Callstrike
Compliance

Voice phishing simulations in Ireland

Phone numbers in IrelandSelf-provisioned after approval

Ireland asks for less paperwork than almost anywhere else in this portal, and your own team rents the number once the company is cleared. The obstacle to an Irish voice phishing simulation is not the law and not the filing: it is a network blocking rule that decides whether your calls arrive at all, and it is worth settling before you write a single scenario.

Phone numbers

Supplied by Callstrike

Local numbers in Ireland, after a one-time approval.

Running a simulation

Permitted

The impact assessment is effectively compulsory here rather than advisable.

Consent

The regulator says rarely

Adequate only in exceptional circumstances, in the regulator's own words.

Getting a phone number in Ireland

One approval per country, completed in the console.

Self-provisioned after approval

Your company files its regulatory details once for this country. Once that is approved, your team provisions numbers directly from available inventory. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Ireland asks for one thing and it asks for it precisely: an address, with the Eircode, inside the area the number's own prefix covers. Not an address somewhere in the country. A Cork address will not support a Dublin number, because the requirement comes from a numbering condition binding your carrier rather than from a form somebody designed, and there is no discretion to waive it. Once the clearance is through, your own team rents Irish numbers directly.

Plan the origination path in the same conversation, because it decides more than the paperwork does. Since 2024 gateway operators have had to block inbound international calls presenting an Irish fixed number, and Irish mobile numbers unless the user is verifiably roaming. A campaign presenting an Irish landline from a platform outside the country does not look suspicious to the person being tested; it simply never reaches them, and no amount of clearance changes that.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03Search the inventory and rent your numberYour team
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Proof of addressMust include Eircode and be within locality or region covered by the phone number's prefix; a PO Box is not acceptable where a local address is required.Business address

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Ireland?

The position in short, before your counsel reads the detail below.

Yes, and Ireland is one of the more workable jurisdictions in Europe for this. The automated calling rule people expect to bite is written for direct marketing in every operative paragraph that could touch a voice call, and there is no general non-marketing prohibition anywhere in it, so an authorised test of your own workforce is outside it. That was established from the Irish text rather than assumed from the position across the Irish Sea, which matters because the two books do diverge.

The basis is legitimate interests, written down, and the regulator has said in its own words that employee agreement is adequate only in exceptional circumstances because of the power imbalance in the relationship. There is a calibration in its guidance worth taking seriously: legitimate interests works most easily where the impact on the person is minimal, and an unannounced call designed to see whether somebody can be manipulated is not a minimal-impact activity. Plan on making the compelling case rather than the easy one.

Treat the impact assessment as compulsory. The regulator's own list of processing that requires one names systematically monitoring, tracking or observing behaviour, and separately names processing where the person may not be aware it is happening. Both describe this exercise. Do it before the programme rather than after it, and keep it, because it is the document that answers the compelling-case question above.

Two things you do not have to worry about, and it is worth knowing why rather than just being told. There is no works council veto: the consultation machinery applies from fifty employees but starts only if a tenth of your staff ask for it in writing, and even then the strongest duty in it is that consultation take place with a view to agreement. And recording is lawful with one party's agreement, so as a party you are covered under the criminal law, whatever the published version of the statute appears to say.

What your company needs to do

6 items, in the order you will need them.

