Callstrike
Compliance

Voice phishing simulations in Malta

Phone numbers in MaltaProvisioned by Callstrike after approval

Malta is the one country in this portal whose telecoms regulator has already written about this exact product, and it drew the line in your favour: manipulating the identity you present is not spoofing where there is no malicious intent. A voice phishing simulation runs here on unusually clear ground, and what Malta asks of you is documentary rather than procedural.

Phone numbers

Supplied by Callstrike

Local numbers in Malta, after a one-time approval.

Running a simulation

Permitted, on the regulator's own reasoning

The communications authority addressed the caller identity question directly and carved out honest use.

Consent

Rarely free, always evidenced

The regulator says employees are seldom able to agree freely, so this is your record of notice.

Getting a phone number in Malta

One approval per country, with no documentation to gather.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days.

Malta is one of the few countries where the carrier publishes no documentation requirement at all, so the evidence-gathering that dominates most of this portal has no counterpart here. What you are waiting on is the country being enabled against your workspace rather than a regulator reading a submission, and the planning that does matter is about your provider rather than about a form.

The Maltese constraint runs through the operator, and it is worth knowing before you design around a display number. Where a Maltese number is presented as the calling identity on a call placed through an overseas or decoupled platform, the undertaking must validate the subscriber and be able to show that only validated end users holding the right of use for that number are using it, with technical verification such as a one-time password delivered in a call to the number itself and revalidation every quarter. Since November 2024 operators of international network interfaces must block all incoming calls over those interfaces carrying a Maltese calling number from the main national ranges. So this is a procurement conversation with your provider rather than a policy one, and the answer is that you present a number you genuinely hold.

  1. 01Ask for the country to be enabled for your workspaceYour administrator, in the Callstrike console.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Malta is assigned to youCallstrike
  4. 04Build and launch the campaignYour team

No regulatory documentation is required to hold a number here. The clearance step is Callstrike enabling the country for your workspace, with no forms to complete and no evidence to gather.

Is it lawful to run a simulation in Malta?

The position in short, before your counsel reads the detail below.

Yes, and Malta is the country where the answer needs the least construction. The Maltese transposition of the European rule on unsolicited communications is scoped by purpose on every limb: no publicly available service may be used to make an unsolicited communication for the purpose of direct marketing by automatic calling machine, fax or electronic mail without prior written agreement, and a further paragraph applies the same gate to any other means used for direct marketing. An authorised internal test markets nothing, so the regulation does not reach it, and nothing turns on whether the caller is a person or a synthetic voice. The honest limit is that direct marketing is defined nowhere in the instrument or its parent act, so the boundary of the scoping is undefined even though the scoping is clear.

Recording is easier here than almost anywhere in this cluster, and the reason is structural rather than interpretive. Maltese criminal law contains no general eavesdropping offence at all; the only interception offence sits inside the computer misuse provisions and turns on whether the person was duly authorised by someone entitled to control the activity, not on who was on the call. The confidentiality rule in the communications instrument then excepts you by its opening words, which bind any person other than the user.

That comfort comes with a documentation requirement attached, and it is the most operationally important line on the Maltese page. The Criminal Code says it is not for the prosecution to negative any authorisation, that the burden of proving it lies on whoever alleges it, and that the burden is not discharged by the uncorroborated testimony of the person charged. Read that plainly: in Malta the written, signed, corroborated authorisation for the programme is not governance hygiene. It is the evidence you would have to produce, and your own account of it would not be enough. Get the sign-off in writing, from someone entitled to give it, before the first call rather than after a complaint.

The paperwork is where Malta actually bites. The regulator's published list catches an exercise like this on four independent limbs and only one is needed: systematic monitoring, the use of innovative technologies, employees named expressly as vulnerable data subjects, and an employee-monitoring limb covering processing that evaluates performance or increases the power imbalance, particularly where employees may be unable easily to agree to or oppose it. Deception is exactly the condition that last limb describes. One helpful counterpart: the regulator says in terms that assessments are not subject to its authorisation, so this is a document you produce and keep rather than a submission you wait on.

What your company needs to do

6 items, in the order you will need them.

