Callstrike
Compliance

Voice phishing simulations in Portugal

Phone numbers in PortugalProvisioned by Callstrike after approval

Portugal permits an authorised voice phishing simulation against your own workforce, and Callstrike clears the country and assigns the number. The Portuguese constraint is not the one you would check for. It is a rule about what the exercise is allowed to produce, and it can decide whether the programme is worth running before any question about the lawful basis arises.

Phone numbers

Supplied by Callstrike

Local numbers in Portugal, after a one-time approval.

Running a simulation

Permitted, with a limit on the output

What you may hold and report afterwards is the harder question here, not whether you may call.

Consent

Not adequate as the ground

The regulator's published position, on the imbalance. It remains how you evidence notice.

Getting a phone number in Portugal

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Portugal is one of a small number of countries where the carrier publishes no requirements table for the type of number supplied here, so the clearance form in the console is the authority on what you will be asked for rather than this page. Your administrator completes it once, and Callstrike provisions a dedicated Portuguese number against your workspace when it clears.

What is worth knowing in advance is the exposure sitting underneath the number rather than beside the form. Using numbering resources without holding the corresponding right of use, or otherwise than in conformity with its terms, is a very serious administrative offence in Portugal, running from seven hundred and fifty euro for an individual to five million for a large undertaking. Portugal is unusual in that there is no standing duty on operators to block spoofed national numbers, and the regulator's own guidance on which ranges may be presented is a note from 2008 that is expressly non-binding. Do not read that gap as permission: the right-of-use offence does not depend on anybody blocking anything, so originate on numbers your organisation or its supplier genuinely holds.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Portugal is assigned to youCallstrike
  4. 04Build and launch the campaignYour team

The carrier does not publish a requirements table for the number type we supply here, so what you will be asked for is whatever the clearance form in the console requests at the time. Treat that form as authoritative.

Is it lawful to run a simulation in Portugal?

The position in short, before your counsel reads the detail below.

Yes, and then the Portuguese question is a different one from anywhere else in this cluster. The act executing the European Regulation provides that personal data registered through video systems or other technological means of remote surveillance may be used only within criminal proceedings, with disciplinary use parasitic on a criminal case existing. Read that against what an awareness programme is for. If your exercise is characterised as remote surveillance, then what it produces cannot lawfully feed reporting, per-person scoring or training analytics, not because that would be disproportionate but because the statute confines the use to a forum a security exercise will never reach. Test the design against that before anything else.

The second Portuguese answer is about audio and it is close to absolute. The criminal code punishes recording words spoken by another and not intended for the public even where they are addressed to you, and the clause doing the work is that last one: most European recording offences are built around the outsider listening in, and this one expressly reaches the person the words were spoken to. Its second limb is a separate offence for using such a recording even where it was lawfully made, so a coaching or reporting workflow can offend where the capture did not. The shortest true statement on this page is that a Portuguese programme should be built so that it does not need the audio.

The labour code article that governs is easier to misread than to apply, and it has three parts. A prohibition framed by purpose, on using remote surveillance means at the workplace to control a worker's professional performance. A permission framed by purpose, where the aim is protection and safety of persons and property or where the nature of the activity justifies it. And an information duty attached only to the permitted cases. The trap is in the next article, which says the use of remote surveillance means requires the data protection commission's authorisation. That requirement ceased to be in force when the European Regulation applied and the commission says so on its own site, but the official consolidated labour code still prints it with no marker at all, in a document that demonstrably marks repeals elsewhere. The conditions live. The permit does not, and do not spend a quarter waiting for one.

The rest is the ordinary European shape with two Portuguese specifics. The regulator's published position is that a worker's agreement is not an adequate ground, both because the imbalance means it would not be freely given and because employment processing is mostly provided for by law or necessary to the contract, so the route is the balancing test read through the labour code. And the impact assessment is mandatory rather than discretionary: the commission's binding list names processing that allows the behaviours of data subjects to be tracked, giving workers as its first example, where the effect is to evaluate or classify them.

What your company needs to do

6 items, in the order you will need them.

