Callstrike
Compliance

Voice phishing simulations in Estonia

Phone numbers in EstoniaProvisioned by Callstrike after approval

Estonia is permissive about the call and specific about the pretext, so a voice phishing simulation runs here on comfortable ground and Callstrike supplies the number. The decision that belongs at the start is whose identity your scenario borrows: the sharpest Estonian exposure is a criminal offence about assuming a real person's identity, and the mitigation for it costs one email.

Phone numbers

Supplied by Callstrike

Local numbers in Estonia, after a one-time approval.

Running a simulation

Permitted, and lightly regulated

No national employment rules at all, so the Regulation's own balancing test governs.

Consent

Avoid it as the ground, collect it for the persona

The regulator recommends avoiding it in employment; a borrowed identity is different.

Getting a phone number in Estonia

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Estonian numbers are not released from open inventory, so your workspace is cleared for Estonia once and Callstrike then provisions a dedicated number against that clearance. The carrier's ask is the lightest in this batch, a single piece of evidence identifying the business from the commercial register, which for a company that already trades here is a document somebody can produce the same afternoon.

What number a call may present is decided by a rule addressed to the operator rather than to you, and it is short and exhaustive. A communications undertaking may, at the end user's request, replace the caller's number display only with another domestic number that the same undertaking gave that same end user under a services contract. Every qualifier in that sentence does work, and anything outside it has no basis a compliant Estonian operator can rely on. There is no express prohibition addressed to the calling party and we are not going to read one in, and Estonia has no standing inbound blocking regime either: the measure that would create one exists as a ministry draft and appears in no version of the act through November 2026.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Estonia is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Business nameExtract from the commercial register

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Estonia?

The position in short, before your counsel reads the detail below.

Yes, and Estonia is one of the lighter regimes in this portal because it declined to legislate in this area. Its data protection act has no employment chapter at all, so you are on the Regulation itself and in practice on the balancing ground. The regulator is unusually direct about the alternative: situations where employee agreement works are rare in practice, which is why it recommends avoiding it as a basis in employment relations, and it describes monitoring devices as the most intense interference with private life compared with other ways of collecting personal data, so you are expected to choose the least harmful measure available.

It also settles a question other regulators leave open, and it is worth planning to. Informing means both advance notice of the specific action and general notice to the employee. A published policy does not substitute for telling people about a particular measure, and telling them about a particular measure does not remove the need for the policy, so a covert exercise has to be justified against both halves rather than one. On the assessment the regulator is procedural rather than encouraging: processing on the balancing ground is lawful only once the analysis has been properly carried out and documented in writing before the processing begins. Written, and before. That is the Estonian deliverable and its timing is the part that gets missed.

Now the decision this page exists for. It is an offence in Estonia to use personal data that establish or may enable establishing the identity of another person, without that person's agreement, with the aim of knowingly causing a misconception of that person by assuming their identity, where damage is thereby caused to another person's legally protected rights or interests. The penalty is a fine or up to three years and a legal person is liable too. Read it against the standard pretext: a caller who says this is the finance director, using the finance director's name, is using data that identify a real person, without their agreement, to create a knowingly false impression by assuming their identity. Whether damage results is the element in issue, and it is not obviously absent when somebody's name is used to extract credentials from their colleagues. No published Estonian guidance connects this provision to security testing at all, which is why almost nobody is managing it.

The two provisions people reach for instead are both narrower than their names. The surveillance offence was narrowed by the supreme court in April 2026, which requires the manner and circumstances to permit a finding of the intensity of data processing characteristic of surveillance activity, on facts involving a hidden bedroom camera and covert access to an email account; a recording made by a party to a call and disclosed in policy is a poor fit. The message confidentiality offence runs to the correspondents and against outsiders, which is not the position of a party to the call. And the marketing rule excludes you twice over, being gated to direct marketing and then saying in terms that it does not apply to multi-party voice calls in real time, so Estonia has no standalone prohibition on automated calling systems anywhere in its communications act.

What your company needs to do

7 items, in the order you will need them.

