Callstrike
Compliance

Voice phishing simulations in Spain

Phone numbers in SpainProvisioned by Callstrike after approval

Callstrike supplies Spanish numbers for voice phishing simulations once one clearance is through, and Spanish law permits an authorised test of your own workforce. What makes Spain different from the rest of Europe is the ground you stand on: the data protection authority does not route employee monitoring through a balancing test at all, so a file translated from a German or Dutch programme is written the wrong way here.

Phone numbers

Supplied by Callstrike

Local numbers in Spain, after a one-time approval.

Running a simulation

Permitted, on a Spanish footing

The authority names the Workers' Statute rather than a balancing test, and the difference is your paperwork.

Consent

Not the ground, still the record

The authority calls employee agreement invalid here, because of the imbalance it is given under.

Getting a phone number in Spain

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Your company files its regulatory details once for this country. Local rules require the order to be placed by the provider of record, so Callstrike provisions the number on your behalf once the filing is approved. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Callstrike places the Spanish order once your filing clears, so the work on your side is one submission in the console. What sends a Spanish filing back is geography rather than volume. A resolution of April 2026 requires the holder of a fixed number to have a legal domicile inside the provincial area the number's own prefix covers, and to prove it to the operator as a condition of taking the service. A registered office in Madrid does not evidence a domicile in Valencia, and the number you want is what decides which province you have to show.

You will also be asked for a Spanish fiscal identification number and a registration document carrying it, and it is worth knowing which authority wants which. The regulator's condition is the domicile, and it names no document at all; the tax number is what your carrier needs in order to satisfy itself who you are. Both are asked for on the same form, and neither is a filing you make with the regulator yourself.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Spain is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Proof of business identityExample documents include: AEAT “certificado de situación censal” (available here) or the Registro Mercantil “nota simple” (available here)Registration document showing business name and NIF/CIF
Proof of spanish fiscal identification numberNúmero de identificación fiscal (NIF), formerly called CIFRegistration document showing business name and NIF/CIF
Proof of business addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable.Registration document showing business name and NIF/CIF and address, Utility bill, Tax notice, Rent receipt, Title deed

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Spain?

The position in short, before your counsel reads the detail below.

Yes. The Spanish rule you would expect to bite has two limbs, one requiring prior agreement for automated calls placed without human intervention and one covering unwanted calls more generally, and both carry the same qualifier: for the purposes of commercial communication. The authority's own binding circular confirms that scope and states that it does not address the automated limb at all. An authorised test of your own staff publicises nothing and sells nothing, so neither limb reaches it.

The genuinely Spanish part is the ground, and it is where an imported programme gives itself away. The authority does not reach for a balancing test for employee monitoring. It says the worker's agreement is not needed because the ground already sits in the Workers' Statute, in the power to adopt measures to check compliance with employment obligations. Write the file the way the Spanish regulator frames it, and carry the Statute's own conditions across with it: due regard to dignity, and the digital-rights provisions of the organic act whose criteria are settled with employee representatives.

Two things then belong in your Spanish timeline rather than at the end of it. The works committee has a right to be informed and consulted and to issue a report on the implementation of systems of work organisation and control. That is a report and a consultation rather than an approval, so it costs you calendar time and not the campaign, but only if you open it early. And an impact assessment is effectively unavoidable, because systematic monitoring of employees sits on the authority's own published list of processing that requires one.

On recording, Spain reads permissive and settles less than it appears to. The Constitutional Court has held that there is no secret as against the person a communication is directed at, so a participant recording their own call is outside the constitutional protection of secrecy. Read the Court's next move as well: it says a duty of reserve may still arise under the right to personal privacy, so the ruling disposes of one question and leaves the other open. The authority has published nothing on employer call recording since the current regime began, and the two opinions you will find were decided under a law repealed in 2018. Ask first whether you need the audio at all.

What your company needs to do

6 items, in the order you will need them.

