Phone numbers in CanadaProvisioned by Callstrike after approval
Canada is one of the few countries where getting a number takes no paperwork at all, and one of the few where the design of the call is a real decision rather than a formality. A live-operator voice phishing simulation runs here on settled ground. An automated one rests on two arguments that no regulator has yet resolved, and this page sets out both so you can choose deliberately.
Phone numbers
Supplied by Callstrike
Local numbers in Canada, after a one-time approval.
Running a simulation
Permitted, but the call design is a decision
A live caller is settled. An automated caller turns on two unresolved questions.
Consent
Part of the argument, not a permission
It cannot switch off the telecom rule, but it bears on whether the call is unsolicited.
Getting a phone number in Canada
One approval per country, with no documentation to gather.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days.
Canada is one of a handful of countries where the carrier publishes no documentation requirement at all, so the evidence-gathering that dominates most of this portal simply has no counterpart here. Plan for the days rather than the paperwork: what you are waiting on is the country being enabled against your workspace, not a regulator reading a submission.
What does stand between you and a working campaign is technical rather than legal, and it is worth knowing before you plan the display number. Since November 2021 Canadian carriers have been required to implement caller identity authentication for calls carried over internet protocol, and since 2019 they have been required to block, at the network level, calls whose displayed identity does not conform to the numbering plan. A number your provider cannot associate with you does not earn full attestation, and an improvised display value fails on the wire rather than in an argument.
01Ask for the country to be enabled for your workspaceYour administrator, in the Callstrike console.
02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
03A dedicated number in Canada is assigned to youCallstrike
04Build and launch the campaignYour team
No regulatory documentation is required to hold a number here. The clearance step is Callstrike enabling the country for your workspace, with no forms to complete and no evidence to gather.
Is it lawful to run a simulation in Canada?
The position in short, before your counsel reads the detail below.
Yes, and Canada is the country on this portal where that answer needs the most care, because the binding constraint is a telecom rule rather than a privacy one and it does not care what your purpose is. The regulator's rules on unsolicited telecommunications say that an automatic dialling-announcing device placing a call with no solicitation in it must open with a clear message identifying who the call is from and briefly describing its purpose, with a reachable address and number. An opening announcement of who is calling and why is not compatible with a covert test, and the only exemption in the rule is for public-service callers such as police, fire departments, schools and hospitals. Nothing in it turns on agreement, so no policy your staff signed can switch it off.
Two questions sit in front of that rule, though, and both are genuinely open rather than convenient. The first is whether a conversational agent is such a device at all: the definition covers equipment used to convey a pre-recorded or synthesised voice message, which reads as a one-way announcement, and a system that listens and answers is not obviously the thing being described. No regulator decision, policy or bulletin resolves it. The second is whether the call is unsolicited, which is the word the entire part hangs on and which is defined nowhere, neither in the rules nor in the statute they are made under. An employee who accepted a security-testing policy has a real argument that a call under that programme was solicited. Note what this does and does not do: it does not switch the rule off, it goes to whether the rule was ever engaged.
So the practical shape of a Canadian campaign is a choice, and it is better made at the start than defended later. A live operator whose own voice is transformed in real time is not an automatic dialling-announcing device on any reading, so a human-led vishing simulation runs here without needing either argument. An autonomous deepfake voice campaign is the one that depends on them, and how comfortable you are with that is a question for your own counsel rather than for us. Penalties are modest per violation, up to fifteen hundred dollars for an individual and fifteen thousand for a corporation, but they are per violation and a campaign multiplies quickly.
Underneath the telecom rule sit four separate privacy regimes rather than one, and which applies turns on facts about you rather than about the exercise. The federal statute reaches employee information only for federal works, undertakings and businesses, which is a short list: banks, airlines, broadcasters, railways, shipping. Everywhere else it is provincial, and only Alberta, British Columbia and Quebec have a general private-sector statute at all. Ontario, which almost everybody assumes is covered, has none, and its obligation here is an employment standards one instead. Settle which regime applies to you before anything else on this page.
What your company needs to do
7 items, in the order you will need them.
Settle which of the four privacy regimes applies to youCanada-specificThis turns on whether you are a federal work, undertaking or business, and then on which province your staff are in. Getting it wrong means writing the wrong notice, and in Ontario it means looking for a privacy obligation that does not exist while missing the employment standards one that does.
Choose live-operator or automated before you build the campaignCanada-specificThis is the Canadian decision and it cannot be deferred. A live caller sits outside the automated-calling rule on any reading. An autonomous caller depends on two arguments no regulator has resolved, so if you take that route, take it knowingly and record the reasoning.
