Callstrike
Compliance

Voice phishing simulations in Denmark

Phone numbers in DenmarkProvisioned by Callstrike after approval

A voice phishing simulation is lawful in Denmark and Callstrike supplies the Danish number, but the country answers the agreement question by removing it: a collective agreement between the social partners says the individual employee cannot consent to a control measure at all. What you owe instead is six weeks of notice, or a written account, produced afterwards, of why six weeks was impossible.

Phone numbers

Supplied by Callstrike

Local numbers in Denmark, after a one-time approval.

Running a simulation

Permitted, on a clock

Six weeks of notice before the measure starts, unless notice would defeat it.

Consent

Removed by agreement, not by statute

The act permits it; the social partners have agreed it away for covered employers.

Getting a phone number in Denmark

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Danish numbers are not released from open inventory, so nobody on your team goes shopping for one. Your workspace is cleared for Denmark once and Callstrike then provisions a dedicated number against that clearance. The evidence the carrier wants is short by the standards of this portal and it is all about the address: it has to be inside Denmark, and the document you file has to actually show it, which is the step a filing made from a group head office abroad tends to fail.

Two things about Danish caller identity are worth knowing before you design the pretext, because they run against each other. Withholding your own number is expressly lawful, but the same rules let the person you are calling reject calls whose number is withheld, so a withheld-number campaign is not reliably deliverable and a poor answer to a difficult scenario. And while we could find no Danish prohibition on presenting a number you do not hold, the identity misuse offence is the real constraint: it reaches holding yourself out as another person, and it does not reach holding yourself out as an organisation.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Denmark is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Business addressMust be within DenmarkBusiness registration showing danish address, Utility bill, Tax notice, Rent receipt, Title deed

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Denmark?

The position in short, before your counsel reads the detail below.

Yes, and the Danish framework is unusual in that the instrument that decides your programme is an agreement between the employers' and trade union confederations rather than a statute. Its standard is that a control measure has to be objectively justified by operational reasons, have a sensible purpose, not be offensive to employees, not cause them loss or appreciable inconvenience, and keep a reasonable relationship between ends and means. A well-scoped awareness exercise meets that description comfortably. A name-and-shame design is where it starts to struggle.

The timetable is the headline. You must inform employees of a new control measure no later than six weeks before it is implemented, which a covert exercise plainly cannot do. There is an escape, and it fits: the six weeks does not apply where the purpose of the measure would thereby be defeated. But read the sentence that follows it as a deliverable rather than as relief, because the escape is conditional on a duty running the other way in time. You must then inform employees as soon as possible and explain why the six-week deadline could not be observed. Nothing in the data protection layer asks for that document. It is the single most concrete thing a Danish programme produces, and it is produced after the campaign rather than before it, which is exactly why it gets forgotten.

The agreement then removes the design most companies reach for first. The individual employee cannot give agreement to the implementation of control measures, neither on hiring nor at any later time. That takes away both the clause in the employment contract and the acceptance screen at rollout in one line. Note where the removal comes from: the data protection act expressly permits employee agreement, so this is not a regulator's view about free will, it is a bargained term, and a dispute about it goes to the labour court or to industrial arbitration rather than to the data protection authority. Know whether you are bound: the agreement reaches employers in an affiliated employers' association or otherwise covered, is disapplied where a specific collective agreement makes its own rules, and does not bind an unorganised Danish employer at all.

Two smaller points that change a design. Recording is workable but the architecture has to keep the recorder on the call: the criminal provision reaches secret recording of a conversation between others or of a meeting the recorder does not take part in, so a party is outside it, while a silent supervisor leg or a platform capturing a call it is not itself on is squarely inside, and the ceiling rises to six years in aggravating circumstances. And one myth is worth putting down before somebody budgets for it: every secondary summary says systematic employee monitoring is on the Danish regulator's mandatory impact assessment list. That list has eight entries and monitoring is not one of them.

What your company needs to do

6 items, in the order you will need them.