  • Write the file the way the Spanish regulator frames itSpain-specificRecord the Workers' Statute power to check compliance with employment obligations as what you are relying on, with dignity and proportionality answered against it. A balancing assessment lifted from another European programme is not wrong so much as beside the point here, and it is the first thing a Spanish reviewer will notice about your documentation.
  • Open the works committee's report early, not at launchSpain-specificThe right attaches to systems of work organisation and control, and what it produces is a report and a consultation rather than a decision you need. Bring the purpose, the scope, what is measured, who sees it and how long it is kept. The same document answers the impact assessment, so writing it once serves both.
  • Treat the impact assessment as owed rather than as a judgementSystematic employee monitoring is on the authority's own list, so this is not a call you get to make. Record the purpose, why a less intrusive method would not achieve it, what you will hold afterwards and for how long, and what results are never used for.
  • Match the address to the province, not to the countrySpain-specificThe domicile has to sit inside the area the number's prefix covers, proved to the operator, and a post office box is not accepted. Decide which province you want to originate from before you file, because that choice is what determines which evidence you have to produce.
  • Decide whether the programme needs audio at allBeing outside the secrecy protection settles the constitutional question and leaves the privacy and data protection questions untouched, and the regulator has published nothing current on the point. Whether the call was answered, whether anything was disclosed and where the person disengaged are all measurable without keeping the recording.
  • Present a number your own organisation holdsSpain-specificThe general rule is that the number displayed must identify the actual originating line, and the only relief is a ministerial authorisation held by the operator rather than by you. A supplier cannot obtain permission on your behalf to present somebody else's number, so treat the displayed identity as a procurement question settled with your carrier before the campaign is designed around it.

The controls that do the work

How Callstrike is configured, and which provision in Spain each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

Spain makes you answer proportionality in writing before the campaign runs, because systematic employee monitoring is on the authority's own list of processing requiring an impact assessment, and the Workers' Statute conditions the very power you are relying on. The call ends the instant an employee begins to give up a credential, so the credential is never spoken into the system and the assessment is written about an exercise that measures susceptibility without ever acquiring the thing the pretext asked for. That is the shortest honest route to a proportionate answer.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The Spanish power to control comes with dignity attached to it in the Statute's own words, and the authority reads the imbalance in the relationship as demanding particular care over purpose. A call that ends with a second voice breaking character on the spot, and vishing training in writing the same day, is a much harder thing to characterise as an affront to dignity than a caught employee who hears nothing until a report circulates. It is also the concrete commitment worth carrying into the works committee.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

The authority is emphatic that employee agreement is invalid here because of the imbalance it is given under, so this is not what makes the programme lawful and it does not stand in for the committee's report. What it produces is the transparency layer the Statute's conditions rest on: a dated record of what staff were told, or a hashed copy of the policy or collective agreement you already rely on with a signed attestation of the scope it covers.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

This is the route that keeps teaching while the committee's report and the provincial filing are still moving. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, and a call opened in a browser is never carried over the Spanish telephone network, so the numbering order, the provincial domicile condition and the caller identification rule have nothing to attach to.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

The basis Spain actually names, which is not the European one

The first half of the standard answer holds in Spain and the regulator is emphatic about it. The data protection authority states that in employment relations the employee's consent is not valid, because it is given in a context of clear imbalance between the person and the controller, and that the imbalance demands particular care over proportionality and purpose limitation. So consent is the wrong instrument here as everywhere.

The second half is where Spain diverges, and a page that did not say so would read as though it had not looked. The authority does not reach for legitimate interests as the basis for employee monitoring. It says the employee's consent is not necessary because the basis for implementing control measures over workers, and for processing the personal data captured in that context, is found in the Workers' Statute provision on the employer's power to adopt measures to check compliance with employment obligations. That is a different route to the same practical place, and if you are documenting a Spanish programme you should document it the way the Spanish regulator frames it rather than importing a template from another jurisdiction.

The Statute attaches its own conditions to that power, and they are the ones to design against: the employer must have due regard to human dignity, and there are express provisions on digital rights in the workplace in the organic data protection law, including the right to privacy in the use of digital devices, with criteria for their use to be settled with employee representatives. An impact assessment is effectively unavoidable, since systematic employee monitoring appears on the authority's own list of processing that requires one.

