Callstrike
Compliance

Voice phishing simulations in Finland

Phone numbers in FinlandProvisioned by Callstrike after approval

Finland allows a voice phishing simulation against your own staff and Callstrike supplies the number with nothing for you to gather, but it is the only country in this region where getting the paperwork wrong is a criminal offence rather than an accountability failure. Two documents decide a Finnish programme, and neither of them is the one most companies write first.

Phone numbers

Supplied by Callstrike

Local numbers in Finland, after a one-time approval.

Running a simulation

Permitted, on two documents

A co-operation dialogue first, then a written definition and a notice to staff.

Consent

Unavailable for scope, required for sourcing

The statute removes the option outright, and not for the usual power-imbalance reason.

Getting a phone number in Finland

One approval per country, with no documentation to gather.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days.

Finland is the short one. The carrier publishes no documentation requirement for the number type we supply here, so the evidence-gathering that dominates most of this portal has no Finnish counterpart at all: there is nothing to assemble and nothing for a regulator to read. What you are waiting on is the country being enabled against your workspace, after which Callstrike provisions a dedicated Finnish number for your campaigns. Plan for the days, not the file.

Where Finland does get demanding is the wire, and the constraint lands on your operator rather than on your policy folder. The communications agency's interoperability regulation, in force since May 2026 and replacing its 2023 predecessor, puts the geographic area of use of a Finnish number at Finland and prohibits using one abroad as a calling number; requires the originating operator to ensure the calling party number it transmits is correct and unambiguous; requires that operator, where it presents a number not under its own control, to verify the subscriber's unambiguous right to use it; and requires blocking of calls arriving from the international interface with a Finnish number outside genuine roaming. If you are working from the 2023 text, you are working from repealed rules.

  1. 01Ask for the country to be enabled for your workspaceYour administrator, in the Callstrike console.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Finland is assigned to youCallstrike
  4. 04Build and launch the campaignYour team

No regulatory documentation is required to hold a number here. The clearance step is Callstrike enabling the country for your workspace, with no forms to complete and no evidence to gather.

Is it lawful to run a simulation in Finland?

The position in short, before your counsel reads the detail below.

Yes, but Finland runs a working-life privacy statute that the rest of Europe does not have, and it is stricter than the European default in a way that changes the design rather than the answer. You may process only personal data directly necessary for the employment relationship, connected with managing the parties' rights and obligations or with benefits you provide, or arising from the special nature of the work. Then comes the sentence with no counterpart elsewhere in this portal: that necessity requirement cannot be derogated from with the employee's agreement.

Read that as a different point from the one made on every other page here. Elsewhere the argument against relying on an employee's agreement is that a power imbalance makes it unfree. In Finland the statute simply takes the option away, so even a genuinely free and enthusiastic agreement cannot widen what you may collect. There is an unusual pairing to hold in mind alongside it, because Finnish law demands agreement in one place while voiding it in another: you must collect employee data primarily from the employee, and where you collect from another source the employee's agreement is required, with narrow statutory exceptions. Agreement is required for provenance and unavailable for scope. Getting that pairing right is the distinctively Finnish part of the analysis.

The expensive obligation is not the famous one, and this is the point to take away. The necessity rule carries no criminal sanction; it is enforced administratively. What is criminalised, by fine, is failing to define the purpose and the methods of technical monitoring and to inform employees of them. So the deliverable is a written document and a communication, and skipping either is an offence rather than a shortfall in your accountability file. Two smaller duties sit in the same list and are trivially cheap to satisfy: the act itself has to be available for staff to read at the workplace, and enforcement is shared between the occupational safety authorities and the data protection ombudsman, so a labour inspector can ask about this and not only a privacy regulator.

The order matters, because the definition comes after the procedure rather than instead of it. The purpose, introduction and methods of technical monitoring fall within the co-operation dialogue, and it is worth naming the right procedure because most secondary writing does not: this is the regular quarterly dialogue, not change negotiations, which the statute confines to dismissal, lay-off, part-timing and the unilateral alteration of an essential contract term. The dialogue applies at fifty employees with a lighter regime from twenty, and below twenty the working-life privacy act takes over directly by requiring you to give staff or their representatives the opportunity to be heard before you decide. None of those is agreement, and no Finnish provision makes the measure conditional on the employee side agreeing. On the telephony side the marketing rule is scoped to direct marketing, which a security test is not, and the act contains no definition of direct marketing at all, which is a genuine gap in Finnish law rather than in the research.

