Voice phishing simulations in Brazil
Brazil hands you a legitimate interests ground and then bolts a transparency duty onto it, with nothing in the wording that lets you withhold transparency because disclosure would spoil the exercise. So what decides a Brazilian voice phishing simulation is what you publish before it runs. Numbers are cleared once and then assigned to your workspace, and one caller identity rule lands on you rather than only on your carrier.
Phone numbers
Supplied by Callstrike
Local numbers in Brazil, after a one-time approval.
Running a simulation
Permitted, with publication owed
The ground is available. The transparency duty attached to it has no exception in it.
Consent
Publication, not permission
What is owed is transparency about the programme, not anybody's agreement to be called.
Getting a phone number in Brazil
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Brazilian numbers are not released from open inventory. Your administrator clears the country once in the console and Callstrike then provisions a dedicated Brazilian number against that clearance. Two things are typed in, your business name and your CNPJ number, and two things are evidenced, which are the lines in the table below: the identity behind that CNPJ, and a business address. The CNPJ certificate is accepted for both, so in practice one document does most of the work.
The address constraint here is national rather than local, which makes Brazil easier than its neighbours: it has to be within Brazil and a post office box is not accepted, and no prefix has to match anything. The Brazilian planning trap is elsewhere and it is about volume. A subscriber generating more than ten thousand calls on any single day, counted across all of its access codes and irrespective of purpose, has to move to the special high-volume prefix on most of its traffic. The list of declared activities behind that prefix ends with other cases, so there is no purpose-based way out of it, and an unusually large single-day campaign should be planned with the threshold in view.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Brazil is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Proof of business identity | CNPJ certificate |
| Proof of business addressMust be within Brazil; a P.O. Box is not acceptable. | CNPJ certificate, Utility bill, Tax notice, Rent receipt, Title deed |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in Brazil?
The position in short, before your counsel reads the detail below.
Yes, and the Brazilian difficulty is not the ground but what the ground drags along with it. The statute lists ten hypotheses and that list is exhaustive, there is no employment-specific entry, and the realistic choice for a security exercise is the legitimate interests of the controller. The article that follows then says three things: the interest has to be assessed against concrete situations rather than asserted generically, only the data strictly necessary for the purpose may be processed, and measures must be adopted to guarantee the transparency of processing based on that interest. The third of those has no exception attached to it anywhere in the text.
So a Brazilian programme cannot rest on the argument that telling people would spoil the test, and the answer is to separate two things that get confused. Publish the programme in advance: that exercises of this kind happen, what they collect, why, and how long anything is kept. Do not publish the schedule or the scenario. Transparency about the programme is not notice of the individual call, and Brazil makes the first compulsory without requiring the second.
One structural point is easy to get backwards and expensive if you do. Brazil has an impact report, but the duty to produce one is not triggered by risk. Both of the provisions are permissive and both are addressed to the national authority, which may require a controller to prepare one. There is no threshold at which you owe one of your own motion. Preparing it anyway is sensible and cheap; describing it internally as legally required is a misdescription of the statute that someone will eventually check.
Recording is settled here in enacted text rather than by inference: there is no crime where the capture is carried out by one of the interlocutors, a provision inserted in 2019, and the supreme court has separately confirmed that such a recording is admissible as evidence. Neither authorises a recording programme, so the audio stays inside everything above, transparency duty included. And there is one open question worth taking to Brazilian counsel before anything else if your scenario clones the voice of an identifiable person: whether that voice is a biometric datum, which would move the processing into the regime for sensitive data, whose own list has no legitimate interests entry in it.
What your company needs to do
6 items, in the order you will need them.
- Publish the programme before the first callBrazil-specificThis is the Brazilian obligation and it is the one nobody else in this portal imposes. A short public statement that the organisation runs security exercises of this kind, what data they collect, why, and how long it is kept, dated before the campaign. Keeping the timing and the scenario unpublished is a different thing and is not affected by it.
- Write down what the exercise deliberately does not collectOnly data strictly necessary for the purpose may be processed, and the cheapest way to evidence that limit is to record the choice rather than the volume: no credential captured, no audio retained beyond a stated period, outcomes rather than content. A necessity analysis that lists exclusions is far more convincing than one that lists justifications.
- Assess the interest against a concrete situationA generic assertion that security matters is what the wording rules out. Record the specific exposure this campaign addresses, for the roles it addresses, at the time you ran it, and keep that next to the transparency statement rather than in a separate file nobody finds.
- Check the collective instruments that bind your categoryBrazil-specificThere is no Brazilian works council and no federal duty to consult before introducing a measure of this kind. The workplace commission that does exist is for accident and harassment prevention and has no competence here. But free stipulation is subordinated to the collective instruments that apply to you, so a convention or agreement covering your category can create a notice or consultation duty that federal law does not. Read the ones that actually bind you.
- Present a number your organisation holds, because this rule reaches youBrazil-specificMaking calls that unduly hinder identification of the caller is improper use of the service, and the consequence provision names the users responsible for making the calls, not only the provider carrying them. The remedy that arrives first is your numbering resources being blocked, which ends a campaign faster than any fine.
- Do not let anyone describe the impact report as mandatoryIt matters more than it sounds. A programme justified internally on a false obligation loses the argument the moment someone reads the two permissive provisions, and the real position is easier to defend anyway: you prepared one because the authority may ask for it.
The controls that do the work
How Callstrike is configured, and which provision in Brazil each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
Say plainly what this does not do in Brazil: it does not touch the transparency duty, which is the provision that actually decides a Brazilian campaign, and nothing about call design reduces what you have to publish. What it answers is the other limit in the same article, which is that only the data strictly necessary for the purpose may be processed. The call ends the moment an employee starts to give up a credential, so the credential is never processed at all, and a necessity analysis is a much shorter document when the answer is that the thing was never taken.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The internal commission every sizeable Brazilian workplace maintains had its remit extended in 2022 to cover harassment, and that is the forum where a name-and-shame programme would be raised. A call that ends in vishing training delivered on the spot by a second voice, with an email that repeats it in writing, is a poor candidate for that complaint. It also supports the transparency position, because a programme that teaches at the moment of failure is easier to describe publicly than one that only reports.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Brazil's duty is to be transparent, and a duty to publish leaves you needing to prove that you published. This is what produces that: the statement recorded, hashed and timestamped before the campaign ran, with a per-employee trail where you went further and told people directly. It is not the ground you process on, which is legitimate interests, and it does not reduce the transparency duty. It is the evidence you discharged it.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Brazil's calling restriction never reached this exercise in the first place, since it binds licensed providers and governs calls that advertise or offer to consumers, so the web route is not doing telephony work here. What it answers is the country's own tension. A module the learner works through before opting into a call is the one delivery where full transparency and a realistic exercise stop pulling against each other, and Callstrike's vishing simulator carries the same deepfake voice into it.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.