On consultation, the works committee has the right to be informed and consulted and to issue a report on the implementation of systems of work organisation and control. That is a report and consultation right rather than a veto, so it is closer to the French position than to the German one, and it belongs in your timeline as a real step rather than as an approval gate.

A participant may record, and that settles less than it sounds

Spain's answer comes from the Constitutional Court rather than from a statute, and it is worth reading the whole of it rather than the first sentence.

The Court has held that there is no secret as against the person to whom the communication is directed, and that retaining the content of the message by any means does not contravene the constitutional protection of the secrecy of communications. So a participant recording their own call is outside that protection, and in that narrow sense Spain is a one-party jurisdiction.

Then read the Court's next move, because it is the part that matters for an employer. It goes on to say that the participants are not under that duty, but that a possible duty of reserve may arise under a different provision, the right to personal privacy. So the ruling disposes of the secrecy question only. It does not dispose of privacy, and it does not touch data protection at all.

The criminal exposure that remains is aimed at a non-party and carries a specific intent: it punishes with imprisonment anyone who, in order to discover the secrets or violate the privacy of another, without their consent, intercepts their telecommunications or uses technical devices for listening, transmission, recording or reproduction of sound, with a higher penalty where what was discovered is then disseminated. An employer running an authorised test is not acting to violate privacy, which is the argument, and it is an argument about the intent element rather than a general permission.

One gap we will not paper over. The authority has published nothing on recording telephone calls since the current data protection regime came in. Two findable opinions saying consent is required were decided under the repealed 1999 law and are not authority for anything now. So on what the regulator expects of an employer recording an employee's simulated call today, there is nothing current to cite, and the conservative design remains the one that works everywhere: programme-level notice, short retention, tight access, and a serious question about whether you need the audio at all.

Commercial communication is the trigger, and the AI Act is not

The Spanish rule people expect to bite has two limbs and both carry the same scope qualifier. End users have the right not to receive automated calls without human intervention for the purposes of commercial communication without prior consent, and the right not to receive unwanted calls for the purposes of commercial communication unless there is consent or another basis under Article 6(1) of the GDPR. Note the asymmetry inside it, because it is routinely reported wrongly: for the automated limb the only route is prior consent, with no legitimate interests option, whereas for the general limb another basis is available.

Both limbs are scoped to commercial communication purposes, and the authority's own binding circular confirms that scope and says in terms that it does not address the automated-calling limb at all. An authorised internal security test is not commercial communication, so neither limb reaches it. That is a statement about what the rules cover rather than a route around them.

The rule that does reach an AI voice here is European. Article 50 of the EU AI Act has applied since 2 August 2026. It requires a system built to interact directly with people to be designed so the person is informed they are interacting with an AI system, and requires whoever deploys a system generating or manipulating audio constituting a deep fake to disclose that the content is artificially generated, in both cases at the latest at the time of the first interaction or exposure. The two exceptions on the face of the text are use authorised by law to detect, prevent, investigate or prosecute criminal offence, and evidently artistic or fictional works, where the duty is narrowed rather than removed. An employer's own authorisation for a test is not authorisation by law, and the two senses of the word should not be merged.

One element the text leaves genuinely open, which we are not going to close: whether a synthetic voice resembling no identifiable person satisfies a definition requiring resemblance to existing persons, objects, places, entities or events. Where the voice imitates a specific real person it is inside on any reading, and a live operator does not take you outside, because the definition covers content that is generated or manipulated.

A different article of the same Regulation is the one an analytics roadmap runs into, and the recitals matter as much as the text. Inferring emotions of a natural person in the workplace is prohibited, since 2 February 2025, at up to thirty-five million euros or seven per cent of worldwide turnover, save for medical or safety reasons. But the prohibition is gated by the definition of an emotion recognition system, which reaches only inference from biometric data, and the recitals expressly put outside it the mere detection of readily apparent expressions, gestures or movements, and of characteristics of a person's voice such as a raised voice. So noticing that a caller shouted is not the regulated thing. Deriving a claim about their emotional state from the audio is.

