Callstrike
Compliance

Voice phishing simulations in the Netherlands

Phone numbers in the NetherlandsProvisioned by Callstrike after approval

The Dutch answer is unusually well defined, which makes a voice phishing simulation here easier to plan and harder to improvise. Your works council has a consent right over this, the regulator has said out loud what it thinks of recording staff calls to train them, and the rule that governs the number you present carries no purpose limit and no way out of it.

Phone numbers

Supplied by Callstrike

Local numbers in the Netherlands, after a one-time approval.

Running a simulation

Permitted, with the works council's agreement

A decision taken without it is void if the council invokes nullity in writing.

Consent

The published policy is the work

It is what keeps the programme out of the covert-monitoring regime entirely.

Getting a phone number in the Netherlands

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Numbers here are not released from open inventory, so your workspace is cleared once for the country and Callstrike then provisions a dedicated Dutch number against it. The clearance itself is short: the company's name and its address, both evidenced from the commercial register, with the address inside the area the number's prefix covers and never a post box.

The constraint worth understanding before you write a pretext is not the clearance. Dutch law prohibits using number transmission to give the called party incorrect information about the caller, and that test is wider than the usual one about holding a right of use, because it asks what the person was made to believe. Presenting a number your own organisation holds and operates has a real argument under it. Presenting a bank's number, a supplier's number or anyone else's does not.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in the Netherlands is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Business nameExcerpt from the commercial register
Business addressMust be within locality or region covered by the phone number’s prefix; a PO Box is not acceptable where a local address is required.Excerpt from the commercial register, Utility bill, Tax notice, Rent receipt, Title deed

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in the Netherlands?

The position in short, before your counsel reads the detail below.

Yes. The Dutch transposition of the European rule on unsolicited communications is scoped by purpose in every operative paragraph, to commercial, idealistic or charitable purposes, and an authorised security test of your own workforce is none of those three. The second paragraph is the one worth carrying into a supplier conversation, because Dutch law already extends the same rule from automated systems to live human calling. So putting a person on the line neither rescues you from a rule nor drags you into one. There is nothing here to argue about in either direction.

The works council is where the Dutch programme is actually decided. Its agreement is required for any rule about facilities aimed at, or suitable for, observing or controlling the presence, behaviour or performance of the people working in the business. Note the words aimed at or suitable for: being capable of it is enough. A decision taken without agreement is void if the council invokes nullity in writing within a month, and the route past an unreasonable refusal runs through the subdistrict court rather than through persistence.

The design question that really matters is whether your programme is monitoring people who do not know it happens, because that is a separate regime rather than a stricter version of the first. The regulator permits covert monitoring only on a reasonable suspicion of criminal or prohibited conduct, on an incidental basis within a period fixed in advance, with notification afterwards. No simulation can produce a reasonable suspicion. A programme published in advance argues from the ordinary side of that line, because people know monitoring happens and only the moment is withheld. A programme with no published policy has nowhere to argue from at all.

Recording is where the criminal law and the regulator disagree, and the regulator is the one that will reach you. The telecommunications offence carves out recording by or on the instruction of the party entitled to the connection, so an employer recording on its own telephony is outside it. The regulator's position is close to the opposite, and it names this product's shape: you may not covertly record employees' telephone conversations in order to coach, train or assess them. Reasoning from the criminal code alone will leave you confident and exposed.

What your company needs to do

6 items, in the order you will need them.