Give the notice before the exercise, not afterEvery one of the four regimes wants it in advance. Alberta and British Columbia want it three separate times over: before collecting, before using and before disclosing. Quebec wants you to inform people first, in clear and simple language, and to say that technology capable of identifying, locating or profiling them is in use.
Add the Ontario electronic monitoring policy if you employ 25 or more thereCanada-specificThe threshold counts individuals rather than full-time equivalents, on 1 January, with the policy due before 1 March and a copy to every employee within thirty days. Put the programme in it: logging who answered a simulated call and what they disclosed is electronic monitoring on any sensible reading of an undefined term.
In Quebec, budget for the impact assessment and the publicationsCanada-specificQuebec requires an assessment for any project to acquire or overhaul an information system involving personal information, with no risk threshold on whether one is owed. Three separate things also have to be published: who is in charge of protecting personal information, the governance policies, and a confidentiality policy.
Use an invented persona, never a named real personFraudulently personating another person carries up to ten years on indictment, and the words that matter are another person. A generic help desk is not one. Cloning a named executive moves the exercise toward that offence, and that is a scenario-design decision rather than a paperwork one.
Write down the reasonableness analysisEvery regime here gates on what a reasonable person would consider appropriate in the circumstances. Record the purpose, why a less intrusive method would not achieve it, and why the loss of privacy is proportionate to what the programme protects.
The controls that do the work
How Callstrike is configured, and which provision in Canada each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
The federal schedule says information is to be collected by fair and lawful means, and explains that the requirement exists to stop organisations collecting by misleading or deceiving people about the purpose. That clause is uncomfortably close to the mechanism of a pretext call, and it is the one a Canadian privacy officer will find. The call ends the moment an employee starts to give up a credential, so nothing the pretext asked for is ever collected, and a clause about the means of collection has no collection to attach to.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The federal harassment and violence definition is broader than Ontario's: it needs no course of conduct, has no management-action carve-out, and reaches any conduct that could reasonably be expected to cause offence or humiliation. In a federally regulated workplace that is the strongest argument against a name-and-shame design, and a call that ends in immediate teaching rather than in a report circulated weeks later is the answer to it.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Two jobs here, and they are different. It produces the advance notice every one of the four regimes requires, dated before the campaign. And where you are arguing that a call under an accepted security-testing policy was not unsolicited, the signed and timestamped record of what staff were told is the evidence that argument stands on. It cannot make the automated-calling rule go away, and this page does not pretend otherwise.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
This is the route that sidesteps the Canadian question entirely, and in this one country that is worth real money. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module. A call a person initiates in their own browser is not a telecommunication placed by an automatic dialling-announcing device, so the rule that decides everything above has nothing to attach to, and the prudential regulator's expectation that you regularly test employees is satisfied all the same.
Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.
Four regimes split by province, and Ontario is inside none of them
Canada does not have a privacy answer. It has four, and which one applies turns on facts about the employer rather than about the exercise, so this is the first thing to settle.
The federal statute reaches employee information only in connection with the operation of a federal work, undertaking or business. That is a defined term and a short list: banks, aerodromes and air transport, radio broadcasting, railways and other undertakings connecting or extending beyond a province, shipping and ferries. A software company in Toronto is not one. Everywhere else employee privacy is provincial, and only Alberta, British Columbia and Quebec have a general private-sector statute. You can prove that twice over: from the federal provision itself, and from the fact that the Governor in Council has made an exemption order for organizations in exactly those three provinces and no others.
So Ontario, which people assume is covered, has no general private-sector privacy statute at all. Its only exemption order is for health information custodians, and the health statute behind it expressly excludes identifying information in a record that relates primarily to the custodian's own employees and is kept primarily for a purpose other than providing health care. An Ontario employer's obligation on this activity is the employment standards one described further down this page, not a privacy one.
For a federally regulated employer the route is notice rather than agreement. Collection, use and disclosure without the individual's consent is permitted where it is necessary to establish, manage or terminate an employment relationship and where the employer has informed the individual that the information will or may be collected, used or disclosed for those purposes. Over the top of that sits a general appropriateness gate: an organization may collect, use or disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances.
One clause of the federal schedule deserves reading before the script is written, because it is uncomfortably close to the mechanism. Information is to be collected by fair and lawful means, and the schedule explains that this requirement is intended to prevent organizations from collecting information by misleading or deceiving individuals about the purpose for which information is being collected. Its own target is deception used to procure agreement, and an employer using the employment route is not procuring agreement, but the wording is broad enough that the exercise should be designed to measure behaviour rather than to harvest anything.