  • Decide what the exercise is allowed to produce, before you design itPortugal-specificThis is the Portuguese decision and it belongs at the start. Anything gathered through remote surveillance may be used only within criminal proceedings, so a per-person scored record feeding HR reporting is the design most exposed to the characterisation. Aggregate measurement, with coaching delivered rather than recorded against a name, is the one that is not.
  • Build the programme so it never needs the recordingPortugal-specificThe offence reaches a participant in terms, and using the recording is punished separately even where the capture was lawful. Whether the call was answered, whether anything was disclosed and where the person disengaged are all measurable without audio, which removes the question rather than arguing it.
  • Do not go looking for the commission's authorisationPortugal-specificThe consolidated labour code will tell you that remote surveillance needs it, with no repeal marker on the article. It ceased to be in force when the European Regulation applied. The article's substantive conditions, the purpose limits and the information duty, all still bind you, so read the conditions and ignore the permit.
  • Request the works council's opinion in writing and start the clock earlyPortugal-specificThe duty is to request an opinion before measures capable of substantially worsening working conditions or changing work organisation. The opinion is due within ten days of the request, and the obligation is treated as discharged once that period passes without one. It is a timetable rather than a gate, and it is only free if you open it early.
  • Treat the impact assessment as owedThe commission's list is binding rather than indicative, and it names tracking the behaviours of workers where the effect is to evaluate or classify them. Record the purpose, why a less intrusive method would not achieve it, what is retained and for how long, and what the results are never used for.
  • Give the notice at programme level, in advanceThe information duty attaches to existence and purpose, and the prescribed wording in the code was written for closed-circuit television, which leaves the form of notice for a non-camera means unlegislated. A dated programme-level notice given before the first call is what fills that gap, and it is the same document the works council will ask to see.

The controls that do the work

How Callstrike is configured, and which provision in Portugal each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

The Portuguese risk concentrates on what you end up holding about a named person, because that is what drives the remote-surveillance characterisation and the rule confining its output. The call ends the instant an employee begins to give up a credential, so the credential is never spoken into the system and there is nothing whose downstream use has to be confined. It is also the cleanest answer to the commission's binding assessment list, which is aimed at processing that evaluates or classifies workers.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The labour code prohibition is framed by purpose, on remote surveillance used to control a worker's professional performance, so the purpose you can evidence is the whole argument. A call that ends with a second voice breaking character and vishing training in writing the same day is aimed at teaching the person in front of you, which is a different purpose from the one the prohibition describes, and it is evidenced by the artefact rather than asserted in a policy.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

The regulator says a worker's agreement is not an adequate ground here, so this is not what makes the programme lawful. It answers the information duty instead, and in Portugal that duty has a gap worth closing deliberately: the prescribed notice wording was written for cameras, so nothing specifies the form of notice for a voice exercise. A dated record of what staff were told, or a hashed copy of the policy or agreement you already rely on with a signed attestation of its scope, is what fills it.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

In Portugal this is more than a fallback, because it removes the fact the whole analysis turns on. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module. The learner opts in and knows what it is, so there is no covert element for the remote-surveillance characterisation to attach to, and no telephone call for the numbering rules to reach.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

A results rule that can make the whole programme pointless

Start with the provision nobody goes looking for, because it can decide whether a Portuguese programme is worth running at all.

The act executing the European Regulation provides that images recorded and other personal data registered through the use of video systems or other technological means of remote surveillance, within the labour code article described below, may be used only within criminal proceedings. It then adds that in those cases the material may also be used to establish disciplinary liability, but only to the extent that it is so used within the criminal proceedings.

Read that against what an awareness programme is for. If a simulation is characterised as remote surveillance, then what it produces cannot lawfully feed reporting, per-person scoring, or training analytics. Not because processing them would be disproportionate, but because the statute confines their use to a forum a security exercise will never reach. That is a harder constraint than any question about the lawful basis, and it is the first thing to test a Portuguese design against.

