Callstrike
Compliance

Voice phishing simulations in Hong Kong

Phone numbers in Hong KongProvisioned by Callstrike after approval

Hong Kong is one of the cleanest jurisdictions in this portal for a voice phishing simulation, because the interception ordinance binds public officers and nobody else, so a private employer recording its own calls is outside it entirely and the whole question becomes a data protection one. The trap runs the opposite way from how it is usually cited: the regulator's covert-monitoring conditions are ones a simulation can never meet, and the overt route is the one that works.

Phone numbers

Supplied by Callstrike

Local numbers in Hong Kong, after a one-time approval.

Running a simulation

Permitted, on an overt standing policy

Overt as to the practice, unannounced as to the occasion. Nothing needs per-test notice.

Consent

Not needed to collect, needed to repurpose

The purpose may be stated in general terms; using results for a new one is where it bites.

Getting a phone number in Hong Kong

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Hong Kong is one of three countries in this portal where the carrier publishes a requirements table for a number type it sells here but not for the one we supply, so there is nothing for this page to summarise and the clearance form in the console is the only authority on what you will be asked for. Expect the ordinary business-identity and address checks that everything else in this region asks for, and read the panel below rather than planning against a list from a neighbouring country.

The design decision that belongs before the procurement one is where the call originates, and it is a Hong Kong specific. The communications regulator has carriers run a voice or text alert on incoming calls from outside Hong Kong that present a Hong Kong caller number. Such a call is not unlawful and it is not dropped: it connects, and it arrives with a warning attached telling the person to be careful, which destroys the pretext before anyone speaks. Given the fairness requirement described further down, a programme relying on the recipient ignoring a warning it triggered is arguing against itself. Originate in Hong Kong.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Hong Kong is assigned to youCallstrike
  4. 04Build and launch the campaignYour team

The carrier does not publish a requirements table for the number type we supply here, so what you will be asked for is whatever the clearance form in the console requests at the time. Treat that form as authoritative.

Is it lawful to run a simulation in Hong Kong?

The position in short, before your counsel reads the detail below.

Yes, and the criminal half of the question is simply absent. Hong Kong's interception and surveillance ordinance is titled as an ordinance to regulate interception and surveillance by or on behalf of public officers, and both of its operative prohibitions open with the words no public officer. A private employer is not one, so there is nothing in it to comply with, no authorisation to seek and no offence in it available. The telecommunications ordinance does not reach a participant either: its intercept provisions bind a telecommunications officer with official duties, require physical interference with an installation, or confer a power on the Chief Executive. The whole exposure is data protection.

Two phrases in the collection principle then carry the page. Personal data has to be collected for a lawful purpose directly related to a function or activity of the collector, be necessary for and not excessive in relation to it, and be collected by means that are lawful and fair in the circumstances of the case, with the purpose notified on or before collection. The statute lets that purpose be stated in general or specific terms, and that permission is what makes an unannounced test workable: a standing policy saying that security testing including simulated attacks may occur satisfies the principle without anyone being told which Tuesday the call comes. The second phrase, fair in the circumstances, is freestanding and is what a punitive or gratuitously distressing exercise would fail even behind a perfect policy.

The use principle is where a Hong Kong programme is most likely to go wrong, and it goes wrong at the drafting stage rather than at the call. Data may not be used for a new purpose without the person's prescribed consent, and a new purpose means any purpose other than the one for which the data was to be used at collection, or a purpose directly related to it. So if results are collected for awareness measurement, using them to discipline or dismiss is a new purpose unless discipline was inside what the policy stated. Whether the programme can have a consequence for an individual is therefore a question to settle before the first call, not after the first result.

Finally, the correction most likely to change how the exercise is argued. The regulator treats covert monitoring as available only on special circumstances, and every one of the conditions it lists is keyed to reasonable suspicion that an unlawful activity is about to be, is being or has been committed, with a footnote adding that it should be a last resort for the express purpose of identifying the culprits and curtailed once they are identified. A simulation investigates nobody and suspects nobody, so framing it as permitted covert monitoring imports a test it is guaranteed to fail. The route that works is the overt one, and the enforcement shape is forgiving: breach of a data protection principle is not itself an offence, the Commissioner serves an enforcement notice, and it is contravening that notice which is criminal.