Alberta and British Columbia reach nearly the same place through mirror-image drafting, and the numbering catches people out. Alberta speaks of personal employee information at sections fifteen, eighteen and twenty-one; British Columbia speaks of employee personal information at thirteen, sixteen and nineteen. In both provinces the no-agreement route requires the purpose to be solely the employment relationship and the collection to be reasonable, and in both it requires notice three separate times: before collecting, before using, and before disclosing. Alberta folds the notice into the conditional test, so it is a precondition; British Columbia states it as an independent obligation alongside the permission. Alberta adds that its reasonableness standard is what a reasonable person would consider appropriate in the circumstances, and confines those notice paragraphs to an individual who is a current employee.
British Columbia has one arguable covert route and we present it as an argument rather than a basis. Collection without agreement is permitted where it is reasonable to expect that collecting with agreement would compromise the availability or accuracy of the information and the collection is reasonable for an investigation, and investigation is defined to include the prevention of fraud where it is reasonable to believe the fraud may occur or may have occurred. A standing awareness programme is not obviously an investigation into a particular apprehended fraud, and the province's own commissioner has said in a monitoring context that gathering information covertly or for a different purpose would not be authorised.
Quebec is the strictest and the most procedural. Anyone collecting personal information must inform the person, at the time of collection, of the purposes, the means, the rights of access and rectification and the right to withdraw agreement, in clear and simple language whatever the means of collection. A further provision goes directly at this activity: a person collecting information using technology that allows the person to be identified, located or profiled must first inform them of the use of that technology and of the means of activating those functions, and profiling is defined to include analysing that person's work performance. First inform, not inform. And Quebec requires an impact assessment for any project to acquire, develop or overhaul an information system involving personal information, with no risk threshold on whether one is owed and proportionality governing only how deep it goes.
The Criminal Code clears in one line and the privacy statute does not
Canadian call recording splits into two questions that are answered by different bodies of law, and treating the first answer as the whole answer is the common error.
The criminal question is straightforward. Knowingly intercepting a private communication by means of a device is an indictable offence carrying up to five years, and intercept is defined to include listening to, recording or acquiring a communication. But the prohibition does not apply to a person who has the express or implied consent of the originator of the communication or of the person the originator intended to receive it. The operator running the exercise is a party to the call, so that exemption is available on its own facts and no permit is needed. The downstream offence of using or disclosing an intercepted communication does not engage either, because it is conditioned on the interception having been made without a party's consent in the first place.
The privacy question is not answered by any of that. A recording is a collection of personal information, so it needs whichever of the four regimes applies to be satisfied on its own terms, and each of them wants notice before the act. The federal commissioner's published position on recording calls is that an organization may record only for purposes a reasonable person would consider appropriate, that it must inform the person, clearly state the purpose and ask for their agreement, and that agreement is implied where the person continues the call knowing both. It lists narrow situations where that is not required, one of which is a call where the person's knowledge that it is being recorded could hamper the organization's ability to obtain accurate information, which is textually close to a covert exercise.
We flag the scope of that document rather than lean on it. It is about customer calls, not employees, and it should not be presented as employee guidance. For employees the operative provisions are the federal employment route, the Alberta and British Columbia notice triples and the Quebec collection and profiling duties, and every one of those requires the notice to come first.
Two other criminal provisions get raised at this activity and only one of them is a real design constraint. Conveying information known to be false with intent to injure or alarm requires an intent an authorised training exercise does not have. Fraudulently personating another person, with intent to gain an advantage or to cause disadvantage, carries up to ten years on indictment, and the words to notice are another person. An invented persona such as a generic help desk is not another person. Cloning or impersonating a named real individual, a specific executive most obviously, moves the exercise toward that offence, and that is a scenario-design decision rather than a paperwork one.
An automated call has to announce itself, and no agreement buys that away
This is the section that decides whether a Canadian campaign can be delivered the way most buyers imagine it, and the answer is that an automated one cannot.
The regulator's rules on unsolicited telecommunications are made under a statutory power to prohibit or regulate the use of a carrier's facilities for unsolicited telecommunications. Their fourth part governs automatic dialling-announcing devices, defined as automatic equipment incorporating the capability of storing or producing telephone numbers, used alone or with other equipment, to convey a pre-recorded or synthesised voice message. Note the second half of that definition. It is not drafted around one-way playback, and it names synthesised voice in terms.
