Callstrike
Compliance

Voice phishing simulations in Poland

Phone numbers in PolandProvisioned by Callstrike after approval

Poland has the only criminal offence in this portal whose listed purposes map onto a voice phishing simulation almost word for word, carrying three months to five years, with no exemption for authorised testing anywhere in the act. Testing your own staff is lawful and numbers are supplied. What has to be designed deliberately is the identity your calls present, because that is where the offence's two elements sit.

Phone numbers

Supplied by Callstrike

Local numbers in Poland, after a one-time approval.

Running a simulation

Permitted, but the number decides

The sharp Polish constraint is the identity you present, not the testing itself.

Consent

Not a title you can lean on

Refusing or withdrawing it may not count against staff, which leaves it little weight.

Getting a phone number in Poland

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

The Polish filing runs on the company register rather than on your premises, which makes it one of the shorter ones in this region. An excerpt from the business register evidences the company name and the registration number, and a power of attorney or other official document shows that the person filing may act for the company. Your administrator's own name is typed into the form rather than evidenced by anything.

Notice what is absent, because most of Poland's neighbours ask for it: there is no local address row and no premises document to chase. The constraint that will actually shape the campaign is not in the filing at all. The regulator's recommendations require an operator to ensure that an end user can initiate a voice call only from a number assigned to that subscriber under its own contract, and operators are separately obliged to block a call or hide its calling number where the identification does not check out against the ported and made-available databases. A dedicated Polish number held for your workspace answers that. An improvised display value dies on the wire.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Poland is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Authorization of authorized representativePower of attorney, Other official documentation identifying the person as an authorized representative
Business nameExcerpt from a relevant business register
Business registration numberExcerpt from a relevant business register such as national ID

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Poland?

The position in short, before your counsel reads the detail below.

Yes for the exercise, and the reason is worth having precisely. The rule that looks most threatening to a synthetic caller, the prohibition on automatic calling systems, is scoped to the purpose of sending commercial information, which the statute imports as information intended directly or indirectly to promote the goods, services or image of an entrepreneur. An internal security test promotes none of those, so the article is not engaged and nothing turns on whether a person or a synthetic voice is speaking. Note also which act you are reading: the telecommunications law that carried the old automated-calling rule was repealed in November 2024, and it is still widely cited.

The Polish problem is elsewhere, and this is the paragraph to take to your counsel. A dedicated act on combating abuse in electronic communications makes it an offence, carrying three months to five years, to use address information indicating another person when initiating a voice call in order to impersonate another entity, for the purpose of persuading the recipient to hand over personal data, passwords or access codes. Read that list against what an exercise is for. There is no exemption for authorised testing, penetration testing, simulation, audit or agreement anywhere in the act, and a full-text search for each of those words returns nothing.

Two elements cut in your favour, and they are why the decision this page opened with is the whole Polish answer. The address information has to indicate a person other than the calling user, and the use has to be unauthorised. A campaign presenting your own organisation's number, with your own authority, engages both of those on their face. No Polish source resolves it, so treat that as the strongest available argument rather than as an answer, and record the authority in writing before the first call. One asymmetry is worth knowing while you weigh it: the administrative fine beside the offence reaches only a telecommunications undertaking, so a company that is not one has the crime as its whole exposure and nothing else.

The employment side is more ordinary but it has a gap we would rather show you than fill. Monitoring has to be set out in a collective agreement, in the work regulations or in a formal notice, and staff informed two weeks before it starts. But the labour code's security purposes attach to video monitoring, while the limb that would otherwise catch a simulation is scoped to organisation of work and proper use of work tools. Whether a simulated call is monitoring within that article at all, and whether it could serve those purposes if it were, is not settled by the text. Anyone who answers that confidently has not read the purpose gate.

What your company needs to do

7 items, in the order you will need them.