  • Decide whose identity the pretext borrows, before anything elseEstonia-specificThis is the Estonian decision and it is a scenario-design question rather than a paperwork one. Impersonating a fictional employee, or an organisation rather than a person, avoids the identity offence by construction. If your scenario needs a real name to be realistic, that choice has a criminal provision attached and it should be made deliberately.
  • Collect written agreement from any real person the pretext namesEstonia-specificThe offence is drafted around using identifying data without that person's agreement, so obtaining and filing it takes the case outside the words entirely. This is the cheapest mitigation in the whole portal and almost nobody records it. Get it from every executive whose name, title or voice a scenario borrows, and keep it with the campaign file.
  • Write the interest analysis before the processing startsEstonia-specificThe regulator's position is that processing on the balancing ground is lawful only once the analysis has been properly carried out and documented in writing beforehand. An assessment written after the first campaign is not late paperwork in Estonia, it is a defect in the basis, and the date on the document is what shows which one you have.
  • Give both kinds of notice, not oneThe regulator says informing means advance notice of the specific action and general notice to the employee, and it is explicit that neither substitutes for the other. Publish the policy and separately justify what you are doing about the specific measure, because a covert exercise has to answer both halves rather than point at the one it satisfies.
  • Consult on the training, whatever your headcountThe trustee regime starts at thirty employees, but the occupational health and safety act has no threshold and requires you to consult employees or their representative on the organisation of instruction and training and on the selection of new technology, consulting employees directly below ten. Security awareness training is the organisation of instruction and training on any reading.
  • Put the exercise into the written risk assessmentEstonia-specificPsychosocial hazards there are defined to include factors connected with management, work organisation and the working environment that may affect mental health, including by causing work-related stress. The assessment is written, lodged or sent to the inspectorate, notified to staff and retained for fifty-five years where it is not in the database. Fifty-five years is a reason to think about how a distressing pretext is characterised before it runs.
  • Expect the trustee to be heard, not to decideThe parties must seek agreement, but if you do not take the proposals into consideration you give the reasons in writing at the earliest opportunity and proceed. The enforcement is real even though the veto is not: failing to inform or consult carries up to thirty-two thousand euros for a legal person, with the labour inspectorate as the out-of-court authority.

The controls that do the work

How Callstrike is configured, and which provision in Estonia each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

The identity offence turns on damage being caused to the legally protected rights or interests of another person, and the regulator separately expects the least harmful measure available to be the one you chose. The call ends the instant an employee starts to give up a credential, so no credential is ever acquired through the borrowed identity and the exercise produces a susceptibility measurement rather than a set of working credentials obtained in somebody else's name. That is the fact that makes the damage element hard to establish, and it is the same fact the written interest analysis rests on.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

Estonia's occupational safety act makes work-related stress a psychosocial hazard you assess and record, and the assessment is retained for fifty-five years where it is not held in the state database, so how the exercise lands on a person is a durable document rather than a passing question. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is what keeps the entry in that assessment short.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Two different jobs here and Estonia is the country that separates them most clearly. For the workforce this is evidence rather than permission: the dated record of the general notice and of the specific measure the regulator says are both required, or a hashed copy of the policy you already rely on with a signed scope attestation. For any real person whose identity a scenario borrows it is the opposite, because their agreement is an element of the offence, so file that one individually and keep it.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

Estonia's telephony position is already comfortable, so this is the route for the part of the workforce you would rather not cold-call at all. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner opens themselves after working through the module, which also lets the scenario drop the borrowed identity that carries the Estonian criminal question, since a learner who started the call is not being deceived about who it is from.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

No national employment rules, and a regulator that says avoid consent

Estonia did not legislate under the GDPR's employment provision. Its data protection act contains no employment-data chapter at all, so an employer running a security test is on the Regulation itself, and in practice on the legitimate interests ground.

The regulator's advice is unusually direct. Situations where employee consent works are rare in practice, it says, which is why it recommends avoiding consent as a legal basis in employment relations. On monitoring it is blunter still: the use of monitoring devices is the most intense interference with private life compared with other ways of collecting personal data, so the employer must choose the measures least harmful to the employee.

