Voice phishing simulations in Switzerland
Nothing you know about running a voice phishing simulation in the European Union transfers here, and that cuts both ways: the data protection route is cleaner than the European one, and the criminal and labour routes are markedly harder. Switzerland is not stricter or looser than its neighbours. The constraint simply sits somewhere else, and this page says where.
Phone numbers
Supplied by Callstrike
Local numbers in Switzerland, after a one-time approval.
Running a simulation
Permitted, if the purpose is resilience
Labour law prohibits systems aimed at watching how staff behave at work.
Consent
It solves a different problem
The labour prohibition is public law, so no agreement with staff can cure it.
Getting a phone number in Switzerland
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Swiss numbers are not released from open inventory, so your workspace is cleared once and Callstrike then provisions a dedicated Swiss number against it. The clearance is register-based and short: the name and the registered office address, both taken from an extract of the commercial or official business register showing the local address, alongside the enterprise identification number.
The caller identity regime here is engineered against exactly the thing a pretext reaches for first, which is presenting the internal helpdesk number. A provider may let you present further numbers only where you can prove a right of use in them, must act to stop a customer presenting numbers it has no right to, and must coordinate to block a call carrying an invalid or unauthorised one. Since the middle of 2026 a transmitted number also carries an indicator of whether it rests on the customer's own data and whether the provider checked it, so a customer-supplied identity is visibly second class in the signalling and the downstream network can act on that.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Switzerland is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Name | Excerpt from the commercial or official business register |
| Registered office address | Excerpt from the commercial or official business register showing the local address |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in Switzerland?
The position in short, before your counsel reads the detail below.
Yes, and the first thing to get right is that none of the European framework reaches you. Switzerland is outside the European Union and outside the European Economic Area, having declined membership in 1992, and runs on bilateral agreements instead. The artificial intelligence regulation, the network and information security directive and the financial-sector resilience regulation are not Swiss law. Do not carry the answer across from Norway or Iceland either: their position turns on the Agreement Switzerland declined to join.
Data protection is the easy part, which surprises people. Swiss law does not work through a list of lawful bases at all: processing must not unlawfully breach the personality of the people concerned, and a breach is justified by agreement, by an overriding private or public interest, or by law. Better still, the statute expressly permits deferring or dispensing with the information duty where informing the person would defeat the purpose of the processing. That is a cleaner textual hook for a covert exercise than anything in the European Regulation, which reaches a similar result by a much longer route.
Recording is the sharp edge, and it runs opposite to most of Europe. A participant who records a non-public conversation without the consent of the others taking part commits an offence carrying up to a year, and the same provision reaches keeping, evaluating or passing on such a recording. The statutory exemption looks like a lifeline and is not: it covers calls to assistance, rescue and security services, and in business dealings conversations whose content is orders, mandates and reservations. A simulated pretext call is neither. Anyone reasoning that Swiss business calls may be recorded has read the first half of the provision.
The labour rule is the one that decides what your programme is allowed to be. Monitoring and control systems intended to monitor the behaviour of employees at their workplace may not be used at all, and the state secretariat's guidance says the protection is public law and cannot be departed from by private agreement, whether with employees or with their organisations. Its worked example of prohibited behaviour monitoring names telephones with which employees' conversations can be listened to or recorded. An exercise measuring organisational resilience, declared in advance, is arguable under the federal court's test. One that scores named individuals into performance or discipline is the thing the article prohibits, and no agreement fixes it.
What your company needs to do
6 items, in the order you will need them.
- Build the file the labour inspectorate can ask forSwitzerland-specificThe deliverable here is not a submission to a telecoms regulator, it is a file you can produce on request: a written justification of the overriding interest, a proportionality analysis, a record of how employees were involved in planning, the operating times and retention, and an internal regulation telling staff what rights and duties apply where monitoring systems including telephony are used.
- Frame the purpose as resilience, and hold the line internallySwitzerland-specificThe prohibition is on purpose rather than effect, and the federal court's test is whether the system aims exclusively or mainly at monitoring employee behaviour as such. That makes the internal argument about whether results ever feed a performance record a legal question rather than a cultural one. Settle it before the first campaign.
- Do not solve this with an employment contract clauseSwitzerland-specificThe state secretariat is explicit that the protection is public law and that it is not permissible to depart from it by private agreement with employees or their organisations. A clause in the contract, or in a collective agreement, does not cure a system caught by the prohibition. It answers a different question.
- Assume recording needs everyone's agreementSwitzerland-specificBeing on the call does not help, the exemption does not reach a security test, and a supervisor on a monitoring bridge is in the harder provision rather than the easier one. Ask whether the programme needs the audio at all; a campaign recording what happened and when does not have to solve this.
- Use an invented persona, not a named colleagueSince September 2023 there has been an identity-misuse offence aimed at using another person's identity to harm them or to obtain an unlawful advantage. An authorised test normally lacks that intent, but if the scenario impersonates a named real colleague, that person's written agreement is the clean answer rather than an argument about intent.
- Tell the people who would have to report an incidentOperators of listed critical infrastructure must report cyberattacks within 24 hours of discovery. A simulation is not an attack, but a test your security operations centre has not been told about can be escalated and reported as one, and unwinding a false report to a federal office is a worse afternoon than the test was worth.
The controls that do the work
How Callstrike is configured, and which provision in Switzerland each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
The Swiss justification you write turns on an overriding private interest and on proportionality, and the labour guidance requires that justification in writing where security monitoring cannot be cleanly separated from behaviour monitoring. A call that ends the moment an employee starts to give up a credential is what makes that separation stateable: the exercise measures whether the organisation is resilient, and the credential the pretext asked for is never acquired at all, so there is no personal file being built out of it.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The federal court's test asks whether the system aims exclusively or mainly at monitoring employee behaviour as such, and a call that ends in immediate teaching is evidence about aim rather than a claim about it. A second voice breaking character on the spot, and vishing training in writing the same day, is also the part of the design that keeps the recording question small, because there is nothing worth replaying to a third party.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Be precise about what this can and cannot do here. It cannot cure the labour prohibition, which is public law and not contractible around, and this page does not pretend otherwise. What it produces is the advance-notice half of the federal court's test, which turns partly on employees having been informed in advance that the system is in use, plus the record of how employees were involved in planning that the inspectorate file is supposed to contain.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Switzerland has no duty to tell the person on the line that the voice is synthetic, and we report that as an absence rather than as permission, because it is the kind of absence that closes. Meanwhile Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after the module, and a call a person opens in their own browser presents no Swiss number, so the right-of-use rule and the blocking obligations have nothing to attach to.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.