  • Present a number your own organisation holds, and record the authorityPoland-specificThis is the Polish decision and it cannot be deferred to the campaign build. The offence needs address information indicating someone other than the calling user, used without entitlement. Presenting your own number under your own written authority is what engages both elements, so put the authorisation in the programme file before anything is dialled rather than reconstructing it afterwards.
  • Start both two-week clocks, because they run one after the otherPoland-specificStaff have to be informed of the introduction of monitoring, in the manner customary at your company, no later than two weeks before it starts. Work regulations themselves take effect two weeks after being communicated. Using the work regulations route therefore serves both periods sequentially, so quoting only the monitoring notice understates your lead time by a fortnight.
  • Write down which purpose you say the exercise servesPoland-specificDo not assume the other-forms-of-monitoring limb is a general security catch-all: it is scoped to work organisation and proper use of work tools, and the security purposes sit in the video article instead. Record the purpose you are actually relying on and why, because the gap is in the statute and your file is the only place it gets addressed.
  • Deal with the union before you fix the wordingWork regulations are established in agreement with the workplace trade union, and where the content is not agreed within the period the parties set, or where no union operates, you establish them yourself. Several unions must present a jointly agreed position within thirty days or you decide after considering their separate ones. Above fifty employees the works council is owed information and consultation as well.
  • Give new joiners the information before they start workSeparately from the two-week notice, the information about monitoring has to be given in paper or electronic form before an employee is admitted to work. That is an onboarding change rather than a campaign one, and it is the part that quietly lapses once the first campaign is over.
  • Use an invented persona, never a named colleagueImpersonating another person and using their image, personal data or other identifying data, thereby causing them material or personal harm, carries six months to eight years. The harm element is doing the work, but cloning a named executive moves the exercise toward the offence. A generic help desk is not another person.
  • Put the exercise into the dignity regulations arriving in November 2026Poland-specificFrom 5 November 2026 an employer with at least ten employees, far below the fifty that gates the works council, must set rules and procedures against violation of employee dignity and personal rights, agreed with the union or employee representatives. A deliberate deception exercise is exactly what will have to be reconciled with that document, so write it in rather than around it.

The controls that do the work

How Callstrike is configured, and which provision in Poland each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

Be clear about what this does and does not reach in Poland, because the honest answer is narrower here than almost anywhere else in this portal. It does not dispose of the abuse offence: that offence is built around the purpose of persuading someone to hand data over, and the statute draws no line at whether the credential is actually captured. What it does answer is the labour code's closed list of data you may demand, which admits other data only where necessary to exercise a right or perform a legal obligation. The call ends the moment an employee begins to give up a credential, so there is no new category of data to justify holding at all, and the record the exercise leaves is who did what rather than what they said.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The monitoring articles require monitoring not to infringe employee dignity and other personal rights, and from November 2026 a separate set of regulations on exactly that has to exist at ten employees and above. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is a concrete term you can put into that document rather than an intention you describe to a union at the point they ask.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Poland gives agreement almost no weight as a title: the labour code says in terms that its absence or withdrawal may not be a basis for unfavourable treatment or any negative consequence, and the regulator says it will not be frequent as a legal title because of the imbalance between the parties. So this is not what makes the programme lawful. What it produces is the two-week notice, dated, plus the before-admission copy each new joiner is owed, and a hashed record of the work regulations or collective agreement the monitoring was set out in.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

This is the route that answers the Polish offence at its own elements rather than arguing with them. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module. The offence is written about a person who, when initiating a voice call, uses address information indicating another person, and a session a learner opens in their own browser initiates no voice call and presents no address information for the words to attach to. The operator-side blocking recommendations have nothing to act on either.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

The regulator names a basis, and the purposes do not fit

Start with what the Polish authority actually says, because it differs from the answer most of this portal gives. Its published position on employer processing generally names the contract and legal-obligation grounds rather than legitimate interests, and it says the employee's agreement will not be frequent as a legal title because agreement must be a free act, which given the imbalance of the parties in an employment relationship will as a rule not be satisfied. Separately, on monitoring specifically, it identifies legitimate interests as the ground and requires a prior careful assessment described as a balancing test, plus a demonstration that the purpose cannot be achieved by other, less intrusive means, and that the measure is proportionate to the purpose.

