Voice phishing simulations in Ireland
Ireland asks for less paperwork than almost anywhere else in this portal, and your own team rents the number once the company is cleared. The obstacle to an Irish voice phishing simulation is not the law and not the filing: it is a network blocking rule that decides whether your calls arrive at all, and it is worth settling before you write a single scenario.
Phone numbers
Supplied by Callstrike
Local numbers in Ireland, after a one-time approval.
Running a simulation
Permitted
The impact assessment is effectively compulsory here rather than advisable.
Consent
The regulator says rarely
Adequate only in exceptional circumstances, in the regulator's own words.
Getting a phone number in Ireland
One approval per country, completed in the console.
Self-provisioned after approval
Your company files its regulatory details once for this country. Once that is approved, your team provisions numbers directly from available inventory. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Ireland asks for one thing and it asks for it precisely: an address, with the Eircode, inside the area the number's own prefix covers. Not an address somewhere in the country. A Cork address will not support a Dublin number, because the requirement comes from a numbering condition binding your carrier rather than from a form somebody designed, and there is no discretion to waive it. Once the clearance is through, your own team rents Irish numbers directly.
Plan the origination path in the same conversation, because it decides more than the paperwork does. Since 2024 gateway operators have had to block inbound international calls presenting an Irish fixed number, and Irish mobile numbers unless the user is verifiably roaming. A campaign presenting an Irish landline from a platform outside the country does not look suspicious to the person being tested; it simply never reaches them, and no amount of clearance changes that.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03Search the inventory and rent your numberYour team
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Proof of addressMust include Eircode and be within locality or region covered by the phone number's prefix; a PO Box is not acceptable where a local address is required. | Business address |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in Ireland?
The position in short, before your counsel reads the detail below.
Yes, and Ireland is one of the more workable jurisdictions in Europe for this. The automated calling rule people expect to bite is written for direct marketing in every operative paragraph that could touch a voice call, and there is no general non-marketing prohibition anywhere in it, so an authorised test of your own workforce is outside it. That was established from the Irish text rather than assumed from the position across the Irish Sea, which matters because the two books do diverge.
The basis is legitimate interests, written down, and the regulator has said in its own words that employee agreement is adequate only in exceptional circumstances because of the power imbalance in the relationship. There is a calibration in its guidance worth taking seriously: legitimate interests works most easily where the impact on the person is minimal, and an unannounced call designed to see whether somebody can be manipulated is not a minimal-impact activity. Plan on making the compelling case rather than the easy one.
Treat the impact assessment as compulsory. The regulator's own list of processing that requires one names systematically monitoring, tracking or observing behaviour, and separately names processing where the person may not be aware it is happening. Both describe this exercise. Do it before the programme rather than after it, and keep it, because it is the document that answers the compelling-case question above.
Two things you do not have to worry about, and it is worth knowing why rather than just being told. There is no works council veto: the consultation machinery applies from fifty employees but starts only if a tenth of your staff ask for it in writing, and even then the strongest duty in it is that consultation take place with a view to agreement. And recording is lawful with one party's agreement, so as a party you are covered under the criminal law, whatever the published version of the statute appears to say.
What your company needs to do
6 items, in the order you will need them.
- Originate the calls inside IrelandIreland-specificThis is the Irish decision and it is technical rather than legal. A simulation presenting an Irish number has to be handed over on the Irish network or the blocking rules drop it at the gateway. Confirm the origination path with your supplier before you plan anything else, because every other choice depends on it.
- Get an address inside the number's own area, with the EircodeIreland-specificThe condition is a premises in the minimum numbering area for that code, not an address anywhere in the country. If your office and the code you want are in different regions, that is a real constraint on the pretext rather than a form to argue with.
- Write the assessment for a more than minimal impactThe regulator's calibration is explicit: where the impact on the person is more than minimal, the interest pursued has to be a particularly compelling one. Write the assessment to that standard from the start, because an assessment pitched at an easier one has to be redone rather than defended.
- Do the impact assessment before the first campaignTwo separate items on the regulator's mandatory list describe this exercise, so there is no judgement call to make about whether one is owed. Record the purpose, the necessity, the residual risk and what you decided to change as a result.
- Put the caller identity permission in writingIreland-specificThe numbering conditions expressly allow your organisation to permit its call centre contractor to present the organisation's own assigned number while providing the service. The permission is the operative element rather than a formality, so record it as a document your supplier holds.
- Solve transparency, not the criminal question, on recordingOne party's agreement answers the criminal law, and you are that party. The open part is transparency: the regulator publishes nothing on recording employee calls and its nearest principle is hostile to obtaining data without the person's knowledge. Give general prior notice that the programme records, and take the gap to your own counsel.
The controls that do the work
How Callstrike is configured, and which provision in Ireland each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
Ireland's hardest question is proportionality rather than prohibition, and this is the fact that answers it. The regulator asks you to show the exercise is necessary and that a less intrusive method would not do. A campaign that ends the call the instant an employee starts to give up a credential is already the less intrusive method: the credential is not stored somewhere carefully, it is never spoken into the system. That converts the compelling-case argument from an assertion into something the impact assessment can simply record.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The regulator's guidance on legal bases turns on the impact the processing has on the person, and its nearest statement of principle elsewhere is hostile to obtaining data from people without their knowledge. A call that ends in immediate vishing training, from a second voice that breaks character on the spot rather than in a report weeks later, is the design that answers both. It is also what makes the exercise defensible to an information and consultation forum if one has been requested.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
The regulator has said employee agreement is an adequate basis only in exceptional circumstances, so this is not what makes the programme lawful. What it does is produce the general prior notice that the recording question turns on, dated and attributable, either as a per-person record or as a hashed copy of the policy you already rely on with a signed attestation of its scope. It is included on every plan.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
This is the answer to the blocking problem as well as to a nervous stakeholder. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, and a call a person opens in their own browser is not a telephone call, so neither the automated calling rule nor the gateway blocking of Irish caller identities has anything to attach to. It means an Irish programme exists even before the origination path is solved.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.