Voice phishing simulations in Hong Kong
Hong Kong is one of the cleanest jurisdictions in this portal for a voice phishing simulation, because the interception ordinance binds public officers and nobody else, so a private employer recording its own calls is outside it entirely and the whole question becomes a data protection one. The trap runs the opposite way from how it is usually cited: the regulator's covert-monitoring conditions are ones a simulation can never meet, and the overt route is the one that works.
Phone numbers
Supplied by Callstrike
Local numbers in Hong Kong, after a one-time approval.
Running a simulation
Permitted, on an overt standing policy
Overt as to the practice, unannounced as to the occasion. Nothing needs per-test notice.
Consent
Not needed to collect, needed to repurpose
The purpose may be stated in general terms; using results for a new one is where it bites.
Getting a phone number in Hong Kong
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Hong Kong is one of three countries in this portal where the carrier publishes a requirements table for a number type it sells here but not for the one we supply, so there is nothing for this page to summarise and the clearance form in the console is the only authority on what you will be asked for. Expect the ordinary business-identity and address checks that everything else in this region asks for, and read the panel below rather than planning against a list from a neighbouring country.
The design decision that belongs before the procurement one is where the call originates, and it is a Hong Kong specific. The communications regulator has carriers run a voice or text alert on incoming calls from outside Hong Kong that present a Hong Kong caller number. Such a call is not unlawful and it is not dropped: it connects, and it arrives with a warning attached telling the person to be careful, which destroys the pretext before anyone speaks. Given the fairness requirement described further down, a programme relying on the recipient ignoring a warning it triggered is arguing against itself. Originate in Hong Kong.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Hong Kong is assigned to youCallstrike
- 04Build and launch the campaignYour team
The carrier does not publish a requirements table for the number type we supply here, so what you will be asked for is whatever the clearance form in the console requests at the time. Treat that form as authoritative.
Is it lawful to run a simulation in Hong Kong?
The position in short, before your counsel reads the detail below.
Yes, and the criminal half of the question is simply absent. Hong Kong's interception and surveillance ordinance is titled as an ordinance to regulate interception and surveillance by or on behalf of public officers, and both of its operative prohibitions open with the words no public officer. A private employer is not one, so there is nothing in it to comply with, no authorisation to seek and no offence in it available. The telecommunications ordinance does not reach a participant either: its intercept provisions bind a telecommunications officer with official duties, require physical interference with an installation, or confer a power on the Chief Executive. The whole exposure is data protection.
Two phrases in the collection principle then carry the page. Personal data has to be collected for a lawful purpose directly related to a function or activity of the collector, be necessary for and not excessive in relation to it, and be collected by means that are lawful and fair in the circumstances of the case, with the purpose notified on or before collection. The statute lets that purpose be stated in general or specific terms, and that permission is what makes an unannounced test workable: a standing policy saying that security testing including simulated attacks may occur satisfies the principle without anyone being told which Tuesday the call comes. The second phrase, fair in the circumstances, is freestanding and is what a punitive or gratuitously distressing exercise would fail even behind a perfect policy.
The use principle is where a Hong Kong programme is most likely to go wrong, and it goes wrong at the drafting stage rather than at the call. Data may not be used for a new purpose without the person's prescribed consent, and a new purpose means any purpose other than the one for which the data was to be used at collection, or a purpose directly related to it. So if results are collected for awareness measurement, using them to discipline or dismiss is a new purpose unless discipline was inside what the policy stated. Whether the programme can have a consequence for an individual is therefore a question to settle before the first call, not after the first result.
Finally, the correction most likely to change how the exercise is argued. The regulator treats covert monitoring as available only on special circumstances, and every one of the conditions it lists is keyed to reasonable suspicion that an unlawful activity is about to be, is being or has been committed, with a footnote adding that it should be a last resort for the express purpose of identifying the culprits and curtailed once they are identified. A simulation investigates nobody and suspects nobody, so framing it as permitted covert monitoring imports a test it is guaranteed to fail. The route that works is the overt one, and the enforcement shape is forgiving: breach of a data protection principle is not itself an offence, the Commissioner serves an enforcement notice, and it is contravening that notice which is criminal.
What your company needs to do
8 items, in the order you will need them.