  • Work out first whether the collective agreement binds youDenmark-specificEverything else on this page turns on the answer. It reaches employers in an affiliated employers' association or otherwise covered, is disapplied where a specific collective agreement lays down its own rules on control measures, and does not bind an unorganised employer. Getting this wrong means preparing for a six-week clock that does not run, or missing one that does.
  • Decide which side of the six weeks you are on, and say whyDenmark-specificEither you announce the measure six weeks before it starts, which most awareness programmes cannot do without losing the exercise, or you take the escape because notice would defeat the purpose. Make that decision explicitly and record the reasoning at the time, because the reasoning is what the second duty asks you to produce later.
  • Draft the written account before you need itDenmark-specificIf you rely on the escape you must inform employees as soon as possible afterwards and explain in writing why six weeks could not be met. That is the Danish deliverable, it is owed after the campaign, and it is the one nobody diarises. Write it while the reasoning is fresh and issue it with the debrief rather than reconstructing it when somebody asks.
  • Do not build the programme on a signatureFor a covered employer the contractual clause and the acceptance screen are both unavailable, so a design that depends on either has to be rebuilt. Rely on the employment-law ground the act provides, which is the one the regulator itself points the collective machinery at, and use the notice regime to carry the transparency.
  • Keep whoever records on the callThe criminal provision is drawn around the eavesdropper rather than the participant, so the design question is architectural: a silent monitoring leg, or a platform capturing a conversation it is not itself party to, is inside the offence where a party recording is outside it. The regulator separately wants necessity, prior information and deletion at fixed short intervals.
  • Bring the works council in above thirty-five employeesThe cooperation agreement gives it a role in laying down principles for collecting and using personal data and in assessing the consequences of introducing new technology of substantial scope. That is involvement and information rather than consent, and no Danish instrument makes a control measure conditional on the council agreeing, but leaving it out is a visible omission.

The controls that do the work

How Callstrike is configured, and which provision in Denmark each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

The collective agreement's own standard is that a control measure must not be offensive to employees, must not cause them loss or appreciable inconvenience, and must keep a reasonable relationship between ends and means. That is a proportionality test written by the social partners rather than by a regulator, and it is judged in the labour court. The call ends the moment an employee starts to give up a credential, so the exercise measures whether somebody would have disclosed without ever holding what they were about to disclose, which is the cleanest version of that ratio you can put in front of an arbitrator.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The Danish escape from the six-week notice is bought with a duty to inform as soon as possible afterwards, so the back end of the exercise is where the compliance work actually lands here. A second voice that breaks character the instant the call ends, followed by vishing training in writing, is the earliest possible discharge of that duty rather than a nice touch: the employee is told what happened within seconds instead of within weeks.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

In Denmark this is the notice machinery and never the permission, because for a covered employer the individual cannot agree to a control measure at all. Use it for what the agreement does demand: a dated record of the notice, the timestamped account of why six weeks could not be met, and a hashed copy of the policy or collective agreement you rely on with a signed attestation of its scope.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

Where the six-week clock makes a telephone campaign awkward to schedule, this is the route that teaches on your own timetable. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner opens themselves after working through the module. A learner who chooses to start the call has been told in advance by definition, so the notice question that dominates the rest of this page does not arise in the same shape.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

A basis built on collective agreements, and a duty timed to the test

Denmark did use the employment derogation the GDPR offers, and it used it in a way that reflects how the Danish labour market works. The data protection act provides that processing personal data in connection with employment may take place where it is necessary to comply with the controller's or the data subject's employment-law obligations or rights as laid down in other legislation or collective agreements, and that it may also take place where necessary to pursue a legitimate interest arising from other legislation or collective agreements unless the data subject's interests or fundamental rights override it. The travaux say why in terms: the provision has its background in the Regulation's employment article, and it was introduced as a belt-and-braces measure to secure a solid basis for processing across the whole Danish labour market.

One citation note, because it is the commonest error. The operative reference is the consolidated act of March 2024, not the 2018 act it consolidates, and the consolidated text carries no later amendments at all.