What your company needs to do

8 items, in the order you will need them.

  • Write the employee monitoring policy to the regulator's own contents listHong Kong-specificIt should refer explicitly to the business purposes the monitoring seeks to fulfil, the circumstances under which monitoring may take place and the manner of it, the kinds of personal data that may be collected, and the purposes for which the data collected may be used. That last item is where the use principle is satisfied or missed, so treat it as the operative clause rather than the closing one.
  • Decide now whether a result can have a consequence for an individualHong Kong-specificIf it can, discipline has to be inside the purpose stated at collection, or using the result that way is a new purpose needing prescribed consent. This is a drafting instruction with a deadline: it has to be settled in the policy before the campaign runs rather than argued about when the first person fails.
  • Do not argue the exercise as permitted covert monitoringHong Kong-specificEvery entry condition the regulator sets turns on suspicion of unlawful activity and on identifying a culprit, and a simulation has neither. Arguing it that way volunteers for a test that cannot be passed. The correct framing is overt as to the practice and unannounced as to the occasion, which is what the general-terms permission buys you.
  • Justify the risk realistically rather than by assertionThe regulator asks you not only to identify the risks but to justify their existence and extent in a realistic manner, and it says a mere perception of risk unconnected with the nature of the business would not be sufficient to justify employee monitoring. Write down why your own workforce is exposed to voice social engineering specifically.
  • Bring the policy to employees before monitoring is introducedThe regulator offers routes rather than a rule: incorporate it into orientation or training, publish it in the handbook, post it on notice boards, include it in the employment agreement, or link it to a network login screen requiring affirmative acknowledgement before access. What matters is that it lands before the first call and that you can show it did.
  • Originate the call in Hong KongHong Kong-specificAn overseas-originated call presenting a Hong Kong number connects and arrives carrying a voice or text alert warning the recipient. That is a design failure rather than a legal one, and it cannot be cured by documentation. Note the asymmetry with Singapore next door, which blocks the same call outright.
  • Keep the two regulator documents apart when you cite themThe monitoring guidelines are guidance and say of themselves that they are not definitive statements of law but illustrative of best practices. The human resource management text is an approved code, and failing to observe it does not of itself create liability but is admissible and probative in proceedings under the ordinance. Neither is a statutory duty, and conflating them is common.
  • Do not expect a consultation counterpartyHong Kong's employment ordinance is a minimum-terms statute covering wages, notice, leave and severance. It contains no works council provision and nothing touching workplace policy, monitoring or security testing. The expectation that the policy be notified before monitoring begins is a notification expectation in guidance, not a statutory duty to consult.

The controls that do the work

How Callstrike is configured, and which provision in Hong Kong each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

Hong Kong's collection principle has two limbs a deception-based exercise has to satisfy on its own terms: the data must be adequate but not excessive in relation to the purpose, and it must be collected by means fair in the circumstances of the case. The second is freestanding and survives a perfect policy. A call that ends the moment an employee begins to give up a credential collects the behaviour and not the credential, so the excessiveness limb has nothing to weigh and the fairness limb is being asked about a test rather than about a harvest. It also keeps the results narrow enough that the use principle described above stays easy to honour.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

Fairness in the circumstances of the case is the requirement a Hong Kong programme is actually measured against, and it is where a punitive design fails while a diagnostic one passes. A second voice that breaks character the instant the call ends, followed by vishing training in writing the same day, moves the exercise from something done to a person into something done for them, and that is the difference the fairness assessment turns on rather than a nicety layered on top of it.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Hong Kong needs no agreement to collect, so the job here is the notified policy the regulator asks for and the dated evidence that it reached people before monitoring was introduced. The one place agreement does real work is the use principle: taking results outside the purpose stated at collection requires the person's prescribed consent, which in practice means getting the purpose right in the policy instead of collecting agreements afterwards. A hashed copy of the policy with a signed attestation of its scope is what a notice board cannot leave behind.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

Telephony was never the Hong Kong obstacle. The unsolicited messages ordinance covers voice calls and then exempts from its whole application person-to-person interactive communications, including ones whose synthesised element is activated in response to what the caller says, which is an AI voice agent described in a 2007 schedule. The real obstacle is the alert an overseas-originated call triggers, and this route has no calling identity to be alerted on: Callstrike's vishing simulator carries the same deepfake voice into a web call the learner starts themselves after working through the module. The collection and use principles still govern whatever either route collects, and Hong Kong imposes no synthetic-voice disclosure duty for the module to satisfy.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

General terms is what makes an unannounced test workable

Hong Kong does not require consent to collect personal data, so the question is never which basis applies. It is whether the collection principle is satisfied.