It then says something worth quoting because it settles a question other regulators leave open. Informing, it says, means both advance notice of the specific action and general notice to the employee. A published policy is not a substitute for telling people about a particular measure, and telling them about a particular measure does not remove the need for the policy. A covert exercise has to be justified against both halves.

On the assessment itself the regulator is procedural rather than hortatory: processing on the legitimate interests basis is lawful only once a legitimate interest analysis has been properly carried out and documented in writing before the processing begins. Written, and before. That is the Estonian deliverable.

Two warnings for anyone verifying this. The guidance document everyone cites, an eighty-six page file on personal data in employment relations, has been withdrawn: the regulator's own page says the employment guide is being updated. The withdrawn file is pre-GDPR, adopted in 2011 under a provision of a repealed act, and it is still served with no banner on the file itself. The live authority is a web page, last updated in June 2026.

And there is no Estonian regulator treatment of simulated phishing or vishing. The one item that comes close is the authority's write-up of its own podcast, whose guest was a vendor co-founder, endorsing phishing tests as good practice on the footing that the aim of testing is learning rather than punishment. It contains no analysis of legal basis, notification, consultation or impact assessment. It is promotional and we are not going to cite it as regulator guidance, which is what a page in a hurry would do.

Assuming a named person's identity is the offence to worry about

Estonia's recording provisions are narrower than their titles suggest, and the provision that actually fits a vishing call is one that no published Estonian material connects to security testing at all.

Start with the two people reach for. Observation of another person in order to collect information about them, by a person without the lawful right to engage in surveillance, carries a fine or up to three years. The supreme court's criminal chamber narrowed it in April 2026: the manner and circumstances must permit a finding of significant violation of the victim's rights, so that one can speak of the intensity of personal data processing characteristic of surveillance activity. The facts there were a hidden bedroom camera together with covert access to the victim's email account, and the court treated covertness as an element. A recording made by a party to a call, disclosed in policy, is a poor fit for that test.

The second is the confidentiality of a message communicated by letter or other means of communication, punishable by a pecuniary punishment and by up to a year where the offender had access through official duties. The constitutional root gives the game away on scope: everyone has the right to confidentiality of messages sent by him or to him. The right runs to the correspondents and against outsiders, which is not the position of a party to the call.

Now the one that matters. It is an offence to transmit, grant access to or use personal data that establish or may enable establishing the identity of another person, without that person's consent, with the aim of knowingly causing a misconception of that person by assuming that person's identity, where damage is thereby caused to another person's legally protected rights or interests. The penalty is a fine or up to three years, and a legal person is liable to a pecuniary punishment.

Read that against the standard pretext. A caller who says this is the finance director, using the finance director's name, is using personal data that identify a real person, without their consent, to create a knowingly false impression by assuming their identity. Whether damage results to that person's protected interests is the element in issue, and it is not obviously absent when someone's name is used to extract credentials from their colleagues.

The mitigation is cheap and almost nobody does it: obtain and file the written consent of every real person whose identity a pretext assumes. That takes the case outside the words without that person's consent entirely. Impersonating a fictional employee, or an organisation rather than a named individual, avoids the question by construction.

One more provision is often cited in the wrong direction. Communications confidentiality under the electronic communications act binds a communications undertaking, not a party to a call. Nothing in that act imposes a recording duty or prohibition on a caller.

The regulator's position on recording is worth knowing even though it is not a prohibition. It treats a voice on a recording as personal data, observing that a person can be identified from their voice much as from a fingerprint, and it takes the view that a quality assurance purpose can be achieved without recording calls at all. That is a hard sentence to argue with when your purpose is measuring who disclosed something rather than reviewing how they said it.

A marketing gate that then excludes live voice altogether

Estonia is one of the cleanest answers in this portal, and it is clean twice over.

The consent rule provides that the use of the electronic contact details of a subscriber or user who is a natural person for direct marketing is allowed only with that person's prior consent. The section is headed by the phrase for direct marketing, the act's own scope provision repeats it, and an authorised internal security test pursues no marketing purpose. That is the first exclusion.