The regulator then joins the statute to the industrial-relations machinery explicitly. It says that beyond the data protection rules the question of monitoring employees is regulated in agreements between the social partners, gives the control-measures agreement as its example, and states that processing employee data as part of a control measure under that agreement, or similar agreements, may take place under the act's employment provision. So in Denmark the collective agreement is not merely an obligation running alongside the legal basis. It is what the legal basis points at.

Consent is formally available and practically is not. The act permits processing in employment on the basis of the data subject's consent, and the regulator says consent in employment will rarely satisfy the validity condition of being freely given because of the unequal relationship that typically exists, while noting that it is not excluded. The consultation section below explains why for most Danish employers the question does not even get that far.

The information duty is timed rather than deferred, which matters for a test. The regulator says the employer must observe the transparency articles when control measures are implemented, meaning employees must be informed about the processing at the latest at the time the measure is implemented. It then supplies the carve-out a covert exercise depends on: depending on the circumstances the employer will not be obliged to notify the employee of a specific control measure if the information duty would probably render impossible, or seriously impair, the achievement of the purposes of the control. The act's own derogation provision is the hook for that.

One myth is worth putting down while we are here. Every secondary summary asserts that Danish law puts systematic employee monitoring on the regulator's mandatory impact assessment list. It does not. That list has eight entries and monitoring of employees is not among them. The nearest is a conditional entry covering processing that uses new technologies together with at least one further criterion from the European guidelines. State the condition; do not state the conclusion.

The offence is about listening in, not about taking part

The Danish criminal provision is drafted around the eavesdropper, and reading it closely gives a cleaner answer than most European texts.

It is an offence, punishable by a fine or up to six months, for a person without authorisation, by means of an apparatus, secretly to listen to or record statements made in private, telephone conversations or other conversation between others, or negotiations at a closed meeting in which that person does not himself participate or to which they have gained access without authorisation.

Two phrases carry the whole answer: between others, and in which that person does not himself participate. A simulated caller who is a party to the call is not listening in on a conversation between other people, and on the face of the text is outside the offence.

The exemption is for the participant, and that is narrower than it sounds in a modern deployment. A supervisor's silent monitoring leg, or a platform capturing a call that the capturing entity is not itself a party to, is squarely inside the provision. And the ceiling rises hard where the intent is to obtain a company's trade secrets or in other particularly aggravating circumstances: up to six years. Architecture that keeps the recorder on the call is not a nicety in Denmark, it is the difference between being outside an offence and inside one.

A separate provision reaches what happens to the audio afterwards. Passing on messages concerning another person's private affairs without authorisation is an offence, currently punishable by a fine or up to six months and rising to three years in particularly aggravating circumstances. A 2026 act raises that six-month figure to one year, but the item sits in a deferred commencement group and takes effect on 1 January 2027, so as this page is written the shorter figure is the live one. Anyone citing the higher number today is citing law that has not started.

Criminal law is not where the recording risk actually sits for an employer, though. The regulator's position is specific and it is the operational list. Recording telephone conversations cannot as a starting point be based on the employee's consent, because of the inequality between employer and employee, so the consent cannot be regarded as freely given. Recording may instead take place under the public-task ground for public employers or the legitimate interests ground for private ones. It presupposes that the recording is suitable and necessary for the purpose. Recorded conversations must be deleted at fixed short intervals unless there is a specific reason to keep one. And the employee must have been informed that conversations are recorded and told the purpose of the recording.

That last requirement and a covert exercise pull against each other, which is exactly why the derogation described in the previous section has to be assessed and written down before the campaign rather than argued afterwards.

The marketing act reaches products on a market, and stops there

The Danish rule on automated calling is inside the marketing act, and the act tells you its own boundary in its first section: it applies to private business activity, and to public activity to the extent that products are offered on the market. Its definition of a commercial practice is equally tied to promoting, selling or offering a product to consumers.

Inside that boundary, a trader may not contact anyone using electronic mail, an automated calling system or a fax for the purpose of direct marketing unless that person has given prior consent, and must tell them before consent is given that it can be withdrawn easily and free of charge. A second limb prohibits contacting a specific natural person by other means of distance communication for the purpose of direct marketing where they have objected to the trader, where the quarterly register compiled by the central person register shows they have opted out of direct marketing, or where the trader has learned of the opt-out by checking that register.

