Callstrike
Compliance

Voice phishing simulations in Japan

Phone numbers in JapanProvisioned by Callstrike after approval

Japan permits a voice phishing simulation against your own staff, and it does not ask you to choose a lawful basis, because there is no menu to choose from. What it asks is that you specified the purpose, published it, and stayed inside it. The provision that shapes the design is elsewhere: acquiring personal information by deception is flatly prohibited, and the regulator's own worked example of deception reads almost exactly like a pretext.

Phone numbers

Supplied by Callstrike

Local numbers in Japan, after a one-time approval.

Running a simulation

Permitted, and the script is the design question

The rule against acquiring data by deception carries no exception at all.

Consent

Only needed to exceed your purpose

Specify the purpose, publish it in advance, and agreement never enters the analysis.

Getting a phone number in Japan

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Japanese onboarding is the longest in this region and almost none of it is optional. The carrier's own application has to be completed and signed by your authorised representative, in an English or a Japanese version, and it travels with a corporate registration document issued within the last six months. Proof that the representative may act for the company comes from a power of attorney, a registration extract naming them, or a letter on company letterhead under seal, and their identity from a Japanese photo identity document.

Two lines in the table below are the ones that add calendar time rather than effort, and they are worth knowing before anyone promises a launch date. The business address has to fall inside the locality covered by the number's own prefix, entered in Japanese characters, with no post office box accepted, and a non-forwarding mailer is sent to verify it. A second non-forwarding mailer goes to the authorised representative's own home address, which is evidenced separately again by a tax payment certificate or a utility bill issued within six months. Two pieces of post have to arrive and be answered before the number exists.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Japan is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Japan regulatory bundle application & TNUPAn Application must be completed and signed by the authorized representative. Download here: English version Japanese version. NOTE: Resellers should append a copy of their TNUP to the scan of their completed Application for the “Reseller Bundle”. See Notice to Resellers (November 2022)Completed japan regulatory bundle application
Proof of business name and purposeThe supporting document must have been issued within the last 6 months and be valid at the time of upload.Corporate registration document
Proof of addressMust be within the locality or region covered by the phone number’s prefix. A PO Box is not acceptable. Use Japanese characters when entering the business address. Note: A non-forwarding mailer will be sent to verify the locality of the Business Address.Certificate of tax payment of the local corporate entity, Utility bill of the local office address, Corporate registration document
Authorization of representativeProof that representative is authorized to act on behalf of the businessPower of attorney, Corporate registration showing name of the authorized representative, Letter on the company letterhead under seal showing the person is duly authorized to execute contract
Proof of identityA valid photo identification is required to verify the authorized representative's name, photo, date of birth, and current address. *Do not upload the back side of My Number Card.Driver's license, Certificate of driving record, My number card*, "Zairyu" residency card, Certificate of special permanent resident
Proof of authorized representative's addressA non-forwarding mailer will be sent to verify the Authorized Representative’s physical address. The proof of address document(s) must have been issued within the last 6 months and be valid at the time of upload.Certificate of tax payment, Utility bill

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Japan?

The position in short, before your counsel reads the detail below.

Yes. Japan does not work the way the European pages in this portal work, and the difference is structural rather than one of emphasis. There is no list of grounds to pick from. The statute requires you to specify the purpose of use as far as possible, and then not to handle personal information beyond the range necessary to achieve that purpose without the person's prior agreement. The exceptions to that are a closed list of five, covering acts based on laws and regulations, protection of life or property, public health and child welfare, cooperation with a state organ, and academic research. None of them is a balancing test, and Japan needs none, because the article limits purposes rather than authorising processing.

The constraint that actually bites sits somewhere nobody looks first. A business operator must not acquire personal information by deception or other wrongful means, and that is a flat prohibition with nothing attached to it. The regulator's own guideline gives, among its examples of wrongful means, the case where an operator intentionally presents false information about who is acquiring the data or why, and thereby acquires it from the person. Read that against a pretext call, because it is close to a description of one. Enforcement here is administrative rather than criminal, which is the one respect in which Japan is softer than Korea on the same idea.