Two lists that answer different questions, and neither is a subset

Read the panel beside this section carefully, because Spain is the one country in our matrix where the two lists it shows have nothing in common at all. The natural assumption is that the restricted list is a subset of the sellable one, some of what you can buy being unusable. In Spain that is exactly backwards: the two lists are separate answers to separate questions, and nothing appearing in one appears in the other. One says which classes of Spanish number can be supplied at all. The other says which classes carry a restriction on automated outbound use. If you take away one thing from this page, take away that they do not overlap.

We should also be precise about how well each restriction is sourced, because they are not equally well sourced and pretending otherwise would be the easy thing to do.

The mobile restriction is sourced cleanly at regulator level. A ministerial order prohibits the use of numbering ranges attributed to mobile communications services for providing customer service and for making unsolicited commercial calls, sanctioned under the telecommunications law, and it binds the caller rather than only the carrier. It has been in effect since June 2025. The honest limit is that neither that order nor the related consumer legislation defines what a commercial call is, and a security test is not one on the ordinary meaning of the words. So the accurate statement is that mobile numbering is prohibited by the regulator for unsolicited commercial calling and customer service, and whether that prohibition reaches an internal security test turns on a term the regulator has not defined.

The national-range restriction is a different story and we cut the legal claim rather than softening it. Our own records said that range was prohibited to number resellers. We read the numbering plan, the resolution attributing that code, its 2026 amendment and the ministerial order, and no instrument prohibits it to resellers. What exists is a generic rule that sub-assigning any numbering needs prior authorisation from the competition regulator and must match the declared use. Our own product restriction there may well reflect a real carrier policy, and it is not a published Spanish regulatory rule, so we are not going to present it as one. While we were checking, we also found that our internal label for that range was wrong against the numbering plan: it is non-geographic nomadic voice numbering, not personal numbering, which is a different code entirely.

What the regulator does attribute for this kind of traffic is the freephone ranges, which the same order attributes to customer service and to unsolicited commercial calling alongside their existing reverse-charge use, and calls from them remain free to the caller.

Two forward-looking items worth knowing before you plan. A new outbound-only range becomes operative around the middle of October 2026, reserved exclusively as the origin of outbound commercial calls with no ability to receive incoming calls, and binding on the companies within the scope of the consumer services law. On its face that is unlikely to bind a security simulation, because the calls are not commercial and the recipient is not a consumer, but it reshapes the Spanish outbound landscape you are operating inside. And numbering used for customer service by those companies may not be used as the identifier for commercial calls.

On presenting a number, the general rule is that the number shown must identify the actual originating line, unless the operator holds a ministerial authorisation exempting it. Note who holds that: the operator, not you. A supplier cannot obtain permission for its customer to present someone else's number; its carrier has to hold the exemption, and the published conditions attached to such authorisations require that the customer be the holder of the freephone number being presented and that the number allow a free return call.

What the country matrix holds for Spain

Number types:
Local, Toll free
Restricted for automated outbound:
Mobile, National

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

A provincial address, and a document requirement that does not exist

Spain does impose a real end-user requirement, and it is stricter than an address somewhere in the country.

A resolution of April 2026 inserted a new provision requiring that subscribers to the publicly available fixed telephone service hold a legal domicile within the provincial geographic area corresponding to the geographic numbering used, and prove it to their operator as a necessary condition of contracting the service. The parallel rule for the non-geographic nomadic range requires a legal domicile within national territory, proved the same way. So a Madrid number needs a Madrid province domicile, not merely a Spanish one.

There is a trap in checking this yourself, and it is the same shape as several others in this cluster. The official gazette serves the 2005 resolution that this amends in its original text. Read that page alone and you will not see the requirement at all; only the later-references analysis block reveals that the provision was inserted in 2026. A clean-looking page is not a current one.