  • Get the authorisation in writing, signed, and corroboratedMalta-specificThe burden of proving authorisation lands on whoever alleges it, and the Code says an uncorroborated account from the person charged does not discharge it. Name who authorised the programme, what it covers, and who else can attest to it. This is the single most useful hour anyone spends on a Maltese campaign.
  • Write the impact assessment and keep itMalta-specificThe regulator's list catches this on four separate limbs, so whether one is owed is not a judgement call. It also says assessments need no authorisation from it, which means nothing here is waiting on the regulator: produce the document, keep it current, and be able to hand it over.
  • Settle the display number with your provider, not with a policyMalta-specificEvery decision here is addressed to undertakings rather than to you, so you are bound through your provider's validation gate. Expect right-of-use verification and quarterly revalidation, and expect a Maltese number presented from outside the country over an international interface to be blocked.
  • Give the notice at the start of the processing, not after it beginsThe regulator says employees should not be informed once monitoring has already started, and that the required information belongs at the commencement phase. Programme-level notice given in advance is our reading of what satisfies that for an exercise of this kind, and we are labelling it as a reading: the regulator has published nothing on simulations.
  • Use an invented persona, never a named real colleagueMalta-specificThe aggravated tier of the computer misuse offences reaches misuse of another person's personal data to gain a third party's trust, causing prejudice to the rightful identity owner, which describes impersonating a named employee. A generic help desk is not a person. This is a scenario-design decision rather than a paperwork one.
  • Inform and consult where you employ fifty or moreThe regime is real, carries no veto, and is priced unusually: the sanction is a fine calculated for every employee of the undertaking rather than per breach, so the exposure scales with headcount. Below fifty the regulations never commenced at all. Check your own collective agreement separately, because those are private and can go further than the law.

The controls that do the work

How Callstrike is configured, and which provision in Malta each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

The regulator's assessment list reaches processing that evaluates an employee's performance or increases the power imbalance, particularly where employees cannot easily oppose it, and it tells you to consider the least invasive measure available. The call ends the instant an employee begins to give up a credential, so the credential is never spoken into the system and never stored, and the least-invasive answer is a design choice you can evidence rather than a claim you make in the assessment.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

Malta's 2025 addition creates an offence for using an address or domain likely to deceive the recipient as to the sender's identity, or otherwise using an electronic communications network for those purposes, and its gate is knowing intent to cause harm. A call that ends with a second voice breaking character and vishing training in writing the same day is the clearest evidence of the opposite intent, produced by the exercise itself rather than asserted about it.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

The regulator's position is that employees are rarely able to agree genuinely and freely because of the imbalance, so other than exceptionally the ground has to be a different one. Where this earns its place in Malta is evidential: a dated, signed and timestamped record of what staff were told, or a hashed copy of the policy or handbook clause you rely on with an attestation of its scope, is corroboration of exactly the kind the Criminal Code says your own testimony cannot supply.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

The Maltese telephone route is unusually comfortable, so this earns its place for reach rather than for risk. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, and a browser call presents no calling number at all, so the validation and blocking machinery your provider operates has nothing to check.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

No national employment rules, and an assessment you cannot argue out of

Malta did not use the European opening clause for employment-specific rules, and it is worth showing how that negative was established rather than asserting it. The data protection act's own arrangement runs through eight parts covering preliminary matters, applicability, restrictions and prior authorisation, transborder transfers, the Commissioner, fines, appeals and general provisions. There is no employment part, article or heading. The subsidiary legislation series under it runs to fourteen instruments and stops, and none of them is about employment. The power to extend the act to a particular activity or sector exists and is simply unused.

So the basis is the ordinary one, and the regulator is clear about the alternative. Its published position is that employees are rarely in a position genuinely and freely to agree because of the power imbalance in the employer relationship, so that other than in exceptional situations an employer would have to rely on a different ground. On legitimate interests it warns that the threshold is high and that the employer must consider what would be the least invasive measure.

The part that is not arguable is the impact assessment. The regulator's published list of processing requiring one catches a simulation on four independent limbs, and only one is needed. Systematic monitoring is one. The use of innovative technologies or new methods in existing technology is another. Employees are expressly named as vulnerable data subjects, which is a third. And the employee-monitoring item itself is the fourth, covering processing for the evaluation or scoring of aspects of an employee's performance at work, or where the processing increases the power imbalance between the data subject and the controller, particularly where employees may be unable easily to agree to or oppose the processing of their data.