The second is more unusual. The same section provides in terms that its provisions do not apply to multi-party voice calls in real time. So Estonia's opt-in rule is aimed at automated marketing contact, and live calling is outside it by construction, which is the mirror image of the intuition that automation is the regulated thing.

We built the negative positively rather than inferring it. A full-text search of the current Estonian act for the terms for without human intervention, automatic dialling and calling system returns nothing at all. Estonia transposed the European rule through a marketing-purpose gate only and has no standalone automatic calling machine prohibition. The advertising act does not help either: it defines advertising by reference to increasing the provision of a service or the sale of goods, promoting an event, or directing a person's behaviour in the public interest, and a security test meets none of those purposes.

Two currency traps sit on the route to this answer and both are the sort that read as clean passes. The official English translation of the electronic communications act is the version of a two-day window in July 2026 and is marked as no longer in force, while the Estonian version in force is from August. And the English act view offers on-demand machine translation from the same interface as the official translations, so a citable text and an uncitable one are one click apart and look alike. We read the Estonian and compared the amendment markers section by section.

Article 50 of the EU AI Act supplies the transparency duty, and it applies here directly. Since 2 August 2026 a provider must ensure a system intended to interact directly with people is designed so those people are informed they are dealing with an AI system, and a deployer of a system generating or manipulating audio constituting a deep fake must disclose that the content is artificially generated, in each case at the latest at the first interaction or exposure. The definition of a deep fake covers AI-generated or manipulated audio resembling existing persons that would falsely appear authentic. An employer's own authorisation is not authorisation by law, and the carve-out is confined to criminal offences, so there is no security-testing exception.

The companion prohibition is worth a line before anyone adds voice analytics. Inferring emotions of a natural person in the workplace has been prohibited since 2 February 2025, at up to thirty-five million euros or seven per cent of worldwide turnover, outside a narrow medical or safety exception, and the definition that gates it is confined to inference from biometric data with readily apparent expressions and a raised voice excluded by the recitals. Recording outcomes is fine. Scoring how a named employee sounded is not the same activity.

Estonia has not designated an authority for any of this. Its intended regulator's own page, last updated on 3 August 2026, says in the future tense that it will in future fulfil the role of competent authority for AI systems and will in future monitor compliance with the transparency requirements. That page was updated the day after the transparency article started applying. The obligation is live; the supervisor is not.

One operator may swap one of its own numbers for another

The Estonian rule on what number a call may present is short, exhaustive, and addressed to the operator rather than to you.

A communications undertaking may, at the end user's request, change the caller's number display, replacing it with another domestic number display given to that same end user by that same undertaking under a communications services contract. Read the qualifiers: same undertaking, same end user, contract, domestic. Anything outside that sentence is outside the permission, and a compliant Estonian operator has no basis for doing it. Crisis helplines, harmonised social-value short numbers and the emergency number are excluded from the substitution entirely.

Underneath sits the ordinary allocation machinery. Numbers are held by communications undertakings under a numbering licence, reservation gives the licence holder the right to use a specific number, and using numbering without a licence or reservation is an offence carrying up to three thousand two hundred euros for a legal person, with a matching penalty for breaching the conditions of use. The licence itself is applied for electronically, lasts a year, and is not issued to private individuals.

So the direct answer to whether a caller may present a number it holds no right to use is: constructively no through the operator, because the substitution permission is exhaustive, but there is no express prohibition addressed to the calling party and we are not going to read one in.

What Estonia does not have is a standing blocking regime, and this is worth saying because several of its neighbours do. We searched the act in force and both already published future versions for the terms for blocking, filtering, falsification, number display, fraud and inbound, and found no duty of that kind. The nearest live provision is a case-by-case power for the regulator to require an undertaking to restrict a customer's access to a service, or the ability to dial a number, where justified by fraud or misuse. A mandatory operator-blocking measure exists as a ministry draft only, and as this page is written it appears in no version of the act through November 2026. It is not law and we will not describe it as one.