The statutory frame around that is a closed list. The labour code enumerates the data an employer may demand, and permits other data only where necessary to exercise a right or perform an obligation arising from a provision of law. A separate article allows agreement to ground processing of data outside that list, and then removes most of its value: the absence of agreement, or its withdrawal, may not be a basis for unfavourable treatment nor cause any negative consequences.

Now the part that does not fit, and we would rather show you the gap than fill it. The authority's own account of the monitoring regime is that the labour code permits monitoring only for purposes strictly specified in it, and those purposes divide. For video monitoring they are ensuring the safety of employees, protecting property, controlling production, and keeping secret information whose disclosure could expose the employer to damage. For email monitoring and other forms of monitoring they are ensuring an organisation of work enabling full use of working time and the proper use of the work tools made available to the employee.

So the security purposes attach to the video regime, and the regime that would otherwise catch a simulation is scoped to work organisation and tool use. Whether a simulated call is monitoring within that article at all, and whether it could serve those purposes if it were, is not settled by the text. We are not going to resolve it in either direction, and a supplier who tells you the answer confidently has not read the purpose gate.

One thing that is settled and worth knowing: the authority's binding list of processing requiring an impact assessment expressly names workplaces, giving monitoring of information systems, email, software used and access cards as examples, on the criterion of systematic monitoring combined with vulnerable data subjects. The heading that category sits under speaks of publicly accessible places, which does not obviously describe a workplace, and that tension is in the published text rather than in our reading of it.

An offence about information you were not entitled to

The Polish criminal provision is built around entitlement rather than around who was present, and reading its elements is what answers the question.

It punishes whoever, without authorisation, obtains access to information not intended for him by opening a closed writing, connecting to a telecommunications network, or breaking through or circumventing its protection; and separately whoever, for the purpose of obtaining information to which he is not entitled, installs or uses a listening device, a visual device, or another device or software. Disclosing information obtained that way carries the same penalty. The range is a fine, restriction of liberty, or up to two years, and prosecution takes place only on the motion of the injured party rather than of the state's own motion.

There is no all-party agreement rule anywhere in the text. The first limb requires information not intended for the person, obtained by one of four listed means, none of which is taking part in a call; the second requires the purpose of obtaining information to which the person is not entitled. We are stating those elements rather than the conclusion, because we could not source a Polish court decision or regulator position resolving participant recording, and this portal does not assert holdings it has not read.

The telecommunications side points the same way and is easier. The confidentiality provision directs its prohibition at persons other than the sender and the recipient of the electronic communication, and it carries an express permission for recording communications applied in lawful commercial practice to provide evidence of a commercial transaction or for communication purposes in commercial activity.

One adjacent offence deserves naming because a scenario can walk into it. Impersonating another person and using their image, personal data or other data by which they are publicly identified, thereby causing them material or personal harm, carries six months to eight years and is again prosecuted on the injured party's motion. The harm element is doing the work there, and it is why impersonating a named real colleague rather than a generic role is a decision worth taking deliberately and getting that colleague's agreement to in writing.

Commercial information is the gate, and the old article is repealed

The first thing to get right is which act you are reading. The telecommunications law that carried the automated-calling rule was repealed on 10 November 2024, and the corresponding article of the act on providing services by electronic means was repealed by the same instrument on the same day. Both were replaced by the electronic communications law, which entered into force that day. Anyone citing the old provisions is citing repealed law, and they are still widely cited.

The current rule is scoped by purpose. It prohibits using automatic calling systems, and telecommunications terminal equipment in particular within interpersonal communications services, for the purposes of sending commercial information within the meaning of the act on providing services by electronic means, including direct marketing, to a subscriber or end user without prior agreement. The imported definition of commercial information is any information intended directly or indirectly to promote the goods, services or image of an entrepreneur or of a person exercising a regulated profession.