Read that last limb against how a simulation works. Deception means the employee cannot oppose the processing at the time, which is the condition the limb describes. So the assessment is mandatory here on the regulator's own criteria rather than on a judgement call. One helpful counterpart: the regulator states expressly that assessments are not subject to its authorisation, so this is a document you produce and keep rather than a submission you wait on.

One more duty shapes the design. The regulator says employees should not be informed after monitoring has already started, and that the information required must be provided at the commencement phase of the processing cycle. We read that as satisfied by programme-level notice given in advance rather than by disclosure of each call, and we are labelling that as our reading: the regulator has published nothing on phishing or voice phishing simulation, and we searched for it.

No eavesdropping offence, and a burden of proof that lands on you

Malta is the most permissive jurisdiction in this cluster on recording, and the reason is structural rather than a matter of interpretation.

There is no general eavesdropping offence in Maltese criminal law. We searched all four hundred and twenty-three pages of the Criminal Code for the word and it does not appear. The only interception offence sits inside the computer misuse provisions and catches a person who, without authorisation, intercepts by technical means non-public transmissions of data to, from or within an information or computer system. The act then defines the test: a person acts without authorisation if not duly authorised by an entitled person, and an entitled person is one who is himself entitled to control the relevant activities. So the question is authorisation, not who was on the call.

The confidentiality rule that would otherwise bite is in the electronic communications instrument, and it excepts you by its opening words: no person other than the user shall listen, tap, store or undertake any other form of interception or surveillance of communications without the agreement of the user concerned. A user is defined as any natural person using a publicly available electronic communications service for private or business purposes. The same regulation separately preserves legally authorised recording in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication. Breach of that regulation is an administrative fine rather than an offence.

Now the sentence that turns this from comfortable into a documentation requirement, and it is the most operationally important line on the Maltese page. The Criminal Code provides that it is not necessary for the prosecution to negative any authorisation, that the burden of proving such authorisation lies on the person alleging it, and that the burden is not discharged by the uncorroborated testimony of the person charged. So the written, signed, corroborated authorisation for the programme is not governance hygiene in Malta. It is the evidence you would need to produce, and your own account of it would not be enough.

Two further exposures are worth naming because a scenario can walk into them. The aggravated tier of the computer misuse offences includes an offence committed through the misuse of another person's personal data with the aim of gaining the trust of a third party, thereby causing prejudice to the rightful identity owner, which is a description of impersonating a named real colleague. And a 2025 addition creates an offence for whoever, knowingly with intent to cause harm, uses an address or domain likely to deceive the recipient as to the identity of the sender, or otherwise makes use of an electronic communications network for those purposes. That closing limb is wide enough to reach a voice call; the gate is knowing intent to cause harm, which an authorised test with a debrief does not carry.

Direct marketing, and no voice analogue to the email identity rule

The Maltese transposition of the European rule on unsolicited communications is scoped by purpose on every limb, and the drafting is unusually clean.

A person shall not use, or cause to be used, any publicly available electronic communications service to make an unsolicited communication for the purpose of direct marketing by means of an automatic calling machine, a facsimile machine or electronic mail, to a subscriber or user, irrespective of whether that subscriber or user is a natural or a legal person, unless prior written agreement has been given. A further paragraph applies the same gate to any other means of communication used for the purpose of direct marketing. So an authorised internal security test, which markets nothing, sits outside the regulation entirely, and nothing turns on whether the caller is a person or a synthetic voice.

One detail is worth knowing because it is the reverse of what people assume. The regulation does prohibit disguising or concealing the identity of the sender, and that prohibition is confined to electronic mail. There is no voice analogue in the instrument. The caller identity constraint in Malta comes from the telecoms regulator instead, and it is set out in the next section.

Direct marketing is not defined anywhere in the instrument or its parent act, and we checked the definitions that are imported from the two related chapters. We would rather tell you the boundary is undefined than pretend it is bright.

On disclosing a synthetic voice, the European transparency rule reaches Malta directly. Article 50 of the AI Act has applied since 2 August 2026 and carries two duties on two different parties: a provider must design a system built to interact with people so the person is informed they are dealing with an AI system, and a deployer of a system generating or manipulating audio constituting a deep fake must disclose that the content is artificially generated. Both must be satisfied at the latest at the time of the first interaction or exposure, which is in direct tension with an undisclosed pretext call. An employer running the exercise is a deployer, so the second duty is the one that lands on you.

