Callstrike
Compliance

Voice phishing simulations in Czechia

Phone numbers in CzechiaProvisioned by Callstrike after approval

The Czech labour code names the interception and recording of employees' telephone calls in terms, so a recorded voice phishing simulation is inside the provision on its face rather than by analogy. What it sets up is a near-prohibition with one narrow gateway rather than a balancing test, and whether your business can write itself through that gateway is the question to settle before anything else here.

Phone numbers

Supplied by Callstrike

Local numbers in Czechia, after a one-time approval.

Running a simulation

Permitted only through a gateway

The default is that you may not, and one serious reason lifts it. Test that reason first.

Consent

Evidence of notice, not a title

The regulator points employers at the contract and legal-obligation grounds instead.

Getting a phone number in Czechia

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

The Czech clearance is the shortest in this region and only one line of it needs a document at all. The company name, the business identification number and your administrator's name are typed straight into the console form. What has to be evidenced is the business address, and any one of a business registration showing it, a utility bill, a tax notice, a rent receipt or a title deed satisfies it.

Caller identity is settled here in a way that is unusually easy to plan around, and it is not in the numbering decree where most people look for it. The regulator's general authorisation permits an originating operator to insert a number other than the one identifying the endpoint the call comes from only upon the demonstrable request of the subscriber entitled to use it. Presenting your own organisation's number is therefore contemplated by the instrument itself. A number nobody in the chain holds an authorisation for cannot be presented through a compliant Czech originating operator, and a separate clause stops calls arriving from abroad that carry a Czech non-mobile number, which closes the obvious way around the domestic rule.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Czechia is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Business addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable where a local address is required.Business registration showing local address, Utility bill, Tax notice, Rent receipt, Title deed

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Czechia?

The position in short, before your counsel reads the detail below.

The rule everyone expects to be the obstacle is not one. Both operative paragraphs of the Czech transposition of the European unsolicited-communications rule are scoped by purpose, and the automatic calling device paragraph is confined to the purposes of direct marketing. An authorised internal test offers no goods or services and pursues no marketing purpose, so neither paragraph is engaged and nothing turns on whether a person or a machine is speaking. One detail is usually described backwards, and it is worth having right: the first paragraph is not a do-not-call list, it prohibits marketing to anyone who has not affirmatively marked the public directory to say they want it.

The Czech constraint is in the labour code, and it is a different kind of provision from anything in the data protection layer. You may not, without a serious reason consisting in the special nature of your own activity, intrude upon an employee's privacy at your workplaces and common premises by subjecting them to open or covert surveillance, to the interception and recording of their telephone calls, to the checking of electronic mail, or to the checking of postal consignments. Where such a reason does exist, you are then obliged to inform employees directly of the extent of the check and the manner in which it is carried out.

Read what the gateway actually asks for, because it is the whole Czech decision. It wants a serious reason located in the special nature of your own activity, which points at what kind of business you are rather than at how sensitive a role is or how good your threat model looks. Wanting to test your staff is not obviously a reason of that kind on the face of the words, and no Czech regulator or inspectorate material we found closes the gap. The enforcement shape is unusual too, and it is not the data protection authority: breach is a named administrative offence carried by the labour inspectorate at up to one million crowns, with a further hundred thousand for failing to give the direct information about the extent and manner.

One limitation cuts the other way and we would rather surface it than let you assume the worst. The prohibition is expressly bounded to intrusion at the workplaces and in the employer's common premises, and the offence provision repeats the same wording, so a call placed to a remote worker's own phone is not obviously inside that geography. The text does not settle it. Separately, the European transparency duty reaches you directly and does not wait for national machinery: since August 2026 a deployer of a system generating audio constituting a deep fake must disclose that the content is artificially generated, at the latest at first exposure, and the only carve-outs are criminal-law authorisation by law and evidently artistic works. Czechia has not yet designated an authority to supervise it, which changes who watches rather than whether the duty binds.

What your company needs to do

7 items, in the order you will need them.