On the basis itself, the same act routes employment processing back to the labour code, and the regulator closes off the obvious alternative. Its current published position is that in the employment context the worker's agreement is not an adequate basis of legitimacy, both because the imbalance between employer and worker means it would not be effectively free, and because processing relating to workers is in most cases provided for by law or necessary to perform the contract. So the practical route is legitimate interests read through the labour code.

One correction worth making because the opposite is widely repeated. The Constitutional Court decision usually cited in this area struck down the data retention law of 2008, not the act executing the European Regulation, and no Constitutional Court decision against the execution act was found. What did happen is different in kind and weaker: in 2019 the regulator resolved to disapply nine of its provisions in the cases coming before it, in order to secure the primacy of European law. A supervisory authority disapplying a provision in its own casework does not repeal it, and it remains printed in the law. Anyone describing that as a judicial strike-down is overstating it.

An offence that names the case where the words are addressed to you

Portugal is materially stricter than the one-party jurisdictions, and the reason is visible in the drafting rather than in interpretation.

The criminal code punishes whoever, without agreement, records words spoken by another person and not intended for the public, even if they are addressed to him. The phrase doing the work is that last clause. Most European recording offences are built around the outsider listening in; this one expressly reaches the person the words were spoken to. The penalty is up to one year of imprisonment or a fine of up to two hundred and forty days.

The second limb is a separate offence and it is the one an awareness programme is most likely to commit. It punishes whoever uses, or allows the use of, such recordings, even where they were lawfully produced. So lawful capture does not license what happens next, and a reporting or coaching workflow can offend where the recording itself did not.

The constitutional root explains why the rule is shaped this way rather than being an accident. The Constitution lists, among the rights it recognises to everyone, the right to personal identity, to the development of personality, to good name and reputation, to one's image, and separately and expressly to the spoken word. That standalone right to the spoken word is the interest the offence protects, which is why it does not turn on the recorder being a stranger to the conversation.

Prosecution requires a complaint, so it is semi-public rather than pursued of the state's own motion. And the aggravating provision applies correspondingly, raising the penalties by a third where the act is done for reward or to cause loss.

Agreement is the escape and the code sets its shape. It excludes unlawfulness where it concerns freely disposable interests and does not offend good morals, must express a serious, free and informed will, and may be revoked at any time before the act. Two details matter for a simulation. The agreement must be known to the recorder at the time, because an unknown agreement leaves the act punishable as an attempt. And it must be free, which is exactly the quality the regulator says is missing inside an employment relationship. Criminal-law agreement and data protection agreement are different doctrines and should not be merged, but the same freedom problem is present in the text of both.

There is a second, independent gate in the electronic communications privacy act, which prohibits interception or surveillance of communications by third parties without prior and express agreement, and permits recording in the course of lawful commercial practices to prove a transaction or another communication within a contractual relationship, provided the person has been informed and has agreed. Whether an employer on its own call is a third party, and whether an internal test fits a carve-out drawn around commercial transactions, is not answered by any source we read. Either way that route also requires information and agreement.

The practical conclusion is the shortest on this page. In Portugal, design the programme so it does not need the audio.

Direct marketing is the gate, and the 2022 act did not move it

There is a trap in identifying the right instrument here, and it resolves the opposite way from the one people expect. The 2022 electronic communications act did not replace the 2004 privacy act. Its repealing provision lists four instruments and the 2004 privacy act is not among them; what it revoked was the 2004 communications act, and what it did to the privacy act was amend it. So the transposition of the European rule on unsolicited communications is intact and lives where it always did.

That rule is scoped by purpose on the face of the operative text. Sending unsolicited communications for direct marketing purposes, in particular through automated calling and communication systems operating without human intervention, fax machines or electronic mail including short and multimedia messaging, requires the prior express agreement of a subscriber who is a natural person or of the user. A separate paragraph makes the position opt-out rather than opt-in for corporate subscribers.

An authorised internal security test is not direct marketing, so the automated-calling requirement does not reach it, and nothing turns on whether a person or a synthetic voice is speaking. Two corroborating points: the anti-concealment rule beside it is confined to electronic mail with no voice equivalent, and across the whole of the 2022 act the phrases for direct marketing and automatic calling do not appear at all, so Portugal did not migrate any automated-calling rule into the newer framework.