  • Originate the calls inside IrelandIreland-specificThis is the Irish decision and it is technical rather than legal. A simulation presenting an Irish number has to be handed over on the Irish network or the blocking rules drop it at the gateway. Confirm the origination path with your supplier before you plan anything else, because every other choice depends on it.
  • Get an address inside the number's own area, with the EircodeIreland-specificThe condition is a premises in the minimum numbering area for that code, not an address anywhere in the country. If your office and the code you want are in different regions, that is a real constraint on the pretext rather than a form to argue with.
  • Write the assessment for a more than minimal impactThe regulator's calibration is explicit: where the impact on the person is more than minimal, the interest pursued has to be a particularly compelling one. Write the assessment to that standard from the start, because an assessment pitched at an easier one has to be redone rather than defended.
  • Do the impact assessment before the first campaignTwo separate items on the regulator's mandatory list describe this exercise, so there is no judgement call to make about whether one is owed. Record the purpose, the necessity, the residual risk and what you decided to change as a result.
  • Put the caller identity permission in writingIreland-specificThe numbering conditions expressly allow your organisation to permit its call centre contractor to present the organisation's own assigned number while providing the service. The permission is the operative element rather than a formality, so record it as a document your supplier holds.
  • Solve transparency, not the criminal question, on recordingOne party's agreement answers the criminal law, and you are that party. The open part is transparency: the regulator publishes nothing on recording employee calls and its nearest principle is hostile to obtaining data without the person's knowledge. Give general prior notice that the programme records, and take the gap to your own counsel.

The controls that do the work

How Callstrike is configured, and which provision in Ireland each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

Ireland's hardest question is proportionality rather than prohibition, and this is the fact that answers it. The regulator asks you to show the exercise is necessary and that a less intrusive method would not do. A campaign that ends the call the instant an employee starts to give up a credential is already the less intrusive method: the credential is not stored somewhere carefully, it is never spoken into the system. That converts the compelling-case argument from an assertion into something the impact assessment can simply record.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The regulator's guidance on legal bases turns on the impact the processing has on the person, and its nearest statement of principle elsewhere is hostile to obtaining data from people without their knowledge. A call that ends in immediate vishing training, from a second voice that breaks character on the spot rather than in a report weeks later, is the design that answers both. It is also what makes the exercise defensible to an information and consultation forum if one has been requested.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

The regulator has said employee agreement is an adequate basis only in exceptional circumstances, so this is not what makes the programme lawful. What it does is produce the general prior notice that the recording question turns on, dated and attributable, either as a per-person record or as a hashed copy of the policy you already rely on with a signed attestation of its scope. It is included on every plan.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

This is the answer to the blocking problem as well as to a nervous stakeholder. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, and a call a person opens in their own browser is not a telephone call, so neither the automated calling rule nor the gateway blocking of Irish caller identities has anything to attach to. It means an Irish programme exists even before the origination path is solved.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

The basis to document, and who you have to tell

The GDPR applies directly and Ireland adds nothing on top for ordinary personal data. The Data Protection Act 2018 has no employment-monitoring provision of the kind Article 88 permits: its only employment-specific processing rule, section 46, is confined to special categories of data, which a simulation does not ordinarily touch. So the basis is legitimate interests under Article 6(1)(f), written down as an assessment that identifies the interest, shows the processing is necessary to achieve it, and balances it against the rights of the people being tested.

The Data Protection Commission has said in its own guidance that employee consent will only be an adequate basis in exceptional circumstances, because of the difficulty of obtaining freely given consent given the power imbalance inherent in the relationship between employee and employer. That is the regulator saying what competitor pages get backwards. Asking would also end the exercise, since a person who knows the call is coming is not being tested.

The Commission's guidance on legal bases adds a calibration that matters for an unannounced test. Legitimate interests is likely to be appropriate where people are processed in a way they would reasonably expect and with minimal impact on their privacy. Where the impact is more than minimal, the basis can still be used, but the interest pursued has to be a particularly compelling one. An unannounced call designed to see whether someone can be manipulated is not a minimal-impact activity, so plan on making the compelling case rather than the easy one.

An impact assessment is not optional in practice. The Commission's list of operations requiring one, adopted under Article 35(4), includes systematically monitoring, tracking or observing individuals' behaviour, and separately names processing where the individual may not be aware of the processing or of the identity of the controller. That is a description of a vishing simulation. Do the assessment before the programme, not after it.