Every limb carries the same qualifier, for the purpose of direct marketing, and the register itself is described by the body that compiles it as covering unsolicited approaches for marketing purposes. An employer calling its own staff in an authorised exercise is not offering products on a market and is not marketing, so the automated calling limb does not reach it and there is no obligation to screen your own employees against the opt-out register.

One drafting note for anyone checking this. The scope formula quoted in most older commentary, about the sale of goods, real property and other assets and services, is the pre-2017 act. It does not appear in the current text at all, which uses the product and commercial practice definitions above.

The European transparency rule that applies here directly is Article 50 of the EU AI Act. Since 2 August 2026 a provider must ensure that systems intended to interact directly with people are designed so that those people are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed and observant person in the circumstances, and a deployer of a system generating or manipulating audio constituting a deep fake must disclose that the content was artificially generated or manipulated. The information must reach the person clearly and visibly at the latest at the time of the first interaction or exposure. Neither exception, for uses authorised by law to detect, prevent, investigate or prosecute criminal offences, nor the one for evidently artistic work, covers an employer authorising its own test.

There is a companion prohibition worth reading before adding voice analytics. Inferring emotions of a natural person in the workplace is prohibited outright, subject to a narrow medical or safety exception, and has been since 2 February 2025 at up to thirty-five million euros or seven per cent of worldwide turnover. It is gated by a definition tied to inference from biometric data, and the recitals leave the mere detection of readily apparent expressions or of a raised voice outside it. Logging who gave up a credential is untouched. Scoring how anxious a named person sounded is not.

Denmark's own implementing position is the surprise. The Danish act designates competent authorities and market surveillance authorities, but every market-surveillance designation in it is expressly tied to the prohibited-practices article. There is no designation for the transparency article. The bill that would have replaced that act with a full statute, and would have made breach of the transparency obligations punishable, is recorded as having lapsed: introduced in February 2026, first reading in March, and never taken further. So the transparency duty has been directly applicable in Denmark since August 2026 with no Danish market surveillance authority for it and no Danish penalty for breaching it. The duty binds regardless; the enforcement route is simply not built yet.

Numbers belong to providers, and the ban you expect is not there

We looked hard for a Danish prohibition on presenting a calling number you do not hold, and we are reporting that we could not find one rather than paraphrasing something that nearly says it.

Start with who holds numbers at all. The telecoms act provides that the national digital agency allocates numbers, number series, codes and addresses on request to anyone who commercially provides electronic communications networks or services. Numbers are allocated to providers, not to end users, so whether a particular number may be presented is governed by the terms of the provider that holds it rather than by the numbering rules.

The Danish caller identification rules then turn out to be about the opposite question. They require providers offering calling line identification to let the calling subscriber prevent transmission of the number free of charge, per call and per connection, and to let the called subscriber prevent display of an incoming number and reject incoming calls where the caller has blocked display. Blocking must be suspended for lawful interception and for calls to the emergency service. Those are withholding rules. None of them prohibits presenting a number you do not hold.

One trap for anyone verifying this. The regulator's own live page on numbering legislation still links the telecoms act at a consolidation that the official register renders as historical; the current consolidation is from June 2025, and the numbering administrator's name changed between the two. Following the regulator's own link gets you a superseded text with no banner on it.

What does bite is not telecoms law at all. Identity misuse is an offence: using information about another person, including their identity number, name or picture, to hold oneself out improperly as that person, or disseminating material using another person's information to manipulate improperly how that person appears. Both limbs turn on the words without authorisation and improperly, and an authorised, documented internal exercise with a clear remit is the argument against both. We found no Danish authority deciding the point either way.

Two consequences follow for campaign design. Impersonating a named real individual, their number, their name or their voice, engages that offence and should not be done without advice. Impersonating an organisation rather than a person falls outside it on the face of the text, because the provision speaks of another person.

And one practical point that decides deliverability rather than legality. Withholding the number is expressly lawful, but the same rules give the called subscriber the right to reject calls whose number is withheld, so a withheld-number campaign is not reliably deliverable. Denmark's response to spoofed calls is described by the regulator as operators blocking numbers, and its page on the subject cites no provision at all. We are not going to dress that up as a legal prohibition.

