Callstrike
Compliance

Voice phishing simulations in Brazil

Phone numbers in BrazilProvisioned by Callstrike after approval

Brazil hands you a legitimate interests ground and then bolts a transparency duty onto it, with nothing in the wording that lets you withhold transparency because disclosure would spoil the exercise. So what decides a Brazilian voice phishing simulation is what you publish before it runs. Numbers are cleared once and then assigned to your workspace, and one caller identity rule lands on you rather than only on your carrier.

Phone numbers

Supplied by Callstrike

Local numbers in Brazil, after a one-time approval.

Running a simulation

Permitted, with publication owed

The ground is available. The transparency duty attached to it has no exception in it.

Consent

Publication, not permission

What is owed is transparency about the programme, not anybody's agreement to be called.

Getting a phone number in Brazil

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Brazilian numbers are not released from open inventory. Your administrator clears the country once in the console and Callstrike then provisions a dedicated Brazilian number against that clearance. Two things are typed in, your business name and your CNPJ number, and two things are evidenced, which are the lines in the table below: the identity behind that CNPJ, and a business address. The CNPJ certificate is accepted for both, so in practice one document does most of the work.

The address constraint here is national rather than local, which makes Brazil easier than its neighbours: it has to be within Brazil and a post office box is not accepted, and no prefix has to match anything. The Brazilian planning trap is elsewhere and it is about volume. A subscriber generating more than ten thousand calls on any single day, counted across all of its access codes and irrespective of purpose, has to move to the special high-volume prefix on most of its traffic. The list of declared activities behind that prefix ends with other cases, so there is no purpose-based way out of it, and an unusually large single-day campaign should be planned with the threshold in view.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Brazil is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Proof of business identityCNPJ certificate
Proof of business addressMust be within Brazil; a P.O. Box is not acceptable.CNPJ certificate, Utility bill, Tax notice, Rent receipt, Title deed

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Brazil?

The position in short, before your counsel reads the detail below.

Yes, and the Brazilian difficulty is not the ground but what the ground drags along with it. The statute lists ten hypotheses and that list is exhaustive, there is no employment-specific entry, and the realistic choice for a security exercise is the legitimate interests of the controller. The article that follows then says three things: the interest has to be assessed against concrete situations rather than asserted generically, only the data strictly necessary for the purpose may be processed, and measures must be adopted to guarantee the transparency of processing based on that interest. The third of those has no exception attached to it anywhere in the text.

So a Brazilian programme cannot rest on the argument that telling people would spoil the test, and the answer is to separate two things that get confused. Publish the programme in advance: that exercises of this kind happen, what they collect, why, and how long anything is kept. Do not publish the schedule or the scenario. Transparency about the programme is not notice of the individual call, and Brazil makes the first compulsory without requiring the second.

One structural point is easy to get backwards and expensive if you do. Brazil has an impact report, but the duty to produce one is not triggered by risk. Both of the provisions are permissive and both are addressed to the national authority, which may require a controller to prepare one. There is no threshold at which you owe one of your own motion. Preparing it anyway is sensible and cheap; describing it internally as legally required is a misdescription of the statute that someone will eventually check.

Recording is settled here in enacted text rather than by inference: there is no crime where the capture is carried out by one of the interlocutors, a provision inserted in 2019, and the supreme court has separately confirmed that such a recording is admissible as evidence. Neither authorises a recording programme, so the audio stays inside everything above, transparency duty included. And there is one open question worth taking to Brazilian counsel before anything else if your scenario clones the voice of an identifiable person: whether that voice is a biometric datum, which would move the processing into the regime for sensitive data, whose own list has no legitimate interests entry in it.

What your company needs to do

6 items, in the order you will need them.

