Callstrike
Compliance

Voice phishing simulations in Italy

Phone numbers in ItalyProvisioned by Callstrike after approval

Italy is the one country in this portal where a voice phishing simulation is not something you decide and document. Article 4 of the Workers' Statute requires a union agreement or a labour inspectorate authorisation before an instrument capable of remote monitoring is installed at all, and Callstrike supplies the Italian number on the other side of that. Budget for the procedure before you budget for the campaign.

Phone numbers

Supplied by Callstrike

Mobile numbers in Italy, after a one-time approval.

Running a simulation

Permitted, after prior authorisation

One of two routes has to be completed before installation, and neither is a formality.

Consent

Never what authorises this

The union agreement or the inspectorate does that, and nothing else substitutes for it.

Getting a phone number in Italy

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Your company files its regulatory details once for this country. Local rules require the order to be placed by the provider of record, so Callstrike provisions the number on your behalf once the filing is approved. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

The Italian requirements are the mobile ones, which is true of no other page in this portal and makes the filing a different shape. Rather than a company address inside a prefix area, what the carrier wants is a named authorised representative: their identity document, their date and place of birth, their nationality and their fiscal code, alongside the company's own name and VAT number. That is not the carrier being nosy. Italian law requires customers to be identified before a mobile service is activated, with the contract holder's details taken from an identity document and a copy retained, and it permits that to be done remotely provided the data are correctly captured.

The business address the form asks for may be anywhere in the world, which surprises people arriving from the rest of this cluster, and it is consistent with what the regulator actually requires: neither the communications authority nor the ministry publishes any requirement that a business end user hold an Italian registered address or an Italian company registration. Plan instead for where the calls originate, which is the Italian constraint that stops campaigns dead and has nothing to do with paperwork. Since 2025 operators must block incoming international calls presenting an Italian fixed number, and Italian mobile numbers unless they have verified that the user is roaming abroad. We originate Italian traffic inside Italy for that reason.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Italy is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Name of authorized representativeGovernment-issued ID, Passport
Business addressMay be anywhere in the worldBusiness registry showing the address, Utility bill, Tax notice, Rent receipt, Title deed

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Italy?

The position in short, before your counsel reads the detail below.

Yes, and Italy is the country on this portal where that answer needs the most work done before it is worth anything. The telephone rule is the easy half: the unwanted-communications article requires agreement for automated calling systems used without operator intervention for advertising, direct sales, market research or commercial communication. Four purposes, all commercial, and an authorised test of your own workforce is none of them.

The hard half is the Workers' Statute, and it is different in kind from a consultation duty. Instruments from which the possibility of remote monitoring of workers' activity also derives may be used only for organisational and production needs, workplace safety and the protection of company assets, and may be installed only after a collective agreement with the unitary or company union representatives, or failing that with the prior authorisation of the territorial office of the labour inspectorate. Four things in that wording decide your project. The three purposes are exhaustive and none of them is security awareness. The trigger is incidental capability rather than monitoring as an aim. The union agreement is the primary route and the inspectorate is the fallback. And it bites at installation, which makes it authorisation rather than consultation.

What raises the stakes is what the privacy code does with that. Compliance with the Statute article is treated as a condition of the lawfulness of the processing itself, so a flawless balancing assessment and a thorough impact assessment do not make the programme lawful if the procedure was never run: they are necessary and they are not sufficient. And the exposure is personal as well as corporate, because the code routes a breach of the first paragraph to criminal penalties running to arrest of between fifteen days and one year, alongside the administrative fines.

There is a second Italian decision, and it is about what your evidence looks like rather than about permission. The data protection authority has endorsed the view that quality monitoring falls outside the Statute article altogether where the worker cannot be identified: voices unattributable at capture, the opening seconds carrying a name discarded, no per-operator report and no tracking. Design a simulation the obvious way, with a scored per-employee record and the audio attached, and you are squarely inside the article and need the agreement or the authorisation first. Design it so nothing is attributable and you are arguing you were never inside it, which for a programme whose whole output is who needs coaching is usually not the design you wanted. Choose deliberately rather than discovering the choice afterwards.

