Voice phishing simulations in Finland
Finland allows a voice phishing simulation against your own staff and Callstrike supplies the number with nothing for you to gather, but it is the only country in this region where getting the paperwork wrong is a criminal offence rather than an accountability failure. Two documents decide a Finnish programme, and neither of them is the one most companies write first.
Phone numbers
Supplied by Callstrike
Local numbers in Finland, after a one-time approval.
Running a simulation
Permitted, on two documents
A co-operation dialogue first, then a written definition and a notice to staff.
Consent
Unavailable for scope, required for sourcing
The statute removes the option outright, and not for the usual power-imbalance reason.
Getting a phone number in Finland
One approval per country, with no documentation to gather.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days.
Finland is the short one. The carrier publishes no documentation requirement for the number type we supply here, so the evidence-gathering that dominates most of this portal has no Finnish counterpart at all: there is nothing to assemble and nothing for a regulator to read. What you are waiting on is the country being enabled against your workspace, after which Callstrike provisions a dedicated Finnish number for your campaigns. Plan for the days, not the file.
Where Finland does get demanding is the wire, and the constraint lands on your operator rather than on your policy folder. The communications agency's interoperability regulation, in force since May 2026 and replacing its 2023 predecessor, puts the geographic area of use of a Finnish number at Finland and prohibits using one abroad as a calling number; requires the originating operator to ensure the calling party number it transmits is correct and unambiguous; requires that operator, where it presents a number not under its own control, to verify the subscriber's unambiguous right to use it; and requires blocking of calls arriving from the international interface with a Finnish number outside genuine roaming. If you are working from the 2023 text, you are working from repealed rules.
- 01Ask for the country to be enabled for your workspaceYour administrator, in the Callstrike console.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Finland is assigned to youCallstrike
- 04Build and launch the campaignYour team
No regulatory documentation is required to hold a number here. The clearance step is Callstrike enabling the country for your workspace, with no forms to complete and no evidence to gather.
Is it lawful to run a simulation in Finland?
The position in short, before your counsel reads the detail below.
Yes, but Finland runs a working-life privacy statute that the rest of Europe does not have, and it is stricter than the European default in a way that changes the design rather than the answer. You may process only personal data directly necessary for the employment relationship, connected with managing the parties' rights and obligations or with benefits you provide, or arising from the special nature of the work. Then comes the sentence with no counterpart elsewhere in this portal: that necessity requirement cannot be derogated from with the employee's agreement.
Read that as a different point from the one made on every other page here. Elsewhere the argument against relying on an employee's agreement is that a power imbalance makes it unfree. In Finland the statute simply takes the option away, so even a genuinely free and enthusiastic agreement cannot widen what you may collect. There is an unusual pairing to hold in mind alongside it, because Finnish law demands agreement in one place while voiding it in another: you must collect employee data primarily from the employee, and where you collect from another source the employee's agreement is required, with narrow statutory exceptions. Agreement is required for provenance and unavailable for scope. Getting that pairing right is the distinctively Finnish part of the analysis.
The expensive obligation is not the famous one, and this is the point to take away. The necessity rule carries no criminal sanction; it is enforced administratively. What is criminalised, by fine, is failing to define the purpose and the methods of technical monitoring and to inform employees of them. So the deliverable is a written document and a communication, and skipping either is an offence rather than a shortfall in your accountability file. Two smaller duties sit in the same list and are trivially cheap to satisfy: the act itself has to be available for staff to read at the workplace, and enforcement is shared between the occupational safety authorities and the data protection ombudsman, so a labour inspector can ask about this and not only a privacy regulator.
The order matters, because the definition comes after the procedure rather than instead of it. The purpose, introduction and methods of technical monitoring fall within the co-operation dialogue, and it is worth naming the right procedure because most secondary writing does not: this is the regular quarterly dialogue, not change negotiations, which the statute confines to dismissal, lay-off, part-timing and the unilateral alteration of an essential contract term. The dialogue applies at fifty employees with a lighter regime from twenty, and below twenty the working-life privacy act takes over directly by requiring you to give staff or their representatives the opportunity to be heard before you decide. None of those is agreement, and no Finnish provision makes the measure conditional on the employee side agreeing. On the telephony side the marketing rule is scoped to direct marketing, which a security test is not, and the act contains no definition of direct marketing at all, which is a genuine gap in Finnish law rather than in the research.
What your company needs to do
6 items, in the order you will need them.
- Put the programme through the co-operation dialogue, not change negotiationsFinland-specificTechnical monitoring is a regular dialogue matter: a meeting at least quarterly, written information to the employee representative at least a week beforehand unless otherwise agreed, and minutes on request recording the date, who attended, the main content and the outcome. Naming the wrong procedure is the commonest Finnish error and it is visible in the minutes.
- Write the definition of purpose and methods, then issue the noticeFinland-specificThis is the one enforced by the criminal courts. After the dialogue, define the purpose of the technical monitoring and the methods used in it, then inform employees of the purpose, the introduction and the methods. Both halves are owed and a fine attaches to omitting either, so treat them as gating the first call rather than as documentation to catch up on.
- Do not design around a signatureFinland-specificThe necessity requirement cannot be derogated from with the employee's agreement, so a Finnish programme cannot buy itself more scope by asking. Design to what is directly necessary for the employment relationship and record why each thing you collect meets that test, which is a narrower question than whether the exercise is useful to the business.
- Collect from the employee, or get agreement for the other sourceFinland-specificThe same statute requires you to collect employee data primarily from the employee, and where you collect from another source the employee's agreement must be obtained, subject to narrow exceptions. If your scoping draws on directory data, helpdesk logs or anything else sourced around the person, that is the provision to check before the campaign is built.
- Do not claim a mandatory impact assessment you cannot sourceThe ombudsman's published list of processing that always requires one has five categories, and employee security testing is not among them. An assessment can still be required on the facts under the general rule, and often will be, but the list cannot be cited for it and a page or a proposal that says otherwise is overstating a sourceable position.
- Keep the act available at the workplaceIt sounds like a formality and it sits in the same penal list as the notice duty, which makes it the cheapest item on this page to discharge and an embarrassing one to be caught without. Put a copy where staff can see it alongside the monitoring notice you have just written.
The controls that do the work
How Callstrike is configured, and which provision in Finland each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
Finland's central rule is that you may process only what is directly necessary for the employment relationship, and that limit cannot be widened by agreement, so necessity is the only argument available and it has to hold on its own. The call ends the instant an employee starts to give up a credential, so what the programme holds is the fact that somebody was about to disclose rather than the thing they were about to disclose. That is a much easier item to defend as directly necessary, and it is the difference between a narrow written definition and one a labour inspector will want to talk about.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The co-operation dialogue is a standing quarterly conversation rather than a one-off approval, so what you say the exercise does to people is something you will be back in the room explaining. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is a concrete answer to the representative who wants to know what happens to the person who fails, and it belongs in the written definition of purpose alongside the methods.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Finland is the country where this most clearly cannot be a permission, because the statute voids agreement as a way of widening scope. Its job here is the notice duty that carries a fine: a dated, evidenced record that employees were told the purpose, the introduction and the methods of the monitoring, or a hashed copy of the policy you already rely on with a signed attestation of its scope.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
This is the fallback where the numbering regulation makes telephony awkward, and Finland's is strict: a Finnish number may not be used abroad as a calling number and calls presenting one from the international interface are blocked. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, and a call opened in a browser is not carried on the Finnish telephone network, so none of those clauses has anything to attach to.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.