The rule that matters applies to automated calls where there is no attempt to solicit anything, which is exactly what an internal exercise is. Such a call must begin with a clear message identifying the person on whose behalf it is made and a brief description of its purpose, and that identification must include an email or postal address and a local or toll-free number at which a representative of the originator can be reached, repeated at the end if the message runs beyond sixty seconds and kept valid for sixty days afterwards. The same rule confines calling to nine in the morning until half past nine at night on weekdays and ten until six at weekends in the recipient's own time, bars sequential dialling, bars calls to emergency lines and healthcare facilities, and requires equipment to disconnect within ten seconds of the recipient hanging up.
An opening announcement of who is calling and why is not compatible with a covert test, and there is no way to agree around it. The single exemption from those conditions is for calls made for public-service reasons, and the examples given are emergency and administration calls by police and fire departments, schools, hospitals or similar organizations. A private employer's awareness exercise is not that. The practical consequence is that the Canadian route to a covert exercise is a live caller rather than an automated one, and the design decision has to be made before the campaign is built.
Two things about all of this are genuinely unresolved and we would rather say so than give you false comfort in either direction. No regulator decision, policy or bulletin determines whether a conversational voice agent, which dials automatically and speaks with a synthesised voice but converses rather than plays a recording, is such a device. And the phrase unsolicited telecommunication is nowhere defined, in the rules or in the statute they are made under, so whether an employer's automated call to its own employee is unsolicited at all is unsettled on the face of the instrument. A consultation on reviewing the rules opened in June 2026 and closed in August with no decision issued. A consultation is not law.
Penalties are per violation and modest individually: up to fifteen hundred dollars for an individual and fifteen thousand for a corporation, which multiplies quickly across a campaign.
Two clean negatives complete the picture. The anti-spam statute does not reach voice at all: it expressly does not apply to an interactive two-way voice communication between individuals, or to a voice recording sent to a telephone account, and the telecom statute preserves the regulator's jurisdiction over exactly those categories. That is a deliberate handoff rather than a gap. And Canada has no in-force artificial intelligence statute: the bill that would have created one never left committee and expired with its Parliament in January 2025, no bill in the current Parliament replaces it, and no federal statute or regulator rule requires a caller to disclose that a voice is synthetic. The rules require disclosure of who is calling and why, not of what is speaking. The nearest Canadian norm is a voluntary federal code that asks signatories to identify systems that could be mistaken for humans, and it binds nobody else.
No spoofing offence, and an attestation system that settles it anyway
Canada is one of the clearer countries in this portal on caller identity, once you stop looking for a prohibition that does not exist.
There is no general Canadian statutory bar on presenting a number other than the one you are calling from. The regulator says as much on its own consumer page, in terms, and then lists legitimate uses: a call centre placing calls on behalf of clients and altering its display to show the client's name and number, or a doctor discussing results who wants the hospital's general call-back number to appear. Where it says spoofing is illegal, the sentence is about telemarketers, who are separately required to identify themselves and their client accurately.
That framing is what makes the answer for an internal exercise different from the answer most pages give, because the telemarketing rules switch themselves off for calls made for purposes other than solicitation. So the display requirement that lives in those rules does not reach a security test at all.
What does reach it is the display condition inside the automated-calling rule described above, and it is worth reading for what it permits as much as for what it requires. An automated call must display the originating number or an alternate number at which the originator of the call can be reached, and that number has to remain valid for sixty days. Presenting something other than the literal originating line is contemplated, provided you can be reached on what you present. Presenting a number belonging to somebody else is not authorised by it.
The constraint that actually bites is structural rather than prohibitory, and it operates before any of this becomes a legal question. Since 30 November 2021 the regulator has required telecommunications service providers, as a condition of offering service, to implement the caller identity authentication framework for calls carried over internet protocol. The duty runs to the providers, so an enterprise is bound through its carrier rather than directly, but the effect on a campaign is immediate: a number your provider cannot associate with you does not earn full attestation, and the certificate eligibility conditions turn on a provider having access to numbering resources.
Separately, providers have been required since 2019 to block, at the network level, calls whose displayed identity does not conform to established numbering plans or which matches the number of the person being called. The regulator's own consumer wording is that calls exceeding fifteen digits or not dialable under the North American plan are blocked before reaching the subscriber. So an improvised display value fails on the wire rather than in an argument, which is the more useful thing to know.
