Callstrike
Compliance

Voice phishing simulations in Slovenia

Phone numbers in SloveniaProvisioned by Callstrike after approval

Slovenia permits an authorised voice phishing simulation against your own workforce, and Callstrike clears the country and assigns the number. Two things here are not where you would look for them. The data protection act has no employment chapter at all, so the rules that bite come from the labour code and the telecoms act. And the data protection regulator says in terms that it does not supervise call recording.

Phone numbers

Supplied by Callstrike

Local numbers in Slovenia, after a one-time approval.

Running a simulation

Permitted, and recording is the live question

The telecoms rule reaches participants where recording is not customary and cannot be expected.

Consent

Exceptional at best

The regulator allows it only where refusal would carry no consequence at all, so treat it as evidence.

Getting a phone number in Slovenia

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

The Slovenian filing is the lightest in this cluster. What the carrier asks for is an address evidenced by an excerpt from the commercial register, a utility bill, a tax notice, a rent receipt or a title deed, sitting inside the locality or region the number's own prefix covers, with a post office box not accepted where a local address is required. Callstrike clears the country against your workspace and provisions the number once that is through.

Slovenia is also the country in this cluster where a campaign is least likely to be stopped at the border, and that finding is stated as an absence rather than dressed up. The communications act contains no false-presentation prohibition of the kind its neighbour has, the numbering plan is purely structural and carries no caller identification rule, and no general act imposing an anti-spoofing obligation could be found. Do not read that as a permission. Numbering is a right of use conferred by the agency on operators and assignees, the caller identification article gives you a right to withhold your number rather than to substitute a different one, and your operator's own terms govern what identity it will pass. Use a number you hold.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Slovenia is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
AddressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable where a local address is required.Excerpt from the commercial register showing the local address, Utility bill, Tax notice, Rent receipt, Title deed

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Slovenia?

The position in short, before your counsel reads the detail below.

Yes, and the marketing rule is not the obstacle. Automated calling and communication systems used without human intervention, including automatic calling machines, and faxes and electronic mail, require prior agreement where the purpose is direct marketing, and an internal security test is not direct marketing. One adjacent duty is worth noticing because its wording is broader: subscribers may mark their directory entry against calls having a commercial or research purpose, and callers must respect the marker. A security exercise is neither, but a programme that describes itself internally as research should see that word before it uses it.

The Slovenian question is recording, and the first thing to get right is who is in charge, because the regulator most people write to disclaims it. The Information Commissioner opens its own opinions by saying it is not competent to supervise the lawfulness of recording telephone calls, that the conditions are in the electronic communications act, and that the data protection act does not expressly regulate sound recording at all. Supervision belongs to the communications agency.

The operative paragraph then reaches further than the usual third-party rule. Recording and storing communications without the participants' prior agreement is prohibited for users too, where the communications are such that this processing is not customary and the participants, by the nature of the communication, do not and cannot expect it in advance. Read that against a simulated attack call, whose whole design is that the recipient cannot foresee what is happening. Being a party to the call does not obviously help, which is the opposite of the position under the criminal code, where the main paragraph turns on the conversation not being intended for the recorder and a participant is reached only where the statement is confidential and the recording is made in order to misuse it. The business exception is narrow and its notice has to be given in the same medium as the communication, which for a telephone call means an audible announcement rather than a handbook clause. Design the Slovenian programme without audio and the whole section becomes somebody else's problem.

On the employment side, Slovenian machinery is strong in the wrong places for this activity. The consultation and co-decision lists in the worker participation act are closed by their own drafting, and monitoring, surveillance, recording and testing appear in neither. The two places a programme can touch them are both indirect and both worth designing around: adopting new general rules on disciplinary liability is a consultation matter on a thirty-day and fifteen-day timetable, and changing the criteria for assessing workers' work performance needs the council's consent, which it can refuse. Running the exercise itself is on no list at all. The consultation duties Slovenia does impose for monitoring are technique-specific and sit in the data protection act, covering video and biometrics, and neither has an audio equivalent, so a voice exercise falls into the gap between them.