What separates a defensible Japanese exercise from an indefensible one is therefore a single design fact rather than a document. A simulation that records who answered, who complied and who reported it is not acquiring personal information from the person by presenting false information about who is collecting it. A simulation that induces an employee to disclose a credential under a false identity sits directly on the regulator's example. Callstrike is configured so that the first happens and the second cannot.

Two further points close the position, and one of them is a refusal. On notification, the defensible route is to publish the purpose in advance, saying that simulated social-engineering exercises are conducted for security assurance, and not to publish the schedule. Note that the phrase legitimate interests appears once in the whole Act and is an exception to the notification duty rather than a ground, so a European assessment does not transfer. On recording, this portal declines to answer for Japan: the statute protects the secrecy of carrier-handled communications and does not say who may record, and the reading that a party to a call does not violate the secrecy of their own communication is settled in commentary but is in no primary source we can cite. Take that one point to Japanese counsel before a Japanese programme records anything.

What your company needs to do

8 items, in the order you will need them.

  • Publish the purpose before the first call, not the scheduleJapan-specificThe duty is to notify or publicly announce the purpose of use, and it falls away where the purpose was publicly announced in advance. So a standing statement that simulated social-engineering exercises are conducted for security assurance discharges it, and nothing requires you to say which Tuesday the call comes.
  • Draw the programme into your work rules and hear the opinionJapan-specificAt ten or more workers the work rules cover it twice over: through the matters concerning the kinds and degree of commendations and sanctions, and through the catch-all for provisions applying to all workers. Drawing them up or changing them requires you to hear the opinion of the majority union, or of the person representing a majority of workers, and to file the rules with the labour standards inspection office with a document recording that opinion and naming the representative.
  • Hear the opinion; do not go looking for agreementJapan-specificNothing in the article says agreement, consent or approval, and a negative opinion does not block the filing. Where the depth of the consultation actually tells is the separate reasonableness test that decides whether a change to the rules stands at all, which weighs the disadvantage to workers, the need for the change, the appropriateness of its content and the state of negotiations.
  • Check that the representative you consulted is a valid oneJapan-specificThe person representing a majority of workers must not hold a supervisory or managerial position, must be chosen by a vote or a show of hands with the purpose made clear, and must not be chosen on the employer's initiative. A consultation with the wrong person is not a consultation, and the defect surfaces later than it should.
  • Make the rules known, because that is when they take effectJapan-specificThe rules have to be made known by posting or keeping them at a conspicuous place, by delivering documents, or by another prescribed method, and the ministry's own model rules state that they take effect from the time they are made known rather than from being drawn up or from the opinion having been heard. Skipping the drawing-up, opinion-hearing or notification duties carries a fine of up to three hundred thousand yen.
  • Cap any wage-reduction sanction before you write it inJapan-specificWhere the rules provide for a wage reduction as a sanction, a single instance may not exceed half of one day's average wage and the total may not exceed one tenth of the wages for a pay period. It is a small provision that is easy to breach by copying a disciplinary schedule from another jurisdiction.
  • Present a number your own organisation holdsThere is no Japanese offence for a caller who presents a false number: the anti-spoofing duty binds the carrier and carries an express proviso for cases with no risk of misapprehension about the origin. Geographic numbers are location-bound, though, so the number's prefix and the address you filed have to describe the same place.
  • Do not go looking for a Japanese mandate to point atThe financial regulator's cybersecurity guideline requires periodic exercises and drills twenty-five times over and never once contemplates a simulated attack on staff; its single phishing reference is about warning customers. Its threat-led testing item points at the defending team rather than at the workforce. Justify the programme on its own merits.