So the gate is the purpose of sending commercial information, not the fact of automated calling. An authorised internal security test promotes no goods, no services and no image, and sits outside the article on the face of the text. Nothing turns on whether a person or a synthetic voice is speaking, and there is correspondingly nothing for a live operator to bypass. The penalty if the article did apply is worth knowing for scale: up to three per cent of the previous year's revenue or one million zloty, whichever is higher.

Two small honest notes. The act nowhere defines an automatic calling system; the phrase occurs only in the prohibition and in the corresponding penalty provision. And a breach of the prohibition is additionally declared an act of unfair competition, which opens a private route as well as a regulatory one.

The European transparency rule reaches Poland directly. Article 50 of the AI Act has applied since 2 August 2026, requiring the person to be informed they are interacting with an AI system and requiring a deployer of a system generating or manipulating audio constituting a deep fake to disclose it, at the latest at the time of the first interaction or exposure, with exceptions only for use authorised by law to detect, prevent, investigate or prosecute criminal offences and for evidently artistic works. Poland designated its authority for that in an act in force since 11 August 2026, roughly a year past the Regulation's own deadline. The designation is real; the machinery is not yet, because the chapters carrying inspection, proceedings and fines do not enter into force until late October 2026. The duty binds regardless, since a Regulation does not wait for national machinery.

The other article of that Regulation to settle before building anything is the emotion prohibition, and the practical line it draws is easier to hold than the legal argument about it. Inferring emotions of a natural person in the workplace by an AI system has been prohibited since 2 February 2025, at up to thirty-five million euros or seven per cent of worldwide turnover, with an exception for medical or safety reasons. A programme that records whether a person disclosed a credential, whether they verified the caller and whether they reported it afterwards is recording conduct, and conduct is not emotion. A product that ranks employees by how convincingly they were deceived, or by how anxious they sounded, has crossed into the definitional argument, and the tier it argues in is the highest one there is.

A criminal offence written around a spoofed pretext call

This is the section that should shape a Polish programme, and the answer is adverse. We are not going to soften it.

Poland has a dedicated act on combating abuse in electronic communications. It prohibits, as one of several named abuses, the unauthorised use by a caller of address information indicating a person other than that caller, serving to impersonate another entity, in particular for the purpose of inducing fear, a sense of threat, or persuading the recipient to a particular behaviour, especially to hand over personal data, to make a disadvantageous disposal of property, or to install software.

The criminal provision then narrows that into elements. Whoever, for the purpose of obtaining a material benefit, a personal benefit, or causing damage to another person, when initiating a voice call uses, not being entitled to do so, address information indicating another person in order to impersonate another entity, for the purpose of persuading the recipient to hand over personal data, to make a disadvantageous disposal of property or to install software, or to hand over computer passwords, access codes or other data enabling unauthorised access to information stored in a system or network, is liable to imprisonment from three months to five years.

Read that list against what a vishing simulation is for. Handing over personal data, passwords or access codes is the exercise. The statute draws no line at whether the credentials are actually captured or abused. There is no exemption for authorised testing, penetration testing, simulation, audit or agreement anywhere in the act; a full-text search for each of those words returns nothing.

Two structural points cut in your favour and we would rather you had them precisely than vaguely. The address information must indicate a person other than the calling user, and the use must be unauthorised, so where a vendor presents the client employer's own number with that employer's authority there is a real argument on both elements. And the intent element is the only genuine filter, though it is wider than fraud: the three branches are material benefit, personal benefit, and causing damage, and personal benefit is a non-pecuniary advantage that need not accrue to the person acting. The administrative prohibition beside it is broader still, because its purposes are prefaced with words meaning in particular and are therefore illustrative rather than elements, so conduct can be a prohibited abuse without being an offence.

One asymmetry worth knowing: the administrative fine reaches only a telecommunications undertaking. An employer or a vendor that is not one sits outside the fining regime, and its whole exposure is the crime.

Finally, the operational layer, which is where such a call actually dies. Undertakings are obliged to block the voice call or hide the calling number identification in order to prevent this abuse, and the regulator's recommendations require an operator to ensure that an end user can initiate a voice call only from a number assigned to that subscriber in its own contract with that provider, and recommend hiding the identification where there is a mismatch against the ported and made-available number databases. A third party presenting a client's extension over its own carrier is the exact pattern those provisions exist to defeat.