Consultation is real but weak, and Ireland is a clean counterpoint to Germany here. The Employees (Provision of Information and Consultation) Act 2006 applies to undertakings with fifty or more employees, but nothing happens automatically: the employer must enter negotiations only at the written request of at least ten per cent of employees, itself floored at fifteen and capped at one hundred. Where the standard rules apply, the strongest duty in the Act is that consultation take place with a view to reaching an agreement. That is the ceiling. No provision makes a decision conditional on the forum's agreement, none suspends a measure while talks continue, and no body can substitute its decision for the employer's. If a forum exists, brief it. If none exists, the Act does not require you to create one.

Recording, and why the published statute gives the wrong answer

Read this section before you read the legislation, because the legislation as published will mislead you.

Interception of a telecommunications message is a criminal offence under section 98 of the Postal and Telecommunications Services Act 1983, carrying up to five years on indictment. The Irish Statute Book serves that Act as enacted, and the definition of interception in the as-enacted subsection (5) covers recording without the agreement of the person on whose behalf the message is sent and of the person intended to receive it. Both parties. Read that page and you would conclude Ireland requires everyone on the call to agree.

It does not. Section 13(3) of the Interception of Postal Packets and Telecommunications Messages (Regulation) Act 1993 substituted that subsection out, and moved the definition to a new subsection (6), which excludes listening or recording where either the person on whose behalf the message is transmitted or the person intended to receive it has agreed to it. Either, not both. A caller recording a call it is itself making is not intercepting. The 1983 page carries no banner saying any of this, so reading it is a false pass rather than a wrong answer: it does not tell you it is out of date, it simply does not say.

The ePrivacy layer points the same way from a different direction. Regulation 5 of the 2011 Regulations prohibits interception and surveillance of communications by persons other than users. A party to the call is a user, so a party recording its own call sits outside that prohibition too.

Two honest limits. First, section 98 speaks of messages transmitted by a licensed operator, a concept from a licensing regime that the general authorisation rules have since overtaken, and we could not find a provision expressly re-mapping it onto a modern authorised undertaking. That is a technical uncertainty about the section's reach rather than about the direction of the answer, and it is worth your own counsel's attention. Second, the criminal law is only half the question. The Commission publishes nothing at all on recording employee telephone calls, and the nearest statement of principle is about covert video: that using recording mechanisms to obtain data without an individual's knowledge is generally unlawful. So the workable design is the standard one, general prior notice that the programme exists rather than notice of each call, and that gap between one party under the criminal law and transparency under the GDPR is the part to take advice on.

An AI voice, a live operator, and the two rules that actually apply

The rule everyone expects to bite is regulation 13 of the 2011 ePrivacy Regulations, which restricts unsolicited communications sent by an automated calling machine. Read its words: the prohibition applies to a communication sent for the purpose of direct marketing. Those scope words appear in every operative paragraph of regulation 13 that could touch a voice call, and there is no general non-marketing prohibition anywhere in it. An authorised test of your own workforce is not direct marketing, so regulation 13 is not the rule that governs it. That is a statement about what the rule covers, not a route around it, and it was established from the Irish text rather than assumed from the position across the Irish Sea.

The definition is worth knowing too, because it is not about voices. An automated calling machine is defined as one which, when activated, operates to make calls without human intervention. That describes how the call is placed, not how the audio is produced. A dialler that places calls unattended is an automated calling machine whether a synthetic voice or a person speaks; a call placed by a live operator is not one.

The rule that does reach an AI voice is European. Article 50 of the EU AI Act has applied since 2 August 2026. It requires that a system designed to interact directly with people be built so that the person is told they are interacting with an AI system, and separately requires whoever deploys a system that generates or manipulates audio constituting a deep fake to disclose that the content is artificially generated. The timing rule is that this be provided at the latest at the time of the first interaction or exposure. There are two exceptions on the face of the text: use authorised by law to detect, prevent, investigate or prosecute criminal offence, and content forming part of an evidently artistic or fictional work, which limits the duty rather than removing it. An employer's authorisation for a security test comes from its own management and its own contracts. It is not authorisation by law, and the two senses of the word should not be run together.