  • Publish the programme before the first callBrazil-specificThis is the Brazilian obligation and it is the one nobody else in this portal imposes. A short public statement that the organisation runs security exercises of this kind, what data they collect, why, and how long it is kept, dated before the campaign. Keeping the timing and the scenario unpublished is a different thing and is not affected by it.
  • Write down what the exercise deliberately does not collectOnly data strictly necessary for the purpose may be processed, and the cheapest way to evidence that limit is to record the choice rather than the volume: no credential captured, no audio retained beyond a stated period, outcomes rather than content. A necessity analysis that lists exclusions is far more convincing than one that lists justifications.
  • Assess the interest against a concrete situationA generic assertion that security matters is what the wording rules out. Record the specific exposure this campaign addresses, for the roles it addresses, at the time you ran it, and keep that next to the transparency statement rather than in a separate file nobody finds.
  • Check the collective instruments that bind your categoryBrazil-specificThere is no Brazilian works council and no federal duty to consult before introducing a measure of this kind. The workplace commission that does exist is for accident and harassment prevention and has no competence here. But free stipulation is subordinated to the collective instruments that apply to you, so a convention or agreement covering your category can create a notice or consultation duty that federal law does not. Read the ones that actually bind you.
  • Present a number your organisation holds, because this rule reaches youBrazil-specificMaking calls that unduly hinder identification of the caller is improper use of the service, and the consequence provision names the users responsible for making the calls, not only the provider carrying them. The remedy that arrives first is your numbering resources being blocked, which ends a campaign faster than any fine.
  • Do not let anyone describe the impact report as mandatoryIt matters more than it sounds. A programme justified internally on a false obligation loses the argument the moment someone reads the two permissive provisions, and the real position is easier to defend anyway: you prepared one because the authority may ask for it.

The controls that do the work

How Callstrike is configured, and which provision in Brazil each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

Say plainly what this does not do in Brazil: it does not touch the transparency duty, which is the provision that actually decides a Brazilian campaign, and nothing about call design reduces what you have to publish. What it answers is the other limit in the same article, which is that only the data strictly necessary for the purpose may be processed. The call ends the moment an employee starts to give up a credential, so the credential is never processed at all, and a necessity analysis is a much shorter document when the answer is that the thing was never taken.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The internal commission every sizeable Brazilian workplace maintains had its remit extended in 2022 to cover harassment, and that is the forum where a name-and-shame programme would be raised. A call that ends in vishing training delivered on the spot by a second voice, with an email that repeats it in writing, is a poor candidate for that complaint. It also supports the transparency position, because a programme that teaches at the moment of failure is easier to describe publicly than one that only reports.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Brazil's duty is to be transparent, and a duty to publish leaves you needing to prove that you published. This is what produces that: the statement recorded, hashed and timestamped before the campaign ran, with a per-employee trail where you went further and told people directly. It is not the ground you process on, which is legitimate interests, and it does not reduce the transparency duty. It is the evidence you discharged it.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

Brazil's calling restriction never reached this exercise in the first place, since it binds licensed providers and governs calls that advertise or offer to consumers, so the web route is not doing telephony work here. What it answers is the country's own tension. A module the learner works through before opting into a call is the one delivery where full transparency and a realistic exercise stop pulling against each other, and Callstrike's vishing simulator carries the same deepfake voice into it.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

A ground with a transparency duty bolted to it

The Brazilian statute lists ten hypotheses under which personal data may be processed, and that list is exhaustive. There is no employment-specific hypothesis, so an employer is choosing among the general ones, and the realistic choice for a security exercise is the legitimate interests of the controller or of a third party, except where the data subject's fundamental rights and freedoms which require protection of personal data prevail.

What makes Brazil different is the article that follows. The controller's legitimate interest may ground processing only for legitimate purposes considered on the basis of concrete situations, which rules out a generic assertion. Only the personal data strictly necessary for the intended purpose may be processed. And then the sentence that decides the design: the controller must adopt measures to guarantee the transparency of processing based on its legitimate interest.