What your company needs to do

6 items, in the order you will need them.

  • Start the article 4 procedure before anything elseItaly-specificDecide early whether you have unitary or company union representatives to agree with, because if you do not, the route is a prior authorisation from the territorial office of the labour inspectorate and that takes its own calendar. The requirement bites at installation, so a project that books this for the month before launch has already missed it.
  • Write the purpose against the three the statute allowsItaly-specificOrganisational and production needs, workplace safety, and protection of company assets are the whole list, and security awareness is not on it. Say which of the three your programme sits under and why, in the words the statute uses, because that framing is what the agreement or the authorisation is granted against.
  • Decide whether results are attributable to a named personItaly-specificThis is the design decision that determines which regime you are in. A scored per-employee record with audio attached is remote monitoring on the authority's own 2012 reasoning. Unattributable capture with no per-person report is the shape it held to be outside the article. Most awareness programmes need the first, so plan for the procedure rather than for the argument.
  • Do the assessments anyway, and do not mistake them for the authorisationThe underlying basis is still the balancing test with a documented assessment, and an impact assessment is still owed. Both are necessary. Neither cures a missing agreement, and the file that treats them as though they did is the one that turns a fine into an unlawfulness finding.
  • Keep a real executive's cloned voice out of the scenarioItaly-specificSince October 2025 an Italian offence punishes disseminating voices altered by artificial intelligence without the person's agreement where unjust harm follows, at one to five years, with a general aggravating circumstance for using such systems as an insidious means. An invented persona does not engage it. If you do clone a named person, hold their written agreement.
  • Originate the calls inside ItalyItaly-specificOperators must block incoming international calls presenting Italian fixed numbers, and Italian mobile numbers unless the end user is verifiably roaming, with a 2026 decision pushing the check upstream to the originating provider. An offshore Italian campaign does not produce suspicious calls, it produces no calls, and the campaign report will not tell you which.

The controls that do the work

How Callstrike is configured, and which provision in Italy each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

The Italian authority's reasoning turns on identifiability and on what the employer ends up able to learn about a named person, which is exactly what the agreement or the authorisation is granted against. The call ends the instant an employee begins to give up a credential, so what the pretext asked for is never spoken into the system and never held. That does not remove the article 4 procedure and this page does not pretend otherwise; it narrows what you are asking the union or the inspectorate to approve, which is the difference between a short conversation and a long one.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The article 4 route puts you across a table from union representatives, and what that conversation is really about is what the exercise does to the people inside it. A second voice that breaks character the moment the call ends, with vishing training in writing the same day and an undertaking that results never enter anybody's disciplinary record, is a concrete commitment you can put into the agreement rather than a promise you make about your intentions.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Nothing here substitutes for the collective agreement or the inspectorate's authorisation, and in Italy that distinction matters more than anywhere else in this portal. What it does is produce the transparency layer the privacy code requires alongside the procedure: a dated record of what staff were told, or a hashed copy of the policy or company regulation you already rely on with a signed attestation of the scope it covers, both dated before the campaign rather than assembled when somebody asks.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

This is the route that keeps teaching while the article 4 procedure runs, and in Italy it also answers the delivery problem. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, and a call opened in a browser never crosses the Italian international interconnect at all, so the blocking rules that decide whether an Italian campaign connects have nothing to reject.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

Article 4, and why a legitimate interest assessment is not enough

Every other page in this cluster tells you to document a basis and consult where a consultation duty applies. Italy is different in kind, and the difference is the single most important thing on this page.

Article 4 of the Workers' Statute provides that audiovisual equipment and other instruments from which the possibility of remote monitoring of workers' activity also derives may be used exclusively for organisational and production needs, for workplace safety, and for the protection of company assets, and may be installed only following a collective agreement concluded with the unitary union representatives or the company union representatives. Where there is no agreement, they may be installed only with the prior authorisation of the territorial office of the National Labour Inspectorate. Four things in that wording matter. The three purposes are exhaustive, and there is no security awareness purpose and no residual business interest purpose in the statute. The trigger is not monitoring as an objective but any instrument from which the possibility of remote monitoring also derives, so incidental capability is enough. The union agreement is the primary route and the Inspectorate is the fallback. And the requirement bites at installation, which makes it prior authorisation rather than consultation.