What the country matrix holds for Poland

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Two separate two-week clocks, and a new instrument arriving

Polish procedure is specific and there is more of it than a single notice period.

The purposes, scope and manner of applying monitoring must be laid down in a collective labour agreement, in the work regulations, or in a formal notice where the employer is not covered by a collective agreement and is not obliged to establish work regulations. The employer must inform employees of the introduction of monitoring, in the manner customary at that employer, no later than two weeks before it is started up. And before admitting an employee to work the employer must give them that information in paper or electronic form. Those provisions are pulled into the email and other-forms-of-monitoring regime by an express cross-reference.

The second clock is easy to miss and it is sequential rather than concurrent. Work regulations themselves enter into force two weeks after being communicated to employees, and the employer must acquaint an employee with their content before admitting them to work. An employer using the work regulations route therefore serves both periods one after the other, so quoting only the monitoring notice understates the lead time.

On who has to be consulted, the answer is negotiation with a unilateral fallback rather than agreement. Work regulations are established by the employer in agreement with the workplace trade union organisation, and where the content is not agreed within a period set by the parties, or where no union operates at that employer, the employer establishes them. Where several unions exist they must present a jointly agreed position, and if they do not do so within thirty days of receiving the document the employer decides after considering their separate positions. Work regulations are mandatory at fifty employees and above, and between twenty and forty-nine only if a union requests them.

The works council route is information and consultation, not agreement. The relevant act binds employers carrying on economic activity with at least fifty employees, requires information about actions which may cause significant changes in the organisation of work or in the bases of employment, and requires consultation on that category conducted in good faith and with a view to enabling agreement to be reached. Enabling agreement to be reached is a description of the process, not a requirement to obtain it.

One structural note that catches out anyone citing older material: the labour code no longer contains the collective agreements chapter at all. It was repealed and replaced by a dedicated act in force since 13 December 2025, so the monitoring article still names a collective agreement as one of the three instruments while the rules for making one now live outside the code.

Finally, something arriving that is squarely on point. From 5 November 2026 an employer with at least ten employees, a much lower threshold than the fifty that gates the works council act, must set the rules, procedures and frequency of measures against violation of employee dignity and other personal rights, against unequal treatment, against discrimination and against mobbing, in a dedicated set of regulations agreed with the union or, where none operates, with employee representatives, again with a thirty-day fallback. The monitoring articles already require monitoring not to infringe employee dignity and other personal rights, so a deliberate deception exercise is exactly the kind of measure that will have to be reconciled with that document.

Transposed in April, and invisible in the consolidated text

Poland has transposed the network and information security directive, which is worth saying plainly because the commonly repeated position that it is still outstanding is out of date. The amending act was promulgated on 2 March 2026 and entered into force on 3 April 2026, roughly seventeen months after the deadline.

There is a trap in checking that for yourself, and it is the reverse of the usual one. The cybersecurity act's most recent consolidated text was promulgated on 9 January 2026, seven weeks before the amending act, and the amending act operates on that consolidation. So reading the latest consolidated text gives pre-transposition law, while the official portal labels the base act as having a consolidated version, which reads as reassurance. The transposition is real; the consolidation has not caught up.

What the transposed regime requires of people is modest. The security measures provision lists, among technical and organisational measures appropriate and proportionate to assessed risk, policies and procedures for assessing the effectiveness of those measures, cybersecurity education for the entity's personnel, and basic cyber hygiene principles. A separate provision requires the head of a key or important entity to undergo training once each calendar year, documented. We searched the amending act and the consolidated act for the Polish terms for social engineering, phishing, voice phishing, simulation and penetration testing: every one of them returns zero occurrences in both documents.

The closest thing to a staff-testing provision is in an annex, and it carries four limits worth stating together: it is in a section introduced by words meaning may additionally include rather than the mandatory section, it applies only to an important entity that is also a public entity, it speaks of testing security levels and cyber-hygiene practices rather than deception, and it sits beside a mandatory item that is training alone.