The remaining caller identity rules are the European ones about withholding: a caller may prevent presentation of their number and a called party may reject calls whose number is withheld. There is no accuracy duty attached to them.

One machine-to-machine detail catches people building automated dialling: the ranges reserved for machine communications may not be used to carry two-way voice.

What the country matrix holds for Estonia

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

The statute expects you to proceed, and to write down why

Estonia is one of the few countries in this portal where the consultation statute openly contemplates the employer going ahead over objection, and saying so precisely is more useful than implying a veto that does not exist.

The employee trustee regime applies to an employer with at least thirty employees. When consulting, the employer must explain the planned activity and its consequences for employees, and the parties must seek to reach an agreement. If the employer does not take the proposals into consideration, it must give the reasons at the earliest opportunity in writing or in a form reproducible in writing. That is the whole consequence. And the trustee's access to a labour dispute body is confined by the statute to disputes arising from the confidentiality of information obtained or a refusal to provide information, never from the substance of the decision.

The enforcement is real even though the veto is not: failing to inform or consult is an offence carrying up to thirty-two thousand euros for a legal person, and the labour inspectorate is the out-of-court authority. The subject matter the statute lists is structure and staffing, decisions likely to bring about substantial changes in work organisation, and decisions likely to substantially change employment contract relationships. Monitoring, testing and security measures are not named, and whether a simulation is a substantial change in work organisation is not resolvable from the text.

The consultation duty that actually bites for a smaller Estonian employer is somewhere almost nobody looks. The occupational health and safety act requires the employer to consult employees or their representative on questions concerning the planning of measures to improve the working environment, the organisation of instruction and training, and the selection and application of new technology and work equipment, and to take submitted proposals into account where possible. There is no headcount threshold, and below ten employees the employer consults employees directly. Security awareness training is the organisation of instruction and training on any reading.

The same act supplies the documentation Estonia genuinely demands, and it is a longer commitment than anything in the data protection layer. Psychosocial hazards are defined to include factors connected with management, work organisation and the working environment that may affect an employee's mental or physical health, including by causing work-related stress. The risk assessment must be in writing, lodged in the working environment database or sent to the labour inspectorate, updated when working conditions change significantly, notified to employees and to their representatives, and retained for fifty-five years where it is not held in the database.

Fifty-five years is not a typographical error, and it is the reason to think about how a simulation is characterised before it runs rather than after somebody complains about a distressing pretext.

Collective agreements add nothing mandatory here. The statute defines one as a voluntary agreement regulating employment relationships, and there is no statutory subject a simulation must be bargained into.

Boards get trained, staff get awareness, nobody gets tested

The Estonian cybersecurity stack is a clean negative at every level, and we checked all three of them rather than the top one.

The cybersecurity act, as amended with effect from 1 January 2026, requires a service provider to implement appropriate and proportionate technical, operational and organisational security measures on a permanent basis, including by preparing a risk assessment, and delegates the measure catalogue to a government regulation. Its only training duty binds the board: a member of the management body must regularly undergo training in order to acquire sufficient knowledge and skills to understand and assess risks. We counted the act through for the Estonian terms for security testing, testing, exercise, phishing, social manipulation and simulation. Every one of them returns zero. Training returns one and awareness returns two.

One level down, the government regulation lists nine measure areas, of which the second is user awareness, training and user rights. The same term counts hold: nothing about testing, simulation or phishing.

Two levels down is where a currency trap sits, and it is fresh. The Estonian information security standard that everyone cites was repealed with effect from 1 September 2026 and replaced by a new standard made in August 2026. Any Estonian analysis written even a month before this page is citing a repealed instrument. The new standard's personnel training provision requires the organisation to arrange continuous training in order to improve and raise security awareness, to prevent risk behaviour, and to increase awareness of preventing, detecting and responding to cyber incidents. It too names no test.