One element is genuinely open and we are not going to close it for you. The Act defines a deep fake as content resembling existing persons, objects, places, entities or events that would falsely appear to be authentic. Whether a synthetic voice imitating no identifiable individual meets that description is not settled by the operative words. Where a voice imitates a specific real person, it is inside on any reading. Note also that a live operator does not move you outside the definition, because the words are generated or manipulated, and transforming a real person's voice in real time is manipulation.

So the practical difference between the two modes in Ireland is operational rather than a question of which rules apply. An autonomous voice scales across a whole workforce. A live operator holds a conversation that adapts, which is what a test of a senior target actually needs.

The Regulation carries a second duty for anyone shipping voice analytics, and the penalties are not on the same scale as the transparency ones. Breach of the transparency article sits in the fifteen million euro or three per cent tier. Using an AI system to infer emotions of a natural person in the workplace is a prohibited practice, applicable since 2 February 2025, and it sits in the thirty-five million euro or seven per cent tier, the highest the Regulation has, with an exception only for medical or safety reasons. The difference in exposure is a reason to resolve the question early. What decides it is the definition of an emotion recognition system, confined to inference from biometric data, so a product that reports outcomes rather than affect stays outside the higher tier altogether.

The caller ID rule, and the blocking rule that decides whether calls land

ComReg's numbering conditions require that the number presented to the person you are calling be a number assigned to the caller, and that a geographic presentation number be one appropriate to the numbering area it belongs to. So presenting an arbitrary Irish number is not an option, and presenting a Dublin number on a service whose number belongs elsewhere is not either.

There is a condition that speaks directly to how a simulation is normally run, and it is permissive. ComReg's conditions expressly allow an end-user organisation to give permission to its call centre contractor to use the organisation's assigned number as caller ID while providing the service. That is regulator authority for the ordinary shape of this work: your number, presented by your testing supplier, with your permission. Put the permission in writing, because it is the operative element of the condition rather than a formality.

The constraint that will decide whether your calls arrive at all is newer. Since 2024 ComReg has required gateway operators to block all inbound international calls presenting an Irish fixed number, with only narrow exceptions, and to do the same for Irish mobile numbers unless the user is verifiably roaming. The practical consequence is blunt: a simulation presenting an Irish landline number has to originate on the Irish network. Injected from an international gateway it will be blocked outright however legitimate it is, and no amount of paperwork changes that. ComReg also maintains a list of numbers that are never to be used for outgoing calls, so if your organisation has placed its inbound-only numbers on it, those numbers cannot be your presentation caller ID.

What the country matrix holds for Ireland

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Why Irish clearance is one thing rather than five

Ireland asks for less than almost anywhere else in our matrix, and the reason is traceable to a single condition rather than to a carrier being relaxed. ComReg's rights of use conditions provide that a geographic number shall only be assigned to an end user whose residential or business premises is physically located within the designated minimum numbering area for that number. That is the whole of the evidential requirement: prove your premises is in the area the number belongs to.

Note that it is stricter than it is usually described. The requirement is not an address somewhere in Ireland; it is an address inside the specific numbering area of the code being assigned. A Cork address will not support a Dublin number.

Note also who the condition binds. It is a condition on the authorised undertaking that holds the numbers, not on you directly. You experience it as your carrier asking for a physical Irish address and matching proof, and the carrier has no discretion to waive it. So it is a regulator requirement, administered by the carrier, and worth distinguishing from the things a carrier asks for on its own account.

Mobile numbers carry no equivalent. The rights of use conditions for mobile numbers are purely about digit structure, with no premises, address or residence condition at all, so do not assume the geographic rule generalises. And ComReg publishes no requirement that a number's end user be a registered Irish company. Where a carrier asks for company registration, that is its own onboarding process. There is a draft know-your-customer guidance document out for consultation, and being a draft it is not a current requirement and should not be quoted at you as one.

