Voice phishing simulations in Czechia
The Czech labour code names the interception and recording of employees' telephone calls in terms, so a recorded voice phishing simulation is inside the provision on its face rather than by analogy. What it sets up is a near-prohibition with one narrow gateway rather than a balancing test, and whether your business can write itself through that gateway is the question to settle before anything else here.
Phone numbers
Supplied by Callstrike
Local numbers in Czechia, after a one-time approval.
Running a simulation
Permitted only through a gateway
The default is that you may not, and one serious reason lifts it. Test that reason first.
Consent
Evidence of notice, not a title
The regulator points employers at the contract and legal-obligation grounds instead.
Getting a phone number in Czechia
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
The Czech clearance is the shortest in this region and only one line of it needs a document at all. The company name, the business identification number and your administrator's name are typed straight into the console form. What has to be evidenced is the business address, and any one of a business registration showing it, a utility bill, a tax notice, a rent receipt or a title deed satisfies it.
Caller identity is settled here in a way that is unusually easy to plan around, and it is not in the numbering decree where most people look for it. The regulator's general authorisation permits an originating operator to insert a number other than the one identifying the endpoint the call comes from only upon the demonstrable request of the subscriber entitled to use it. Presenting your own organisation's number is therefore contemplated by the instrument itself. A number nobody in the chain holds an authorisation for cannot be presented through a compliant Czech originating operator, and a separate clause stops calls arriving from abroad that carry a Czech non-mobile number, which closes the obvious way around the domestic rule.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Czechia is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Business addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable where a local address is required. | Business registration showing local address, Utility bill, Tax notice, Rent receipt, Title deed |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in Czechia?
The position in short, before your counsel reads the detail below.
The rule everyone expects to be the obstacle is not one. Both operative paragraphs of the Czech transposition of the European unsolicited-communications rule are scoped by purpose, and the automatic calling device paragraph is confined to the purposes of direct marketing. An authorised internal test offers no goods or services and pursues no marketing purpose, so neither paragraph is engaged and nothing turns on whether a person or a machine is speaking. One detail is usually described backwards, and it is worth having right: the first paragraph is not a do-not-call list, it prohibits marketing to anyone who has not affirmatively marked the public directory to say they want it.
The Czech constraint is in the labour code, and it is a different kind of provision from anything in the data protection layer. You may not, without a serious reason consisting in the special nature of your own activity, intrude upon an employee's privacy at your workplaces and common premises by subjecting them to open or covert surveillance, to the interception and recording of their telephone calls, to the checking of electronic mail, or to the checking of postal consignments. Where such a reason does exist, you are then obliged to inform employees directly of the extent of the check and the manner in which it is carried out.
Read what the gateway actually asks for, because it is the whole Czech decision. It wants a serious reason located in the special nature of your own activity, which points at what kind of business you are rather than at how sensitive a role is or how good your threat model looks. Wanting to test your staff is not obviously a reason of that kind on the face of the words, and no Czech regulator or inspectorate material we found closes the gap. The enforcement shape is unusual too, and it is not the data protection authority: breach is a named administrative offence carried by the labour inspectorate at up to one million crowns, with a further hundred thousand for failing to give the direct information about the extent and manner.
One limitation cuts the other way and we would rather surface it than let you assume the worst. The prohibition is expressly bounded to intrusion at the workplaces and in the employer's common premises, and the offence provision repeats the same wording, so a call placed to a remote worker's own phone is not obviously inside that geography. The text does not settle it. Separately, the European transparency duty reaches you directly and does not wait for national machinery: since August 2026 a deployer of a system generating audio constituting a deep fake must disclose that the content is artificially generated, at the latest at first exposure, and the only carve-outs are criminal-law authorisation by law and evidently artistic works. Czechia has not yet designated an authority to supervise it, which changes who watches rather than whether the duty binds.
What your company needs to do
7 items, in the order you will need them.
- Write the serious reason down, and find out whether you canCzechia-specificThis is the one item on the Czech list that decides everything else, and it is the one most programmes cannot write convincingly. The reason has to rest in the special nature of your own activity, not in your threat model. Draft it first, before the campaign is designed, because discovering you cannot write it is much cheaper before a complaint than after one.
- Inform employees directly, and say the extent and the mannerCzechia-specificDirectly is doing work in a code that elsewhere routes duties through representatives, and this duty carries its own inspectorate penalty separate from the intrusion offence. Set out how far the check goes and how it is carried out. This is the single most concrete thing a Czech programme has to produce.
- Run the information and consultation, and do not wait for agreementConsultation is defined as an exchange of positions with the aim of reaching agreement, and that describes the negotiation rather than conditioning the measure on it. There is no Czech works-council veto. The hook for a monitoring measure is the working-conditions limb, and the relaxation for employers under ten employees reaches only certain other limbs.
- Decide deliberately whether remote workers are in scopeCzechia-specificThe prohibition is written about intrusion at your workplaces and common premises, and a call to a remote worker's own handset is not obviously inside that geography. That is unresolved rather than settled in your favour. Take the position knowingly and record which reading you adopted, instead of discovering the question when somebody else raises it.
- Disclose that the voice is generatedThe European transparency duty binds a deployer directly, at the latest at the first exposure, and its exceptions are criminal-law authorisation by law and evidently artistic works. Your own authorisation of your own exercise is not authorisation by law. The debrief that closes the call is where this belongs, and it is the same moment the training lands.
- Present a number your organisation is entitled to useThe general authorisation lets an operator insert a different number only on the demonstrable request of the subscriber entitled to it, so make the request demonstrable and keep it. Every obligation in that instrument is addressed to the operator rather than to you, and we could find no Czech rule imposing a caller identity duty on the calling party directly.
- Keep the credential out of the systemMeasure the behaviour and discard what the pretext asked for. It keeps the exercise on the metadata side of the line the regulator has already described as adequate, and it makes the proportionality half of the gateway argument much shorter to write.
The controls that do the work
How Callstrike is configured, and which provision in Czechia each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
The Czech regulator's own yardstick for what is adequate in workplace monitoring is unusually concrete: it says monitoring the quantity and size of mail sent and received, or the domains of websites visited, can be regarded as adequate. That is a line drawn at metadata rather than at content. The call ends the instant an employee begins to give up a credential, so what the exercise holds is that a call happened and what the person did, never what they said. It puts the exercise on the side of that line the regulator has already spoken about, which is the half of the gateway argument you can actually win.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The offence the labour inspectorate enforces is intruding upon an employee's privacy, and how the exercise ends is a large part of what that intrusion looks like to an inspector. A second voice that breaks character the moment the call ends, with vishing training in writing while the moment is still sharp, is a much harder thing to characterise that way than a caught employee, no explanation, and a report circulating some weeks later.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
The Czech authority says agreement will not be a frequent legal title for employer processing, because agreement must be a free act and the imbalance between the parties means that will as a rule not be met, and it names the contract and legal-obligation grounds instead. So this is not the ground the programme rests on. What it produces is the direct information the labour code demands, dated before the campaign rather than assembled afterwards, and a hashed copy of the written statement of the serious reason with a signed attestation of the scope it covers.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Where the gateway argument is one you would rather not have, this is the delivery that does not need it. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module. The labour code limb is written about the interception and recording of the employee's telephone calls, and a session a learner opens in their own browser intercepts and records no telephone call for those words to reach. The European transparency duty is unaffected and still applies, which is why the module discloses the synthetic voice on its own face.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.