One honest gap. The criteria that separate full, partial and gateway attestation are published by the industry governance authority rather than by the regulator, and we do not cite them here because that is not a source this portal treats as primary. What we can show you is the regulator naming the three levels and stating the numbering-resource condition on certificates.
Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.
A written policy in Ontario, publication in Quebec, and nobody to consult
The Canadian file is a set of documents rather than a set of approvals, because no Canadian jurisdiction requires an employer to consult employees or a union before introducing workplace monitoring or a security test. That is a checked negative rather than an absence of research, and it is worth saying plainly because readers arriving from a European page will be looking for a body to convene.
The nearest candidates were examined and none of them supplies one. Ontario's occupational health and safety statute does require a harassment programme to be developed in consultation with the joint committee or a representative, but that is a standing document, and the statute expressly says that a reasonable action taken by an employer relating to the management and direction of workers is not workplace harassment. The federal harassment and violence regulations impose genuinely joint duties on assessment, risk factors, policy and training, but they attach to the standing framework rather than to any exercise, and where employer and policy committee cannot agree the employer's decision prevails. Quebec's labour standards statute requires a psychological harassment policy and contains no employer consultation duty. The only consultation language found anywhere is a regulator asking, in a video surveillance leaflet, whether you should consult the people concerned in advance. That is a suggested question, not a duty, and we are not going to upgrade it.
The federal definition of harassment and violence is worth one line as a design input even so, because it is broader than Ontario's: it needs no course of conduct, has no management-action carve-out, and reaches any action, conduct or comment that can reasonably be expected to cause offence or humiliation. In a federally regulated workplace that is the strongest available argument against a name-and-shame simulation design. It is an argument rather than a rule.
Ontario's real obligation is an employment standards one and it is the most concrete document requirement in the country. An employer that on 1 January of any year employs twenty-five or more employees must, before 1 March of that year, have a written policy in place for all employees on electronic monitoring, stating whether it monitors employees electronically and if so describing how and in what circumstances, and the purposes for which the information obtained may be used, with the date the policy was prepared and the date of any change. A copy goes to every employee within thirty days, to a new employee within thirty days of starting, and to an assignment employee within twenty-four hours, and the policy must be retained for three years after it ceases to have effect. The threshold counts individuals rather than full-time equivalents, and counts everyone employed in Ontario.
Two features of that provision are usually described loosely and are worth stating exactly. Its enforcement is deliberately narrow: a complaint may be made only about failure to provide a copy, and expressly not about the content of the policy or about the monitoring itself. And the only saving clause in the section says that nothing in it affects or limits the employer's ability to use information obtained through electronic monitoring, which is about use of information already collected rather than a general licence to monitor. The broader proposition that the requirements create no new privacy rights appears in the ministry's guide, which is official interpretation and not the statute.
Whether a simulation programme belongs in that policy is not really arguable. Electronic monitoring is undefined across the whole statute, and the ministry's gloss is deliberately open, covering all forms of monitoring done electronically and expressly not limited to employer-issued devices or to monitoring at the workplace. An employer that logs who answered a simulated call and what they disclosed is on the wrong side of any argument that this is not electronic monitoring.
Quebec adds publication rather than consultation, and there are three separate obligations rather than one. The title and contact details of the person in charge of protecting personal information must be published on the enterprise's website. Detailed information about the enterprise's governance policies and practices must be published in simple and clear language. And anyone collecting personal information through technological means must publish a confidentiality policy in clear and simple language. On top of those sits the impact assessment for the project of acquiring the system, which requires consulting the person in charge from the outset of the project.
So a Canadian file looks like this. Establish which of the four regimes applies before anything else. Write the notice, and give it before the exercise rather than after, three times over in Alberta and British Columbia. Add the Ontario electronic monitoring policy where the headcount reaches the threshold, and put the programme in it. In Quebec add the impact assessment, the pre-collection profiling notice and the three publications. Everywhere, record the reasonableness analysis: the purpose, why a less intrusive method would not do, and why the loss of privacy is proportionate.
The banking regulator expects you to test people and never says how
Canada has one instrument that comes closer to requiring this activity than anything in most jurisdictions, and it never uses any of the words you would search for.
The prudential regulator's technology and cyber risk guideline applies to all federally regulated financial institutions, including foreign bank and foreign insurance company branches, and has been effective since 1 January 2024. One of its sections is titled cyber awareness is promoted and tested, and what it says is that institutions should enable and encourage employees, customers and third parties to report suspicious cyber activity, should create awareness of attack scenarios directly targeting them, and, in addition, should regularly test employees to assess their awareness of cyber threats and the effectiveness of their reporting processes and tools.