Malta has designated an authority for the AI Act, which puts it ahead of most of this cluster, and the designation does not reach either of the provisions that matter here. The instrument designates the data protection commissioner as market surveillance authority for a closed list of high-risk systems covering biometrics for law enforcement, border management, justice, emergency call triage, migration and asylum, and gives powers over four prohibited practices. It cross-references Articles 5, 18, 23 and 77 and nothing else. The transparency article is not mentioned in it at all.

One more provision of that Regulation applies here without any national instrument standing behind it, which is worth saying on a page about a country whose domestic AI legislation predates the Regulation entirely. Using an AI system to infer emotions of a natural person in the workplace is prohibited outright, has been since 2 February 2025, and carries up to thirty-five million euros or seven per cent of worldwide turnover, with an exception only for medical or safety reasons. No local transposition is needed for it to bite and none can soften it. The gate is the definition of an emotion recognition system, confined to inference from biometric data, so a programme that records what people did rather than what they felt is outside it.

The regulator drew the line itself, and it drew it in your favour

This is the most useful section in the portal, because for once the answer is not ours. Malta's communications authority published a decision notice in April 2024 whose title names caller identity spoofing and voice phishing scams, and it addresses the exact distinction a simulation turns on.

The decision itself is strict. Where a Maltese number is to be presented as the calling line identity on a call placed through an overseas or decoupled solution, the undertaking must employ subscriber validation processes and be able to ensure that such solutions are used only by validated end users who hold the right of use for that Maltese number. The validation parameters include technical verification of the right of use, for example by a one-time password delivered in a call to the number itself, and revalidation on a quarterly basis. Since November 2024, operators of international network interfaces must block all incoming calls over those interfaces carrying a Maltese calling number from the main national ranges.

And then the footnote, which is the sentence to take to a procurement conversation. The authority records that there can be legitimate reasons for the calling identity of an outbound call to be manipulated by the caller, giving as its example calls from the mobile phones used by a company's employees presenting the same company's contact number to the called party, and states that such manipulation would not constitute spoofing if there is no malicious intent.

So the Maltese answer is two-sided and unusually precise. You may present a number you do hold the right of use in, including through a decoupled platform, subject to your provider's validation. You may not present a Maltese number you do not hold. And the regulator has already said in terms that manipulating the presented identity without malicious intent is not the mischief it is regulating.

Two structural notes. Every decision is addressed to undertakings rather than to you, so you are bound indirectly, through your provider's validation gate, which makes this a procurement conversation rather than a policy one. And the authority expressly put call-origination authentication schemes out of scope of this notice, so do not expect a Maltese equivalent of the American attestation regime.

We could not find a Maltese statutory prohibition binding the caller directly. We searched the electronic communications act and its subsidiary legislation in full; the nearest analogue is confined by its opening words to a person employed with or attached to an undertaking, which is telecoms personnel rather than a customer. So the obligation runs through the operator, and that is the honest shape of it.

What the country matrix holds for Malta

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Inform and consult, with a fine counted per employee

Malta's employee consultation regime is real, bounded, and carries no veto. We say that having read the definitions rather than having assumed it.

The regulations define consultation as the exchange of views and establishment of dialogue between the employees' representatives and the employer, and information as the transmission by the employer to those representatives of data enabling them to acquaint themselves with the subject matter and examine it. Neither definition contains the words agreement, approval or assent. The strongest outcome duty is that the representatives must be able to meet the employer and obtain a reasoned response to any opinion they express, and that consultation on the relevant category takes place with a view to reaching agreement on decisions within the scope of the employer's powers. With a view to reaching agreement describes the aim of the process; it is not a condition of acting.

The threshold is fifty employees and above, reached by a phased commencement that ran from the largest undertakings in 2006 down to fifty and above in March 2008, so below fifty the regulations never came into force at all rather than merely not applying.

What happens if you skip it is unusual and worth pricing. The sanction is a fine calculated for every employee of the undertaking, within a range set per employee rather than per breach. That is a different shape of exposure from a single administrative penalty and it scales with headcount.

The parent employment act adds nothing on this subject. We searched its full text for surveillance, monitoring, privacy, data protection and personal data, and every one of them returns nothing; its only relevant provision is the power under which these regulations were made.

One honest limit on the no-veto finding. It rests on the statutory instruments, and Maltese collective agreements are private and unpublished. A unionised employer should check its own agreement, because the European opening clause permits employment rules to be made by collective agreement as well as by law, and we can only speak to the law.