What your company needs to do

6 items, in the order you will need them.

  • Settle the recording question with the right regulator in mindSlovenia-specificThe Information Commissioner disclaims competence and the communications agency supervises, under a paragraph that reaches participants where recording is not customary and cannot be expected. That describes a pretext call closely. The simplest answer is to capture outcomes rather than audio, which removes the question instead of arguing it.
  • Write the internal act that says in which cases, how and by whomSlovenia-specificThe regulator's standard is that every form of monitoring interfering with privacy must either be justified in advance and transparently set out in the company's internal acts, saying in which cases, in what manner and by whom it may be carried out, or else have a statutory basis. That is the Slovenian deliverable, and it is more specific than a policy paragraph.
  • Carry out the balancing assessment before you rely on itThe regulator names the balancing ground as available and says it is absolutely necessary to carry out the assessment first. It also warns that prior notification of employees is a necessary but not necessarily a sufficient condition of lawfulness, so the assessment has to do real work rather than record that you told people.
  • Check the two indirect works council hooks, not the obvious oneSlovenia-specificRunning the exercise is on no statutory list. But if the programme brings new general rules on disciplinary liability, adopting those is a consultation matter with information due thirty days and consultation fifteen days before the decision. And if its results feed the criteria for assessing work performance, changing those needs the council's consent, refusable within eight days.
  • Know who supervises the AI transparency duty here, and what it costsSlovenia-specificSlovenia has actually built the machinery and split it: the communications agency supervises the transparency article and the Information Commissioner the prohibited practices, with national fine schedules of fifteen million euro or three per cent for the first and thirty-five million or seven per cent for the second. Disclosure of a synthetic voice is a supervised duty here, not an unattended one.
  • Do not build emotion scoring into the Slovenian programmeSlovenia reproduced the European prohibition on inferring emotions in the workplace word for word in its own offence provision, and separately, emotion recognition is high-risk, which obliges an employer to inform workers' representatives and the affected workers before use. Counting what people did is outside it. Scoring how a named person sounded is an argument at the top penalty tier.

The controls that do the work

How Callstrike is configured, and which provision in Slovenia each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

The Slovenian labour code permits worker data to be processed only where that is necessary for exercising rights and obligations arising from the employment relationship, and requires data to be deleted the moment the basis for holding them falls away. The call ends the instant an employee begins to give up a credential, so the credential is never spoken into the system, never held and never has to be deleted. It is the cleanest thing to put in the internal act the regulator expects you to have written.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The regulator's warning is that prior notification is necessary but not necessarily sufficient for lawfulness, which puts the weight on what the exercise actually does to people rather than on what you told them it would. A second voice that breaks character the moment the call ends, with vishing training in writing the same day and results that never touch anybody's performance criteria, is the substance behind the notice rather than a restatement of it.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

The regulator allows agreement as a ground only exceptionally, and only where the individual could genuinely refuse without any consequence whatsoever for the employment relationship, so this is not what makes a Slovenian programme lawful. What it produces is the dated evidence sitting behind the internal act: a record of what staff were told, or a hashed copy of the internal act or agreement you already rely on with a signed attestation of the scope it covers.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

This is the route that answers the sharpest Slovenian provision on its own terms. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module. The telecoms paragraph that reaches participants bites where recording is not customary and the participants cannot expect it in advance; a learner who opts in, is told what the session is and starts it themselves is in the opposite position on both counts.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

The act everyone reaches for has nothing about employment in it

Slovenia's data protection act is one of the newest in Europe, in force since January 2023, and it has no chapter or article on processing in the employment relationship. Its sectoral part has nine chapters and none of them is about employment; the phrase for in the employment relationship returns nothing across the whole consolidated text. Its general provision on lawful bases simply says personal data may be processed only in accordance with the bases in Articles 6 and 9 of the Regulation.

What Slovenia does instead is regulate by technique. There are employment-specific rules inside the video surveillance chapter and inside the biometrics chapter, each with its own procedural gate, and no analogue anywhere for audio. That structural fact governs most of this page.