What the country matrix holds for Denmark

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Six weeks, two ways out, and an account written afterwards

This is the section that decides a Danish programme, and the instrument that governs it is an agreement between the employers' confederation and the trade union confederation rather than a statute.

Its first clause sets the standard: the employer may implement control measures under the managerial prerogative and in accordance with the collective agreements, but the measures must be objectively justified by operational reasons and have a sensible purpose, must not be offensive to employees, must not cause them loss or appreciable inconvenience, and must be arranged so that there is a reasonable relationship between ends and means.

Its second clause sets the timetable, and the timetable is the headline. The employer must inform employees of new control measures no later than six weeks before they are implemented. That does not apply where the purpose of the measure would thereby be defeated, or where compelling operational reasons prevent it. In that case the employer must inform employees as soon as possible and explain the reason why the six-week deadline could not be observed.

Read that second sentence as a deliverable rather than as relief. A covert simulation will usually engage the first escape, because announcing it six weeks out defeats its purpose entirely. But the escape is conditional on a duty that runs the other way in time: after the exercise you must notify promptly and produce a written account of why six weeks was impossible. Nothing in the data protection layer requires that document. It is the single most concrete thing a Danish employer has to produce, and it is produced afterwards.

The third clause is the one that surprises people. The individual employee cannot give consent to the implementation of control measures, neither on hiring nor at any later time. For a covered employer that removes both of the usual designs at once: the clause in the employment contract and the acceptance screen at rollout. The statute permits employee consent; the social partners have agreed it away.

Know who is bound, because the agreement is not universal. It is a protocol to the main agreement between the two confederations, so it reaches employers who are members of an affiliated employers' association or otherwise covered, and it is disapplied where the parties to a specific collective agreement have made their own rules on control measures. An unorganised Danish employer with no collective agreement is not bound by it, and at least one other bargaining area has its own separate control-measures agreement. The employee remedy is also distinctive: where employees consider the conditions were not met, the dispute goes down the industrial-relations route to the labour court or industrial arbitration, not to the data protection authority and not to the ordinary courts.

Above thirty-five employees a second body enters. The cooperation agreement gives the works council a role that must be involved in laying down principles for the undertaking's internal collection, storage and use of personal data, and in assessing the technical, economic, personnel, training and environmental consequences of introducing new or changed technology where the introduction is of substantial scope. Management must also keep the council informed of major changes in the use of new technology in production and administration. That is involvement and information. It is not consent, and no Danish instrument makes a control measure conditional on the council agreeing.

The statutory information and consultation act is the fallback and will often not apply at all. It reaches undertakings with at least thirty-five employees, and it expressly does not apply where a duty to inform and consult follows from a collective agreement containing rules at least equivalent to the European directive. Where it does apply, consultation on decisions likely to lead to substantial changes in work organisation and contractual relations takes place with a view to reaching an agreement, but the act adds in terms that carrying out the consultation does not affect the employer's prerogatives, and exempts the undertaking entirely in special cases where informing or consulting would seriously harm or affect its operations.

A currency warning if you go to that act yourself. The official register serves it as current, but there is no consolidated version, and the text it serves still displays a subsection that was repealed in 2017. The provisions quoted here survive only because we pulled the amending act and checked that it does not touch them.

Training in the statute, and social engineering only in a test plan

Denmark transposed the European network and information security directive by an act of May 2025 which entered into force on 1 July 2025, with the first registration information due by 1 October 2025. Its minimum measures for essential and important entities include basic cyber hygiene practices and cybersecurity training, and its governance provision requires members of the management body to take relevant courses on managing cybersecurity risk and to encourage similar courses being offered to the entity's other employees.

We searched the whole act for the Danish words for test, penetration test, exercise and awareness. Those two provisions are the only hits. The Danish transposition requires training and encouragement, and it does not mandate a simulated phishing or vishing exercise.