  • Write the serious reason down, and find out whether you canCzechia-specificThis is the one item on the Czech list that decides everything else, and it is the one most programmes cannot write convincingly. The reason has to rest in the special nature of your own activity, not in your threat model. Draft it first, before the campaign is designed, because discovering you cannot write it is much cheaper before a complaint than after one.
  • Inform employees directly, and say the extent and the mannerCzechia-specificDirectly is doing work in a code that elsewhere routes duties through representatives, and this duty carries its own inspectorate penalty separate from the intrusion offence. Set out how far the check goes and how it is carried out. This is the single most concrete thing a Czech programme has to produce.
  • Run the information and consultation, and do not wait for agreementConsultation is defined as an exchange of positions with the aim of reaching agreement, and that describes the negotiation rather than conditioning the measure on it. There is no Czech works-council veto. The hook for a monitoring measure is the working-conditions limb, and the relaxation for employers under ten employees reaches only certain other limbs.
  • Decide deliberately whether remote workers are in scopeCzechia-specificThe prohibition is written about intrusion at your workplaces and common premises, and a call to a remote worker's own handset is not obviously inside that geography. That is unresolved rather than settled in your favour. Take the position knowingly and record which reading you adopted, instead of discovering the question when somebody else raises it.
  • Disclose that the voice is generatedThe European transparency duty binds a deployer directly, at the latest at the first exposure, and its exceptions are criminal-law authorisation by law and evidently artistic works. Your own authorisation of your own exercise is not authorisation by law. The debrief that closes the call is where this belongs, and it is the same moment the training lands.
  • Present a number your organisation is entitled to useThe general authorisation lets an operator insert a different number only on the demonstrable request of the subscriber entitled to it, so make the request demonstrable and keep it. Every obligation in that instrument is addressed to the operator rather than to you, and we could find no Czech rule imposing a caller identity duty on the calling party directly.
  • Keep the credential out of the systemMeasure the behaviour and discard what the pretext asked for. It keeps the exercise on the metadata side of the line the regulator has already described as adequate, and it makes the proportionality half of the gateway argument much shorter to write.

The controls that do the work

How Callstrike is configured, and which provision in Czechia each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

The Czech regulator's own yardstick for what is adequate in workplace monitoring is unusually concrete: it says monitoring the quantity and size of mail sent and received, or the domains of websites visited, can be regarded as adequate. That is a line drawn at metadata rather than at content. The call ends the instant an employee begins to give up a credential, so what the exercise holds is that a call happened and what the person did, never what they said. It puts the exercise on the side of that line the regulator has already spoken about, which is the half of the gateway argument you can actually win.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The offence the labour inspectorate enforces is intruding upon an employee's privacy, and how the exercise ends is a large part of what that intrusion looks like to an inspector. A second voice that breaks character the moment the call ends, with vishing training in writing while the moment is still sharp, is a much harder thing to characterise that way than a caught employee, no explanation, and a report circulating some weeks later.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

The Czech authority says agreement will not be a frequent legal title for employer processing, because agreement must be a free act and the imbalance between the parties means that will as a rule not be met, and it names the contract and legal-obligation grounds instead. So this is not the ground the programme rests on. What it produces is the direct information the labour code demands, dated before the campaign rather than assembled afterwards, and a hashed copy of the written statement of the serious reason with a signed attestation of the scope it covers.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

Where the gateway argument is one you would rather not have, this is the delivery that does not need it. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module. The labour code limb is written about the interception and recording of the employee's telephone calls, and a session a learner opens in their own browser intercepts and records no telephone call for those words to reach. The European transparency duty is unaffected and still applies, which is why the module discloses the synthetic voice on its own face.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

The regulator names two grounds, and neither is the usual one

Czechia enacted no employment-specific data protection rules. Its implementing act is an adaptation statute covering the authority's powers, law enforcement processing and journalistic exemptions; the word for employee appears nine times in the whole text, every one of them about the authority's own staff, criminal record checks or transitional provisions, and none of them creating a processing rule for employers.

What the Czech authority does say diverges from the answer most of this portal gives, and we would rather report the divergence than iron it out. Its published position is that the employee's agreement will not be a frequent legal title for employer processing, because agreement must be a free act and, given the imbalance of the parties in an employment relationship, that will as a rule not be met. So far so familiar. But it then names the grounds the employer does use as the contract ground and the legal obligation ground, not the legitimate interests ground that carries most of the weight elsewhere in this cluster.

We are not going to pretend that settles the basis for a simulation, because the authority is describing ordinary employment processing rather than a security test, and a test is not necessary for the performance of an employment contract in any obvious sense. Its guidance on monitoring specifically is thinner: it says that monitoring the quantity and size of mail sent and received, or the domains of websites visited, can be regarded as adequate, and that where monitoring tools are introduced the employer is obliged to inform employees directly about it.

That word directly is not decoration. It reappears in the labour code provision set out below, and in Czechia the direct information duty is the concrete deliverable rather than the assessment.