That is an express people-testing expectation, and it is unusual: most financial regulators in this portal require drills of the response function and stop there. But we counted the terms over the full text rather than trusting the impression, and phishing, vishing, social engineering, simulation and simulated all return zero. The guideline's only mentions of penetration testing and red teaming are about systems, in a passage about identifying vulnerabilities or control gaps using an intelligence-led approach.
Stated precisely, then: the guideline expects regular testing of employees on threat awareness and on whether they actually report, and it does not prescribe a method. A vishing exercise is one way to satisfy it and is not the required way. And the instrument uses should throughout, which makes it a supervisory expectation rather than a statutory duty, so the consequence of ignoring it is a supervisory conversation rather than a penalty.
The rest of the sector picture is negative and each negative was measured. The same regulator's integrity and security guideline returns zero for phishing, vishing, social engineering, simulation, test, awareness and insider, and contains no personnel security-testing expectation at all. Ontario's health information statute requires steps that are reasonable in the circumstances to protect information, and returns zero across the whole Act for phishing, vishing, social engineering, simulation, awareness and training: it does not require staff testing.
On critical infrastructure, the bill that would have created a Canadian regime died after third reading in the Senate and expired with its Parliament in January 2025. A separate cyber security act did receive Royal Assent in June 2026, and it says nothing about testing employees. The national cyber centre publishes guidance that is advisory and should be cited as advisory.
So the honest summary for a Canadian buyer is that one supervisory expectation, binding on federally regulated financial institutions and phrased as a should, asks you to test your people regularly. Everywhere else this is good practice with nothing behind it.
Paste into Claude, Harvey or your firm's tool to pressure-test the position above.
You are advising on an authorised internal security exercise in CANADA. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance and the programme is covered by an accepted security-testing policy.
Tell me first which privacy regime governs us, then verify or correct each proposition below against primary Canadian sources:
1. PIPEDA reaches employee personal information only in connection with a federal work, undertaking or business (s 4(1)(b)); otherwise only AB, BC and QC have a general private-sector statute, and Ontario has none.
2. CRTC Unsolicited Telecommunications Rules Part IV r.4(d) (NOT Part III) requires a non-solicitation ADAD call to open by identifying the originator and describing its purpose, and the only exemption, r.4(i), is for public-service callers.
3. Whether a CONVERSATIONAL AI voice agent falls within the ADAD definition, which turns on "a pre-recorded or synthesized voice message". Is there any CRTC decision, policy or bulletin on this, or the June 2026 consultation's outcome?
4. Whether a call to our own employee under an accepted security-testing policy is an "unsolicited telecommunication" at all, that term being undefined in the UTRs and in Telecom Act s 2.
5. Criminal Code s 184(2)(a) clears participant recording, but each privacy regime still requires notice first; s 403 is engaged only by personating another real person.
6. ESA Part XI.1 s 41.1.1 obliges a written electronic monitoring policy at 25+ Ontario employees, and a simulation programme belongs in it.
7. OSFI B-13 s 3.1.7 expects FRFIs to regularly test employees, using "should", and never names phishing, vishing, social engineering or simulation.
Flag anything that has changed since September 2026. ⚠ Verify every Quebec section number against the live legisquebec text: our source was an Archive capture stating currency 27 May 2025.
Common questions
Can we run an automated vishing call in Canada?
Not covertly. An automated call carrying a recorded or synthesised voice must open by identifying who it is from and describing its purpose, with a reachable address and number. The only exemption covers public-service callers such as police and hospitals. A live caller is the workable route.
Which Canadian privacy law applies to our employees?
It depends on the employer, not the exercise. The federal statute covers employee data only for federal works, undertakings and businesses such as banks, airlines and broadcasters. Otherwise it is Alberta, British Columbia or Quebec law. Ontario has no general private-sector privacy statute at all.
Do we need the Ontario electronic monitoring policy?
If you employ twenty-five or more people in Ontario on 1 January, yes, and the programme belongs in it. Electronic monitoring is undefined in the statute and the ministry reads it broadly, so logging who answered a simulated call and what they disclosed is caught on any sensible reading.
Does any Canadian regulator require this kind of testing?
One expects it. The prudential regulator's technology and cyber guideline says federally regulated financial institutions should regularly test employees on threat awareness and on whether they report. It never names phishing, vishing, social engineering or simulation, so the method is yours to choose.
Elsewhere in the Americas
The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.