What your company needs to do

6 items, in the order you will need them.

  • Put the programme through the co-operation dialogue, not change negotiationsFinland-specificTechnical monitoring is a regular dialogue matter: a meeting at least quarterly, written information to the employee representative at least a week beforehand unless otherwise agreed, and minutes on request recording the date, who attended, the main content and the outcome. Naming the wrong procedure is the commonest Finnish error and it is visible in the minutes.
  • Write the definition of purpose and methods, then issue the noticeFinland-specificThis is the one enforced by the criminal courts. After the dialogue, define the purpose of the technical monitoring and the methods used in it, then inform employees of the purpose, the introduction and the methods. Both halves are owed and a fine attaches to omitting either, so treat them as gating the first call rather than as documentation to catch up on.
  • Do not design around a signatureFinland-specificThe necessity requirement cannot be derogated from with the employee's agreement, so a Finnish programme cannot buy itself more scope by asking. Design to what is directly necessary for the employment relationship and record why each thing you collect meets that test, which is a narrower question than whether the exercise is useful to the business.
  • Collect from the employee, or get agreement for the other sourceFinland-specificThe same statute requires you to collect employee data primarily from the employee, and where you collect from another source the employee's agreement must be obtained, subject to narrow exceptions. If your scoping draws on directory data, helpdesk logs or anything else sourced around the person, that is the provision to check before the campaign is built.
  • Do not claim a mandatory impact assessment you cannot sourceThe ombudsman's published list of processing that always requires one has five categories, and employee security testing is not among them. An assessment can still be required on the facts under the general rule, and often will be, but the list cannot be cited for it and a page or a proposal that says otherwise is overstating a sourceable position.
  • Keep the act available at the workplaceIt sounds like a formality and it sits in the same penal list as the notice duty, which makes it the cheapest item on this page to discharge and an embarrassing one to be caught without. Put a copy where staff can see it alongside the monitoring notice you have just written.

The controls that do the work

How Callstrike is configured, and which provision in Finland each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

Finland's central rule is that you may process only what is directly necessary for the employment relationship, and that limit cannot be widened by agreement, so necessity is the only argument available and it has to hold on its own. The call ends the instant an employee starts to give up a credential, so what the programme holds is the fact that somebody was about to disclose rather than the thing they were about to disclose. That is a much easier item to defend as directly necessary, and it is the difference between a narrow written definition and one a labour inspector will want to talk about.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The co-operation dialogue is a standing quarterly conversation rather than a one-off approval, so what you say the exercise does to people is something you will be back in the room explaining. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is a concrete answer to the representative who wants to know what happens to the person who fails, and it belongs in the written definition of purpose alongside the methods.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Finland is the country where this most clearly cannot be a permission, because the statute voids agreement as a way of widening scope. Its job here is the notice duty that carries a fine: a dated, evidenced record that employees were told the purpose, the introduction and the methods of the monitoring, or a hashed copy of the policy you already rely on with a signed attestation of its scope.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

This is the fallback where the numbering regulation makes telephony awkward, and Finland's is strict: a Finnish number may not be used abroad as a calling number and calls presenting one from the international interface are blocked. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, and a call opened in a browser is not carried on the Finnish telephone network, so none of those clauses has anything to attach to.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

A necessity rule that agreement cannot switch off

Finland is the country in this portal where the national statute does the most work, and its central provision has no counterpart anywhere else in the cluster.

The working-life privacy act provides that the employer may process only personal data directly necessary for the employee's employment relationship, connected with managing the rights and obligations of the parties or with benefits the employer provides, or arising from the special nature of the work tasks. Then comes the sentence that changes how a Finnish programme is designed: the necessity requirement cannot be derogated from with the employee's agreement.

Read that carefully, because it is a different point from the one made on most of these pages. Elsewhere the argument against relying on an employee's agreement is that the power imbalance makes it unfree. In Finland the statute simply removes the option: even a genuinely free, informed and enthusiastic agreement cannot widen what the employer may collect. The data protection ombudsman restates it in its own words and goes further on one point, publishing that an employee cannot validly agree to the employer monitoring their web browsing at all.