Financial services, and a directive Ireland has not transposed

Start with the thing most compliance programmes assume and get wrong. NIS2 has not been transposed in Ireland. The National Cyber Security Bill is the intended vehicle and its general scheme was published in 2024, but no Bill appears in the Oireachtas records for 2024, 2025 or 2026, and no transposing statutory instrument appears in the 2025 or 2026 indexes. The National Cyber Security Centre says on its own site that the October 2024 deadline has not been met and that the predecessor regime remains in full effect. So what actually binds Irish operators of essential services today is the 2018 Regulations, which cover a much narrower population than NIS2 will when it arrives. If your programme is being justified by reference to NIS2 obligations in Ireland, the obligations are not there yet.

In financial services the binding instrument is DORA, and its people obligation is unusually direct: financial entities must develop security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes, applicable to all employees and to senior management. Alongside it sits a testing programme obligation whose menu of test types expressly includes scenario-based tests, and threat-led penetration testing for entities that meet the criteria. Social engineering is a standard technique in that kind of testing and it is not named in the Regulation, so do not let anyone tell you DORA requires vishing specifically.

The Central Bank's cross industry guidance on operational resilience took effect in January 2024 and asks firms to test their ability to remain within impact tolerances through severe but plausible scenarios, at least annually for all firms, considering methods including paper based and simulation testing. It is guidance rather than a rule, and it does not require social engineering testing. What it does do is make a scenario that ignores people an incomplete answer, since people are the route into most important business services.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in IRELAND. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance through a published policy.

Verify or correct each proposition below against primary Irish sources:

1. The basis is GDPR Art 6(1)(f); DPA 2018 s.46 is confined to special categories and Ireland used no Art 88 employment derogation for ordinary data.
2. The DPC's Art 35(4) list makes a DPIA mandatory here, on both the systematic observation item and the item on processing the person may be unaware of.
3. S.I. 336/2011 reg 13 is scoped to direct marketing in every operative limb that could reach a voice call, and reg 2 defines an automated calling machine by how the call is placed rather than by how the audio is produced.
4. ⚠ Ireland is ONE-PARTY for recording. The Irish Statute Book serves the 1983 Act as enacted, whose s.98(5) reads as all-party; s.13(3) of the 1993 Act substituted it and the surviving s.98(6) says either. Confirm against the revised text, and advise on s.98's reference to a licensed operator under the general authorisation regime.
5. ComReg 15/136R4 permits an end-user organisation to authorise its call centre contractor to present the organisation's assigned number.
6. ComReg 24/24 requires gateway blocking of inbound international calls presenting Irish fixed CLI, and Irish mobile CLI absent verifiable roaming.
7. NIS2 is NOT transposed in Ireland; S.I. 360/2018 remains the operative regime.

Flag anything that has changed since September 2026, and tell me whether the draft ComReg KYC guidance has been finalised.

Common questions

Do we need employee consent to run a vishing simulation in Ireland?
No. The Data Protection Commission has said employee consent is an adequate basis only in exceptional circumstances, because of the power imbalance in the employment relationship. Use legitimate interests with a documented assessment and an impact assessment, plus a transparency notice covering the programme rather than each call.
Can we record the calls in Ireland?
One party's agreement is enough under the criminal law, so as a party you are covered. Be careful with the published statute: the 1983 Act as served online still shows an all-party definition that was substituted out in 1993. The open question is transparency under the GDPR, not the criminal law.
Does the automated calling rule stop us using an AI voice?
Regulation 13 is written for direct marketing, and an authorised test of your own staff is not that, so it is not the governing rule. Article 50 of the EU AI Act is, and it has applied since August 2026. Its exceptions cover criminal law enforcement and artistic works, neither of which fits a workforce test.
Why do our Irish test calls never connect?
Almost certainly because they originate outside Ireland. Since 2024 gateway operators must block inbound international calls presenting an Irish fixed number, and Irish mobile numbers unless the user is verifiably roaming. A simulation presenting an Irish number has to originate on the Irish network to survive that filter.

Elsewhere in Western Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.