A statute that names your product, and the reason it asks for

Few countries in this portal legislate this as directly, so read the provision rather than a summary of it.

The labour code provides that the employer may not, without a serious reason consisting in the special nature of the employer's activity, intrude upon the employee's privacy at the workplaces and in the employer's common premises by subjecting the employee to open or covert surveillance, to the interception and recording of the employee's telephone calls, to the checking of electronic mail, or to the checking of postal consignments addressed to the employee. Where such a serious reason does exist, the employer is obliged to inform employees directly of the extent of the check and of the manners in which it is carried out.

Three things about that are worth separating out, because they are usually run together.

The first is that this is a near-prohibition rather than a balancing test. The default is that the employer may not do it, and a gateway lifts the default. The second is what the gateway actually asks for. It is a serious reason located in the special nature of the employer's own activity, which points at what kind of business the employer is rather than at how sensitive a role is or how good the threat model looks. We cannot tell you that wanting to test your staff is a reason of that kind, and on the face of the text it is not obviously the sort of reason the words describe. That is a real gap and no Czech regulator or inspectorate material we found closes it.

The third is the consequence where the gateway is satisfied, which is not a licence but a duty: inform employees directly of the extent and the manner. Directly, in a provision that elsewhere routes duties through employee representatives, is doing work.

The enforcement shape is unusual too, and it is worth knowing because it is not the data protection authority. Breach is a named administrative offence under the labour inspection act. Intruding on employee privacy in any of the ways the labour code lists carries up to one million crowns; failing to give the direct information about the extent and manner of the check carries up to one hundred thousand. Very few monitoring provisions in Europe come with their own dedicated labour-inspection penalty.

One limitation almost nobody notices, and we would rather surface it than let you assume the worst. The prohibition is expressly bounded to intrusion at the workplaces and in the employer's common premises, and the offence provision repeats the same wording. A call placed to a remote worker's own phone is not obviously inside that geography. The text does not settle it, and we are not going to.

The criminal and civil layers are milder than the labour one, which is the reverse of most countries here. The offence of violating the secrecy of transported messages is framed around a secret in a communication not intended for the person, and its second limb additionally requires intent to cause damage or obtain an unjustified benefit. The civil code prohibits recording a person's private life without permission, but supplies a licence where the recording is made or used for the exercise or protection of the rights or legally protected interests of others, subject to a proportionality cap. Neither is where the Czech risk sits.

Marketing is the gate, and the dialler rule is inside it

The Czech transposition of the European rule on unsolicited communications is scoped by purpose in both of its operative paragraphs, which is the answer to the question everyone asks about automated calling.

The first prohibits offering, through electronic communications networks or services, marketing advertising or another similar manner of offering goods or services to subscribers or users who have not indicated in the public directory that they wish to be contacted for marketing purposes. The second prohibits using subscriber directories, or an electronic communications network or service, for the purposes of direct marketing by means of automatic calling systems without human intervention, fax machines or electronic mail, without the prior agreement of the subscriber or user.

So the provision that looks most threatening to a synthetic-voice caller, the automatic calling device rule, is itself confined to the purposes of direct marketing. An authorised internal security test offers no goods or services and pursues no marketing purpose, so neither paragraph is engaged and nothing turns on whether a person or a machine is speaking.

One detail about the first paragraph is worth correcting because it is usually described backwards. It is not a do-not-call list. It prohibits marketing to anyone who has not affirmatively indicated in the public directory that they want it, so the directory marker is an opt-in flag rather than an opt-out one.

The European transparency rule reaches Czechia directly. Article 50 of the AI Act has applied since 2 August 2026, requiring a system built to interact with people to be designed so the person is informed they are dealing with an AI system, and requiring a deployer of a system generating or manipulating audio constituting a deep fake to disclose that the content is artificially generated, in both cases at the latest at the time of the first interaction or exposure. The exceptions are use authorised by law to detect, prevent, investigate or prosecute criminal offences, and evidently artistic works. An employer authorising its own exercise is not authorisation by law.

Czechia has not designated a national authority for that article in binding law. The telecoms regulator's own published position is that it was proposed as the market surveillance authority by a government resolution of May 2025, and that it can currently exercise only those competences by which it does not interfere with the rights and obligations of entities, because the relevant adaptation act is still in the legislative process. Its press material from July 2026 is still in the future tense about who will supervise. The duty binds regardless.