There is an unusual pairing to hold in mind, because Finnish law both demands agreement in one place and voids it in another. A separate section requires the employer to collect employee data primarily from the employee, and where it collects from another source the employee's agreement must be obtained, with narrow statutory exceptions. So agreement is required for provenance and is unavailable for scope. Getting that pairing right is the distinctively Finnish part of the analysis.

One negative worth stating because it is commonly asserted the other way. The ombudsman's published list of processing operations that always require an impact assessment has five categories, and employee security testing is not among them. An assessment can still be required on the facts under the general rule, but the list cannot be cited for it, and a page claiming a Finnish impact assessment is mandatory for this activity would be overstating a sourceable position.

Outside the offence, because the words were meant for you

The Finnish criminal provision is drawn around the outsider, and the drafting makes the participant question easy to answer from the text alone.

Illicit listening punishes a person who unlawfully, with a technical device, listens to or records a conversation, speech or other sound arising from private life that is not intended for their knowledge and that occurs in a place protected by domestic peace; or, elsewhere, secretly records speech that is not intended for their knowledge nor for that of any other outsider, in circumstances where the speaker has no reason to assume an outsider hears them. Both limbs turn on the speech not being intended for the recorder. A party to a call is an intended recipient, so the elements are not met.

The electronic communications side agrees rather than complicating it. The confidentiality chapter opens by providing that a party to the communication may process its own electronic messages and the associated traffic data unless otherwise provided by law. That is an express permission rather than an inference.

The data protection ombudsman has published the same conclusion, saying an employee may record calls and conversations in which they themselves take part and cannot thereby commit illicit listening, while noting that good practice at a workplace is to tell the other party, particularly where the conversation was meant to be confidential. We cite it with a caveat rather than as authority: that decision is from 2007 and its data protection reasoning is framed on a statute that has since been repealed. Its criminal-law proposition tracks a provision that has not changed, which is why the paragraphs above are written to the criminal code directly.

The ombudsman is also explicit that it has no power to decide how a recording may then be used or to whom it may be given, which is the honest boundary of the answer: capture is comfortable in Finland, and what you do with the audio afterwards is a question the necessity rule in the previous section governs.

Direct marketing is the gate, and the gate has no definition

The Finnish transposition of the European rule on unsolicited communications is scoped by purpose. Direct marketing carried out by means of automated calling systems, fax machines, email, text, voice, sound or image messages may be directed only at natural persons who have given prior agreement. The operative noun is direct marketing, so the prohibition attaches to the purpose and not to the technology, and an automated call that is not direct marketing is not caught.

There is a gap in that answer which we would rather name than paper over. The act contains no definition of direct marketing at all. We searched the full consolidated text for the definitional form of the word and it does not appear; the term is used throughout the chapter and never defined. So the scoping is clear and the boundary of the scoping is not, and that is the state of Finnish law rather than a gap in the research.

A related question the statute also declines to answer: whether an employee reached on a work line is protected as a natural person or falls under the separate opt-out rule for corporate bodies. Neither provision keys off who owns or pays for the line. The only textual signal points weakly the other way, because a further section contemplates a corporate subscriber blocking natural-person marketing on behalf of its users, which implies the natural-person rule can operate on a work line. That is an inference and we are labelling it as one.

The European transparency rule reaches Finland directly. Article 50 of the AI Act has applied since 2 August 2026: a system built to interact with people must be designed so the person is informed they are dealing with an AI system, and a deployer of a system generating or manipulating audio constituting a deep fake must disclose that the content is artificially generated, in both cases at the latest at the time of the first interaction or exposure. The exceptions are use authorised by law to detect, prevent, investigate or prosecute criminal offences, and evidently artistic or fictional works. An employer authorising its own exercise is not authorisation by law, and the exemption for cases where the artificial origin is obvious is unavailable in an exercise designed so that it is not.

Finland is ahead of most of this cluster on the enforcement side, which is worth knowing because it changes who you would be answering to. Its act on the supervision of certain artificial intelligence systems, in force since 1 January 2026, designates the transport and communications agency as the market surveillance authority for the Article 50 transparency obligations specifically, with the data protection ombudsman taking the prohibited-practices side.

