Callstrike
Compliance

Voice phishing simulations in Norway

Phone numbers in NorwayProvisioned by Callstrike after approval

Norway permits a voice phishing simulation against your own staff and Callstrike supplies the Norwegian number, and the country has the most specific employee-monitoring statute in this portal. Two questions have to be answered under two different acts, and the one that can actually stop a programme is not about consent or notice at all.

Phone numbers

Supplied by Callstrike

Local numbers in Norway, after a one-time approval.

Running a simulation

Permitted, if the burden is proportionate

Objective justification in your own circumstances, and no disproportionate burden.

Consent

The weaker position, not the stronger

The regulator's clear main rule is that it is unavailable to an employer here.

Getting a phone number in Norway

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Norwegian numbers are not released from open inventory, so your workspace is cleared for Norway once and Callstrike then provisions a dedicated number against that clearance. This is the heaviest filing in the region and the part that catches companies out is not the company evidence, it is the person: alongside proof of who the business is and an address inside Norway that is not a post box, the carrier wants proof of the authorised representative's identity from a Norwegian-issued document, and proof that the person is authorised to act. Decide who that representative is going to be before the filing starts, because a group signatory sitting in another country is the answer that does not work.

The rule that decides whether a Norwegian campaign connects is not addressed to you at all, which makes it easy to miss and impossible to argue with. Providers must block calls and messages where the calling end user has no right of use in the number presented, where the number cannot be routed, or where the call concerns fraud, and they must keep statistics on what they blocked and why. A Norwegian simulation presenting a number the organisation does not hold is not exposed to a later argument about legality. It is designed to be dropped before it rings. Withholding your own number, by contrast, is an ordinary end user facility and is lawful.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Norway is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Proof of business identityNorwegian certificate of registration
Proof of business addressMust be within Norway; a PO Box is not acceptable.Norwegian certificate of registration, Utility bill
Proof of authorized representative's identityMust be issued in NorwayNorwegian government-issued ID, Norwegian passport
Proof of authorizationMust show name of Authorized RepresentativePower of attorney, Norwegian certificate of registration

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Norway?

The position in short, before your counsel reads the detail below.

Yes, and the structural point to carry into any internal discussion is that two questions are governed by two different acts and both have to be answered. Whether you may introduce a control measure at all is a labour law question under chapter 9 of the working environment act. Whether you may process the personal data the measure produces is a data protection question. The supervisory authority states plainly that the two acts apply in parallel, so a programme that has done a lawful basis assessment and skipped the labour law procedure has answered half of it.

Chapter 9 has two limbs doing different jobs, and the first is the gate that can genuinely stop you. You may implement a control measure in relation to an employee only where it has objective justification in the undertaking's circumstances and does not involve a disproportionate burden on the employee. That second half is not about agreement and not about notice. It asks whether the burden you are imposing is out of proportion to the reason for imposing it, which is a question a badly designed campaign can fail on its own facts, and it is the reason scenario design belongs in the compliance conversation rather than after it.

The second limb is procedural, and its verbs are the whole answer. As early as possible you must discuss the need, the design, the implementation and any significant change with the employees' elected representatives. Before the measure is implemented you must give affected employees information about its purpose, its practical consequences including how it will be carried out, and its anticipated duration. And you must, together with those representatives, regularly evaluate the need for what you have implemented. Discuss and inform are not obtain agreement: you decide, but you may not decide without having discussed first, and the evaluation duty keeps running rather than being ticked at launch. The regulator's position is that it applies whether or not there is a union in the workplace. Where a collective agreement applies there is a further layer with its own control-measure provision.

On the European instruments the honest answer is a position rather than a verdict, and Norway is one of only two countries in this portal where that is true. Norway is in the European Economic Area and not in the Union, so an instrument marked as relevant to the Area reaches it only once a decision of the EEA Joint Committee incorporates it into the Agreement's annexes. The three instruments people ask about have not moved together. The financial resilience regulation completed that route, was incorporated by a Joint Committee decision taken in February 2025, and the supervisory authority gives its Norwegian entry into force as July 2025. The EU AI Act and the network and information security directive are both recorded on EFTA's own register as under scrutiny with no Joint Committee decision, so they are not incorporated. That means the duty to disclose that audio is artificially generated, which our German and Dutch pages spend a section on, is an absence in Norway today rather than a permission, and we have found no Norwegian domestic duty supplying one. The register is where you check, because this is the position that will change first.