The employment rule proper is in the labour code. Workers' personal data may be collected, processed, used and transmitted to third persons only if that is provided for by that or another act, or if it is necessary for the exercise of rights and obligations arising from or in connection with the employment relationship. A second paragraph adds a restriction on who may do it: only the employer, or a worker specially authorised by the employer for that purpose. A third requires data to be deleted immediately once the statutory basis for collecting them no longer exists, and a fourth extends all of it to job candidates. Two neighbouring articles oblige the employer to protect and respect the worker's personality and to have regard to and protect the worker's privacy.

The regulator's position on consent is worth quoting because of the standard it sets. Because of the pronounced inequality of power in employment relationships, it says, and because of the protection of the worker as unquestionably the weaker party, the legislator regulated this field more strictly, so processing on the basis of consent comes into consideration in practice only exceptionally, and only if the individual can genuinely refuse consent without any consequences whatsoever for the employment relationship. It then names the legitimate interests ground as a possible basis and adds that it is absolutely necessary to carry out a prior legitimate interest assessment first.

On monitoring generally its guidance sets a standard other regulators leave implicit. The boundary between the employer's power of control and the worker's privacy is not expressly regulated by any Slovenian statute, it says, so every form of monitoring that interferes with privacy must be either justified in advance and transparently presented to employees in the company's internal acts, saying in which cases, in what manner and by whom it may be carried out, or else have a statutory basis. And then the sentence that matters: prior notification of employees is a necessary, but not necessarily a sufficient, condition for the lawfulness of monitoring.

One caveat on that guidance and we would rather give it than hide it. The document is version 1.1 of November 2019, and it still describes video surveillance and biometrics at work as governed by the previous data protection act, which was repealed in 2023. Its reasoning under the Regulation and under European human rights case law survives intact. Its statutory citations do not.

The data regulator disclaims it, and the telecoms act reaches you

The first thing to know about recording a call in Slovenia is who is in charge, because it is not who you would guess and the regulator says so itself.

The Information Commissioner opens its own opinion on the subject by emphasising that it is not competent to supervise the lawfulness of recording telephone calls, that the bases, conditions and limits of recording calls are governed by the electronic communications act, and that supervision of that act belongs to the communications agency. It adds, in terms, that the data protection act does not expressly regulate sound recording at all.

So the operative provision is a telecoms one, and it has four paragraphs that matter. All forms of surveillance or interception carried out by third persons who are not users participating in the communication, including listening, recording, storing and forwarding, are prohibited without the consent of the users concerned. Then the paragraph most people miss: recording and storing communications without the prior consent of the participants is prohibited also for users, where the communications are such that this processing is not customary and the participants, by reason of the nature of the communication, do not and cannot expect it in advance.

Read that against a simulated attack call. The whole design is that the call is not what it appears to be and the recipient cannot foresee what is happening, which is close to the definition of a communication where recording is not customary and cannot be expected. Being a party to the call does not obviously help here, which is the opposite of the position under the criminal code below.

There is a business exception and it is narrow. Recording communications and the related traffic data is permitted within lawful business practice in order to provide evidence of a commercial transaction or of any other business communication, on condition that the parties are informed in advance of the recording, its purpose and the retention period, with automatic answering systems given as the example. The recording must be deleted immediately, at the latest when the period for lawfully challenging the transaction expires. And the notice must be given by the same kind of medium and in the same form as the recorded communication, which for a telephone call means an audible announcement rather than a line in a handbook.

The regulator has also closed the obvious workaround. It is impermissible, it says, to exploit customers' calls in order to monitor employees, because other measures exist for monitoring that do not require recording and processing the callers' personal data, so recording calls for the purpose of monitoring employees is a disproportionate interference with the individual's privacy. It adds that the general labour code provision cannot supply the basis in that case, given the telecoms act.