The controls that do the work

How Callstrike is configured, and which provision in Japan each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

This is the control that answers the prohibition on acquiring personal information by deception, which is the sharpest Japanese provision and the one whose regulator example describes a pretext. The prohibition is written about the act of acquisition: intentionally presenting false information about who is acquiring and why, and thereby acquiring the information from the person. The call ends the moment an employee begins to give up a credential, so the acquisition the example describes never occurs and the prohibition has nothing to attach to. It also keeps the exercise inside the purpose you specified, which is the only other question the Act asks.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

Japan's reasonableness test weighs the extent of the disadvantage to workers against the need for the change and the appropriateness of its content, and that test decides whether a change to the work rules stands rather than merely whether it was filed correctly. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is a concrete answer to the disadvantage limb and something you can put in front of a worker representative at the point they ask what the programme does to the people in it.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Agreement is not the ground here, because Japan has no ground to select: the Act asks for a purpose and the exceptions to notification are a closed list. What this produces is the two dated records the Japanese file actually needs. The advance publication of the purpose, which is what removes the per-collection notification duty. And evidence that the work rules were made known to each worker, which matters more here than the filing does, because the rules take effect from the moment they are made known and a notice board leaves nothing behind to show that they were.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

Japan is the one country in this portal where we decline to answer the recording question, and this is the delivery that does not raise it. Callstrike's vishing simulator can carry the same deepfake voice into a web call the learner starts themselves after working through the module, and the secrecy provision is written about communications being handled by a telecommunications carrier. Be precise about the limit, though: the prohibition on acquiring personal information by deception is not a telephony rule and follows the exercise into either delivery, and Japan imposes no synthetic-voice disclosure duty for the module to satisfy in the first place.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

Specify the purpose, and do not acquire by deception

Japan does not work the way the European pages in this portal work, and the difference is structural rather than one of emphasis.

There is no menu of lawful bases. In handling personal information a business operator must specify the purpose of use as far as possible, and must not, without the prior consent of the person concerned, handle personal information beyond the range necessary to achieve the purpose so specified. Consent is required only to exceed the purpose. The exceptions to that rule are a closed list covering acts based on laws and regulations, protection of life, body or property where consent is difficult to obtain, public health and child welfare on the same condition, cooperation with a state organ performing statutory affairs, and academic research. None of them is a balancing test, and Japan does not need one, because the article is a purpose-limitation rule rather than a lawful-basis rule.

So the Japanese question is not which ground supports a security test. It is whether the purpose was properly specified and whether the handling stays inside it.

The constraint that actually bites is elsewhere and is easy to miss. A business operator must not acquire personal information by deception or other wrongful means. That is a flat prohibition with no exception attached, and the regulator's own guideline gives, among its examples of acquiring by wrongful means, the case where the operator intentionally presents false information as to the entity acquiring the personal information or the purpose of use, and thereby acquires personal information from the person concerned.

Read that against a pretext call, because it is close to a description of one. The distinction that matters is between a simulation that records who answered, who clicked or who complied, and a simulation that induces the employee to disclose a credential or personal data under a false identity. The first does not obviously acquire personal information from the person by presenting false information about who is collecting it. The second sits directly on the regulator's example. The safe Japanese design is that the call must not actually harvest personal information under the pretext, and that is a product decision rather than a paperwork one.

There is a notification duty and it has an exception worth naming precisely. Where an operator has acquired personal information it must promptly notify the person of, or publicly announce, the purpose of use, except where it has publicly announced the purpose in advance. Those duties do not apply where notification would risk harming the person's or a third party's rights and interests, where it would risk harming the operator's rights or legitimate interests, or where the purpose is clear from the circumstances of acquisition.

The phrase legitimate interests appears there and nowhere else in the Act. It is an exception to notification, not a lawful basis, and translating it into the European concept is a mistake that would restructure the whole analysis. The defensible reading is that an employer publishes the purpose in advance, saying that simulated social-engineering exercises are conducted for security assurance, and does not publish the schedule.