The other article of that Regulation worth reading before a purchase is the prohibition on emotion inference, and it is drafted to catch both sides of the transaction. It bites on placing on the market, putting into service and using an AI system to infer emotions of a natural person in the workplace, so a buyer cannot push the exposure onto a supplier and a supplier cannot push it onto a buyer. It has applied since 2 February 2025 and carries up to thirty-five million euros or seven per cent of worldwide turnover, with an exception only for medical or safety reasons. Its gate is the definition of an emotion recognition system, confined to inference from biometric data, which is why a plain record of who disclosed what stays outside it.

The rule is a general authorisation, and it binds your operator

Czech caller identity rules are not in the numbering decree, which catches people out. The numbering plan is an ordinary decree; the conditions that govern what identity may be presented live in the regulator's general authorisation, an instrument of a different kind, amended in 2024 specifically to address spoofing.

It requires the originating operator to insert valid information about the calling subscriber's number, and then defines valid: the number must conform to the full format under the numbering plan, must be a number for the use of which a valid authorisation to use numbers exists under the act, must be unambiguously linked to a specific electronic communications service and a specific subscriber, must not be a premium-rate number and must not be a short number.

The next clause is the one that decides whether your campaign can present the number you want. The originating operator may insert a number other than the one identifying the endpoint the call comes from only upon the demonstrable request of the entitled subscriber that uses that number for the purpose of using a voice communication service, and where the signalling permits it must also insert the number of the endpoint the call actually originated from.

So the Czech position is clear and workable: presenting your own organisation's number is contemplated by the text, provided the request is demonstrable and comes from the subscriber entitled to it. Presenting a number nobody in the chain holds an authorisation for is not available through a compliant Czech originating operator, because the operator would be inserting information the instrument does not permit it to insert.

A separate clause requires operators to prevent transit or termination of calls arriving from abroad where the calling party is presented with a Czech country code other than a mobile access code, which closes the obvious route around the domestic rule.

Two honest notes. Every obligation here is addressed to the operator rather than to you, and we could find no Czech instrument imposing a caller identity duty on the calling party directly. And the consolidated version of the general authorisation carries the regulator's own warning that it is informative only, the operative texts being the individual measures, so we read both and they agree.

What the country matrix holds for Czechia

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Direct information to employees, and consultation aimed at agreement

Czechia asks for two different things from two different directions, and only one of them routes through representatives.

The first is the direct information duty already described: where the gateway in the monitoring provision is satisfied, the employer is obliged to inform employees directly of the extent of the check and of the manner in which it is carried out. That duty is owed to employees rather than to a body, it is enforced by the labour inspectorate with its own penalty, and it is the single most concrete thing a Czech programme has to produce.

The second is the general information and consultation machinery, and it is weaker than the first in every respect that matters. Employees have a right to information and consultation, and the employer is obliged to inform them and deal with them directly where no trade union organisation, works council or health and safety representative operates. Informing means providing necessary data in sufficient time and in a suitable manner so that employees can assess them and, where appropriate, prepare for consultation and express their position before the measure is implemented. Consultation means negotiation between employer and employees, an exchange of positions and explanations with the aim of reaching agreement, in which employees have the right to receive a reasoned reply to their position.

With the aim of reaching agreement is a description of the negotiation, not a condition of acting, and nothing in those provisions makes a measure conditional on the representatives agreeing. So Czechia has no works-council veto, and saying so with the source is more useful than leaving a reader to assume one exists.

The hook for a monitoring measure is the working conditions limb: information on fundamental questions of working conditions and their changes, and consultation on the same. Both duties are relaxed only for employers with fewer than ten employees, and only as to certain other limbs.

So the Czech file is short and specific. A written statement of the serious reason consisting in the special nature of your activity, a direct notice to employees setting out the extent and manner of the check, and a record of the information and consultation. The first of those is the one most programmes will not be able to write convincingly, and it is better to discover that before the campaign than after a complaint.

A new act, a repealed one, and a decree that says assess rather than simulate

Czechia's cybersecurity regime changed completely on 1 November 2025, and citing the old one is the commonest error in this area. The new cybersecurity act entered into force that day and its repeal provision expressly abolishes both the 2014 act and the 2018 security measures decree. Anything describing the Czech regime by reference to either is describing repealed law.

The new act lists human resources security among the organisational measures for providers in both the higher and lower duty regimes. Its only reference to a simulated attack is a power of the national cyber security authority rather than a duty on you: the authority may order the performance of a vulnerability scan or the identification and verification of vulnerabilities by means of a simulation of a real attack, which the act calls a penetration test. Its government computer emergency response team may test the implementation and resilience of asset protection including penetration testing, and the act says expressly that it does so with the agreement of the person affected by the testing. We searched the whole act for the Czech words for phishing and social engineering and both return nothing.