There is no Portuguese counterpart to the American duty to identify the business at the start of an artificial-voice message. The nearest thing is a consumer contracts rule requiring the supplier's identity and the commercial purpose of the call to be stated at the start of any contact with a consumer, and an internal simulation has neither a consumer nor a commercial purpose.

The European transparency rule does reach Portugal. Article 50 of the AI Act has applied since 2 August 2026 and carries two duties on two parties: a provider must design a system built to interact with people so the person is informed they are dealing with an AI system, and a deployer of a system generating or manipulating audio constituting a deep fake must disclose that the content is artificially generated, in both cases at the latest at the time of the first interaction or exposure. The carve-outs are use authorised by law to detect, prevent, investigate or prosecute criminal offences, and evidently artistic works. An employer authorising its own exercise is not authorisation by law, and merging those two senses of authorised is the most likely false step on any European page.

Portugal has designated no national authority for that article in binding law. Its national artificial intelligence agenda, adopted in January 2026, never cites the Regulation at all, and its own action plan lists defining the competent authorities as a deliverable for the first half of 2026. So the duty binds while the enforcement channel is still being built.

It is worth being clear that the Regulation does two different jobs here through two different articles, because they are often collapsed into one. The transparency article tells you what you must disclose and does not stop you doing anything. The prohibition on using AI systems to infer emotions of a natural person in the workplace, applicable since 2 February 2025 and carrying up to thirty-five million euros or seven per cent of worldwide turnover, tells you what you may not do at all, subject only to an exception for medical or safety reasons. One is a labelling duty and the other is a bar. What decides whether the bar applies is the definition of an emotion recognition system, which reaches only inference from biometric data, so a report of outcomes stays clear of it.

A statute with no regulation behind it, and a note from 2008

Portugal has an anti-spoofing statute and no implementing regulation, which makes this block unusual: the binding rule on which numbers you may present is old, short and expressly non-binding.

What is binding is the right of use. Using numbering resources depends on the regulator granting rights of use, and using numbering resources without obtaining the corresponding right, or otherwise than in conformity with its terms, is a very serious administrative offence. The range runs from seven hundred and fifty euro for a natural person to five million for a large undertaking. So the answer to whether you may present a number you hold no right of use in is no, and the exposure is real.

What is not binding is the guidance on which ranges may be presented. The regulator's standing statement on the subject is a note from 2008, which says the calling party number must uniquely identify the access of the call originator, that it is an obligation of the operator holding the number to validate the information where the user supplies it, and then lists the ranges it considers may be presented: the fixed and mobile ranges and nomadic voice over internet protocol. Levels six, seven and eight are not on that list, and using a machine-to-machine number as voice calling identity would breach the service designation attached to it.

The gap between those two is the honest finding. The statute's caller-identity integrity provisions are Portuguese additions rather than transpositions of the European code, which contains no such requirement, and the procedure to write a regulation under them opened in March 2023 and has not produced a draft since. There is no standing blocking or filtering duty on Portuguese operators for spoofed national numbers. What exists instead is a case-by-case power: where justified by fraud or abusive use, the regulator, the courts or another competent body may order undertakings to block access to numbers or services.

Two practical consequences. Originate from numbers your organisation or its supplier genuinely holds, through the sub-assignment route the regulator's own numbering regulation provides for, under which the beneficiary is responsible for complying with the service designation. And do not read the absence of a blocking regime as permission: the right-of-use offence does not depend on anyone blocking anything.

What the country matrix holds for Portugal

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

A prohibition, a dead authorisation, and consultation that lapses in ten days

The labour code article is the centrepiece and it has three moving parts that are usually run together, so take them separately.