The affirmative hook for the whole activity is a separate duty. Where an operator has its employees handle personal data, it must exercise necessary and appropriate supervision over those employees so as to ensure the security control of that data, and the guideline adds that it is desirable to take measures such as enriching the content and frequency of education and training for them.

The statute protects secrecy and does not say who may record

Japan is the one page in this portal where we are going to decline to answer the central question, and it is worth explaining why rather than hedging.

The provision is short. The secrecy of communications being handled by a telecommunications carrier shall not be violated, and a person engaged in the telecommunications business must protect the secrets of others that they came to know while in service in relation to such communications, including after leaving that position.

The penalties are serious and worth stating with the right sentence type. A person who violates the secrecy of communications being handled by a carrier is punished by imprisonment of not more than two years or a fine of not more than one million yen, rising to three years or two million yen where the offender is engaged in the telecommunications business, and attempts are punishable. The custodial sentence is the unified one introduced on 1 June 2025, so material written earlier will name the older sentence types.

One structural point removes an argument before it is made. The Act exempts certain small or single-user telecommunications businesses from its provisions, but a separate paragraph provides that the secrecy articles continue to apply to their traffic anyway. Exemption from the Act is not exemption from the secrecy duty.

Now the part we will not resolve. The statutory text does not say who may record. It says the secrecy of carrier-handled communications shall not be violated, and the penalty provision punishes a person. The proposition that a party to a call does not violate the secrecy of their own communication is the settled reading in Japanese academic writing and case law, and we have no doubt it is what a Japanese lawyer would say. It is not in any primary source we can cite under this portal's source standard, which admits statutes and regulators and not commentary.

So the honest statement is this: the statute and the penalty are as set out above, the position of a party to the call is not settled by any primary text we can point you to, and this specific point should go to Japanese counsel before a Japanese programme records anything. The United Kingdom page in this portal takes the same posture for the same reason, and we would rather be consistent about the limits of what we can source than fill the gap with something that reads confidently.

One thing that is clear: an employer calling its own employees over a carrier's service is not itself a telecommunications carrier. A telecommunications service means mediating the communications of others or otherwise making facilities available for the communications of others, and a telecommunications business is one that provides such services to meet the demand of others. An employer mediates nobody else's communications: it is a user, and the registration and notification duties do not bite on it.

Selling is the trigger, and nothing regulates a synthetic voice

Japan's telemarketing statute is scoped to selling in both its actor and its object, and an internal exercise is outside it on the face of the definition.

Telephone solicitation sales means a seller or service provider making a telephone call, or causing one to be made, and by solicitation conducted on that call concerning the conclusion of a sales contract or a service-provision contract, receiving an application by post or concluding such a contract, and thereby selling goods or specified rights or providing services. Both the actor and the object are commercial, and the definition is expressly scoped to that chapter.

The two duties everyone cites hang off that definition. Before soliciting, the seller must tell the other party its name, the name of the person soliciting, the type of goods, rights or services, and the fact that the call is for the purpose of soliciting the conclusion of a contract. And it must not solicit a person who has indicated an intention not to conclude such a contract. Both are confined to telephone solicitation sales.

The consequence is worth stating plainly because people assume otherwise. There is no general Japanese duty to identify yourself on a call, and no general do-not-call duty, outside selling.

On automated and synthetic voice the answer is a corpus-wide negative, and we established it against the whole national statute database rather than by reading a few Acts. Searching every law in the corpus returns nothing for automated voice, auto-call, auto-dial, robocall, speech synthesis, deepfake, generative AI, nuisance call and impersonation call. Automatic transmission returns twelve results and every one is a maritime distress-radio rule. The control search for telephone solicitation sales returns seventy-eight, so the endpoint was working.

Japan therefore has no statutory rule on automated, pre-recorded, auto-dialled or synthetic-voice calling as such.

Japan does have an AI statute and it is in force, which surprises people who expect the opposite. It imposes no binding obligation on a private deployer and no disclosure duty of any kind. Its only provision addressed to a deployer requires them to endeavour, on their own initiative, to make active use of the technology and to cooperate with measures the State and local authorities implement. Its only propriety provision is addressed to the State, requiring it to take necessary measures such as developing guidelines conforming to international norms. The Act has four chapters and no penalty chapter at all.