Personal data may not be collected unless it is collected for a lawful purpose directly related to a function or activity of the data user, the collection is necessary for or directly related to that purpose, and the data is adequate but not excessive in relation to it. It must be collected by means that are lawful and fair in the circumstances of the case. And where the data is collected from the individual, all practicable steps must be taken to ensure they are explicitly informed, on or before collection, of the purpose for which the data is to be used and the classes of persons to whom it may be transferred, and on or before first use of the access and correction rights and of who handles such requests.

Two phrases in that carry the page. The first is in general or specific terms, which is how the statute allows the purpose to be stated. Hong Kong requires the purpose to be notified before collection, and permits it to be stated generally. A standing employee monitoring policy saying that security testing including simulated attacks may occur therefore satisfies the principle without anyone being warned which Tuesday the call comes.

The second is fair in the circumstances of the case. That is a freestanding requirement about the means of collection, independent of notification, and it is what a punitive, humiliating or gratuitously distressing simulation would fail even with a perfect policy behind it.

The use principle is where a Hong Kong programme is most likely to go wrong, and it is worth setting out precisely. Personal data may not, without the prescribed consent of the data subject, be used for a new purpose, and a new purpose means any purpose other than the purpose for which the data was to be used at the time of collection, or a purpose directly related to it.

So if the results of a simulation are collected for awareness measurement, using them to discipline or dismiss is a new purpose unless discipline is directly related to what was stated at collection. If the employer intends any consequence for individuals, that consequence has to be inside the purpose stated in the policy. That is a drafting instruction, and it has to be settled before the first call rather than after the first result.

The regulator's expectations are set out in two documents of different weight, and conflating them is common. The monitoring guidelines are issued under the section empowering the Commissioner to publish guidance indicating how he proposes to exercise his powers, and they say of themselves that they are not definitive statements of law but constitute an approach illustrative of best practices and recommended standards. The code of practice on human resource management is an approved code, and the Ordinance provides that failure to observe a provision of an approved code shall not of itself render the data user liable to civil or criminal proceedings, but is admissible and probative in proceedings under the Ordinance. Neither is a statutory duty; both are what the Commissioner measures you against.

One line from the guidelines is worth carrying into any assessment because it sets the bar for necessity. In assessing the risks to be managed, employers should not only identify the risks but justify, in a realistic manner, their existence and extent, and a mere perception of risk unconnected with the nature of the business would not be sufficient to justify employee monitoring.

The interception ordinance is about public officers, and only them

This is the cleanest negative in the portal, and it is worth stating with the words the statute uses rather than as a general impression.

Hong Kong's interception and surveillance ordinance is titled as an Ordinance to regulate the conduct of interception of communications and the use of surveillance devices by or on behalf of public officers. Its first operative prohibition provides that, subject to an exception, no public officer shall directly or indirectly carry out any interception. Its second provides that no public officer shall directly or indirectly carry out any covert surveillance.

A private employer is not a public officer. There is nothing in that Ordinance for it to comply with, no authorisation for it to seek, and no offence in it available against it. That is a stronger statement than saying the Ordinance probably does not apply, and it is available on the face of the long title and both prohibitions.

The telecommunications ordinance does not reach a participant either. We read every occurrence of the word intercept in it. One provision binds a telecommunications officer with official duties in connection with a telecommunications service who wilfully intercepts or detains a message, which is an insider rule. Another requires damaging, removing or interfering in any way with a telecommunications installation, with intent to obstruct transmission or to intercept or discover the contents of a message, which requires physical interference with the installation. A third is a power for the Chief Executive to order interception of classes of messages, which is not a conduct rule at all.

So the criminal exposure for a participant recording its own call in Hong Kong is, on these instruments, none. The entire exposure is data protection. A voice recording of an identifiable employee is personal data, because data is defined to mean any representation of information in any document, so the collection principle governs making it, the use principle governs what is done with it afterwards, the security principle governs how it is held and the retention principle governs how long.