The implementing decree gets closer to this activity than the act does, and it is worth quoting precisely because the distinction is fine. Within security awareness the obliged person must ensure regular training and verification of employees' security awareness in accordance with their job description, must keep records of that instruction and training including a list of the people who completed it, and its annex makes social engineering techniques a compulsory topic for awareness development.

Verification of awareness is not the same as a simulated attack, and the word simulation appears nowhere in the decree. So the strongest true statement for a Czech buyer is that the regime requires you to train staff on social engineering and to verify that the training worked, and prescribes no method for the verification.

For financial entities DORA applies directly. The two regulators have published a joint statement setting out how the regimes interact: entities in scope of DORA are supervised primarily by the central bank, with supplementary supervision by the cybersecurity authority where an entity carries out activities the Regulation does not equivalently regulate, and the cybersecurity act applies to DORA entities where the Regulation does not equivalently regulate the area. DORA itself mentions neither phishing nor social engineering anywhere in its text.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in CZECHIA. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance at the programme level.

Verify or correct each proposition below against primary Czech sources, and tell me whether we can satisfy the gateway at all:

1. ⚠⚠ Zákoník práce § 316(2) prohibits intruding on employee privacy by «odposlech a záznam jeho telefonických hovorů» absent «závažný důvod spočívající ve zvláštní povaze činnosti zaměstnavatele». Assess whether an assurance purpose can ever be a reason of that kind, and supply any inspectorate or court material on the phrase.
2. ⚠ § 316(2) is bounded to intrusion «na pracovištích a ve společných prostorách zaměstnavatele», and § 11a of the inspection act repeats it. Is a call to a remote worker's own handset inside or outside that geography?
3. Where the gateway is satisfied, the duty is to inform employees DIRECTLY of the extent and manner. Confirm the separate CZK 100,000 offence for failing to, alongside the CZK 1,000,000 intrusion offence.
4. ⚠ ÚOOÚ's published position names Art 6(1)(b) and (c) for employer processing, NOT 6(1)(f). What is the correct basis for a security test on that view, given a test is not necessary for performance of the employment contract?
5. §§ 276 to 280 create information and consultation with «cílem dosáhnout shody», which is not a veto. Confirm no Czech works-council agreement requirement exists here.
6. Zákon č. 127/2005 Sb. § 96 is scoped in both paragraphs to marketing purposes, so an internal test is outside it; and § 96(1) is an opt-IN directory marker, not a do-not-call list.
7. ČTÚ VO-S/2 art 2(3) permits inserting another number only «na prokazatelnou žádost» of the entitled subscriber. Is any duty imposed on the CALLING PARTY directly anywhere in Czech law?
8. AI Act Art 50 binds us as deployer with no Czech designation yet in force; and the Art 5(1)(f) emotion prohibition is gated on inference from biometric data.
9. ⚠ Zákon č. 264/2025 Sb. repealed 181/2014 Sb. and vyhláška 82/2018 Sb. on 1 November 2025. Confirm nothing in vyhláška 409/2025 Sb. mandates a simulated attack on staff, as opposed to «ověřování» of awareness.

Flag anything that has changed since September 2026, and identify any obligation in our own kolektivní smlouva that this analysis omits.

Common questions

Does Czech law really name call recording of employees?
Yes, and no other country in our coverage does. The labour code prohibits the employer from subjecting employees to the interception and recording of their telephone calls absent a serious reason consisting in the special nature of the employer's activity. That is a near-prohibition with a gateway, not a balancing test.
Is wanting to test our staff a serious reason within that gateway?
The text does not say, and we are not going to say it for you. The gateway asks for a reason located in the special nature of the employer's own activity, which points at what kind of business you are rather than at your threat model. Take it to Czech counsel before the campaign.
Who enforces this, and how much is it?
The labour inspectorate, not the data protection authority. Intruding on employee privacy in any of the ways the labour code lists is an offence carrying up to one million crowns, and failing to inform employees directly of the extent and manner of the check carries up to one hundred thousand.
Can we present our own company number in Czechia?
Yes, on the face of the general authorisation. An originating operator may insert a number other than the originating endpoint's only on the demonstrable request of the subscriber entitled to use that number. Presenting a number nobody holds an authorisation for is not available through a compliant Czech operator.

Elsewhere in Central and Eastern Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.