Voice phishing simulations in Denmark
A voice phishing simulation is lawful in Denmark and Callstrike supplies the Danish number, but the country answers the agreement question by removing it: a collective agreement between the social partners says the individual employee cannot consent to a control measure at all. What you owe instead is six weeks of notice, or a written account, produced afterwards, of why six weeks was impossible.
Phone numbers
Supplied by Callstrike
Local numbers in Denmark, after a one-time approval.
Running a simulation
Permitted, on a clock
Six weeks of notice before the measure starts, unless notice would defeat it.
Consent
Removed by agreement, not by statute
The act permits it; the social partners have agreed it away for covered employers.
Getting a phone number in Denmark
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Danish numbers are not released from open inventory, so nobody on your team goes shopping for one. Your workspace is cleared for Denmark once and Callstrike then provisions a dedicated number against that clearance. The evidence the carrier wants is short by the standards of this portal and it is all about the address: it has to be inside Denmark, and the document you file has to actually show it, which is the step a filing made from a group head office abroad tends to fail.
Two things about Danish caller identity are worth knowing before you design the pretext, because they run against each other. Withholding your own number is expressly lawful, but the same rules let the person you are calling reject calls whose number is withheld, so a withheld-number campaign is not reliably deliverable and a poor answer to a difficult scenario. And while we could find no Danish prohibition on presenting a number you do not hold, the identity misuse offence is the real constraint: it reaches holding yourself out as another person, and it does not reach holding yourself out as an organisation.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Denmark is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Business addressMust be within Denmark | Business registration showing danish address, Utility bill, Tax notice, Rent receipt, Title deed |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in Denmark?
The position in short, before your counsel reads the detail below.
Yes, and the Danish framework is unusual in that the instrument that decides your programme is an agreement between the employers' and trade union confederations rather than a statute. Its standard is that a control measure has to be objectively justified by operational reasons, have a sensible purpose, not be offensive to employees, not cause them loss or appreciable inconvenience, and keep a reasonable relationship between ends and means. A well-scoped awareness exercise meets that description comfortably. A name-and-shame design is where it starts to struggle.
The timetable is the headline. You must inform employees of a new control measure no later than six weeks before it is implemented, which a covert exercise plainly cannot do. There is an escape, and it fits: the six weeks does not apply where the purpose of the measure would thereby be defeated. But read the sentence that follows it as a deliverable rather than as relief, because the escape is conditional on a duty running the other way in time. You must then inform employees as soon as possible and explain why the six-week deadline could not be observed. Nothing in the data protection layer asks for that document. It is the single most concrete thing a Danish programme produces, and it is produced after the campaign rather than before it, which is exactly why it gets forgotten.
The agreement then removes the design most companies reach for first. The individual employee cannot give agreement to the implementation of control measures, neither on hiring nor at any later time. That takes away both the clause in the employment contract and the acceptance screen at rollout in one line. Note where the removal comes from: the data protection act expressly permits employee agreement, so this is not a regulator's view about free will, it is a bargained term, and a dispute about it goes to the labour court or to industrial arbitration rather than to the data protection authority. Know whether you are bound: the agreement reaches employers in an affiliated employers' association or otherwise covered, is disapplied where a specific collective agreement makes its own rules, and does not bind an unorganised Danish employer at all.
Two smaller points that change a design. Recording is workable but the architecture has to keep the recorder on the call: the criminal provision reaches secret recording of a conversation between others or of a meeting the recorder does not take part in, so a party is outside it, while a silent supervisor leg or a platform capturing a call it is not itself on is squarely inside, and the ceiling rises to six years in aggravating circumstances. And one myth is worth putting down before somebody budgets for it: every secondary summary says systematic employee monitoring is on the Danish regulator's mandatory impact assessment list. That list has eight entries and monitoring is not one of them.
What your company needs to do
6 items, in the order you will need them.
- Work out first whether the collective agreement binds youDenmark-specificEverything else on this page turns on the answer. It reaches employers in an affiliated employers' association or otherwise covered, is disapplied where a specific collective agreement lays down its own rules on control measures, and does not bind an unorganised employer. Getting this wrong means preparing for a six-week clock that does not run, or missing one that does.
- Decide which side of the six weeks you are on, and say whyDenmark-specificEither you announce the measure six weeks before it starts, which most awareness programmes cannot do without losing the exercise, or you take the escape because notice would defeat the purpose. Make that decision explicitly and record the reasoning at the time, because the reasoning is what the second duty asks you to produce later.
- Draft the written account before you need itDenmark-specificIf you rely on the escape you must inform employees as soon as possible afterwards and explain in writing why six weeks could not be met. That is the Danish deliverable, it is owed after the campaign, and it is the one nobody diarises. Write it while the reasoning is fresh and issue it with the debrief rather than reconstructing it when somebody asks.
- Do not build the programme on a signatureFor a covered employer the contractual clause and the acceptance screen are both unavailable, so a design that depends on either has to be rebuilt. Rely on the employment-law ground the act provides, which is the one the regulator itself points the collective machinery at, and use the notice regime to carry the transparency.
- Keep whoever records on the callThe criminal provision is drawn around the eavesdropper rather than the participant, so the design question is architectural: a silent monitoring leg, or a platform capturing a conversation it is not itself party to, is inside the offence where a party recording is outside it. The regulator separately wants necessity, prior information and deletion at fixed short intervals.
- Bring the works council in above thirty-five employeesThe cooperation agreement gives it a role in laying down principles for collecting and using personal data and in assessing the consequences of introducing new technology of substantial scope. That is involvement and information rather than consent, and no Danish instrument makes a control measure conditional on the council agreeing, but leaving it out is a visible omission.
The controls that do the work
How Callstrike is configured, and which provision in Denmark each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
The collective agreement's own standard is that a control measure must not be offensive to employees, must not cause them loss or appreciable inconvenience, and must keep a reasonable relationship between ends and means. That is a proportionality test written by the social partners rather than by a regulator, and it is judged in the labour court. The call ends the moment an employee starts to give up a credential, so the exercise measures whether somebody would have disclosed without ever holding what they were about to disclose, which is the cleanest version of that ratio you can put in front of an arbitrator.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The Danish escape from the six-week notice is bought with a duty to inform as soon as possible afterwards, so the back end of the exercise is where the compliance work actually lands here. A second voice that breaks character the instant the call ends, followed by vishing training in writing, is the earliest possible discharge of that duty rather than a nice touch: the employee is told what happened within seconds instead of within weeks.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
In Denmark this is the notice machinery and never the permission, because for a covered employer the individual cannot agree to a control measure at all. Use it for what the agreement does demand: a dated record of the notice, the timestamped account of why six weeks could not be met, and a hashed copy of the policy or collective agreement you rely on with a signed attestation of its scope.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Where the six-week clock makes a telephone campaign awkward to schedule, this is the route that teaches on your own timetable. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner opens themselves after working through the module. A learner who chooses to start the call has been told in advance by definition, so the notice question that dominates the rest of this page does not arise in the same shape.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.