That is a hard duty with no exception attached to it. There is no wording permitting an employer to withhold transparency where disclosure would defeat the purpose, and no regulator instrument we could reach supplies one. So a Brazilian programme cannot rest on the argument that telling people would spoil the test. The workable answer is the same one that works in most of this portal, and Brazil simply makes it compulsory rather than advisable: publish in advance that the organisation runs security exercises of this kind, what data they collect, why, and how long it is kept, without publishing the schedule or the scenario. Transparency about the programme is not the same as notice of the individual call.

One point of structure is easy to get backwards and expensive if you do. Brazil has an impact report, but the duty to produce one is not triggered by risk. Both the provision attached to legitimate interests and the general one are permissive and both are addressed to the national authority: the authority may determine that the controller prepare an impact report. There is no threshold at which a Brazilian controller must produce one on its own initiative. Preparing one anyway is sensible, and describing it as legally required is not accurate.

A question the text raises and that we are not going to answer for you. Sensitive personal data includes a biometric datum when linked to a natural person, and if a cloned voice were treated that way the processing would move out of the ordinary hypotheses and into the stricter regime for sensitive data, which has its own shorter list and no legitimate interests entry in it. The national authority has published a technical study asserting that manipulation of faces and voices directly involves the processing of sensitive personal data. That is a study, not a binding norm, and we could find no court ruling on the point. If your scenario clones an identifiable person's voice, this is the question to take to Brazilian counsel first.

The statute answers the crime and the court answers the evidence

Brazil is one of the countries where the participant question is settled in enacted text, so it can be stated flatly rather than hedged. But two different authorities answer two different halves of it and they are not interchangeable, which is where summaries go wrong.

The constitutional starting point is that the secrecy of telephone communications is inviolable, save by judicial order for the purposes of criminal investigation or criminal procedure. The statute implementing that makes it a crime to intercept telephone, computer or telematic communications, or to conduct ambient listening, without judicial authorisation, punishable by two to four years of imprisonment and a fine.

The criminal answer is then given in one line of that same statute: there is no crime if the capture is carried out by one of the interlocutors. That provision was inserted in 2019 and it means the position does not depend on how a court characterises interception. An operator who is a party to the call is outside the offence by the words of the statute.

The evidential answer comes from the Supreme Federal Court, which in a general repercussion decision reaffirmed the admissibility, as a means of proof, of an ambient recording made by one of the interlocutors without the other's knowledge. We would rather label that precisely than let it do more work than it can. It removes an illegality objection in criminal proceedings. It does not authorise an employer's recording programme, and no formal thesis was fixed for it.

So the recording is not a crime and would not be excluded as unlawfully obtained. It is still a processing of personal data, and everything in the section above applies to it: the ground, the strict necessity limit, and above all the transparency duty. In practice the Brazilian decision to make in advance is not whether you may record but what you have already told people about recording, and how long the audio is kept afterwards.

A rule aimed at operators selling to consumers, and no rule about voices

Everything published about Brazilian calling rules before late 2025 is describing either a revoked instrument or one that had not started, so it is worth being exact about which text is live. The 2014 resolution everyone cites was revoked by a 2023 replacement, and the advertising-call article of that replacement only took substantive effect on 1 September 2025.

That article is scoped twice over, and both scopings put an internal exercise outside it. It binds the licensed providers rather than any caller, and it governs calls that are advertising or that offer services and products to consumers. The consumer protection code defines a consumer as a natural or legal person who acquires or uses a product or service as final recipient. An employee receiving a test call from their own employer is not one, the employer is not a licensed provider, and the call offers nothing.

So the calling restriction and its opt-out platform do not reach a security exercise, and nothing in the article turns on whether the voice at the other end is a person or a machine.

On synthetic voice specifically, the answer today is that Brazil has no disclosure duty in force. The comprehensive artificial intelligence bill was approved by the Senate and sent to the Chamber of Deputies in March 2025, where it remains. The Senate's own tramitação record shows the proceeding closed at the Senate stage and the matter forwarded onward, which is a bill in progress and not a statute. We checked that record on the day this page was written rather than relying on secondary reporting, because this is exactly the fact most likely to be described as if it had already happened.

