Voice phishing simulations in Poland
Poland has the only criminal offence in this portal whose listed purposes map onto a voice phishing simulation almost word for word, carrying three months to five years, with no exemption for authorised testing anywhere in the act. Testing your own staff is lawful and numbers are supplied. What has to be designed deliberately is the identity your calls present, because that is where the offence's two elements sit.
Phone numbers
Supplied by Callstrike
Local numbers in Poland, after a one-time approval.
Running a simulation
Permitted, but the number decides
The sharp Polish constraint is the identity you present, not the testing itself.
Consent
Not a title you can lean on
Refusing or withdrawing it may not count against staff, which leaves it little weight.
Getting a phone number in Poland
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
The Polish filing runs on the company register rather than on your premises, which makes it one of the shorter ones in this region. An excerpt from the business register evidences the company name and the registration number, and a power of attorney or other official document shows that the person filing may act for the company. Your administrator's own name is typed into the form rather than evidenced by anything.
Notice what is absent, because most of Poland's neighbours ask for it: there is no local address row and no premises document to chase. The constraint that will actually shape the campaign is not in the filing at all. The regulator's recommendations require an operator to ensure that an end user can initiate a voice call only from a number assigned to that subscriber under its own contract, and operators are separately obliged to block a call or hide its calling number where the identification does not check out against the ported and made-available databases. A dedicated Polish number held for your workspace answers that. An improvised display value dies on the wire.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Poland is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Authorization of authorized representative | Power of attorney, Other official documentation identifying the person as an authorized representative |
| Business name | Excerpt from a relevant business register |
| Business registration number | Excerpt from a relevant business register such as national ID |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in Poland?
The position in short, before your counsel reads the detail below.
Yes for the exercise, and the reason is worth having precisely. The rule that looks most threatening to a synthetic caller, the prohibition on automatic calling systems, is scoped to the purpose of sending commercial information, which the statute imports as information intended directly or indirectly to promote the goods, services or image of an entrepreneur. An internal security test promotes none of those, so the article is not engaged and nothing turns on whether a person or a synthetic voice is speaking. Note also which act you are reading: the telecommunications law that carried the old automated-calling rule was repealed in November 2024, and it is still widely cited.
The Polish problem is elsewhere, and this is the paragraph to take to your counsel. A dedicated act on combating abuse in electronic communications makes it an offence, carrying three months to five years, to use address information indicating another person when initiating a voice call in order to impersonate another entity, for the purpose of persuading the recipient to hand over personal data, passwords or access codes. Read that list against what an exercise is for. There is no exemption for authorised testing, penetration testing, simulation, audit or agreement anywhere in the act, and a full-text search for each of those words returns nothing.
Two elements cut in your favour, and they are why the decision this page opened with is the whole Polish answer. The address information has to indicate a person other than the calling user, and the use has to be unauthorised. A campaign presenting your own organisation's number, with your own authority, engages both of those on their face. No Polish source resolves it, so treat that as the strongest available argument rather than as an answer, and record the authority in writing before the first call. One asymmetry is worth knowing while you weigh it: the administrative fine beside the offence reaches only a telecommunications undertaking, so a company that is not one has the crime as its whole exposure and nothing else.
The employment side is more ordinary but it has a gap we would rather show you than fill. Monitoring has to be set out in a collective agreement, in the work regulations or in a formal notice, and staff informed two weeks before it starts. But the labour code's security purposes attach to video monitoring, while the limb that would otherwise catch a simulation is scoped to organisation of work and proper use of work tools. Whether a simulated call is monitoring within that article at all, and whether it could serve those purposes if it were, is not settled by the text. Anyone who answers that confidently has not read the purpose gate.
What your company needs to do
7 items, in the order you will need them.
- Present a number your own organisation holds, and record the authorityPoland-specificThis is the Polish decision and it cannot be deferred to the campaign build. The offence needs address information indicating someone other than the calling user, used without entitlement. Presenting your own number under your own written authority is what engages both elements, so put the authorisation in the programme file before anything is dialled rather than reconstructing it afterwards.
- Start both two-week clocks, because they run one after the otherPoland-specificStaff have to be informed of the introduction of monitoring, in the manner customary at your company, no later than two weeks before it starts. Work regulations themselves take effect two weeks after being communicated. Using the work regulations route therefore serves both periods sequentially, so quoting only the monitoring notice understates your lead time by a fortnight.
- Write down which purpose you say the exercise servesPoland-specificDo not assume the other-forms-of-monitoring limb is a general security catch-all: it is scoped to work organisation and proper use of work tools, and the security purposes sit in the video article instead. Record the purpose you are actually relying on and why, because the gap is in the statute and your file is the only place it gets addressed.
- Deal with the union before you fix the wordingWork regulations are established in agreement with the workplace trade union, and where the content is not agreed within the period the parties set, or where no union operates, you establish them yourself. Several unions must present a jointly agreed position within thirty days or you decide after considering their separate ones. Above fifty employees the works council is owed information and consultation as well.
- Give new joiners the information before they start workSeparately from the two-week notice, the information about monitoring has to be given in paper or electronic form before an employee is admitted to work. That is an onboarding change rather than a campaign one, and it is the part that quietly lapses once the first campaign is over.
- Use an invented persona, never a named colleagueImpersonating another person and using their image, personal data or other identifying data, thereby causing them material or personal harm, carries six months to eight years. The harm element is doing the work, but cloning a named executive moves the exercise toward the offence. A generic help desk is not another person.
- Put the exercise into the dignity regulations arriving in November 2026Poland-specificFrom 5 November 2026 an employer with at least ten employees, far below the fifty that gates the works council, must set rules and procedures against violation of employee dignity and personal rights, agreed with the union or employee representatives. A deliberate deception exercise is exactly what will have to be reconciled with that document, so write it in rather than around it.
The controls that do the work
How Callstrike is configured, and which provision in Poland each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
Be clear about what this does and does not reach in Poland, because the honest answer is narrower here than almost anywhere else in this portal. It does not dispose of the abuse offence: that offence is built around the purpose of persuading someone to hand data over, and the statute draws no line at whether the credential is actually captured. What it does answer is the labour code's closed list of data you may demand, which admits other data only where necessary to exercise a right or perform a legal obligation. The call ends the moment an employee begins to give up a credential, so there is no new category of data to justify holding at all, and the record the exercise leaves is who did what rather than what they said.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The monitoring articles require monitoring not to infringe employee dignity and other personal rights, and from November 2026 a separate set of regulations on exactly that has to exist at ten employees and above. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is a concrete term you can put into that document rather than an intention you describe to a union at the point they ask.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Poland gives agreement almost no weight as a title: the labour code says in terms that its absence or withdrawal may not be a basis for unfavourable treatment or any negative consequence, and the regulator says it will not be frequent as a legal title because of the imbalance between the parties. So this is not what makes the programme lawful. What it produces is the two-week notice, dated, plus the before-admission copy each new joiner is owed, and a hashed record of the work regulations or collective agreement the monitoring was set out in.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
This is the route that answers the Polish offence at its own elements rather than arguing with them. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module. The offence is written about a person who, when initiating a voice call, uses address information indicating another person, and a session a learner opens in their own browser initiates no voice call and presents no address information for the words to attach to. The operator-side blocking recommendations have nothing to act on either.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.