The criminal layer is more forgiving than the telecoms one, and reading the two together is the only way to get Slovenia right. The offence of unjustified eavesdropping and sound recording has two paragraphs that turn on different things. The first punishes eavesdropping by special devices on, or sound recording of, a conversation or statement that is not intended for the recorder, so a person to whom the conversation is addressed falls outside it. The second reaches a participant, but only where the statement is confidential, is recorded without the speaker's consent, and is recorded with the intention of misusing it. Mere absence of consent is not enough.

The penalties are a fine or up to a year, rising to three months to five years where an official abuses their position. And the prosecution modes differ between the two paragraphs: the first is prosecuted on the injured party's proposal, the second by private prosecution. The regulator's own caution is a fair summary of the whole section: a person's right to their own voice falls within the wider right to privacy, protected before the civil and criminal courts, and unjustified sound recording may in certain cases amount to that offence.

Marketing is the gate, and the AI supervisor is already named

The Slovenian rule on automated calling is conventionally scoped. The use of automated calling and communication systems for making calls to a subscriber's telephone number without human intervention, including automatic calling machines and text and multimedia messages, and the use of faxes or electronic mail, for the purposes of direct marketing, is permitted only with the subscriber's or user's prior consent. Other means of direct marketing by electronic communications likewise require consent, and the opt-in paragraphs apply to subscribers who are natural persons.

So Slovenia is opt-in for automated marketing calls, and an internal security test is not direct marketing and sits outside the article. One adjacent duty is worth knowing because its wording is broader than marketing: subscribers must be able to prohibit the use of their directory entry for calls having a commercial or research purpose, and callers making commercial or research calls must respect that marker as it appears in the most recent published directory. A security test is neither commercial nor research in the sense that provision contemplates, but a programme that describes itself as research should notice the word.

The European transparency duty applies directly and is Article 50 of the EU AI Act. Since 2 August 2026 a provider must design a system intended to interact directly with people so that they are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person in the circumstances; a provider of a system generating synthetic audio must ensure the outputs are marked in a machine-readable format and detectable as artificially generated; and a deployer of a system generating or manipulating audio constituting a deep fake must disclose that the content is artificially generated. All of it must reach the person clearly and distinguishably at the latest at the first interaction or exposure, and the carve-out is confined to uses authorised by law to detect, prevent, investigate or prosecute criminal offences, which an employer's own authorisation is not.

Slovenia is one of the few countries in this portal that has actually built the machinery, and it split it. A 2025 implementing act names the communications agency as the single point of contact and as the authority competent for supervision over the transparency article, and names the Information Commissioner as the authority competent for supervision over the prohibited practices article. Both carry national fine schedules: breach of the transparency article rises to fifteen million euros or three per cent of worldwide turnover, and breach of the prohibitions to thirty-five million euros or seven per cent.

The prohibition to read before building analytics is the emotion one, and Slovenia has reproduced it word for word in its own offence provision: an AI system for inferring the emotions of a natural person in the workplace or in educational institutions, except where the use is intended for medical or safety reasons. It has applied since 2 February 2025. Its gate is the definition of an emotion recognition system, confined to inference from biometric data. A platform that scores a called employee's stress, fear or hesitation from voice is arguing about that gate at the top penalty tier.

One further provision applies even where the prohibition does not. Emotion recognition is listed as high-risk, and a deployer who is an employer must, before putting a high-risk system into service or using it at the workplace, inform workers' representatives and the affected workers that they will be subject to it. In a country whose domestic consultation lists do not reach monitoring, that European duty is the one that would put a works council in the loop.

We looked for the spoofing rule and there is not one

This section is short because the honest answer is short. We could not establish any Slovenian rule prohibiting a caller from presenting a number it does not hold, and we are reporting that rather than paraphrasing something adjacent.

What the primary texts do establish is narrow. Operators and the persons entitled under the act may use numbering elements only on the basis of an assignment decision by which the agency confers the right of use, which is a duty addressed to operators and assignees rather than to callers. The caller identification article grants the calling party a right to suppress presentation of the number and the called party a right to reject calls whose number is suppressed, and says nothing about substituting a different one. And a separate article provides a tracing mechanism for malicious or nuisance calls on the subscriber's request, which is a remedy rather than a prohibition.