- Write the employee monitoring policy to the regulator's own contents listHong Kong-specificIt should refer explicitly to the business purposes the monitoring seeks to fulfil, the circumstances under which monitoring may take place and the manner of it, the kinds of personal data that may be collected, and the purposes for which the data collected may be used. That last item is where the use principle is satisfied or missed, so treat it as the operative clause rather than the closing one.
- Decide now whether a result can have a consequence for an individualHong Kong-specificIf it can, discipline has to be inside the purpose stated at collection, or using the result that way is a new purpose needing prescribed consent. This is a drafting instruction with a deadline: it has to be settled in the policy before the campaign runs rather than argued about when the first person fails.
- Do not argue the exercise as permitted covert monitoringHong Kong-specificEvery entry condition the regulator sets turns on suspicion of unlawful activity and on identifying a culprit, and a simulation has neither. Arguing it that way volunteers for a test that cannot be passed. The correct framing is overt as to the practice and unannounced as to the occasion, which is what the general-terms permission buys you.
- Justify the risk realistically rather than by assertionThe regulator asks you not only to identify the risks but to justify their existence and extent in a realistic manner, and it says a mere perception of risk unconnected with the nature of the business would not be sufficient to justify employee monitoring. Write down why your own workforce is exposed to voice social engineering specifically.
- Bring the policy to employees before monitoring is introducedThe regulator offers routes rather than a rule: incorporate it into orientation or training, publish it in the handbook, post it on notice boards, include it in the employment agreement, or link it to a network login screen requiring affirmative acknowledgement before access. What matters is that it lands before the first call and that you can show it did.
- Originate the call in Hong KongHong Kong-specificAn overseas-originated call presenting a Hong Kong number connects and arrives carrying a voice or text alert warning the recipient. That is a design failure rather than a legal one, and it cannot be cured by documentation. Note the asymmetry with Singapore next door, which blocks the same call outright.
- Keep the two regulator documents apart when you cite themThe monitoring guidelines are guidance and say of themselves that they are not definitive statements of law but illustrative of best practices. The human resource management text is an approved code, and failing to observe it does not of itself create liability but is admissible and probative in proceedings under the ordinance. Neither is a statutory duty, and conflating them is common.
- Do not expect a consultation counterpartyHong Kong's employment ordinance is a minimum-terms statute covering wages, notice, leave and severance. It contains no works council provision and nothing touching workplace policy, monitoring or security testing. The expectation that the policy be notified before monitoring begins is a notification expectation in guidance, not a statutory duty to consult.
The controls that do the work
How Callstrike is configured, and which provision in Hong Kong each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
Hong Kong's collection principle has two limbs a deception-based exercise has to satisfy on its own terms: the data must be adequate but not excessive in relation to the purpose, and it must be collected by means fair in the circumstances of the case. The second is freestanding and survives a perfect policy. A call that ends the moment an employee begins to give up a credential collects the behaviour and not the credential, so the excessiveness limb has nothing to weigh and the fairness limb is being asked about a test rather than about a harvest. It also keeps the results narrow enough that the use principle described above stays easy to honour.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
Fairness in the circumstances of the case is the requirement a Hong Kong programme is actually measured against, and it is where a punitive design fails while a diagnostic one passes. A second voice that breaks character the instant the call ends, followed by vishing training in writing the same day, moves the exercise from something done to a person into something done for them, and that is the difference the fairness assessment turns on rather than a nicety layered on top of it.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Hong Kong needs no agreement to collect, so the job here is the notified policy the regulator asks for and the dated evidence that it reached people before monitoring was introduced. The one place agreement does real work is the use principle: taking results outside the purpose stated at collection requires the person's prescribed consent, which in practice means getting the purpose right in the policy instead of collecting agreements afterwards. A hashed copy of the policy with a signed attestation of its scope is what a notice board cannot leave behind.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Telephony was never the Hong Kong obstacle. The unsolicited messages ordinance covers voice calls and then exempts from its whole application person-to-person interactive communications, including ones whose synthesised element is activated in response to what the caller says, which is an AI voice agent described in a 2007 schedule. The real obstacle is the alert an overseas-originated call triggers, and this route has no calling identity to be alerted on: Callstrike's vishing simulator carries the same deepfake voice into a web call the learner starts themselves after working through the module. The collection and use principles still govern whatever either route collects, and Hong Kong imposes no synthetic-voice disclosure duty for the module to satisfy.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.