For financial entities the European digital operational resilience Regulation has applied directly since 17 January 2025, supervised here by the financial supervisory authority. Denmark took up the option to designate a single public authority for threat-led penetration testing: an act of May 2024 gave the minister power to make rules designating one, and an executive order of December 2024 designates the central bank. That order does more than name it. The bank designates the financial undertakings that must carry out such a test, plans each test with the designated undertaking, oversees its conduct and closes it.

The Danish implementation of the European threat-led testing framework is where social engineering finally appears in writing, and it appears as a documentation duty rather than as a requirement to do it. The specification in the red team test plan must include the tactics, techniques and procedures allowed and forbidden during active testing, including ethical boundaries for social engineering and how the privacy of the involved parties is safeguarded.

Put conservatively, which is how it should be put: the Danish threat-led testing regime assumes social engineering may be on the table and insists it be bounded and written down, while the network and information security act asks for training rather than testing. Neither is a legal mandate for a vishing simulation, and nothing on this page should be read as saying otherwise.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in DENMARK. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed at the programme level.

Tell me first whether the DA/FH aftale om kontrolforanstaltninger binds us, then verify or correct each proposition below against primary Danish sources:

1. Databeskyttelsesloven § 12 (LBK nr 289 af 08/03/2024, no later amendments) is the employment basis, and the regulator points it at control measures taken under the collective agreement.
2. ⚠ Clause 3 of the aftale removes the individual employee's consent entirely, on hiring or later, even though § 12, stk. 3 expressly permits it. Confirm scope: affiliated employers, disapplication where a specific overenskomst has its own rules, and the Arbejdsretten route.
3. Clause 2 requires six weeks' notice, excused where the purpose «vil forspildes», with a BACK-END duty to notify as soon as possible AND account for why six weeks failed. Draft the account for us.
4. ⚠ That is a DIFFERENT test from Datatilsynet's Art 13/14 derogation, which excuses information where it would «sandsynligvis gore det umuligt eller i alvorlig grad hindre» the purpose. Clearing one does not clear the other. Advise on both.
5. Straffeloven § 263 reaches recording of a conversation «mellem andre» or a meeting the recorder does not take part in, so a participant is outside it and a silent monitoring leg is inside it. § 264 d rises to one year only on 01-01-2027.
6. ⚠ Systematic employee monitoring is NOT on Datatilsynet's Art 35(4) list of eight; entry 4 is conditional. Confirm, and advise whether a DPIA is owed on the facts.
7. Markedsforingsloven §§ 1, 2 and 10 are gated on «direkte markedsforing» and on products offered on a market, so neither the automated-calling limb nor the Robinsonliste screening duty reaches an internal exercise.
8. There is NO Danish prohibition on presenting a number one does not hold; the constraint is § 264 e identitetsmisbrug, which speaks of «en anden person» and so reaches a named individual rather than an organisation.

Flag anything that has changed since September 2026. ⚠ LOV 303/2005 renders GAELDENDE with no lovbekendtgorelse and still displays § 2, stk. 3, repealed by LOV 385/2017: check any provision of it you rely on against the amending act.

Common questions

How much notice do Danish employees need?
Six weeks before a new control measure starts, under the collective agreement between the social partners. If notice would defeat the purpose, or compelling operational reasons prevent it, you notify as soon as possible instead and must explain in writing why the six-week deadline could not be met.
Is employee consent an available route in Denmark?
For a covered employer, no. The control-measures agreement says the individual employee cannot consent to a control measure, on hiring or later, and the regulator says consent will rarely be freely given and cannot as a starting point support recording calls. Use the employment-law basis and the notice regime instead.
May we record the simulation call?
A party to the call is outside the criminal provision, which reaches secret recording of conversations between others. A silent monitoring leg by someone who is not on the call is inside it. The regulator separately requires necessity, prior information, and deletion at fixed short intervals.
Does Denmark ban presenting a number we do not hold?
We could find no such provision. The telecoms rules govern withholding a number, not presenting an unheld one, and the regulator's own anti-spoofing page cites nothing. The real constraint is the identity misuse offence, which reaches impersonating a named person rather than an organisation.

Elsewhere in Northern Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.