Voice phishing simulations in Slovenia
Slovenia permits an authorised voice phishing simulation against your own workforce, and Callstrike clears the country and assigns the number. Two things here are not where you would look for them. The data protection act has no employment chapter at all, so the rules that bite come from the labour code and the telecoms act. And the data protection regulator says in terms that it does not supervise call recording.
Phone numbers
Supplied by Callstrike
Local numbers in Slovenia, after a one-time approval.
Running a simulation
Permitted, and recording is the live question
The telecoms rule reaches participants where recording is not customary and cannot be expected.
Consent
Exceptional at best
The regulator allows it only where refusal would carry no consequence at all, so treat it as evidence.
Getting a phone number in Slovenia
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
The Slovenian filing is the lightest in this cluster. What the carrier asks for is an address evidenced by an excerpt from the commercial register, a utility bill, a tax notice, a rent receipt or a title deed, sitting inside the locality or region the number's own prefix covers, with a post office box not accepted where a local address is required. Callstrike clears the country against your workspace and provisions the number once that is through.
Slovenia is also the country in this cluster where a campaign is least likely to be stopped at the border, and that finding is stated as an absence rather than dressed up. The communications act contains no false-presentation prohibition of the kind its neighbour has, the numbering plan is purely structural and carries no caller identification rule, and no general act imposing an anti-spoofing obligation could be found. Do not read that as a permission. Numbering is a right of use conferred by the agency on operators and assignees, the caller identification article gives you a right to withhold your number rather than to substitute a different one, and your operator's own terms govern what identity it will pass. Use a number you hold.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Slovenia is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| AddressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable where a local address is required. | Excerpt from the commercial register showing the local address, Utility bill, Tax notice, Rent receipt, Title deed |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in Slovenia?
The position in short, before your counsel reads the detail below.
Yes, and the marketing rule is not the obstacle. Automated calling and communication systems used without human intervention, including automatic calling machines, and faxes and electronic mail, require prior agreement where the purpose is direct marketing, and an internal security test is not direct marketing. One adjacent duty is worth noticing because its wording is broader: subscribers may mark their directory entry against calls having a commercial or research purpose, and callers must respect the marker. A security exercise is neither, but a programme that describes itself internally as research should see that word before it uses it.
The Slovenian question is recording, and the first thing to get right is who is in charge, because the regulator most people write to disclaims it. The Information Commissioner opens its own opinions by saying it is not competent to supervise the lawfulness of recording telephone calls, that the conditions are in the electronic communications act, and that the data protection act does not expressly regulate sound recording at all. Supervision belongs to the communications agency.
The operative paragraph then reaches further than the usual third-party rule. Recording and storing communications without the participants' prior agreement is prohibited for users too, where the communications are such that this processing is not customary and the participants, by the nature of the communication, do not and cannot expect it in advance. Read that against a simulated attack call, whose whole design is that the recipient cannot foresee what is happening. Being a party to the call does not obviously help, which is the opposite of the position under the criminal code, where the main paragraph turns on the conversation not being intended for the recorder and a participant is reached only where the statement is confidential and the recording is made in order to misuse it. The business exception is narrow and its notice has to be given in the same medium as the communication, which for a telephone call means an audible announcement rather than a handbook clause. Design the Slovenian programme without audio and the whole section becomes somebody else's problem.
On the employment side, Slovenian machinery is strong in the wrong places for this activity. The consultation and co-decision lists in the worker participation act are closed by their own drafting, and monitoring, surveillance, recording and testing appear in neither. The two places a programme can touch them are both indirect and both worth designing around: adopting new general rules on disciplinary liability is a consultation matter on a thirty-day and fifteen-day timetable, and changing the criteria for assessing workers' work performance needs the council's consent, which it can refuse. Running the exercise itself is on no list at all. The consultation duties Slovenia does impose for monitoring are technique-specific and sit in the data protection act, covering video and biometrics, and neither has an audio equivalent, so a voice exercise falls into the gap between them.
What your company needs to do
6 items, in the order you will need them.
- Settle the recording question with the right regulator in mindSlovenia-specificThe Information Commissioner disclaims competence and the communications agency supervises, under a paragraph that reaches participants where recording is not customary and cannot be expected. That describes a pretext call closely. The simplest answer is to capture outcomes rather than audio, which removes the question instead of arguing it.
- Write the internal act that says in which cases, how and by whomSlovenia-specificThe regulator's standard is that every form of monitoring interfering with privacy must either be justified in advance and transparently set out in the company's internal acts, saying in which cases, in what manner and by whom it may be carried out, or else have a statutory basis. That is the Slovenian deliverable, and it is more specific than a policy paragraph.
- Carry out the balancing assessment before you rely on itThe regulator names the balancing ground as available and says it is absolutely necessary to carry out the assessment first. It also warns that prior notification of employees is a necessary but not necessarily a sufficient condition of lawfulness, so the assessment has to do real work rather than record that you told people.
- Check the two indirect works council hooks, not the obvious oneSlovenia-specificRunning the exercise is on no statutory list. But if the programme brings new general rules on disciplinary liability, adopting those is a consultation matter with information due thirty days and consultation fifteen days before the decision. And if its results feed the criteria for assessing work performance, changing those needs the council's consent, refusable within eight days.
- Know who supervises the AI transparency duty here, and what it costsSlovenia-specificSlovenia has actually built the machinery and split it: the communications agency supervises the transparency article and the Information Commissioner the prohibited practices, with national fine schedules of fifteen million euro or three per cent for the first and thirty-five million or seven per cent for the second. Disclosure of a synthetic voice is a supervised duty here, not an unattended one.
- Do not build emotion scoring into the Slovenian programmeSlovenia reproduced the European prohibition on inferring emotions in the workplace word for word in its own offence provision, and separately, emotion recognition is high-risk, which obliges an employer to inform workers' representatives and the affected workers before use. Counting what people did is outside it. Scoring how a named person sounded is an argument at the top penalty tier.
The controls that do the work
How Callstrike is configured, and which provision in Slovenia each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
The Slovenian labour code permits worker data to be processed only where that is necessary for exercising rights and obligations arising from the employment relationship, and requires data to be deleted the moment the basis for holding them falls away. The call ends the instant an employee begins to give up a credential, so the credential is never spoken into the system, never held and never has to be deleted. It is the cleanest thing to put in the internal act the regulator expects you to have written.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The regulator's warning is that prior notification is necessary but not necessarily sufficient for lawfulness, which puts the weight on what the exercise actually does to people rather than on what you told them it would. A second voice that breaks character the moment the call ends, with vishing training in writing the same day and results that never touch anybody's performance criteria, is the substance behind the notice rather than a restatement of it.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
The regulator allows agreement as a ground only exceptionally, and only where the individual could genuinely refuse without any consequence whatsoever for the employment relationship, so this is not what makes a Slovenian programme lawful. What it produces is the dated evidence sitting behind the internal act: a record of what staff were told, or a hashed copy of the internal act or agreement you already rely on with a signed attestation of the scope it covers.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
This is the route that answers the sharpest Slovenian provision on its own terms. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module. The telecoms paragraph that reaches participants bites where recording is not customary and the participants cannot expect it in advance; a learner who opts in, is told what the session is and starts it themselves is in the opposite position on both counts.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.