One more provision of that Regulation deserves a look, and its exception is thinner than it sounds. Using an AI system to infer emotions of a natural person in the workplace has been prohibited since 2 February 2025, at up to thirty-five million euros or seven per cent of worldwide turnover, except where the use is intended for medical or safety reasons. That phrase appears exactly once in the whole Regulation, inside the exception itself, and is defined nowhere in it, so anyone planning to rely on it is relying on an undefined term. The safer question is the gate rather than the exception: an emotion recognition system is defined by inference from biometric data, and a feature that stops at recording what a person did rather than what they felt does not reach it.

The rule that binds you is a regulator's order, not the act

Finland's caller identification constraint is not in the electronic communications act and it moved four months ago, so this is a section where an out-of-date source is likely.

The operative instrument is the communications agency's regulation on the interoperability of communications networks and services, issued in December 2025, in force since 4 May 2026, and repealing its 2023 predecessor. Three of its clauses matter here.

The geographic scope clause provides that the geographical area of use of Finnish telephone numbers is Finland, and that using Finnish telephone numbers abroad as the numbers of calling and transferring connections is prohibited. The correctness clause requires the originating operator to ensure that the calling party number it transmits is correct and unambiguous. And the clause that decides a simulation's design provides that where the originating operator uses, on a subscription, a number other than one under its own control as the calling party number, it must verify that the subscriber has an unambiguous right to use that number.

A fourth clause closes the international route: the operator must block calls arriving from the general international interface whose calling party number is clearly incorrect, or whose number is a Finnish telephone number where the call is not a genuine roaming case.

The practical consequence is precise and worth planning around: the constraint lands on procurement and on your operator's paperwork rather than on your own policy file. The operator must be able to evidence your unambiguous right to use the number you want presented, and the traffic must originate inside Finland. A Finnish number injected from abroad is blocked regardless of what anyone intended.

What the country matrix holds for Finland

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Dialogue, then a written definition, and a fine if you skip it

Finland's procedural requirements are unusually concrete, and one of them is enforced by the criminal courts rather than by a regulator. Take them in the order they happen.

First, the co-operation stage. The purpose, introduction and methods of camera surveillance, access control and other technical monitoring directed at employees, and the use of email and other information networks, fall within the co-operation dialogue. It is worth being exact about which procedure that is, because most secondary writing gets it wrong: this is the regular dialogue, not change negotiations, which are confined by their own section to dismissal, lay-off, part-timing and unilateral alteration of an essential contract term. Practically that means a meeting at least once each quarter, written information to the employee representative at least a week beforehand unless otherwise agreed, and minutes on the representative's request recording the date, who attended, the main content and the outcome or the parties' differing views.

Thresholds matter. The co-operation act applies to undertakings regularly employing at least fifty people, with a separate lighter regime bridging matters of this kind into dialogue for undertakings of twenty to forty-nine. Below twenty the working-life privacy act takes over directly: the employer must, before deciding, give employees or their representatives the opportunity to be heard on those same matters. That is still not agreement, and no Finnish provision makes the measure conditional on the employee side agreeing.

Second, and this is the part with teeth. After that procedure the employer must define the purpose of the technical monitoring and the methods used in it, and must inform employees of the purpose, the introduction and the methods, and of the use of email and the information network. Breach of that definition and notification duty is listed in the act's penal section and is punishable by a fine.

So the Finnish deliverable is a written document and a communication, and skipping either is an offence rather than an accountability failure. There is one more small obligation in the same penal list that is easy to overlook and trivially cheap to satisfy: the employer must keep the act itself available for employees to see at the workplace.

Enforcement is shared, which is worth knowing when planning who to brief internally. The act provides that compliance is supervised by the occupational safety and health authorities within their competence together with the data protection ombudsman, so this is not purely a data protection matter and a labour inspector can ask about it.

Training is required, testing is not, and the difference is the whole point

Finland transposed the network and information security directive by an act in force since 8 April 2025, and it is unusually easy to check what that act does and does not require, because its risk-management provision is a closed list.

Of the ten items on that list one touches people: personnel security and cybersecurity training. Nothing in the section requires simulated attacks, phishing tests or voice phishing tests, and the section has not been amended since enactment even though several other parts of the act have. There is also a documented deadline worth knowing if you are being sold urgency: the risk-management model had to be drawn up within three months of the act entering into force.