  • Get the works council's agreement to a written ruleNetherlands-specificThe deliverable is an instrument rather than a project plan: the purpose, the scope, what is collected, who sees it, how long it is kept and what it will never be used for, in a form the council can agree to. Agreement is not needed insofar as the matter is already substantively regulated in a collective labour agreement.
  • Publish the policy before the first campaign, not after itNetherlands-specificIn the Netherlands the policy is doing legal work rather than housekeeping. It is what puts the programme in the ordinary monitoring regime, where staff know that checking happens, instead of the covert one, which requires a reasonable suspicion of criminal conduct that a simulation can never produce.
  • Treat the recording question as the regulator's, not the code'sNetherlands-specificThe published position is that people have the right to know when a conversation is recorded, that a single notice at hire is not enough, that the other party must be told too, and that covert recording to coach, train or assess is not permitted. Either solve notification properly or capture outcomes instead of audio.
  • Document the four cumulative conditionsThe regulator sets them out plainly: necessity, meaning no less intrusive route to the aim; informing staff about what is checked, why, when, how and which data are involved; respect for confidential communication; and an impact assessment with prior consultation where a high residual risk remains.
  • Present a number your own organisation holdsNetherlands-specificThe governing rule has no purpose qualifier and no exemption route, and its test is whether the called party was given incorrect information about the caller. The explanatory memorandum leaves room for uses that harm no third party's interest, which is where a number you hold and operate sits. Nobody has adjudicated the internal extension case, and we are not going to tell you it is settled.
  • Plan for the AI transparency duty rather than around itThe European duties bind here directly even though the Dutch implementing act naming national authorities is still in consultation. The exception on the face of the text is for use authorised by law to detect or prosecute criminal offences, which is a different thing from your own management's sign-off. A national enforcement channel still being built is a reason to comply, not a reason to wait.

The controls that do the work

How Callstrike is configured, and which provision in the Netherlands each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

The first of the regulator's four cumulative conditions is necessity, meaning that you cannot reach the aim in a way less intrusive for employees, and that is the condition a covert exercise finds hardest. A programme that ends the call the moment an employee begins to give up a credential is already the least intrusive version of itself: the aim is measured and the credential is never captured. That is also the concession that makes the works council conversation go somewhere.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The council's consent right attaches because the facility is suitable for observing behaviour, so the negotiation is about what the observation does to people. A call that ends with a second voice explaining what happened, and vishing training in writing the same day, is a design the council can be shown rather than described. Write into the rule that results are never individualised into performance records, because that is the fear the consent right exists to answer.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Here this control does the single most load-bearing job it does anywhere in the portal. Whether your programme sits in the ordinary monitoring regime or in the covert one turns on whether staff were told that checking of this kind happens, and the regulator accepts internal guidelines, rules of conduct or a protocol as the vehicle. A hashed copy of that policy with a signed, timestamped attestation of its scope is the evidence that the answer is the first regime and not the second.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

Where the works council process is still running, or where you would rather not solve the recording notification question at all, this is the route that still teaches. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after the module, and a call a person opens in their own browser is not a telecommunication carrying a presented caller identity, so the rule about what the called party was made to believe has nothing to attach to.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

Legitimate interests, and a second regime for anything genuinely covert

The supervisory authority states the basis in its own words: you need a ground for monitoring your personnel, and often the legitimate interests ground will apply. On the alternative it is equally direct, warning that employees find it difficult to refuse a request from their employer because of the power relationship, so that agreement is not well usable as a ground for monitoring staff. It sets four further cumulative conditions: necessity, meaning you cannot reach your aim in a way less intrusive for employees; informing staff about what is and is not allowed, that checking is possible, why and when you check, how you check and which data are involved; respect for confidential communication; and an impact assessment with prior consultation where a high residual risk remains.

It also says the information may be given through internal guidelines such as rules of conduct or a protocol, which is exactly where a simulation programme belongs.

Now the part that decides how a Dutch programme is designed, and it is a second regime rather than a stricter version of the first. The authority treats monitoring staff without their knowledge as a distinct category which is normally not permitted, and permits it only on a reasonable suspicion that one or more employees are doing something criminal or prohibited, such as theft or fraud, only on an incidental basis within a period fixed in advance, and always with notification of the employees concerned afterwards, including where the suspicion turned out to be unfounded.

No simulation programme can produce a reasonable suspicion of criminal conduct, so the question is whether a simulation is in that category at all. The authority defines the category as monitoring without employees knowing it is happening. A programme run under a published policy that tells staff simulated calls occur satisfies the ordinary duty to inform: they know monitoring happens, they do not know the moment. A programme with no such policy is monitoring people who do not know, and lands in a regime it cannot satisfy.