What your company needs to do

6 items, in the order you will need them.

  • Answer the disproportionate-burden question in writingNorway-specificThis is the Norwegian gate and it is substantive rather than procedural. Record the objective justification in your own undertaking's circumstances, then set the burden on the individual against it: who is called, how often, what happens to someone who fails, and why a less intrusive method would not achieve the purpose. A campaign can fail here on its design while every other box is ticked.
  • Discuss with the elected representatives as early as possibleNorway-specificThe duty is to discuss the need, the design, the implementation and any significant change, and the regulator says it runs whether or not there is a union in the workplace. You decide at the end of it, but you may not decide before it, so book the conversation against the design phase rather than against the launch date.
  • Inform affected staff before the measure startsSeparately from the discussion, and before implementation, tell the people affected the purpose, the practical consequences including how it will be carried out, and the anticipated duration. Anticipated duration is the item most notices omit, and it is the one that turns a standing programme into something people can hold you to.
  • Diarise the standing evaluationNorway-specificThe act requires you, together with the elected representatives, to regularly evaluate the need for the measures implemented. That is a continuing obligation rather than a launch task, and a programme that ran for three years without one revisit has a visible gap. Build the record as you go, because assembling it afterwards is how a programme discovers it skipped the step.
  • Treat the European instruments as a position, not an answerNorway-specificDo not assume the AI transparency duties reach Norway, and do not assume they never will. What is sourceable is the incorporation status on EFTA's own register, and it differs per instrument: the financial resilience regulation is in, and the other two show no Joint Committee decision. Check the register at the point you plan the campaign rather than relying on this page's date.
  • Decide whether the programme needs audioThe criminal provision reaches recording a conversation between others or a meeting the recorder does not take part in, so a participant is outside it. The regulator is restrictive quite independently of that, and its published answer is that as a rule you may not record your staff's telephone conversations, with exceptions such as securities firms and some telephone sales and customer service. Treat the regulator's position as the operative constraint rather than the criminal threshold.

The controls that do the work

How Callstrike is configured, and which provision in Norway each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

Chapter 9's gate is whether the control measure imposes a disproportionate burden on the employee, which is a question about the exercise rather than about your paperwork, and it is the one a Norwegian programme can actually fail. The call ends the moment an employee begins to give up a credential, so the burden is a conversation that stopped rather than a credential in somebody's system and a file recording that a named person handed it over. That is the difference between a proportionate measure and one an elected representative can reasonably object to.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

You have to discuss design and implementation with the elected representatives before you decide, and then keep evaluating with them, so the thing you are repeatedly being asked is what happens to the person who fails. A second voice that breaks character the instant the call ends, with vishing training in writing the same day, is the concrete answer, and it belongs in the information you give affected staff about the practical consequences of the measure.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

The supervisory authority's clear main rule is that you may not use agreement as the basis for control measures that monitor employees, so collecting signatures in Norway buys you a weaker position rather than a stronger one. What this produces instead is the two records the working environment act actually asks for: dated evidence of the information given to affected staff before the measure started, and a hashed copy with a signed scope attestation of the policy or collective agreement you rely on.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

This is the route to use while the chapter 9 discussion and the standing evaluation are still running, and it also steps around the blocking regime that quietly kills Norwegian campaigns. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner opens themselves after working through the module, and a call started in a browser never presents an A number to a Norwegian provider, so the duty to block calls with no right of use has nothing to act on.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

Two statutes running in parallel, and only one of them is the GDPR

Norway reaches the European data protection rules by a different road from an EU member state, and its own statute says so in its first section: the EEA Agreement annex provision covering Regulation 2016/679 applies as Norwegian law with the adaptations that follow from the annex, the protocol and the Agreement. That is worth noticing rather than glossing, because the same mechanism is what leaves two other instruments outside Norwegian law entirely, as the last section explains.