For financial entities the European digital operational resilience Regulation applies directly. It requires information and communications technology security awareness programmes and resilience training as compulsory modules in staff training schemes for all employees and senior management; it requires appropriate tests on all systems supporting critical or important functions at least yearly, conducted by independent parties whether internal or external; and it requires threat-led penetration testing at least every three years, on live production systems, for the entities identified for it.

The term counts across that Regulation are worth having because they close the argument. Social engineering appears zero times, phishing zero times and voice phishing zero times, in the articles and in the recitals alike; penetration test appears nine times and awareness twelve. Where European financial law requires scenario-based or threat-led testing, it names test types and not social engineering techniques. Nothing in the Estonian stack or above it mandates a vishing simulation.

One honest gap. The new standard has two annexes, a management-system requirements document and a baseline control catalogue, which we did not read. If a control requiring simulated phishing exists anywhere in the Estonian regime, that catalogue is the only place left it could be.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in ESTONIA. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance.

Answer the identity question first, then verify or correct each proposition below against primary Estonian sources:

1. ⚠ KarS § 157² punishes using personal data identifying another person, WITHOUT THAT PERSON'S CONSENT, to knowingly create a misconception by assuming their identity where damage results, at up to three years with legal-person liability. Assess a pretext naming a real executive, and confirm that that person's written consent removes the element.
2. ⚠ KarS § 137 was narrowed by Riigikohus 1-24-4898/33 (27.04.2026) to require covertness plus 'jalitustegevusele iseloomulik isikuandmete tootlemise intensiivsus'. KarS § 156 runs to correspondents against outsiders, not to a party.
3. IKS has NO employment chapter, so the basis is GDPR Art 6(1)(f), and AKI's position is that the LIA must be carried out and documented IN WRITING BEFORE the processing begins, with informing meaning BOTH advance notice of the specific action AND general notice.
4. ESS § 103¹ is gated to direct marketing AND excludes real-time multi-party voice calls in terms; the act contains no automatic-dialling provision. Reklaamiseadus § 2 does not reach a security test either.
5. Numeratsiooniplaan § 8(5) permits display substitution only with another domestic number given to the same end user by the same undertaking under contract, and Estonia has NO standing inbound blocking duty, only a ministry draft.
6. TUIS applies at 30 employees, requires written reasons where proposals are not taken into account, and confines the trustee's dispute route to confidentiality or refusal to inform. TTOS § 13⁴ consultation has NO threshold.
7. TTOS treats work-related stress as a psychosocial hazard, and the written risk assessment is retained 55 years where not held in the tookeskkonna andmekogu.
8. Kuberturvalisuse seadus and maarus nr 30 of 25.08.2026 (which REPLACED the repealed Eesti infoturbestandard on 01.09.2026) require training and awareness and name no test. Check the new standard's two annexes, which we did not read.

Flag anything that has changed since September 2026. ⚠ On riigiteataja the official English ESS is a two-day July 2026 window marked KEHTINUD while the Estonian in force is later, and on-demand machine translation is offered from the same interface as the official ones: cite the Estonian redaktsioon.

Common questions

What is the biggest criminal risk in an Estonian campaign?
Assuming a real person's identity. It is an offence to use data identifying another person, without their consent, to knowingly create a false impression by assuming their identity where damage results, carrying up to three years. Collect written consent from anyone whose name a pretext borrows.
Does Estonia's opt-in rule cover our calls?
Twice not. The rule is gated to direct marketing, which an internal security test is not, and the same section says in terms that it does not apply to real-time multi-party voice calls. Estonia has no standalone prohibition on automated calling systems anywhere in its communications act.
Can the employee trustee stop the campaign?
No, and the statute says so by implication. The parties must seek agreement, but if the employer does not take the proposals into account it simply gives written reasons and proceeds. The trustee can go to a dispute body over confidentiality or a refusal to inform, never over the decision itself.
May our platform present an Estonian number we do not hold?
Not through a compliant operator. It may substitute the display only with another domestic number that the same undertaking gave the same end user under a service contract. There is no express prohibition on the caller, and Estonia has no standing inbound blocking regime, only a draft.

Elsewhere in Northern Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.