We could find no published Dutch text resolving the case in between, where the programme is disclosed and the individual test is not. So we are stating the two regimes, stating which side a properly announced programme argues from, and not pretending the boundary has been settled. What we can say plainly is that the policy is doing real legal work in the Netherlands rather than being a formality.

One negative worth recording because it removes a common assumption: there is no Dutch employment derogation of the kind Germany and Finland have. The implementing act has five chapters and no employment chapter, and a full-text search of it returns no occurrence of the article number under which such a derogation would be made.

Not a crime, and still the most exposed part of the programme

Two bodies of law give opposite answers here and both matter, so take them in order.

The criminal code does not stop you. Recording a conversation in a dwelling or enclosed premises is an offence only for someone recording without being a participant and other than on a participant's instruction, and the same article expressly disapplies itself to the recording of data processed or transmitted by means of telecommunication. A telephone call therefore falls to the separate telecommunications offence, which catches intentionally and unlawfully tapping or recording data not intended for you, and then carves out tapping or recording by or on the instruction of the party entitled to the connection used for the telecommunication, save in the case of manifest abuse.

Read the shape of that exemption, because it is narrower and better than a general participant rule. It is keyed to the holder of the connection rather than to anyone on the call, which puts an employer recording on its own telephony squarely inside it, and it is qualified by manifest abuse, which is the clause an aggrieved employee would reach for.

The supervisory authority is where the real constraint lives, and it is close to the opposite of the criminal answer. Its published position is that employees have the right to know when their conversation is being recorded, for example by an audible signal at the start; that informing staff once when they enter employment that you may record their conversations is not enough; that the person your employee is calling must also be told in advance; and that you may almost never record telephone conversations covertly, the exceptions given being threats, bomb threats, and a suspicion that an employee is doing something criminal such as leaking trade secrets.

Then the sentence that names this product's exact shape: you therefore may not covertly record employees' telephone conversations in order to coach, train or assess them.

We are not going to soften that. Anyone reasoning only from the criminal code will conclude that recording a Dutch simulation is fine, and will be wrong about the risk they are carrying. The design answer is the same one that works everywhere else and is simply more necessary here: record what happened and when rather than the conversation, or solve the notification question before switching audio on.

The marketing rule misses you, and it misses live callers too

The Dutch transposition of the European rule on unsolicited communications is scoped by purpose, and the scoping is repeated in every operative paragraph. The prohibition is on using automatic calling and communication systems without human intervention, faxes and electronic messages to transmit unsolicited communication for commercial, idealistic or charitable purposes without the end user's prior agreement. An authorised security test of an employer's own workforce is none of those three things.

The second paragraph is the one worth carrying into a supplier conversation. It applies the same rule to means other than those listed, again for commercial, idealistic or charitable purposes, directed at natural persons. So Dutch law already extends the marketing regime from automated systems to live human calling. The consequence runs both ways and it is the honest version of the human-in-the-loop question: putting a person on the line does not take you out of a rule you were in, because the rule already covers live calls, and using a synthetic voice does not pull you into a rule you were outside, because the rule turns on purpose. There is nothing here to bypass in either direction.

A third paragraph tells a marketing caller it may not withhold its number. It carries the same purpose qualifier, so it does not reach a security test, and the constraint that does is a different article described in the next section.

On disclosing that a voice is synthetic, the European transparency rule in Article 50 of the AI Act has applied since 2 August 2026 and reaches the Netherlands directly. It carries two duties on two different parties: whoever provides a system built to interact with people must design it so the person is informed they are dealing with an AI system, and whoever deploys a system generating or manipulating audio constituting a deep fake must disclose that the content is artificially generated, in both cases at the latest at the time of the first interaction or exposure. The exceptions on the face of the text are use authorised by law to detect, prevent, investigate or prosecute criminal offences, and evidently artistic or fictional works, where the duty narrows rather than disappears. An employer authorising its own test is not authorisation by law.

There is an awkward Dutch footnote to that. The implementing act naming national authorities went into public consultation on 20 April 2026 and the supervisory authority itself describes it as still in consultation. The Regulation set 2 August 2025 as the date by which Member States were to communicate their authorities. So the duty binds here while the national enforcement channel is still being built, which is a reason to comply rather than a reason to wait.