The enforcement shape is worth knowing because it is unusual. Breach of a data protection principle is not itself an offence in Hong Kong. The Commissioner serves an enforcement notice, and it is contravention of that notice which is criminal. That gives an employer a chance to correct, and it means the first consequence of getting this wrong is an instruction rather than a prosecution.

One practical note from the guidelines, offered as good practice rather than as a rule: where telephone monitoring is used to record conversations between employees and members of the public, it would be good practice to activate a pre-recorded message informing incoming callers that the conversation may be recorded and of the purposes.

It does cover voice, and then exempts an interactive call entirely

Hong Kong's unsolicited messages ordinance covers voice calls, which distinguishes it from several comparable statutes, and then lets a simulation out twice over.

The coverage is established by two definitions rather than by inference. An electronic message includes a message in any form sent over a public telecommunications service to an electronic address, and expressly includes a voice message. An electronic address means a string used to specify a source or destination of an electronic message, and expressly includes a telephone number. Voice and telephone number are both in scope.

The first way out is purpose. Every operative rule in the Ordinance is textually limited to a commercial electronic message, defined as a message a purpose of which is to offer to supply, or to advertise or promote, goods, services, facilities, land, a business opportunity or an investment opportunity, or a supplier or provider of any of them, in the course of or in furtherance of any business. The section headings make the point without argument: commercial electronic messages must include accurate sender information, must contain an unsubscribe facility, must not be sent to an address on the do-not-call register, and must not be sent with calling line identification concealed. An internal awareness test offers, advertises and promotes nothing.

The second way out is more interesting, because it draws the exact line that matters for modern voice products and it drew it in 2007. The Ordinance's schedule lists matters exempted from the application of the Ordinance, and the first two items are voice, sound, image or video messages that involve person-to-person interactive communications between a caller and a recipient without any pre-recorded or synthesized, that is machine-generated or simulated, element; and those that involve person-to-person interactive communications together with a pre-recorded or synthesized element where that element is activated in response to information communicated by the caller.

Read that against an AI voice agent. A live call is inside the first item. An agent that responds interactively to what the person says is inside the second, because its synthesized element is activated in response to information communicated by the caller. Either way the exemption is from the whole Ordinance, not merely from one Part. What falls outside both items is a pure one-way pre-recorded blast with no interactivity, and even that would still need to be a commercial message before any rule bit. The regulator confirms the position in its own words, listing person-to-person calls among the exempted messages to which the regulatory requirements will not apply.

So for a simulation the belt and the braces both hold, and a broadcast-style robocall relies on the commercial scoping alone.

Hong Kong has no binding synthetic-voice or AI disclosure duty. The privacy regulator's artificial intelligence framework describes itself as providing a set of recommendations on best practices, to be considered and adopted in proportion to the risks a system may pose, and its companion ethical guidance is recommendation-shaped throughout. Neither is law, and neither imposes a duty to disclose that a voice is synthetic. The binding constraint on an AI-voiced simulation in Hong Kong remains the requirement that collection be by means fair in the circumstances of the case, which is where a synthetic-voice deception would actually be tested.

Hong Kong labels the call rather than dropping it

There is no Hong Kong rule binding a non-commercial caller's choice of presented number, and the anti-scam measures that do exist bind licensed operators rather than callers.

The one statutory caller identity rule provides that a person who sends a commercial electronic message with a Hong Kong link from a telephone or fax number must not conceal or withhold the calling line identification of the sending number, nor perform any operation with the purpose or effect of concealing it. Two limits follow. It prohibits concealing, not falsifying. And it applies to a commercial message, which an internal test is not. The regulator confirms the scoping in its own summary, listing the duty not to hide the calling line identification among the obligations of a sender of a commercial electronic message.

The measures against scam calls are operator-facing and worth reading for what they do to your call rather than for what they require of you. The communications regulator describes working with providers on a series of measures including full implementation of real-name registration for SIM cards, the sender registration scheme for text messages, the provision of a voice or text alert service for incoming calls from outside Hong Kong with caller numbers prefixed with the Hong Kong country code, blocking of suspected fraudulent numbers on police information, and a requirement that providers continuously optimise network management and promptly suspend suspicious numbers. A newer measure plays a voice alert stating that a call is made from a new pre-paid SIM card before connecting it.