The supervisory authority is unusually direct about consent. Its published position is that as a clear main rule employers cannot use consent as a lawful basis for introducing control measures that involve monitoring employees, because of the uneven power relationship and the pressure an employee may feel. The basis it names instead is the balancing of interests under Article 6(1)(f). Anyone offering to solve your Norwegian programme by collecting signatures is offering you a weaker position, not a stronger one.

The structural point worth carrying into any internal discussion is that two questions are governed by two different statutes and both must be answered. Whether the employer may introduce a control measure at all is a labour law question under chapter 9 of the working environment act. Whether it may process the personal data the measure produces is a data protection question. The authority states plainly that the two acts apply in parallel. A programme that has done a lawful basis assessment and skipped the labour law procedure has answered half the question.

On the employment specifics, Norway does have dedicated rules: the data protection act has its own provision on special categories in the employment relationship, and the working environment act authorises a regulation on employer access to an employee's mailbox. We are not going to describe this as an Article 88 derogation, because no notification instrument could be found and the difference between having employment-specific rules and having formally derogated is the kind of detail this page exists to get right.

Lawful under the penal code, restricted by the regulator anyway

The criminal provision is narrower than people expect and it turns on one word. It punishes whoever unjustifiably, using technical means, secretly listens to or records a telephone conversation or other communication between others, or negotiations in a closed meeting in which he does not himself take part. The phrases are between others and in which he does not himself take part. A participant is neither, so a participant recording is outside the offence. The supervisory authority puts the same rule in one sentence: to avoid the penal code you must yourself be present when making a recording.

That is where the comfortable reading stops. The same authority's position on employers recording their staff is restrictive quite independently of the criminal law. Its published answer is that as a rule the employer cannot record employees' telephone conversations, with some exceptions such as securities firms and, in some cases, telephone sales and customer service. There is no bespoke recording regime to fall back on either, because the authority states that the data protection rules contain no separate provisions on audio recording. So the criminal law is permissive here and the regulator is not, and a page citing only the penal code would send you off confidently in the wrong direction.

One duty that sounds like it constrains you does not. The confidentiality obligation in the electronic communications act runs to providers and installers and those working for them, not to an employer commissioning a test. It reaches your telephony supplier in the chain rather than you.

The practical consequence is the same as elsewhere and worth stating in Norwegian terms: decide whether the programme needs audio before you design it. Recording what happened and when raises none of this.

Norway already separates a live caller from a voice machine

The marketing act draws exactly the distinction this industry argues about, and then draws it somewhere that does not help. Its rule is that in business activity it is prohibited, without the recipient's prior consent, to direct marketing approaches to natural persons by electronic communication methods permitting individual communication, such as electronic mail, fax or an automated calling system, the statute's own parenthesis being talemaskin, a voice machine. The next paragraph then says the prior consent requirement does not apply to marketing where the person is contacted orally by telephone.

So Norwegian law does distinguish a human speaking from a machine speaking, and it treats the machine more strictly. But both limbs are inside the words marketing approaches and in business activity. An authorised test of an employer's own staff is not a marketing approach and is not directed at people as a market, so neither limb reaches it. The reservation register works the same way, being scoped to telephone marketing directed at consumers.

The error to avoid is the tempting one. Reasoning that Norway regulates automated voice calls, therefore a simulation using a synthetic voice needs consent, is a scope mistake: the rule that regulates automated voice calls regulates them as marketing. And the reverse dodge is not available either, because nothing here turns on the presence of a human once you are outside marketing altogether.

As for a duty to tell the person that the voice is synthetic, Norwegian law has none that we could find. We searched the marketing act, the copyright act and the supervisory authority's own material on artificial intelligence. The European transparency rule that would supply one has not been made applicable here, for the reasons set out in the final section, so today the answer is an absence rather than a permission.

A blocking duty, not a penalty, and it is the reason a spoof fails

Norway's answer to caller identification is more useful than most because it is not phrased as a prohibition on you at all. It is phrased as an instruction to the network.