Two more provisions of that Regulation land on an employer here, and the second applies even when the first does not. Inferring emotions of a natural person in the workplace by an AI system is prohibited, since 2 February 2025, at up to thirty-five million euros or seven per cent of worldwide turnover, excepted only for medical or safety reasons, and gated by the definition of an emotion recognition system, which requires inference from biometric data. Emotion recognition is separately listed as a high-risk use, and a deployer who is an employer must inform workers' representatives and the affected workers before putting a high-risk system into service or using it at the workplace. So even a feature that clears the prohibition brings its own duty to tell people first.

One flat rule, no purpose limit, and no way out of it

This is the article to plan a Dutch campaign around, and it is not the one most people find first.

It provides, in a single sentence, that a facility for providing the calling number to the network termination point where the connection is established shall not be used to give the called user incorrect information about that termination point or that individual user. Notice what the test actually is. It is not framed as presenting a number you hold no right of use in. It is framed as giving the called party incorrect information, which is a different and in some ways wider question, and it is exactly the thing a pretext call is designed to do.

Three features make it the hardest constraint on this page. It carries no purpose qualifier, unlike everything in the previous section. The explanatory memorandum states that it is technology neutral and covers both live communication such as a voice call and messaging traffic, and names the signalling protocols including the one used for internet telephony, so an origination over internet protocol is inside rather than outside. And there is no exemption route: the chapter's exceptions provision does not list it, and the exemption available to network and service providers for analogue exchanges does not reach it either.

The memorandum does leave a door open and it is worth quoting the shape of it. It says there can be good reasons for forwarding a number other than the one the connection is established from, in situations where innovative use of number transmission adds value for end users without harming the interests of third parties, and that the article leaves room for certain innovative use. Presenting a number the employer itself holds and operates, in a programme the employer has authorised, has a real argument under that wording because no third party's interest is engaged. Presenting a number belonging to a bank, a supplier or anyone else outside the organisation has none.

We could find no decision or published guidance from the regulator applying this article to authorised security testing, so the boundary is unadjudicated and we are not going to tell you that spoofing an internal extension is lawful. What we can say is where the safer side is.

One structural distinction is worth knowing because it cuts the other way. The act's prohibition on using plan numbers without an allocation expressly does not apply to network-internal numbers. So a purely internal extension sits outside the allocation regime even though the article above draws no such distinction, and the two provisions are testing different things: one asks who the number was allocated to, the other asks what the called party was made to believe.

What the country matrix holds for the Netherlands

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

The works council can stop you, and a court can unstop you

The Dutch works council right is the strongest employee instrument in this batch after Austria's, and it is widely described inaccurately, including by the supervisory authority. Here is what the statute says.

The employer requires the works council's agreement for every proposed decision to adopt, amend or withdraw a rule concerning facilities that are aimed at, or suitable for, observation of or control over the presence, behaviour or performance of the persons working in the undertaking, and separately for a rule on the processing and protection of their personal data, in each case insofar as it relates to all or to a group of them. Note the words aimed at or suitable for. A programme need not be designed to control anyone to be caught; being capable of it is enough.

Two paragraphs then decide how much of a veto that really is, and the regulator's own page omits the second of them. Where the employer has not obtained agreement it may ask the subdistrict court for permission to take the decision, and the court grants permission only where the refusal is unreasonable or where compelling organisational, economic or social business reasons require the decision. And a decision taken without either the works council's agreement or the court's permission is void if the works council invokes nullity in writing, which it may do within one month.

So the accurate statement is that the works council can stop you in the first instance, that running the programme over its objection risks the decision being void rather than merely contested, and that there is a route past an unreasonable refusal which runs through a judge rather than through persistence. Two further scoping facts: agreement is not required insofar as the matter is already substantively regulated in a collective labour agreement, and the obligation to establish a works council applies to undertakings in which as a rule at least fifty persons work.