The first is a prohibition framed by purpose: the employer may not use remote surveillance means at the workplace, by means of technological equipment, for the purpose of controlling the worker's professional performance. Breach is a very serious administrative offence. The second is a permission framed by purpose: use is lawful whenever its purpose is the protection and safety of persons and property, or where particular requirements inherent in the nature of the activity justify it. The third is an information duty attached only to the permitted cases, requiring the employer to inform the worker of the existence and the purpose of the means used. The prescribed signage wording is written for closed-circuit television, which leaves the required form of notice for a non-camera means unlegislated.

The regulator reads the prohibition as filling gaps rather than as confined to cameras. In guidance on remote working it says that because no legal provision regulates remote control in that setting, the general rule prohibiting remote surveillance means for the purpose of controlling performance is fully applicable, and that technological solutions for remote control of performance are therefore not permitted. That guidance was written in a pandemic context, and its gap-filling reasoning is general.

Now the false pass, which is the most important practical point on this page. The next article of the labour code says the use of remote surveillance means is subject to authorisation by the data protection commission, and requires the authorisation request to be accompanied by the works council's opinion. The official consolidated text prints that with no repeal or amendment marker, in a document that demonstrably marks repeals elsewhere. It is dead: the execution act provides that all rules requiring authorisations or notifications to the commission, outside the cases provided for in the Regulation and in that act, ceased to be in force when the Regulation applied. The commission says the same thing on its own current site, that the labour code conditions for remote surveillance remain in force with the exception of the need to request its authorisation, which is incompatible with the Regulation. So the conditions live and the authorisation does not, and reading the consolidated labour code alone would tell you the opposite.

One prior authorisation does survive, and it is the one nearest to a voice exercise. Where video surveillance is permitted, capturing sound is prohibited except while the premises are closed, or with the commission's prior authorisation. Because that rule sits in the execution act itself it falls outside the provision that killed the others.

On consultation, the answer is bounded and it is never agreement. We counted: the phrase for agreement of the works council appears nowhere in the labour code, while the phrase for its opinion appears four times. The employer must request the opinion in writing before certain acts, including any measure resulting or capable of resulting substantially in a worsening of working conditions or changes in work organisation. The opinion must be issued within ten days of the request, and the obligation is deemed fulfilled once that period has elapsed without one being issued. Separately, the works council is heard when the internal company regulation is drawn up, and failing to do that is a serious offence.

One question we are deliberately leaving open. The two surveillance-specific opinion duties are drafted as attachments to the authorisation step that no longer operates. Whether an opinion duty survives standalone once its host procedure is gone is answered by no source we read. The general consultation duty may capture the same programme independently through the work-organisation limb, but that is an argument rather than a citation.

Finally, the impact assessment is mandatory rather than discretionary. The commission's binding list names processing that allows the location or behaviours of data subjects to be tracked, giving workers as its first example, where that has the effect of evaluating or classifying them. A simulation that records who disclosed and scores them is squarely within it.

A safe harbour that forbids this technique, and a consent defence that does not

Portugal's cybersecurity regime does something no other country in this portal does: it names phishing and social engineering, and it names them in order to forbid them. The detail of where it does that is what makes it usable rather than fatal.

The decree-law transposing the European network and information security directive amends the cybercrime law to create acts that are not punishable in the public interest of cybersecurity. Inside that provision, the researcher route is expressly barred from using denial of service mechanisms, social engineering, defined as deceiving those responsible for or users of information systems with a view to the disclosure of sensitive or confidential information, phishing and its variants, and theft of passwords or other sensitive information. A vishing simulation is squarely both of the middle two on that definition.

The asymmetry is the finding. That prohibition qualifies the researcher limb. The separate agreement limb, which makes acts not punishable where carried out with the agreement of the owner or administrator of the information system, product or service, carries no such list. It does carry a duty to notify any vulnerabilities identified to the national coordinating authority for incident response. So the operative Portuguese route for an authorised exercise is the agreement defence with a notification attached, not the researcher safe harbour.

One limit on that route has to be stated plainly, because it is the most likely place for a page to over-claim. Those defences are confined by their own opening words to the two cybercrime offences of illegitimate access and illegitimate interception. Nothing in them touches the recording offence in the criminal code described earlier. The agreement defence does not cure that.