Note the asymmetry with Singapore, because it changes whether a cross-border test fails or merely underperforms. Hong Kong alerts; Singapore blocks. An overseas-originated call presenting a Hong Kong number will connect, and will arrive with a voice or text alert attached telling the recipient to be careful. The call is not unlawful and it is not dropped. It is pre-labelled as suspicious, which destroys the pretext entirely and makes it a poor design choice rather than an illegal one. Given the fairness requirement in the collection principle and the express purpose of the alert, a programme that relies on the recipient ignoring a warning it triggered is arguing against itself.

Every measure quoted above is an obligation imposed on telecommunications service providers. The employer is a caller, not a licensee.

What the country matrix holds for Hong Kong

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Covert monitoring is the wrong door, and the policy is the right one

This is the analytical correction most likely to change how a Hong Kong programme is argued, and it cuts the opposite way from how the covert-monitoring guidance is usually cited.

The regulator's position is that as a general rule employee monitoring should be conducted in an overt manner, and that owing to its highly intrusive nature covert monitoring should not be used unless justified by relevant special circumstances. It then lists the factors: that there is reasonable suspicion to believe an unlawful activity is about to be committed, is being committed or has been committed; that resorting to covert monitoring to detect or collect evidence of that activity is absolutely necessary; that overt monitoring would likely prejudice detection or successful gathering of evidence; and that the covert monitoring can be limited in scope to areas where the unlawful activity is likely to take place and undertaken for a limited duration. A footnote adds that it should be a last resort, for the express purpose of identifying the culprits and for no other purpose, curtailed immediately once they are identified.

Every one of those conditions is keyed to suspicion of unlawful activity. A vishing simulation investigates nobody, suspects nobody and is looking for no culprit. An employer therefore cannot justify an unannounced simulation as permitted covert monitoring: those entry conditions can never be satisfied, and framing the exercise that way imports a test it is guaranteed to fail.

The correct route is the overt one, and it works. The simulation is disclosed in advance as a standing practice through a notified policy, which satisfies the requirement to state the purpose in general terms, while individual tests remain unannounced because nothing requires per-instance notice. Overt as to the practice, unannounced as to the occasion.

The regulator is specific about the document. Employers who decide to monitor should accept responsibility and be accountable for the proper conduct of their monitoring, and have a duty to ensure that a privacy policy pertaining to employee monitoring is developed and brought to the notice of employees before the monitoring is introduced, and that privacy-compliant measures are developed to protect employee data.

And it prescribes the contents. An employee monitoring policy should explicitly refer to the business purposes that the monitoring seeks to fulfil, the circumstances under which monitoring may take place and the manner in which it may be conducted, the kinds of personal data that may be collected in the course of monitoring, and the purposes for which the personal data collected in monitoring records may be used. That last item is where the use principle described earlier gets satisfied or missed.

On communicating it, the regulator offers a list rather than a rule: incorporate the policy into personnel training or orientation, publish it in the employee handbook, post it on notice boards, include it in the employment agreement, or link it to a network login screen requiring affirmative acknowledgement before access.

There is no consultation duty behind any of this. Hong Kong's employment ordinance is a minimum-terms statute covering wages, notice, leave and severance, not a workplace-governance one. We counted it through: works council, collective, monitor, privacy and surveillance each return nothing across its three hundred and thirty-eight pages, and the four occurrences of consult concern the Commissioner consulting medical experts on long service payment entitlement and an employee taking pro rata annual leave after consultation with the employer. Nothing in it touches workplace policy, monitoring or security testing.

So the expectation that the policy be developed and notified before monitoring begins is a notification expectation in non-binding guidance, not a statutory consultation duty, and the two should not be conflated in either direction.

An intelligence-led test the regulator has never described in public

Hong Kong's banking regulator runs a cyber assessment framework whose third stage is an intelligence-led attack simulation, and the honest finding about it is a negative that is more useful than it sounds.

The framework was introduced in 2016 and updated in 2020. Its published description sets out three stages: an inherent risk assessment, a maturity assessment, and intelligence-led cyber attack simulation testing, described as a test of the institution's cyber resilience by simulating real-life cyber attacks from adversaries making use of relevant cyber intelligence, which institutions assessed at medium or high inherent risk are expected to conduct within a reasonable time. The 2020 update introduced blue team requirements for that testing, to measure the effectiveness of detection, response and recovery functions.

