear once each, and both occurrences are in the same recital, which is not a binding provision: it says essential and important entities should adopt a wide range of basic cyber hygiene practices, organise training for their staff and raise awareness concerning cyber threats, phishing or social engineering techniques. The binding article says only basic cyber hygiene practices and cybersecurity training.

DORA is starker. Phishing, voice phishing, social engineering and simulation each appear zero times across the entire Regulation. Its nearest provision requires financial entities to develop security awareness programmes and digital operational resilience training as compulsory modules in staff training schemes, applicable to all employees and senior management. Its testing regime requires threat-led penetration testing at least every three years for entities in scope, and defines that by reference to mimicking real threat actors without naming any channel.

So if anyone tells you a security regime requires you to run voice phishing tests, the term counts refute it. The strongest true statement available is that the delegated regulation supplementing DORA presupposes social engineering as an available technique and requires the red team test plan to record the ethical boundaries for it.

We could not establish the central bank's role under DORA from a primary source in this pass, so nothing is asserted about it here.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in CYPRUS. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance at the programme level.

Verify or correct each proposition below against primary Cypriot sources, and tell me who inside our company carries the exposure:

1. ⚠ Ν. 92(Ι)/1996 art 3(3) requires prior express approval «από όλα τα πρόσωπα», and art 2 defines the prohibited act to include «μαγνητοφώνηση». Ceiling ten years or EUR 100,000. Confirm party status is irrelevant.
2. ⚠ THE LOAD-BEARING READING: the approval must be ΠΡΟΗΓΟΥΜΕΝΗ and nothing requires it to be call-specific. Assess whether a documented advance approval covering recording, from every party, satisfies art 3(3). Is there any Supreme Court authority?
3. Ν. 125(Ι)/2018 art 33 makes failure to carry out a required DPIA, and failure to keep the art 30 record, criminal offences at up to three years or EUR 30,000, with art 33(5)(a) fixing liability on the most senior executive body.
4. The Commissioner's DPIA list is «ενδεικτικός» and dated August 2018. Given the criminal penalty, advise whether a DPIA should be treated as mandatory here.
5. ⚠ The employment directive's «απαγορεύεται η μυστική παρακολούθηση» rests on Ν. 138(Ι)/2001, which Ν. 125(Ι)/2018 art 36 REPEALED, yet the Commissioner re-uploaded it in September 2025. What weight does it carry, and does advance programme-level notice of purpose, manner, duration and technical characteristics answer it?
6. Ν. 112(Ι)/2004 Part 14 is scoped to direct commercial promotion, and the identity-concealment prohibition is confined to electronic mail.
7. Ν. 78(Ι)/2005 applies at 30+ employees and contains no veto. Confirm whether a standing per-employee-scored programme is a subject on which consultation is owed.
8. ⚠ We could source NO Cypriot rule against presenting a number one does not hold. Confirm or supply one.

Flag anything that has changed since September 2026.

Common questions

Can we record simulated calls in Cyprus?
Only with prior express approval from every party to the call, which the statute spells out in those words. The ceiling is ten years or a hundred thousand euro. The one opening is that the approval must be prior rather than call-specific, so a documented advance approval is the route to explore locally.
Is skipping the impact assessment really a crime here?
Yes, and this is unique in our coverage. The implementing act makes a controller who does not carry out a required assessment guilty of an offence carrying up to three years or thirty thousand euro or both, and fixes liability on the person designated as the undertaking's most senior executive body.
The regulator says covert monitoring is prohibited. Does that end it?
It is the regulator's stated position and it carries real weight, but the directive it appears in rests on a data protection law repealed in 2018. Our reading is that advance programme-level notice of purpose, manner, duration and technical characteristics answers it. No Cypriot source confirms that.
What are the Cypriot rules on presenting a caller number?
We could not find any. The electronic communications act governs only the right to withhold identification, and the 2023 numbering decision covers assignment and fees. We are not asserting that no rule exists, and certainly not that presenting another party's number is therefore acceptable.

Elsewhere in Southern Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.