On what the regime positively requires, the honest answer is less than you would expect, twice over. Its risk-management article lists basic cyber-hygiene practices and cybersecurity training including for top management and workers, and separately policies and procedures to assess the effectiveness of the measures, which prescribes no method. Across the whole act the words for simulation and for test do not appear at all. And the training article is not yet in effect: it takes effect twenty-four months after the publication of implementing regulations that had not been published when we read it, even though the decree-law itself is in force.

For financial entities DORA applies directly and its counts are starker: the phrases social engineering and phishing appear nowhere in the Regulation. Its only staff-facing mandate is compulsory awareness programmes and resilience training, and its enumerated list of appropriate tests contains no human-layer test at all. The delegated regulation below it mentions social engineering three times, as a tester competence and as something whose ethical boundaries must be written into the red team test plan. That is a documentation duty conditional on doing it, not a duty to do it.

The national threat-led testing framework is run by the central bank, and it never says social engineering either. What it does say about staff is a prohibition and a privacy rule: threatening or bribing employees is on its list of activities not allowed, and employees' private information is to be left out of test reports under all circumstances.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in PORTUGAL. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance at the programme level.

Verify or correct each proposition below against primary Portuguese sources, and tell me what our programme may lawfully produce:

1. ⚠ Lei 58/2019 art 28(4) confines data registered through remote surveillance to use within criminal proceedings. Assess whether a vishing simulation is 'meios tecnologicos de vigilancia a distancia' within CT art 20, and what that means for per-person scoring and HR reporting.
2. CP art 199 punishes recording words spoken by another and not intended for the public 'mesmo que lhe sejam dirigidas', with a SEPARATE offence for use 'mesmo que licitamente produzidas'. Confirm a participant is inside it.
3. ⚠ CT art 21's CNPD prior-authorisation requirement is DEAD by Lei 58/2019 art 62(2), though DRE prints it with no marker. Confirm, and confirm which of art 20's conditions survive.
4. CT art 425 requires a written request for the works council's opinion, due in ten days, with the obligation deemed fulfilled after that. ⚠ Assess whether the surveillance-specific opinion duties survive standalone now their host authorisation procedure is gone.
5. Lei 41/2004 art 13-A is scoped to direct marketing, so the automated-calling consent requirement does not reach an internal test. Confirm Lei 16/2022 amended rather than replaced it.
6. CNPD Regulamento 798/2018 makes the DPIA mandatory where workers' behaviours are tracked with the effect of evaluating or classifying them.
7. Lei 16/2022 arts 53(5), 54 and 178(3)(k) make use of numbering without the right of use a very serious offence, and there is no standing operator blocking duty for spoofed national numbers.
8. DL 125/2025's cybercrime defences: the researcher limb expressly excludes social engineering and phishing, the AGREEMENT limb does not but carries a notification duty, and neither reaches CP art 199.

Flag anything that has changed since September 2026, and identify any obligation in our own instrumento de regulamentacao coletiva that this analysis omits.

Common questions

Can we record simulated calls in Portugal?
Assume not. The criminal code punishes recording words spoken by another and not intended for the public even where they are addressed to you, and separately punishes using such a recording even where lawfully made. Agreement is the escape, and it must be free and known to the recorder at the time.
Why might our Portuguese results be unusable even if the test was lawful?
Because of a rule about output rather than about collection. Data registered through video or other technological means of remote surveillance may be used only within criminal proceedings, with disciplinary use parasitic on that. If your programme is remote surveillance, HR reporting and scoring are closed off.
Do we need the data protection commission's authorisation first?
No, and the labour code will tell you otherwise. That authorisation requirement ceased to be in force when the European Regulation applied, and the commission says so on its own site, though the consolidated labour code still prints the article with no marker. The article's substantive conditions do still apply.
Does the new cybersecurity law give us a safe harbour?
Only the agreement limb, and only for two offences. The researcher limb expressly forbids social engineering and phishing. The agreement limb has no such list but carries a duty to notify vulnerabilities, and neither limb reaches the recording offence in the criminal code.

Elsewhere in Southern Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.