For financial entities DORA applies directly and the financial supervisory authority has obliged the most significant supervised entities to perform threat-led penetration tests at regular intervals, extending that in Finland to smaller banks and insurance participants as well, across more than four hundred supervised entities. DORA itself requires compulsory security awareness programmes and digital operational resilience training for all employees and senior management, and threat-led testing at least every three years for entities in scope.

Be precise about what DORA does not say, because it is routinely quoted as though it did. The phrase social engineering appears nowhere in the Regulation, and neither does phishing. Its definition of threat-led testing describes mimicking the tactics, techniques and procedures of real threat actors and names no channel. The only binding text in the whole stack that mentions social engineering is the delegated regulation supplementing it, and it does so as a constraint: the red team test plan must state the techniques allowed and not allowed, including ethical boundaries for social engineering. A compliant plan may place social engineering entirely in the not-allowed column.

The national threat-led testing framework is run by the central bank, and its own published description says a test under it can satisfy the DORA requirement, for which the financial supervisory authority is the competent authority in Finland. We could not retrieve the framework's own implementation guide, so we make no claim about whether it scopes voice channels.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in FINLAND. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance.

Verify or correct each proposition below against primary Finnish sources, and tell me exactly what we must write down and in what order:

1. Laki yksityisyyden suojasta tyoelamassa 759/2004 § 3 permits only data DIRECTLY necessary for the employment relationship, and its second sentence provides that the necessity requirement cannot be derogated from with the employee's consent.
2. § 4 requires collection primarily from the employee and the employee's consent for collection from another source. Reconcile that with proposition 1 for our scoping data.
3. ⚠ § 3 carries NO criminal sanction and is not in the § 24 offence list. What IS criminalised by fine is breach of the § 21(2) duty to define the purpose and methods of technical monitoring and to inform employees. Confirm, and draft the definition.
4. ⚠ It is co-operation DIALOGUE under YTL § 8(6) with § 12(3), NOT muutosneuvottelut, which § 16(1) confines to redundancy-type measures. Confirm the thresholds: 50, the lighter 20 to 49 regime, and § 21 hearing below that.
5. SVPL § 200 is gated on 'suoramarkkinointi', which the act nowhere defines, and § 202 rather than § 201 is the legal-person rule. Advise on whether an employee reached on a work line is a natural person or a corporate subscriber for this purpose.
6. The tietosuojavaltuutettu's mandatory-DPIA list has five categories and employee security testing is not one. Advise whether one is nonetheless owed on our facts.
7. Rikoslaki 24:5 salakuuntelu turns on speech not intended for the recorder, so a party is outside it, and SVPL § 136 expressly permits a party to process its own messages.
8. ⚠ Traficom Maarays 28 L/2025 (in force 04.05.2026, repealing 28 K/2023) is the caller-identity instrument, not the act. Confirm the geographic-use, correctness, right-of-use verification and international-interface blocking clauses.

Flag anything that has changed since September 2026. ⚠ Finlex is client-rendered: a plain fetch of any consolidated text returns an empty shell, so read the payload rather than concluding a provision is absent.

Common questions

Can employees agree to a broader Finnish programme?
No, and this is the distinctively Finnish point. The working-life privacy act says the necessity requirement cannot be derogated from with the employee's agreement, so even a freely given one cannot widen what the employer may collect. Agreement is unavailable for scope while being required for collecting from other sources.
What exactly must a Finnish employer write down?
After the co-operation dialogue, the purpose of the technical monitoring and the methods used, then inform employees of the purpose, the introduction and the methods. Skipping that definition or that notice is listed in the act's penal section and is punishable by a fine, not merely an accountability failure.
Is this co-operation negotiations or something lighter?
Dialogue, not change negotiations, and most secondary writing names the wrong one. Technical monitoring is a regular co-operation dialogue matter, while change negotiations are confined by their own section to dismissal, lay-off, part-timing and the unilateral alteration of an essential term of the employment contract.
Why did our Finnish campaign fail to connect?
Probably the numbering regulation. Finnish numbers may not be used abroad as calling numbers, the originating operator must verify your unambiguous right to use any number not under its control, and operators must block calls from the international interface presenting Finnish numbers outside genuine roaming.

Elsewhere in Northern Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.