Article 114 of the Codice Privacy then does something short and consequential. Its entire text is that what article 4 provides remains unaffected. The Data Protection Authority has said what that means in its own words: articles 113 and 114 are Italy's more specific employment rules under Article 88 of the GDPR, and compliance with them constitutes a condition of the lawfulness of the processing. So the consequence is not that you have two obligations running in parallel. It is that a flawless legitimate interest assessment and a thorough impact assessment do not make the processing lawful if the article 4 procedure was never run. They are necessary and they are not sufficient.

The exposure is personal as well as corporate. Article 171 of the Codice Privacy provides that a breach of article 4(1) is punished with the penalties in article 38 of the Workers' Statute, which run to arrest for between fifteen days and one year or a fine, alongside the administrative fines the GDPR provides. That is what makes Italy materially stricter than a jurisdiction with co-determination alone. One drafting note if you go looking: article 38's own consolidated text no longer names article 4, because the cross-reference was struck out, so citing article 38 by itself cites a provision that does not mention the article you breached. The route runs through article 171.

The underlying basis for the processing is still legitimate interests under Article 6(1)(f) with a documented assessment, and consent is still the wrong answer for the usual reasons. Do the impact assessment too. Just do not mistake either of them for the thing that actually authorises the programme in Italy.

Recording, and why the one-party question is the wrong question

Most jurisdictions answer this with a rule about how many people on the call have to agree. In Italy that is not the question that decides it.

The criminal provision, article 617 of the Penal Code, is drawn around communications between other people or otherwise not directed at the person acting. A party to the conversation is not intercepting it in that sense. Article 615-bis separately protects the private sphere of the home, which is worth remembering when your employees work from theirs. And a newer provision, article 617-septies, criminalises the fraudulent dissemination of a recording made by a participant rather than the making of it.

The rule that actually governs is article 4 again. In 2012 the Data Protection Authority examined an operator that recorded all its staff's calls and listened back to a sample for quality purposes. It held that although the recording could serve organisational or production needs, it also permitted remote monitoring of the workers' activity, and that failure to complete the article 4 formalities affected the lawfulness of the processing itself. The finding that did the work was identifiability: each recording carried the operator's code and their own unmasked voice, so the employer could later learn how a named person had performed. The Authority declared the processing unlawful, declared the data unusable, banned further processing until the article 4 procedure was completed and proper notice given, and sent the file to the prosecuting authorities.

That is a more useful answer than a consent rule, because it tells you what to build. The Authority endorsed the Ministry of Labour's view of what takes quality monitoring outside article 4 altogether: measures that do not allow the worker to be identified, with voices unrecognisable and unattributable at capture, the opening seconds that carry a name discarded, no per-operator report and no tracking. Design your evidence that way and the recording stops being remote monitoring. Design it the obvious way, with a scored per-employee record and the audio attached, and it is squarely inside article 4 and needs the agreement or the authorisation first.

An AI voice in Italy, and one offence written for voice cloning

Italy's transposition of the European automated-calling rule is article 130 of the Codice Privacy, and its scope is on the face of the text. It requires the subscriber's agreement for the use of automated calling or communication systems without operator intervention for sending advertising or direct sales material, or for carrying out market research or commercial communication. Four purposes, all commercial. An authorised internal test of your own workforce is none of them, so article 130's consent requirement does not reach it. That is a statement about the rule's scope and not a route around it.

What does reach it is European. Article 50 of the EU AI Act has applied since 2 August 2026. It requires a system built to interact directly with people to be designed so the person is informed they are interacting with an AI system, and requires whoever deploys a system generating or manipulating audio constituting a deep fake to disclose that the content is artificially generated, in both cases at the latest at the time of the first interaction or exposure. The only exceptions on the face of the text are use authorised by law to detect, prevent, investigate or prosecute criminal offence, and evidently artistic or fictional works, where the duty is reduced rather than removed. An employer's own authorisation for a test is not authorisation by law, and the two uses of the word should not be run together. One element is genuinely open, and we will not close it: whether a synthetic voice resembling no identifiable individual meets the definition, which requires resemblance to existing persons, objects, places, entities or events. Where the voice imitates a specific real person it is inside on any reading.