Now the counting. Across all five publicly retrievable circulars introducing and updating that framework, social engineering, phishing and voice phishing each appear zero times. Simulation appears only as part of the name of the testing stage and in its description. Intelligence-led simulation of adversary attacks in practice encompasses social engineering, but the regulator has not said so in any document we could obtain.

The reason for that gap is worth recording, because it is not an omission on our part. The detailed framework and testing documents are issued to authorized institutions and are not published on the regulator's own site: we searched its document repository and its own indexes and could retrieve only the covering circulars and one annex. The term counts above therefore cover the circulars we actually read, and we are stating that limit rather than presenting a count of the whole framework.

The consequence for a buyer is a caution rather than a conclusion. Anyone telling a Hong Kong institution that its regulator requires vishing simulations is over-reading the public record, and an institution that is in scope for the testing stage should be working from the documents it has been issued rather than from anything published.

The contrast with Singapore next door sharpens the point. There, social engineering is named in a statutory definition and again in the financial regulator's guidelines. Here it is named in neither of the instruments a member of the public can read.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in HONG KONG. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. A standing employee monitoring policy states that security testing including simulated attacks may occur.

Verify or correct each proposition below against primary Hong Kong sources, and tell me what our policy must say before the first call:

1. ⚠⚠ Cap 589's long title and ss 4(1) and 5(1) are confined to public officers, so a private employer is outside the Ordinance entirely, not merely unlikely to be caught.
2. Cap 106 ss 24, 27 and 33 reach only a telecommunications officer with official duties, physical interference with an installation, and a Chief Executive power. Confirm no participant recording offence exists.
3. DPP1(3) permits the purpose to be stated «in general or specific terms», which is what makes an unannounced individual test workable behind a standing policy. Confirm.
4. ⚠ DPP3: results collected for awareness measurement cannot be used for discipline unless discipline is «directly related» to the purpose stated at collection. Assess how specifically our policy must say so.
5. ⚠⚠ Monitoring Guidelines 2.3.3 keys EVERY covert-monitoring condition to «reasonable suspicion ... that an unlawful activity is about to be committed», with fn 11 adding «as a last resort ... for the express purpose of identifying those parties». Confirm a simulation can never satisfy these, and that the overt route is the correct one.
6. Instrument weight: the Monitoring Guidelines are s 8(5) guidance («not definitive statements of law»); the HR Code is a s 12 approved code and s 13(1) makes breach admissible and probative but not of itself actionable.
7. Cap 593 Sch 1 Table 1 exempts from the WHOLE Ordinance person-to-person interactive communications with a «pre-recorded or synthesized ... element ... activated in response to information communicated by the caller». Confirm an interactive AI agent is inside it.
8. Cap 57 contains no works council, monitoring, privacy or surveillance provision, so there is no consultation duty. Confirm.

⚠ HKMA C-RAF 2.0 and iCAST detail documents are issued to authorized institutions and are NOT published; do not assume the public circulars are the whole framework. Flag anything that has changed since September 2026.

Common questions

Does Hong Kong's interception ordinance apply to us?
No. Its long title and both operative prohibitions are confined to public officers, so a private employer is outside it entirely. There is nothing in it to comply with and no offence in it available. The whole question becomes a data protection one.
Can we justify an unannounced test as covert monitoring?
No, and trying is the common mistake. Every condition the regulator sets for covert monitoring turns on reasonable suspicion of unlawful activity and on identifying a culprit. A simulation suspects nobody. Use the overt route: a notified standing policy, with individual tests unannounced.
Does the unsolicited messages ordinance cover an AI voice call?
It covers voice calls, but exempts from the whole Ordinance person-to-person interactive communications, including ones whose synthesized element is activated in response to what the caller says. An interactive AI agent is exempt; a one-way pre-recorded blast is not, though it would still have to be commercial.
Will a spoofed call from overseas reach Hong Kong staff?
It will connect, and it will arrive with a voice or text alert warning the recipient, because incoming calls from outside Hong Kong presenting a Hong Kong number trigger one. Not unlawful, but the pretext is destroyed before anyone speaks. Singapore blocks the same call outright.

Elsewhere in Asia Pacific

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.