What we cut is the document. Our own onboarding has said that Spain requires a company tax identifier. The regulator requires a legal domicile proved to the operator and names no document at all, and the identifier obligations we could find apply to entities registering as operators with the competition regulator rather than to end users holding numbers. Your carrier will very likely still ask for one, because it has to satisfy itself about who you are. That is its process, and it is worth knowing which is which when you are asked for something.

NIS2 has not arrived here, and DORA has

Spain has not transposed NIS2. There is no implementing law in the official gazette and no bill has entered the Cortes; what exists is a draft framework for cybersecurity coordination and governance. The earlier regime from 2018 remains the one in force for operators of essential services. So if a supplier is justifying your Spanish programme by reference to NIS2 duties, those duties are not in Spanish law yet. Plan for them rather than citing them.

For financial entities DORA applies directly, with compulsory security awareness and digital operational resilience training as modules for all employees and senior management, a testing programme whose menu expressly includes scenario-based tests, and threat-led penetration testing for entities meeting the criteria. We were not able to confirm the national designation for that testing from the central bank's own site during this research, because it renders client side and a fetcher's silence there is a false negative rather than an answer, so we are pointing at the Regulation rather than at a national page we did not read.

The usual limit applies throughout: social engineering is a standard technique within that kind of testing and it is not named in the Regulation, so a claim that European financial law requires vishing specifically is a sales line and not a citation.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in SPAIN. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance at the programme level.

Verify or correct each proposition below against primary Spanish sources, and tell me what we must have on file before the first call:

1. ⚠ The AEPD does NOT route employee monitoring through Art 6(1)(f). Its employment guidance names ET art 20.3 as the basis for control measures. Confirm, and tell us what a Spanish-framed record should contain instead of an LIA.
2. LGT art 66.1 has two limbs, both scoped 'a efectos de comunicacion comercial', and AEPD Circular 1/2023 states it does not address the automated limb. Confirm an internal test is outside both.
3. ET art 64 gives the comite de empresa information, consultation and a REPORT on systems of work organisation and control. Confirm it is not an approval gate, and when in the project it must be opened.
4. Systematic employee monitoring is on the AEPD's Art 35(4) list, so a DPIA is owed rather than discretionary.
5. STC 114/1984 FJ 7 puts a participant recording outside Art 18.3 secrecy, but expressly leaves a duty of reserve under Art 18.1. Confirm there is no current AEPD position on an employer recording an employee's call, and that the pre-2018 opinions are not authority.
6. Resolucion SETID de 27 de abril de 2026 inserted a provincial legal-domicile condition for fixed numbering, proved to the operator. ⚠ BOE serves the 2005 instrument in its ORIGINAL text, so check the Referencias posteriores block.
7. The CLI exemption under Orden IET/384/2016 is held by the OPERATOR, not the end user. Confirm we cannot obtain one ourselves.
8. Spain has NOT transposed NIS2; the 2018 regime remains in force. Confirm no Spanish law yet imposes the NIS2 training duties.

Flag anything that has changed since September 2026, and identify any obligation in our own convenio colectivo that this analysis omits.

Common questions

What is the legal basis for employee monitoring in Spain?
Not the one you would expect. The Spanish authority does not route employer control measures through legitimate interests: it names the Workers' Statute provision on the employer's power to check compliance with employment obligations. Consent is still invalid, because of the imbalance between employer and employee.
Why does the panel show different numbers as sellable and as restricted?
Because in Spain the two lists have nothing in common. One answers which classes of Spanish number can be supplied, the other which carry restrictions on automated outbound. The restricted list is not a subset of the sellable one, which is the assumption most readers arrive with and it is backwards here.
Do we need a Spanish company identifier to hold a number?
The regulator requires a legal domicile inside the number's own province, proved to your operator, and names no document at all. The identifier requirements we found apply to entities registering as operators rather than to end users. Your carrier may still ask, as its own process.
Do the Spanish telephone rules stop an AI voice simulation?
Both limbs of the rule are scoped to commercial communication purposes, and the authority's binding circular confirms that scope. An internal security test is not commercial communication. Article 50 of the EU AI Act is the rule that does reach an AI voice, and it has applied since August 2026.

Elsewhere in Southern Europe

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.