Italy has gone further than the Union on that last point, and this is the paragraph to read twice if you are considering cloning an executive. Since October 2025 article 612-quater of the Penal Code punishes with one to five years' imprisonment anyone who causes unjust harm to a person by transferring, publishing or otherwise disseminating, without that person's agreement, images, video or voices falsified or altered by means of artificial intelligence systems and apt to deceive as to their genuineness. The same law inserted a general aggravating circumstance for committing an offence through artificial intelligence systems used as an insidious means. A simulation using an invented persona does not meet those elements. Cloning the voice of a named real executive to call that company's own staff engages every element except, arguably, the unjust harm, and that is not an element you want to be arguing about afterwards. If you clone a real person's voice, obtain and keep that person's written agreement.

A live operator whose own voice is transformed is a live call rather than an automated system, so article 130 was never in play for it either. It does not move the AI Act line, because the definition there covers content that is generated or manipulated, and transforming a real voice in real time is manipulation.

A second article of that Regulation is worth reading in the same sitting, because whether it applies is settled by a definition rather than by a judgement. It prohibits AI systems used to infer emotions of a natural person in the workplace, in force since 2 February 2025, at up to thirty-five million euros or seven per cent of worldwide turnover, with an exception for medical or safety reasons. An emotion recognition system is defined as one for identifying or inferring emotions or intentions on the basis of biometric data, and biometric data is itself a defined term reaching physical, physiological and behavioural characteristics. So the compliance question for a voice product is not whether the feature feels intrusive. It is whether the inference is drawn from biometric data, and that is a question to answer before the feature is built.

The AGCOM filter that will stop your calls at the border

This is the most operationally consequential section on the Italian page, and it has nothing to do with paperwork.

Since 2025 AGCOM has required operators handling incoming international voice calls on their international network interfaces to block calls that do not comply with the relevant numbering recommendations, to block incoming international calls presenting a national geographic or fixed number as caller identification save in justified cases, and to block incoming international calls presenting a national mobile number after checking and verifying that the end user is not roaming abroad. The technical annex to that decision is blunt about how it is implemented.

The practical consequence is that an Italian simulation has to be originated inside Italy. A call presenting an Italian number but entering the country over an international interconnect will be dropped, regardless of how legitimate it is, how well documented the programme is, or whose number it is. A subsequent 2026 decision moves the obligation further upstream, requiring the originating provider to block at origination where the caller identification does not match, and updates which number classes may be presented. If your test calls never arrive, this is almost certainly why, and no amount of clearance changes it.

The general rule underneath is the one you would expect: the number you present has to be one you are entitled to present, and the originating provider is required to verify that rather than take your word for it.

What the country matrix holds for Italy

Number types:
Mobile, Toll free
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

What Italian law asks of you, and what it does not

The regulatory input here is narrower than most people expect, and it is worth separating from what your supplier will ask for.

Numbering rights of use are granted to authorised operators, not to end users, so there is no filing you make with the regulator to hold a number. The one genuinely statutory obligation touching a business customer concerns mobile services: the Electronic Communications Code requires that customers be identified before activation, with the contract holder's personal details taken from an identity document and a copy retained, and it expressly permits that identification to be carried out remotely or indirectly provided the data are correctly captured. Enforcement is real, with closure of the sales outlet for between five and thirty days as an accessory sanction for breach.

What the regulator does not require is worth stating as a finding rather than leaving as silence. We looked in the national numbering plan, in the Code's numbering and user identification provisions and on AGCOM's own numbering pages, and neither AGCOM nor the ministry publishes any requirement that an ordinary business end user hold an Italian registered address, an Italian company registration, or any identification document beyond the contract holder's own. Where your supplier asks for more, that is its own process rather than Italian law, and the distinction matters when someone tells you a rule requires something.