The guidelines made under it say so themselves. The government's guideline is formulated in order to encourage voluntary and proactive efforts by all actors, and the ministries' business-operator guidelines say in terms that they were drafted on a goal-based approach leading to the objectives by means of non-binding soft law. The latter recommends disclosing the fact that AI is being used, the scope of its use and appropriate and inappropriate methods, as a voluntary goal.

So Japan has no synthetic-voice disclosure duty. That is a real divergence from Korea, which does have one in force, and the two countries must not be treated as a pair on this point.

A carrier duty with a carve-out, and no offence for the caller

Japan does have an anti-spoofing rule. It binds the carrier, it has an express escape hatch, and it is almost impossible to find if you search for the obvious term.

The rule provides that a telecommunications carrier must take the measures necessary to ensure that, with respect to a number it has assigned to a user, a number different from the one relating to that user's origination is not transmitted to terminal equipment or to another carrier. And then the proviso: this does not apply where there is no risk of causing other users to be mistaken as to the origin of the call.

Coverage is comprehensive across bearer types by cross-application, reaching internet telephony on both non-geographic and geographic numbers and mobile and personal handyphone services. Enforcement is administrative and runs against the carrier: the minister may order repair or modification of equipment that does not conform to the technical standards, or restrict its use.

The search trap is worth recording because it would have produced a confident negative in the wrong direction. The Japanese term a researcher reaches for, caller number, appears zero times in the entire national statute corpus. The operative phrase is a different telecommunications number, and a search built on the obvious term returns nothing and reads as though no rule exists.

What genuinely does not exist is a criminal offence for a caller who presents a false number. We searched the corpus for caller number, caller number falsification, number falsification and impersonation call and found nothing, and the telecommunications act's penalty chapter contains no number-misuse offence. The numbering rules mention falsification once, as a disqualification criterion for carriers applying for numbers, not as caller conduct.

The numbering plan adds two product-design facts. Geographic numbers are location-bound: the demarcation point between the network and the terminal equipment, or the location where the terminal equipment is installed, must fall inside the number zone for the area code, and technical measures must be taken so that a number different from the geographically identified area is not used. Non-geographic internet telephony numbers carry only technical conditions and no location condition at all, and the contrast is visible on the face of one table.

And for call-forwarding services there is a lever worth knowing. A provider offering such a service on geographic numbers must confirm that the end user's base of activity is inside the number zone. But those verification requirements are disapplied where the provider offers only an origination-transfer function and has taken measures either not to notify the originating number, or to notify a number other than a geographic one, limited to cases where there is no risk of misapprehension about the origin.

One currency caveat. The numbering plan is a ministerial public notice rather than an Act or ordinance, and public notices are not carried by the national law database, so there is no machine-verifiable commencement stamp for it. Its currency rests on it being the version the ministry itself publishes. The companion ordinance is machine-verified.

What the country matrix holds for Japan

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Hear the opinion, file it, and make the rules known

Japan's consultation duty is real, is criminal to skip, and is a duty to hear rather than to agree. Getting that distinction right is what separates a Japanese page from a Korean one, because the two countries are mirror images here.

An employer who continuously employs ten or more workers must draw up work rules covering listed matters and file them with the administrative agency, and the same applies to any change. Two of the listed matters catch a simulation programme: where provisions on commendation and sanctions are made, matters concerning their kinds and degree; and, as a catch-all, where provisions applying to all workers of the workplace are made, matters concerning them. Filing goes to the director of the competent labour standards inspection office, without delay.

Then the procedure. With respect to drawing up or changing work rules, the employer must hear the opinion of the labour union organised by a majority of the workers at the workplace, or, where there is none, of the person representing a majority of the workers. When filing, it must attach a document recording that opinion, and the implementing rules require that document to state the representative's name.