For banks there is a further wrinkle that catches people citing the wrong article. The transposition inserted a provision disapplying the cybersecurity act's staff-education article to banking and financial market infrastructure entities subject to DORA, so for a Polish bank the obligation runs through DORA's own compulsory awareness and resilience training instead. DORA itself mentions neither social engineering nor phishing anywhere in its sixty-four articles, and the financial supervisor is designated as the competent authority for it in Polish primary law.

Poland has no national implementation of the European threat-led testing framework. It is absent from the central bank's published list of adopting jurisdictions, and the supervisor's own page describes a Polish version as planned for the first half of 2025, a target that has since lapsed. That does not block anything, because the delegated regulation expressly allows a financial entity to apply the European framework itself or one of its national implementations.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in POLAND. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, presenting a number our own company holds. No credential is captured or stored. The workforce is informed in advance and the programme is set out in our work regulations.

Verify or correct each proposition below against primary Polish sources, and tell me whether the campaign can lawfully be dialled at all:

1. ⚠⚠ UZNKE art 27 makes it an offence, 3 months to 5 years, to use address information indicating another person when initiating a voice call in order to impersonate another entity for the purpose of persuading the recipient to hand over personal data, passwords or access codes. Assess whether presenting the CLIENT EMPLOYER'S OWN number, with that employer's written authority, fails the elements «wskazujących na inną osobę» and «nie będąc do tego uprawnionym». Is there any Polish authority on this?
2. The intent element (material benefit, personal benefit, or causing damage) is the only genuine filter, and «korzyść osobista» is wider than fraud. Assess it against a paid assurance engagement.
3. UZNKE art 3's administrative prohibition is broader than the offence («w szczególności») but art 31's fine is addressed only to a telecommunications undertaking, so a non-undertaking employer or vendor sits outside the fining regime.
4. ⚠ Kodeks pracy art 22-3 § 4 extends the monitoring regime to other forms of monitoring only for the § 1 purposes (work organisation, proper use of work tools); the SECURITY purposes are in art 22-2 § 1 and attach to video only. Does a simulated call fall inside art 22-3 at all, and on what purpose?
5. The two-week notice under art 22-2 § 6 and the two-week entry into force of the regulamin pracy under art 104-3 run SEQUENTIALLY, not concurrently.
6. PKE art 398's prohibition is scoped to «informacja handlowa» as defined by the uśude, so an internal test is outside it; and the pre-November-2024 Prawo telekomunikacyjne article is repealed.
7. KK art 190a § 2 requires material or personal harm, so a generic persona is outside it while a named colleague may not be.
8. The dignity regulations in force from 5 November 2026 apply at 10+ employees and have to be agreed with the union or employee representatives. Confirm the threshold and what our document has to say about a deception exercise.

Flag anything that has changed since September 2026, and identify any obligation in our own układ zbiorowy that this analysis omits.

Common questions

Is spoofing a caller number a crime in Poland?
It can be. The 2023 abuse act creates an offence carrying three months to five years for unauthorised use of address information indicating another entity in order to persuade the recipient to hand over personal data, passwords or access codes. There is no exemption for authorised security testing anywhere in the act.
Does the employer's authorisation take us outside that offence?
It is the strongest argument available, because the address information must indicate someone other than the calling user and the use must be unauthorised. Presenting the client's own number with the client's authority engages both elements. No Polish source resolves it, so treat it as an argument rather than an answer.
How much notice must Polish employees get?
Two weeks before monitoring starts, plus the information in paper or electronic form before a new employee is admitted to work. If you use the work regulations route there is a second, sequential two-week period before those regulations themselves take effect, so budget for both.
Do the Polish monitoring rules even cover a security test?
The text does not say. The regime extends to other forms of monitoring only where necessary for work organisation and proper use of work tools; the security purposes sit in the video monitoring article. We are not resolving that gap, and anyone who answers it confidently has not read the purpose gate.

Elsewhere in Central and Eastern Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.