NIS2, in force here, and what it actually asks for

Italy transposed NIS2 promptly, which is not true of every country in this cluster. The transposing decree entered into force in October 2024. Entities in scope register or update their registration on the national authority's platform between 1 January and 28 February each year, the authority draws up the list of essential and important entities by 31 March, and listed entities supply further information between 15 April and 31 May. If your organisation is in scope, those dates are already part of your calendar.

The substantive hook is in the risk management measures, and two of them bear directly on this work: policies and procedures to assess the effectiveness of cybersecurity risk management measures, and basic cyber hygiene practices and cybersecurity training. Testing whether your people can be talked into something is one of the few ways to assess effectiveness rather than assert it. Note the limit, because it is the same limit everywhere: neither the directive nor the Italian decree names voice phishing as a required technique, and anyone telling you otherwise is selling.

For financial entities DORA applies directly, with compulsory security awareness and resilience training modules for all staff and senior management, a testing programme, and threat-led penetration testing for entities meeting the criteria, operated in Italy through the national implementation of the European framework. Social engineering is a standard technique in that kind of testing and is not named in the Regulation.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in ITALY. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance at the programme level.

Verify or correct each proposition below against primary Italian sources, and tell me in what order we must do things:

1. ⚠ Statuto dei lavoratori art. 4 is PRIOR AUTHORISATION, not consultation: three exhaustive purposes, RSU/RSA agreement as the primary route, INL territorial office as the fallback, biting at INSTALLATION. Assess whether a vishing simulation platform is an instrument from which the possibility of remote monitoring also derives.
2. Codice Privacy art. 114 makes art. 4 compliance a condition of the LAWFULNESS of the processing (Garante provv. 364/2024), so an LIA and a DPIA are necessary and not sufficient.
3. Art. 171 routes a breach of art. 4(1) to the art. 38 penalties (arrest 15 days to 1 year, or a fine). ⚠ Art. 38's consolidated text no longer names art. 4; the route runs through art. 171.
4. Garante provv. 235/2012 held call-centre recording to be remote monitoring on IDENTIFIABILITY. Confirm the conditions under which unattributable capture sits outside art. 4, and whether a per-employee scored programme can ever qualify.
5. Art. 130 is scoped to four commercial purposes, so an internal test is outside the consent requirement.
6. Art. 612-quater c.p. (Legge 132/2025, in force 17.10.2025) reaches disseminating AI-altered voices causing unjust harm. Confirm an invented persona is outside it.
7. AGCOM delibera 106/25/CONS art. 8 and delibera 21/26/CIR require blocking of inbound international calls presenting Italian fixed CLI, and Italian mobile CLI absent verified roaming.
8. Neither AGCOM nor the ministry imposes an Italian registered address or company registration on a business end user; art. 98-undetricies D.Lgs. 259/2003 requires identification of the contract holder before activation.

Flag anything that has changed since September 2026, and identify any obligation in our applicable CCNL that this analysis omits.

Common questions

Do we need union agreement before running a simulation in Italy?
In practice yes. Article 4 of the Workers' Statute requires a collective agreement with the union representatives, or authorisation from the Labour Inspectorate where there is none, before installing an instrument capable of remote monitoring. It is prior authorisation, it bites at installation, and no assessment substitutes for it.
What happens if we skip the article 4 procedure?
More than a fine. The Data Protection Authority treats compliance as a condition of lawfulness, so the processing is unlawful, the data are unusable, and further processing can be banned. Article 171 of the Codice Privacy also routes the breach to criminal penalties running to arrest, and files have been sent to prosecutors.
Can we clone a real executive's voice for the test?
Only with that person's documented written agreement. Since October 2025 an Italian criminal offence punishes disseminating voices altered by artificial intelligence without the person's agreement where unjust harm results, carrying one to five years. An invented persona does not engage it; a named real person very nearly does.
Why do our Italian test calls never connect?
Because they originate outside Italy. AGCOM requires operators to block incoming international calls presenting Italian fixed numbers, and Italian mobile numbers unless the user is verifiably roaming. A 2026 decision pushes the check upstream to the originating provider. Calls have to originate inside Italy.

Elsewhere in Southern Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.