Must hear the opinion. Nothing in the article says agreement, consent or approval, and a negative opinion does not block the filing. The statute book confirms it structurally: the labour contract act permits an employer to change working conditions to an employee's disadvantage by changing work rules without individual agreement, provided the changed rules are made known and the change is reasonable. If hearing the opinion meant obtaining agreement, that provision would have no field of operation.

The representative has to be a real one. The person representing a majority of workers must not hold a supervisory or managerial position, must be selected by a procedure such as a vote or show of hands carried out with the purpose made clear, and must not be selected on the basis of the employer's intent, and the employer must not treat a worker disadvantageously for being or seeking to be one.

Where consultation acquires practical weight is the reasonableness test. A change is effective if the changed rules are made known and the change is reasonable in light of the extent of the disadvantage to workers, the need for the change, the appropriateness of the content, the status of negotiations with a labour union or the like, and the other circumstances. So a bare hearing satisfies the labour standards act, and the depth of the consultation feeds directly into whether the change stands.

Three enforcement points close the section. The rules must be made known to workers by posting or keeping them at a conspicuous place, by delivering documents, or by another prescribed method, and the ministry's own model rules state the understanding that work rules do not take effect merely by being drawn up or by the representative's opinion having been heard, but from the time they are made known. Breach of the drawing-up, opinion-hearing, sanction-limit or notification duties is punishable by a fine of not more than three hundred thousand yen. And where the rules provide a wage-reduction sanction, a single instance may not exceed half of one day's average wage and the total may not exceed one tenth of the wages for one pay period.

The regulator's own monitoring expectations sit alongside and are softer in modality than the statute. Where video or online monitoring of employees is carried out as part of supervising them or of other security control measures, the points it suggests bearing in mind are to specify the purpose of monitoring in advance, provide for it in internal rules and make it explicit to employees; to determine the person responsible and their authority; to formulate the rules for carrying it out in advance and ensure the operators are thoroughly acquainted with them; and to confirm that it is being carried out properly in accordance with those rules. It adds that where important matters are laid down it is desirable to notify the labour union in advance and hold consultations as necessary, and desirable to make them known to employees.

Bear in mind and desirable, not must. That is an expectation rather than a duty, it is weaker than the statutory obligation to hear an opinion, and it lives in a question and answer document rather than in the guideline: the word for monitoring does not appear in the current guideline at all. Anyone citing the regulator's guideline for a monitoring rule is citing a document that does not contain one.

Twenty-five drills and twenty-five exercises, none of them this

Japan's financial regulator requires exercises and drills in emphatic terms and does not require, mention or contemplate a simulated attack on staff. The counts are what make that statement safe.

Its cybersecurity guideline for the financial sector requires entities to conduct periodic exercises and drills to confirm the effectiveness of their incident response and contingency plans, to identify issues and to improve continuously, including participation in exercises hosted by other organisations, and to participate in cross-industry exercises. Counted over its thirty-seven pages, the words for drill and exercise appear twenty-five times each. Voice phishing appears zero times, social engineering zero times and simulated zero times. Phishing appears exactly once, and it is in a provision about implementing measures for CUSTOMERS, such as posting alerts about phishing emails on the institution's website.

Its threat-led penetration testing item is the nearest thing to unannounced testing and it points at the defenders rather than at the workforce: it is listed among the matters for which a response is desirable rather than basic, it is to evaluate the incident response capability of the defending blue team across defence, detection, reporting and containment, and it is to be conducted on the production environment without giving advance notice to those defenders.

One status point matters more than it sounds. The supervisory guidelines the industry works to describe themselves as a handbook for the staff who carry out inspection and supervision, systematically organising basic thinking, points to note in administrative handling and supervisory evaluation items. Supervisory action rests on the sectoral statutes, not on the guideline. And the current supervisory guidelines page returns phishing nine times, every one of them a customer-facing control such as phishing-resistant authentication, sender-domain authentication, site takedown or bookmarking the genuine site, and drill nine times, all business continuity, system failure or system integration drills. None is a staff simulation.

