Voice phishing simulations in the Netherlands
The Dutch answer is unusually well defined, which makes a voice phishing simulation here easier to plan and harder to improvise. Your works council has a consent right over this, the regulator has said out loud what it thinks of recording staff calls to train them, and the rule that governs the number you present carries no purpose limit and no way out of it.
Phone numbers
Supplied by Callstrike
Local numbers in the Netherlands, after a one-time approval.
Running a simulation
Permitted, with the works council's agreement
A decision taken without it is void if the council invokes nullity in writing.
Consent
The published policy is the work
It is what keeps the programme out of the covert-monitoring regime entirely.
Getting a phone number in the Netherlands
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Numbers here are not released from open inventory, so your workspace is cleared once for the country and Callstrike then provisions a dedicated Dutch number against it. The clearance itself is short: the company's name and its address, both evidenced from the commercial register, with the address inside the area the number's prefix covers and never a post box.
The constraint worth understanding before you write a pretext is not the clearance. Dutch law prohibits using number transmission to give the called party incorrect information about the caller, and that test is wider than the usual one about holding a right of use, because it asks what the person was made to believe. Presenting a number your own organisation holds and operates has a real argument under it. Presenting a bank's number, a supplier's number or anyone else's does not.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in the Netherlands is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Business name | Excerpt from the commercial register |
| Business addressMust be within locality or region covered by the phone number’s prefix; a PO Box is not acceptable where a local address is required. | Excerpt from the commercial register, Utility bill, Tax notice, Rent receipt, Title deed |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in the Netherlands?
The position in short, before your counsel reads the detail below.
Yes. The Dutch transposition of the European rule on unsolicited communications is scoped by purpose in every operative paragraph, to commercial, idealistic or charitable purposes, and an authorised security test of your own workforce is none of those three. The second paragraph is the one worth carrying into a supplier conversation, because Dutch law already extends the same rule from automated systems to live human calling. So putting a person on the line neither rescues you from a rule nor drags you into one. There is nothing here to argue about in either direction.
The works council is where the Dutch programme is actually decided. Its agreement is required for any rule about facilities aimed at, or suitable for, observing or controlling the presence, behaviour or performance of the people working in the business. Note the words aimed at or suitable for: being capable of it is enough. A decision taken without agreement is void if the council invokes nullity in writing within a month, and the route past an unreasonable refusal runs through the subdistrict court rather than through persistence.
The design question that really matters is whether your programme is monitoring people who do not know it happens, because that is a separate regime rather than a stricter version of the first. The regulator permits covert monitoring only on a reasonable suspicion of criminal or prohibited conduct, on an incidental basis within a period fixed in advance, with notification afterwards. No simulation can produce a reasonable suspicion. A programme published in advance argues from the ordinary side of that line, because people know monitoring happens and only the moment is withheld. A programme with no published policy has nowhere to argue from at all.
Recording is where the criminal law and the regulator disagree, and the regulator is the one that will reach you. The telecommunications offence carves out recording by or on the instruction of the party entitled to the connection, so an employer recording on its own telephony is outside it. The regulator's position is close to the opposite, and it names this product's shape: you may not covertly record employees' telephone conversations in order to coach, train or assess them. Reasoning from the criminal code alone will leave you confident and exposed.
What your company needs to do
6 items, in the order you will need them.
- Get the works council's agreement to a written ruleNetherlands-specificThe deliverable is an instrument rather than a project plan: the purpose, the scope, what is collected, who sees it, how long it is kept and what it will never be used for, in a form the council can agree to. Agreement is not needed insofar as the matter is already substantively regulated in a collective labour agreement.
- Publish the policy before the first campaign, not after itNetherlands-specificIn the Netherlands the policy is doing legal work rather than housekeeping. It is what puts the programme in the ordinary monitoring regime, where staff know that checking happens, instead of the covert one, which requires a reasonable suspicion of criminal conduct that a simulation can never produce.
- Treat the recording question as the regulator's, not the code'sNetherlands-specificThe published position is that people have the right to know when a conversation is recorded, that a single notice at hire is not enough, that the other party must be told too, and that covert recording to coach, train or assess is not permitted. Either solve notification properly or capture outcomes instead of audio.
- Document the four cumulative conditionsThe regulator sets them out plainly: necessity, meaning no less intrusive route to the aim; informing staff about what is checked, why, when, how and which data are involved; respect for confidential communication; and an impact assessment with prior consultation where a high residual risk remains.
- Present a number your own organisation holdsNetherlands-specificThe governing rule has no purpose qualifier and no exemption route, and its test is whether the called party was given incorrect information about the caller. The explanatory memorandum leaves room for uses that harm no third party's interest, which is where a number you hold and operate sits. Nobody has adjudicated the internal extension case, and we are not going to tell you it is settled.
- Plan for the AI transparency duty rather than around itThe European duties bind here directly even though the Dutch implementing act naming national authorities is still in consultation. The exception on the face of the text is for use authorised by law to detect or prosecute criminal offences, which is a different thing from your own management's sign-off. A national enforcement channel still being built is a reason to comply, not a reason to wait.
The controls that do the work
How Callstrike is configured, and which provision in the Netherlands each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
The first of the regulator's four cumulative conditions is necessity, meaning that you cannot reach the aim in a way less intrusive for employees, and that is the condition a covert exercise finds hardest. A programme that ends the call the moment an employee begins to give up a credential is already the least intrusive version of itself: the aim is measured and the credential is never captured. That is also the concession that makes the works council conversation go somewhere.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The council's consent right attaches because the facility is suitable for observing behaviour, so the negotiation is about what the observation does to people. A call that ends with a second voice explaining what happened, and vishing training in writing the same day, is a design the council can be shown rather than described. Write into the rule that results are never individualised into performance records, because that is the fear the consent right exists to answer.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Here this control does the single most load-bearing job it does anywhere in the portal. Whether your programme sits in the ordinary monitoring regime or in the covert one turns on whether staff were told that checking of this kind happens, and the regulator accepts internal guidelines, rules of conduct or a protocol as the vehicle. A hashed copy of that policy with a signed, timestamped attestation of its scope is the evidence that the answer is the first regime and not the second.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Where the works council process is still running, or where you would rather not solve the recording notification question at all, this is the route that still teaches. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after the module, and a call a person opens in their own browser is not a telecommunication carrying a presented caller identity, so the rule about what the called party was made to believe has nothing to attach to.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.