The electronic communications regulation provides that providers of public electronic communications networks and of public number-based person-to-person communication services shall block calls and text messages where the calling end user does not have a right of use in the A number, where the A number cannot be routed, or where the call or message concerns fraud. Providers must additionally keep statistics on which numbers were blocked, how many times, and on what ground.

Read that as an operational fact rather than a legal one. A simulation presenting a Norwegian number the organisation does not hold is not merely exposed to some later argument about legality. It is designed to be dropped before it rings. That makes the planning question concrete: originate from a number your organisation or its supplier genuinely holds a right of use in, and confirm that with the supplier before the campaign rather than after the first day of silent failures.

The permission side is worth knowing too. Withholding your own number is an ordinary end user facility under the same regulation, and there is a defined secret number service. Hiding your number is lawful. Wearing somebody else's is not.

What the country matrix holds for Norway

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Discuss it before you build it, and write down what you discussed

Chapter 9 of the working environment act is the most specific employee-monitoring provision anywhere in this portal, and it is the thing to get right in Norway. It has two limbs and they do different jobs.

The substantive limb permits an employer to implement control measures in relation to an employee only where the measure has objective justification in the undertaking's circumstances and does not involve a disproportionate burden on the employee. That second half is the gate that can actually stop a programme. It is not about consent and not about notice; it is about whether the burden you are imposing is out of proportion to the reason you are imposing it, which is a question a badly designed campaign can fail.

The procedural limb is a duty to discuss, and its verbs matter. The employer is obliged as early as possible to discuss the need, the design, the implementation and any significant change of control measures with the employees' elected representatives. Before the measure is implemented the employer shall give the affected employees information about its purpose, its practical consequences including how it will be carried out, and its anticipated duration. And the employer shall, together with the elected representatives, regularly evaluate the need for the measures implemented.

Note what those verbs are not. Discuss and give information are not obtain agreement. The employer decides, but may not decide without having discussed first, and the evaluation duty is continuing rather than a box ticked at launch. The regulator's position is that the duty runs whether or not there is a union in the workplace. Where a collective agreement applies there is a further layer: the basic agreement between the main employer and employee organisations carries its own control-measure provision requiring discussion, requiring measures not to go beyond what is necessary and to be objectively justified in the individual undertaking's activity and needs, and inviting a local agreement on design and implementation where either side wants one. We cite that as the 2022 to 2025 edition, because we could not establish the text of the current term and would rather date the citation than imply it is the latest.

So the Norwegian deliverable is a record: what was discussed, with whom, when, what the purpose and duration are, what information went to affected staff before launch, and the standing evaluation. Build it as you go, because assembling it afterwards is how a programme discovers it skipped the step.

One instrument arrived, two have not, and the register is where you check

This is the section where Norway differs from every EU country in this portal, and the difference is procedural rather than political. An instrument the Union marks as EEA relevant does not become law in Norway on its own. It has to be incorporated into the EEA Agreement by a decision of the EEA Joint Committee, and where it requires legislative change or has budgetary consequences the Norwegian constitutional reservation has to be lifted first. The three instruments people ask about have not moved together, and the register that answers this is EFTA's own EEA-Lex.

DORA, the financial sector digital resilience regulation, has completed the whole route. It was incorporated by Joint Committee Decision 40 of 2025, adopted on 20 February 2025, the Norwegian constitutional requirement was recorded as fulfilled on 27 May 2025, and the financial supervisory authority gives its Norwegian entry into force as 1 July 2025. Its practical content for our readers is threat-led penetration testing at least every three years for the entities identified for it.

The EU AI Act has not been incorporated. EFTA's register records it as marked EEA relevant by the Union and under scrutiny for incorporation into the EEA Agreement by Iceland, Liechtenstein and Norway, with no Joint Committee Decision recorded at all. So the transparency duties that our German and Dutch pages spend a section on, including the duty to disclose that audio content is artificially generated, are not Norwegian law today. We state that with the mechanism and the register attached rather than as a bare verdict, because the position will change and the reader needs to know where to look.