One order, one deadline missed, and no technique named anywhere

Malta transposed the European network and information security directive by a single measure, and it is an order rather than an act: the measures for a high common level of cybersecurity order, published in the government gazette on 8 April 2025 against a transposition deadline of 17 October 2024.

What that regime requires of people is the standard formulation, basic cyber hygiene practices and cybersecurity training. It is worth being precise about how thin the connection to this technique is, because the directive is routinely quoted as though it mandated testing. Across the directive's full text, voice phishing appears zero times, simulation appears zero times, and phishing and social engineering appear once each, both in the same recital, which is not binding. The binding provision says only basic cyber hygiene practices and cybersecurity training.

For financial entities DORA applies directly. Its counts are starker still: phishing zero, social engineering zero, voice phishing zero, simulation zero across the whole Regulation. Its nearest provision requires compulsory security awareness programmes and digital operational resilience training for all employees and senior management, and its testing regime requires threat-led penetration testing at least every three years for entities in scope, defined by reference to mimicking real threat actors and naming no channel.

The only binding text in the whole stack that mentions social engineering is the delegated regulation supplementing DORA, and it does so twice as a constraint rather than a requirement: the tester must possess knowledge of it, and the red team test plan must state the techniques allowed and not allowed, including ethical boundaries for social engineering. A compliant plan may put it entirely in the not-allowed column.

So no Maltese or European instrument requires this technique, and the term counts are the reason we can say that flatly rather than cautiously.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in MALTA. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance at the programme level.

Verify or correct each proposition below against primary Maltese sources, and tell me what we must hold on file before the first call:

1. ⚠ MCA Decision Notice MCA/D/24-5278 footnote 7 records that manipulating the outbound calling identity is NOT spoofing absent malicious intent, giving a company's employees presenting the company's own number as the example. Confirm it is current and identify its limits.
2. There is NO general eavesdropping offence in the Criminal Code; the only interception offence (art 337C) turns on authorisation by an entitled person, and S.L. 586.01 reg 4 excepts 'the user'.
3. ⚠ Criminal Code art 337F(6) puts the burden of proving authorisation on the person alleging it and says uncorroborated testimony does not discharge it. Tell us what corroboration should look like.
4. IDPC's DPIA list catches this on four independent limbs, and the IDPC states DPIAs are not subject to its authorisation.
5. S.L. 586.01 reg 9 is scoped to direct marketing on every limb, and the identity-concealment prohibition is confined to electronic mail with no voice analogue. 'Direct marketing' is undefined.
6. ⚠ S.L. 586.14 designates the Commissioner only for Arts 5, 18, 23 and 77 and never mentions Art 50, so the transparency duty binds with no designated Maltese enforcement authority. Confirm, and confirm it is the IDPC rather than the MDIA.
7. S.L. 452.96 applies at 50+ employees, contains no veto, and its sanction is a fine calculated per employee of the undertaking.
8. Art 337I's aggravated tier reaches misuse of another person's personal data to gain a third party's trust; confirm an invented persona is outside it.

Flag anything that has changed since September 2026, and identify any obligation in our own collective agreement that this analysis omits, since those are unpublished.

Common questions

Can we present our own company number on a Maltese simulation?
The regulator has addressed this directly. Its decision notice records that there can be legitimate reasons for a caller to manipulate the presented identity, giving a company's employees presenting the company's own contact number as the example, and says that is not spoofing where there is no malicious intent.
Is recording a simulated call lawful in Malta?
There is no eavesdropping offence, and the confidentiality rule expressly excepts the user, so the answer is generally yes. But the Criminal Code puts the burden of proving authorisation on whoever alleges it and says an uncorroborated account from the person charged does not discharge it. Get it in writing.
Is a data protection impact assessment optional here?
No. The regulator's published list catches a simulation on four independent limbs, and only one is needed. The employee-monitoring limb covers processing where employees may be unable easily to oppose it, which is what deception means. Assessments need no authorisation from the regulator.
Who enforces the AI Act transparency duty in Malta?
Nobody yet, on the face of the designation. Malta designated its data protection commissioner for a closed list of high-risk systems and four prohibited practices, and the instrument does not mention the transparency article at all. The duty still binds you, because a Regulation applies without national machinery.

Elsewhere in Southern Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.