Voice phishing simulations in Estonia
Estonia is permissive about the call and specific about the pretext, so a voice phishing simulation runs here on comfortable ground and Callstrike supplies the number. The decision that belongs at the start is whose identity your scenario borrows: the sharpest Estonian exposure is a criminal offence about assuming a real person's identity, and the mitigation for it costs one email.
Phone numbers
Supplied by Callstrike
Local numbers in Estonia, after a one-time approval.
Running a simulation
Permitted, and lightly regulated
No national employment rules at all, so the Regulation's own balancing test governs.
Consent
Avoid it as the ground, collect it for the persona
The regulator recommends avoiding it in employment; a borrowed identity is different.
Getting a phone number in Estonia
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Estonian numbers are not released from open inventory, so your workspace is cleared for Estonia once and Callstrike then provisions a dedicated number against that clearance. The carrier's ask is the lightest in this batch, a single piece of evidence identifying the business from the commercial register, which for a company that already trades here is a document somebody can produce the same afternoon.
What number a call may present is decided by a rule addressed to the operator rather than to you, and it is short and exhaustive. A communications undertaking may, at the end user's request, replace the caller's number display only with another domestic number that the same undertaking gave that same end user under a services contract. Every qualifier in that sentence does work, and anything outside it has no basis a compliant Estonian operator can rely on. There is no express prohibition addressed to the calling party and we are not going to read one in, and Estonia has no standing inbound blocking regime either: the measure that would create one exists as a ministry draft and appears in no version of the act through November 2026.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Estonia is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Business name | Extract from the commercial register |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in Estonia?
The position in short, before your counsel reads the detail below.
Yes, and Estonia is one of the lighter regimes in this portal because it declined to legislate in this area. Its data protection act has no employment chapter at all, so you are on the Regulation itself and in practice on the balancing ground. The regulator is unusually direct about the alternative: situations where employee agreement works are rare in practice, which is why it recommends avoiding it as a basis in employment relations, and it describes monitoring devices as the most intense interference with private life compared with other ways of collecting personal data, so you are expected to choose the least harmful measure available.
It also settles a question other regulators leave open, and it is worth planning to. Informing means both advance notice of the specific action and general notice to the employee. A published policy does not substitute for telling people about a particular measure, and telling them about a particular measure does not remove the need for the policy, so a covert exercise has to be justified against both halves rather than one. On the assessment the regulator is procedural rather than encouraging: processing on the balancing ground is lawful only once the analysis has been properly carried out and documented in writing before the processing begins. Written, and before. That is the Estonian deliverable and its timing is the part that gets missed.
Now the decision this page exists for. It is an offence in Estonia to use personal data that establish or may enable establishing the identity of another person, without that person's agreement, with the aim of knowingly causing a misconception of that person by assuming their identity, where damage is thereby caused to another person's legally protected rights or interests. The penalty is a fine or up to three years and a legal person is liable too. Read it against the standard pretext: a caller who says this is the finance director, using the finance director's name, is using data that identify a real person, without their agreement, to create a knowingly false impression by assuming their identity. Whether damage results is the element in issue, and it is not obviously absent when somebody's name is used to extract credentials from their colleagues. No published Estonian guidance connects this provision to security testing at all, which is why almost nobody is managing it.
The two provisions people reach for instead are both narrower than their names. The surveillance offence was narrowed by the supreme court in April 2026, which requires the manner and circumstances to permit a finding of the intensity of data processing characteristic of surveillance activity, on facts involving a hidden bedroom camera and covert access to an email account; a recording made by a party to a call and disclosed in policy is a poor fit. The message confidentiality offence runs to the correspondents and against outsiders, which is not the position of a party to the call. And the marketing rule excludes you twice over, being gated to direct marketing and then saying in terms that it does not apply to multi-party voice calls in real time, so Estonia has no standalone prohibition on automated calling systems anywhere in its communications act.
What your company needs to do
7 items, in the order you will need them.
- Decide whose identity the pretext borrows, before anything elseEstonia-specificThis is the Estonian decision and it is a scenario-design question rather than a paperwork one. Impersonating a fictional employee, or an organisation rather than a person, avoids the identity offence by construction. If your scenario needs a real name to be realistic, that choice has a criminal provision attached and it should be made deliberately.
- Collect written agreement from any real person the pretext namesEstonia-specificThe offence is drafted around using identifying data without that person's agreement, so obtaining and filing it takes the case outside the words entirely. This is the cheapest mitigation in the whole portal and almost nobody records it. Get it from every executive whose name, title or voice a scenario borrows, and keep it with the campaign file.
- Write the interest analysis before the processing startsEstonia-specificThe regulator's position is that processing on the balancing ground is lawful only once the analysis has been properly carried out and documented in writing beforehand. An assessment written after the first campaign is not late paperwork in Estonia, it is a defect in the basis, and the date on the document is what shows which one you have.
- Give both kinds of notice, not oneThe regulator says informing means advance notice of the specific action and general notice to the employee, and it is explicit that neither substitutes for the other. Publish the policy and separately justify what you are doing about the specific measure, because a covert exercise has to answer both halves rather than point at the one it satisfies.
- Consult on the training, whatever your headcountThe trustee regime starts at thirty employees, but the occupational health and safety act has no threshold and requires you to consult employees or their representative on the organisation of instruction and training and on the selection of new technology, consulting employees directly below ten. Security awareness training is the organisation of instruction and training on any reading.
- Put the exercise into the written risk assessmentEstonia-specificPsychosocial hazards there are defined to include factors connected with management, work organisation and the working environment that may affect mental health, including by causing work-related stress. The assessment is written, lodged or sent to the inspectorate, notified to staff and retained for fifty-five years where it is not in the database. Fifty-five years is a reason to think about how a distressing pretext is characterised before it runs.
- Expect the trustee to be heard, not to decideThe parties must seek agreement, but if you do not take the proposals into consideration you give the reasons in writing at the earliest opportunity and proceed. The enforcement is real even though the veto is not: failing to inform or consult carries up to thirty-two thousand euros for a legal person, with the labour inspectorate as the out-of-court authority.
The controls that do the work
How Callstrike is configured, and which provision in Estonia each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
The identity offence turns on damage being caused to the legally protected rights or interests of another person, and the regulator separately expects the least harmful measure available to be the one you chose. The call ends the instant an employee starts to give up a credential, so no credential is ever acquired through the borrowed identity and the exercise produces a susceptibility measurement rather than a set of working credentials obtained in somebody else's name. That is the fact that makes the damage element hard to establish, and it is the same fact the written interest analysis rests on.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
Estonia's occupational safety act makes work-related stress a psychosocial hazard you assess and record, and the assessment is retained for fifty-five years where it is not held in the state database, so how the exercise lands on a person is a durable document rather than a passing question. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is what keeps the entry in that assessment short.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Two different jobs here and Estonia is the country that separates them most clearly. For the workforce this is evidence rather than permission: the dated record of the general notice and of the specific measure the regulator says are both required, or a hashed copy of the policy you already rely on with a signed scope attestation. For any real person whose identity a scenario borrows it is the opposite, because their agreement is an element of the offence, so file that one individually and keep it.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Estonia's telephony position is already comfortable, so this is the route for the part of the workforce you would rather not cold-call at all. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner opens themselves after working through the module, which also lets the scenario drop the borrowed identity that carries the Estonian criminal question, since a learner who started the call is not being deceived about who it is from.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.