NIS2, the network and information security directive, is in the same position: recorded as under scrutiny, no Joint Committee Decision, not incorporated. What Norway actually has is the digital security act, which implements the earlier 2016 directive and was brought into force on 1 October 2025 alongside its regulation. A successor is in preparation. So a Norwegian entity's cybersecurity baseline is the older regime, while a Norwegian bank is already inside the newer financial one, which is an odd shape and an accurate one.

On threat-led testing, the national implementation of the European red-teaming framework exists and is run by the central bank with the financial supervisor. Its own published description says it imitates the tactics, techniques and procedures of real-life attackers. It does not name social engineering, phishing or voice phishing, and it does not say whether participation is mandatory. We are not going to fill either gap for you.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in NORWAY. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance.

Verify or correct each proposition below against primary Norwegian sources:

1. Arbeidsmiljoloven § 9-1 permits a control measure only where it has 'saklig grunn i virksomhetens forhold' AND does not involve 'uforholdsmessig belastning' on the employee. Assess our design against the second limb specifically.
2. § 9-2 requires discussion with elected representatives as early as possible on need, design, implementation and significant change; information to affected employees before implementation on purpose, practical consequences and anticipated duration; and regular joint evaluation. None of those is agreement.
3. Personopplysningsloven § 1 applies the GDPR as Norwegian law via EEA Annex XI no. 5e, and Datatilsynet's clear main rule is that consent is unavailable to an employer for control measures, with interesseavveiing under Art 6(1)(f) instead.
4. ⚠ EEA STATUS, PER INSTRUMENT, from EFTA's EEA-Lex register: DORA incorporated by JCD 40/2025 (constitutional requirement fulfilled 27.05.2025, in force 01.07.2025); the AI Act and NIS2 under scrutiny with NO Joint Committee Decision. Confirm each separately and give the current position rather than an answer either way.
5. Straffeloven § 205 reaches recording of a conversation 'mellom andre' or a meeting the recorder does not take part in, so a participant is outside it. Datatilsynet is nonetheless restrictive on employers recording staff calls.
6. ⚠ The automated-calling rule is markedsforingsloven § 15, not § 13, and both its limbs are inside 'markedsforingshenvendelser' and 'naeringsvirksomhet'. § 12 is the Reservasjonsregister and is scoped to consumer telephone marketing.
7. Ekomforskriften § 9-5 obliges providers to BLOCK calls where the calling end user has no right of use in the A number, and to keep blocking statistics.
8. Digitalsikkerhetsloven implements the 2016 directive and came into force 01.10.2025; a NIS2 successor is in preparation.

Flag anything that has changed since September 2026. ⚠ A widely repeated 2026 Norwegian rule protecting personal characteristics including voice, with a deepfake labelling duty, could not be traced to any primary source and is not relied on here: tell us if a real instrument now exists. ⚠ efta.int and regjeringen.no return HTTP 403 to a plain fetcher, so check the register in a browser.

Common questions

Does the EU AI Act apply in Norway?
Not today. Norway is in the EEA but not the EU, so an EEA-relevant instrument reaches it only once the EEA Joint Committee incorporates it. EFTA's register records the AI Act as still under scrutiny with no decision taken, so its transparency duties are not Norwegian law yet.
Do we need the works council's agreement in Norway?
There is no agreement requirement. The working environment act obliges the employer to discuss the need, design, implementation and any significant change with elected representatives as early as possible, and to inform affected staff before launch. The employer decides, but not before discussing.
Can we record simulated calls in Norway?
The penal code does not stop you, because it reaches recording of conversations between others rather than by a participant. The data protection authority is restrictive anyway, saying employers as a rule cannot record staff calls. Treat the regulator's position as the operative constraint, not the criminal threshold.
What happens if we present a number we do not hold?
The call is meant to be blocked. Norwegian providers must block calls where the calling end user has no right of use in the presented number, and must keep statistics on those blocks. Withholding your own number is lawful; presenting someone else's is a campaign that quietly fails to connect.

Elsewhere in Northern Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.