The practical deliverable is therefore a written rule rather than a project plan. Put the purpose, the scope, what is collected, who sees it, how long it is kept and what it will never be used for into an instrument the works council can agree to, and get that agreement before the first campaign rather than after the first complaint.

A brand new cyber act, and a testing duty that names no technique

The Dutch transposition of the network and information security directive is the Cyberbeveiligingswet, and it is very new: the consolidated text has applied since 15 August 2026 and the article below carries no earlier version to compare against.

Its duty of care requires measures based on an all-hazards approach comprising at least nine listed items, of which two are relevant here. One is basic cyber hygiene practices and training in the field of cybersecurity. The other is policies and procedures to assess the effectiveness of cybersecurity risk management measures. That second limb is the closest anything in the Dutch statute comes to requiring you to test whether your training worked, and it prescribes no method. The word simulation does not appear in the article, and no limb names phishing, voice phishing or social engineering.

For financial entities DORA applies directly and has since 17 January 2025. Its testing regime requires threat-led penetration testing at least every three years for the entities identified for it, performed on live production systems supporting critical or important functions, and its definition describes mimicking the tactics, techniques and procedures of real-life threat actors. It names no attack vector either.

The national threat-led testing framework run by the central bank is explicitly a learning exercise rather than a pass or fail, and its published description says testing potentially targets people, processes and infrastructure without naming a channel. What makes testing mandatory for a given firm is the supervisor's identification under DORA, not the framework itself.

So the honest summary for a Dutch buyer is that two regimes require you to train staff and to check that your measures work, and neither tells you to run a voice phishing test. Anyone quoting either at you as a mandate for this specific technique is going beyond the text.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in the NETHERLANDS. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. A published policy tells staff that simulated calls occur.

Verify or correct each proposition below against primary Dutch sources:

1. Tw art 11.7 is purpose-scoped in every operative limb (commercial, idealistic, charitable), and para 2 extends the same rule to live human calling. ⚠ Art 11.7 was amended with effect from 1 July 2026; confirm the scoping survived.
2. Tw art 11.10a prohibits using number transmission to give the called user incorrect information about the caller, with NO purpose qualifier and no exemption route (art 11.13 does not list it; the art 11.12 ontheffing does not reach it). Advise on presenting a number our own organisation holds.
3. WOR art 27(1)(k) and (l) require works council agreement; art 27(4) gives a kantonrechter route where refusal is unreasonable; art 27(5) makes the decision void on written invocation of nullity within a month. ⚠ The AP's own page omits art 27(4).
4. Sr art 139c(2)(2) exempts recording by or on the instruction of the party entitled to the connection, but the AP states covert recording to coach, train or assess staff is not permitted. Which governs our exposure in practice?
5. Whether a programme disclosed in policy but not per call falls in the AP's 'heimelijke controle' category. ⚠ We found no published Dutch text resolving this.
6. The Uitvoeringswet contains no Art 88 employment derogation.

Flag anything that has changed since September 2026, and tell me the status of the Dutch AI Act implementing act.

Common questions

Can the works council block a vishing programme in the Netherlands?
In the first instance yes, and a decision taken without its agreement is void if it invokes nullity in writing within a month. But the employer may ask the subdistrict court for permission, which is granted where the refusal is unreasonable or compelling business reasons require the decision.
Is recording a simulated call a criminal offence here?
No. The telecommunications offence carves out recording by or on the instruction of the party entitled to the connection, and an employer recording on its own telephony is inside that carve-out. The regulator's position is the real constraint: covert recording to coach, train or assess staff is not permitted.
Does the Dutch marketing rule stop an automated calling system?
Only for commercial, idealistic or charitable purposes. Every operative limb carries that qualifier, and the second one extends the same rule to live human calling. So an authorised internal security test is outside it whether the caller is a person or a synthetic voice.
Can we present an internal number the employee recognises?
Approach it carefully. The rule prohibits using number transmission to give the called user incorrect information about the caller, with no purpose qualifier and no exemption route. Presenting a number your own organisation holds has an argument; presenting a bank's or a supplier's number does not.

Elsewhere in Western Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.