The cross-industry exercise the regulator hosts is invited rather than compulsory: its announcement gives the dates and a planned participant count, and no instrument makes participation a duty. Counted over its annex, the words for drill, voice phishing, social engineering and simulated all return zero; exercise returns nine.

The economic security statute is sometimes raised in this context and does not reach an employer testing its own staff. Its regime is a pre-notification and thirty-day standstill over the procurement of specified critical equipment, defined as equipment, devices, apparatus or programs, and over outsourcing their maintenance or operation. The regulated object is equipment and programs throughout. Counted over the whole Act, phishing, voice phishing, social engineering, drill, exercise and simulated each return zero, as do cyber and information security.

So across every Japanese instrument we counted, voice phishing is zero, social engineering is zero and simulated is zero, and phishing appears only in customer-protection contexts. No Japanese regime mandates a vishing simulation.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in JAPAN. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The purpose is published in advance and the programme is covered by our security testing policy.

Verify or correct each proposition below against primary Japanese sources, and tell me what our company must hold before the first call:

1. APPI art 18 requires consent only to handle personal information BEYOND the range necessary to achieve the purpose specified under art 17, and art 18(3)'s exceptions are exhaustive with no balancing test among them.
2. ⚠⚠ APPI art 20(1) prohibits acquisition 偽りその他不正の手段により, and the PPC 通則編 3-3-1 Example 3 is the intentional presentation of false information about the acquiring entity or the purpose. Assess whether a simulation that records WHO ANSWERED but captures no disclosed data is outside it, and confirm the enforcement route is administrative rather than criminal.
3. APPI art 21(4)(ii)'s 正当な利益 is an exception to the NOTIFICATION duty, not a lawful basis. Confirm it appears nowhere else in the Act.
4. ⚠ 電気通信事業法 art 4 does not say who may record, and art 179 punishes 者. Is the participant reading available in any PRIMARY source (statute, ordinance, 告示 or a regulator publication) rather than in commentary or case law alone?
5. 労基法 art 90 requires the employer only to HEAR the opinion; 労働契約法 art 10 permits a disadvantageous change without individual agreement where the rules are made known and the change is reasonable. Confirm no agreement duty exists.
6. 事業用電気通信設備規則 art 35-2-6 binds the CARRIER and has a no-misapprehension proviso; there is no criminal offence for a caller presenting a false number. ⚠ Note the operative phrase is 異なる電気通信番号 and that 発信者番号 returns zero corpus-wide.
7. The PPC's monitoring expectations are in Q&A A5-7 (「留意することが考えられます」/「望ましい」), not in the guideline. Confirm モニタリング appears zero times in the current 通則編.

Flag anything that has changed since September 2026, and identify any prefectural or collective-agreement obligation this analysis omits.

Common questions

Which lawful basis applies in Japan?
None, because Japan has no lawful-basis menu. The Act requires you to specify the purpose of use as far as possible and then not to exceed it without consent. The question is whether your specified purpose covers the exercise, not which ground you rely on.
What is the sharpest constraint on a Japanese pretext?
The prohibition on acquiring personal information by deception or other wrongful means. The regulator's own example of wrongful means is intentionally presenting false information about who is collecting the data and why, which is close to a description of a pretext call that harvests something.
May a party to the call record it?
We are not going to tell you. The statute protects the secrecy of carrier-handled communications and does not say who may record; the participant reading is settled in commentary and case law but not in any primary source we can cite. Take this specific point to Japanese counsel.
Must we disclose that the voice is AI-generated?
No. Japan's AI statute is in force, imposes no binding obligation on a private deployer, and has no penalty chapter at all; its guidelines describe themselves as non-binding soft law. Korea does impose such a duty, so the two countries diverge and should not be treated as a pair.

Elsewhere in Asia Pacific

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.