What is absent is more informative than what is present. The electronic communications act contains no occurrence at all of the phrase for false self-presentation, so there is no Slovenian analogue of the flat prohibition that exists next door in Croatia. The numbering plan adopted by the agency is purely structural, covering number format, the country code and the ranges by service type, and contains no caller identification rule and no anti-spoofing obligation. We looked for a general act of the agency imposing one and did not find it.

Two things follow for a buyer. Slovenia is not a country where a cross-border campaign is blocked at the border by rule, unlike several of its neighbours, so the operational risk here is lower. And the absence of a caller-facing prohibition is not a permission: the recording rules above, the labour code and the criminal code all still apply, and the operator's own terms govern what identity it will pass. Use a number you hold.

What the country matrix holds for Slovenia

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Closed lists, and the only consent rung is about performance

Slovenia has a strong worker participation statute and the strength is in the wrong places for this activity, which is worth knowing precisely rather than assuming either way.

The act sets out six modes of participation: the right of initiative and to a reply, the right to be informed, the right to give opinions and proposals and to a reply, the possibility or obligation of joint consultation, the right of co-decision, and the right to suspend the employer's decisions. Three of those matter here.

Information is owed on a list headed by the words above all, so it is illustrative rather than closed: the economic position, development objectives, the state of production and sales, the general position of the branch, a change of activity, a reduction of economic activity, changes in the organisation of production, changes of technology, and the annual accounts. On the last five of those the employer must inform the works council before adopting the final decision.

Joint consultation is triggered only by status matters, personnel matters and occupational health and safety, with the information due at least thirty days before the decision and the consultation deadline at least fifteen days before it. But the statute then defines those categories with the words shall be deemed, and the lists are closed. The personnel list runs from needs for new workers through the job classification scheme, reassignments of a larger number of workers, supplementary insurance acts and reductions in headcount to the adoption of general rules on disciplinary liability. Monitoring, surveillance, recording and testing appear nowhere in either list.

Co-decision is a genuine consent requirement and its list is shorter still: the bases for deciding on annual leave and other absences, the criteria for assessing workers' work performance, the criteria for rewarding innovation, disposal of housing and amenity facilities, and the criteria for promotion. The works council has eight days to take a position and is deemed to consent if it does not, and the employer may not adopt the decision if consent was refused within those eight days.

So the two places a simulation programme can touch this machinery are indirect and both are worth designing around. If the programme comes with new general rules on disciplinary liability, adopting those rules is a consultation matter on the thirty-and-fifteen-day timetable. If its results feed the criteria for assessing workers' work performance, changing those criteria needs the works council's consent, which it can refuse. Running the exercise itself is on no list at all.

A works council is formed where more than twenty workers with active voting rights are employed; at twenty or fewer, workers participate through a workers' trustee who must be afforded the same working arrangements and the same rights.

One structural point closes this section. The consultation duties that do exist in Slovenian law for employer monitoring are technique-specific and are in the data protection act, not in the participation act: before introducing video surveillance inside working premises the employer must consult the representative trade unions and the works council or trustee, within thirty days or sixty where the surveillance reaches the places workers usually work, and before processing biometric data it must inform individuals in writing and consult the employees themselves on proportionality, and in the private sector must obtain a prior authorising decision from the Information Commissioner. Neither has an audio equivalent, so a voice exercise falls into the gap between them.

Annual training for administrators, and no simulation anywhere

Slovenia transposed the European network and information security directive by an act adopted in June 2025 and in force from 19 June 2025, replacing the 2018 information security act. It is unamended.

Its training duties are more specific than most transpositions. The responsible persons must ensure regular training of employees so that they acquire sufficient knowledge and skills to recognise risks to information and cyber security, a further paragraph requires annual training for all administrators of information and communications systems, and the risk-management measures include basic cyber-hygiene practices and training in information and cyber security.