Two practical consequences follow. There is currently no Brazilian obligation to announce that a caller is synthetic, so the design constraint on voice mode is the transparency duty in the data protection statute rather than a telecoms or artificial intelligence one. And because a bill is pending rather than absent, a programme built to disclose voluntarily will not need rebuilding if the bill passes in something like its present form.

Obscuring who is calling is improper use, and it reaches the user

Brazil answers the caller identity question clearly and, unusually, in a way that lands on the calling organisation as well as on its carrier. That second half is the part most worth knowing.

The numbering act tells operators two things. Traffic on calls originated from numbering resources that are unassigned, vacant or in quarantine must not be permitted. And providers must not permit the access code of the originating user to be changed on their network. Together those close the network route to presenting a number nobody holds.

The resolution then adds a rule addressed to conduct rather than to networks. It is improper use of telecommunications services, or improper use of numbering resources, to make calls that unduly hinder identification of the caller. And its consequence provision says in terms that improper use subjects the users responsible for making the calls to blocking, including of their numbering resources, and to the sanctions in the administrative sanctions regime. So this is not only a duty your provider owes; it is exposure your own organisation carries, and the remedy that arrives first is having your numbers cut off.

The practical answer is therefore straightforward. Present a number your organisation holds and can be reached on. Do not attempt to obscure the origin of the call, because the wording of the improper-use provision is about hindering identification rather than about impersonating anyone in particular, and a display designed to be unhelpful is inside it.

One Brazilian rule catches people out by being scoped in an unexpected way, and it is worth checking against your call volumes rather than against your purpose. The special prefix for high-volume calling is triggered by volume alone: a subscriber generating more than ten thousand calls on at least one day, across all of its access codes, irrespective of whether the calls conclude and irrespective of what they are for, must use that prefix on at least ninety per cent of the calls it generates. The list of declared activities behind it runs telemarketing, collections, donation requests and then other cases, so there is no purpose-based way out of it. A campaign stays outside this because of its scale, not because it is not marketing, and a very large single-day campaign should be planned with the threshold in view.

What the country matrix holds for Brazil

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Nothing to convene, and a collective instrument that can change that

Brazil has no works council and no federal duty to consult employees before introducing a monitoring or testing measure. That is a checked answer rather than a silence, and each of the three institutions people reach for fails for a different and verifiable reason.

The labour consolidation says nothing about monitoring at all. The Portuguese words for monitoring and video monitoring occur nowhere in the consolidated text, which carries amendments as recent as 2026. Its provision on freedom of contract is a limit on what may be agreed rather than a procedure for agreeing it.

The internal commission that exists in every sizeable Brazilian workplace is a commission for the prevention of accidents and of harassment. Its subject matter was extended in 2022 to cover harassment, and it acquired no competence over monitoring or information security. Promoting it into a works council would be convenient and wrong.

The constitutional provision that comes closest is expressly and exclusively facilitative. In undertakings of more than two hundred employees the election of a representative is guaranteed, with the exclusive purpose of promoting direct dealing between employees and employers. It creates a channel and says in its own words that this is all it creates: no right to be consulted, no power to withhold agreement.

There is one real qualifier and it is per-employer rather than national. Because free stipulation in the employment relationship is subordinated to the applicable collective instruments, a collective convention or agreement covering your category can create a consultation or notice duty that federal law does not impose. That has to be checked against the instruments that actually bind you, and no national-level answer can substitute for reading them.

So the Brazilian file is documentary rather than procedural, and its centre is the transparency duty described in the first section. Publish the programme before it runs. Record the concrete situation the legitimate interest is assessed against, rather than a generic security assertion. Record the strict necessity analysis, which in practice means writing down what the exercise deliberately does not collect. Prepare the impact report on the footing that the authority may ask for it rather than that you owe it. And check the collective instruments for your category before assuming there is nobody to tell.