We counted the act through for simulation, phishing, the Slovenian word for phishing and voice phishing. All of them return zero. Awareness and training return eight and fourteen respectively, and testing returns two.

The comparison worth drawing is with Croatia next door, because it sharpens what the absence means. Croatia's implementing regulation names phishing simulation and grades it voluntary. Slovenia has published no implementing regulation naming phishing simulation at all, so here the activity is neither mandated nor expressly classified as optional. It is simply not addressed, and a Slovenian buyer told that the cybersecurity act requires simulated attacks is being told something the text does not say.

For financial entities the European digital operational resilience Regulation applies directly from 17 January 2025. It makes information and communications technology security awareness programmes and digital operational resilience training compulsory modules in staff training schemes for all employees and senior management, and requires threat-led penetration testing of live production systems at least every three years for the entities identified for it. It names neither phishing nor social engineering anywhere in its text.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in SLOVENIA. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance at the programme level.

Verify or correct each proposition below against primary Slovenian sources, and tell me what we must have written before the first call:

1. ⚠ ZVOP-2 has NO employment chapter: the employment data rule is ZDR-1 čl. 48, and ZVOP-2's employment-specific rules are confined to the videosurveillance (čl. 76 to 80) and biometrics (čl. 81 to 84) chapters, neither with an audio analogue.
2. ⚠ The Information Commissioner states it is NOT competent to supervise the lawfulness of call recording; AKOS is, under ZEKom-2 čl. 214. Confirm.
3. ⚠⚠ ZEKom-2 čl. 214(6) prohibits recording without participants' prior consent «tudi uporabnikom» where the processing is not customary and participants cannot expect it. Assess whether a simulated attack call is inside that, and whether the čl. 214(7) business exception (notice in the same medium) can ever cover it.
4. KZ-1 čl. 137: para 1 turns on the conversation not being intended for the recorder, so a participant is outside it; para 2 reaches a participant only where the statement is confidential and recorded «z namenom, da bi tako izjavo zlorabil».
5. ZSDU's čl. 89 and 94 lists are CLOSED («se štejejo») and exclude monitoring. Confirm the two indirect hooks: general rules on disciplinary liability (consultation) and criteria for assessing work performance (co-decision, eight days).
6. The IP's employment guideline is v1.1 of 25.11.2019 and still cites ZVOP-1. Its GDPR and ECtHR reasoning survives; confirm its statutory citations do not.
7. ZIUDHPUI čl. 7, 10, 26 and 33 name AKOS for AI Act Art 50 and the IP for Art 5, with national fines of EUR 15m or 3% and EUR 35m or 7% respectively.
8. ⚠ We could source NO Slovenian rule against presenting a number one does not hold: ZEKom-2 has zero occurrences of «lažno predstavljanje» and the numbering plan is purely structural. Confirm or supply one.

Flag anything that has changed since September 2026, and identify any obligation in our own kolektivna pogodba that this analysis omits.

Common questions

Who regulates call recording in Slovenia?
The communications agency, not the data protection regulator. The Information Commissioner opens its own opinions by saying it is not competent to supervise the lawfulness of recording telephone calls, and that the data protection act does not expressly regulate sound recording at all.
May a party to the call record it?
Under the criminal code, largely yes: the main paragraph turns on the conversation not being intended for the recorder. Under the telecoms act, not reliably: recording without the participants' prior consent is prohibited for users too, where such recording is not customary and cannot be expected.
Does the works council have to be consulted?
Not for the exercise itself. The consultation and co-decision lists are closed and exclude monitoring. Two indirect hooks exist: adopting general rules on disciplinary liability is a consultation matter, and changing the criteria for assessing work performance needs the council's consent.
Does Slovenia ban presenting a number we do not hold?
We could find no such rule. The communications act has no false-presentation prohibition, the numbering plan is purely structural with no caller identification rule, and no anti-spoofing general act was found. That is an absence of prohibition, not a permission to impersonate.

Elsewhere in Southern Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.