The banking rule legislated about testing, and legislated about machines

The Brazilian financial cyber rule is a national monetary council resolution rather than a central bank one, which is worth getting right because the wrong name leads to the wrong document. It has been in force since March 2021 and amended twice, most recently at the end of 2025.

We counted terms across the whole consolidated text, accent and case insensitively, and the result is a clean set of zeroes. Phishing, vishing, social engineering, simulation, awareness and training all return nothing. Nothing in the instrument names this activity or anything adjacent to it.

Its only people-facing requirement is a policy content requirement. The cyber security policy must set out the mechanisms for disseminating a culture of cyber security in the institution, including the implementation of programmes for the capability development and periodic evaluation of personnel. Periodic evaluation of personnel is real and it is the hook a Brazilian buyer will use, but the provision prescribes no method, and reading it as requiring a simulation would be inference rather than citation.

What the regulator did legislate about, and recently, is testing of a different kind. An article added at the end of 2025 requires institutions to ensure that intrusion tests are carried out at least annually, with independence and impartiality, and with their results documented. That is systems testing with a stated frequency and stated quality conditions, and the contrast is the finding: the regulator turned its attention to testing nine months before this page was written, and what it required was penetration testing of machines.

So the honest position for a Brazilian financial institution is that the periodic evaluation of personnel obligation is satisfiable by a simulation and does not demand one, while the only mandatory test in the instrument is technical. Nobody should be told that Brazilian banking rules require a vishing exercise, because they do not say so.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in BRAZIL. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The programme is published in advance, without its schedule or scenarios.

Verify or correct each proposition below against primary Brazilian sources, and tell me what we must publish and record before the first call:

1. LGPD art 7 is an exhaustive list with no employment-specific hypothesis, and art 10 governs the legitimate interests route.
2. Art 10 paragraph 2 imposes a transparency duty with no exception where disclosure would defeat the purpose, and advise what publication satisfies it for an exercise of this kind.
3. Art 10 paragraph 1's strict necessity limit, and whether recording audio at all survives it where outcomes would do.
4. Arts 10 paragraph 3 and 38 are both permissive and both addressed to the ANPD, so no impact report is owed of the controller's own motion.
5. Lei 9.296 art 10-A paragraph 1 removes the offence where the capture is by one of the interlocutors, and STF Tema 237 answers only evidential admissibility.
6. Whether a cloned voice is a dado biometrico under art 5(II), which would move the processing into art 11. Note ANPD's Radar Tecnologico n. 6 is a technical study rather than a binding norm.
7. ANATEL Res 765 art 44(IV) and its paragraph 2 expose the USER, not only the provider, to blocking and to RASA sanctions.
8. Ato 12712 item 9.1.1's 0303 obligation is triggered by volume alone at ten thousand calls in a single day, irrespective of purpose.

Flag anything that has changed since September 2026, and identify any collective convention or state-level obligation this analysis omits.

Common questions

Can a Brazilian exercise be covert if we use legitimate interests?
Only partly. The statute attaches a transparency duty to that ground with no exception for cases where disclosure would defeat the purpose. Publish the programme, what it collects and why, in advance. Keeping the schedule and the scenario unpublished is a different thing from keeping the programme unpublished.
Do we owe an impact report before running one?
Not automatically, and this is the easiest thing to get backwards. Brazil's impact report is authority-triggered rather than risk-triggered: both of the relevant provisions are permissive and addressed to the national authority, which may require one. Preparing it anyway is sensible, and calling it legally required would misdescribe the statute.
Is recording the call a problem in Brazil?
Not as a crime. The interception statute says in terms that there is no offence where the capture is carried out by one of the interlocutors, and the Supreme Federal Court has confirmed such recordings are admissible. The data protection analysis, including the transparency duty, still applies to the audio.
Which number can we display on a Brazilian campaign?
One your organisation holds. Providers must not carry traffic from unassigned, vacant or quarantined numbering, and must not permit the originating access code to be changed. Making calls that unduly hinder identification of the caller is improper use, and the penalty reaches the user directly.

Elsewhere in the Americas

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.