Callstrike
Compliance

Voice phishing simulations in New Zealand

Phone numbers in New ZealandProvisioned by Callstrike after approval

New Zealand is permissive about the recording and sharp about the deception. Its criminal law lets someone on the call record it and extends that to a platform recording on your behalf, and its privacy code applies to employees in full. The edge nobody expects is employment law: the parties to an employment relationship must not do anything to mislead or deceive each other, flatly and without qualifier, and a voice phishing simulation is a communication designed to deceive.

Phone numbers

Supplied by Callstrike

Local numbers in New Zealand, after a one-time approval.

Running a simulation

Permitted, and one duty is unresolved

The good-faith duty not to deceive has no qualifier, and no case law on a simulation.

Consent

Notice, with a fairness test on top

Every listed exception excuses the notice principle. None of them excuses fairness.

Getting a phone number in New Zealand

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

New Zealand asks for the least of any country in this region, and one line in the table below is unlike every neighbour's. The business address may be anywhere in the world: there is no requirement that it sit inside the area the number's own prefix covers, which is the constraint that shapes procurement everywhere else in Asia Pacific. A post office box is still not accepted. The other line is your business name, evidenced by a commercial register excerpt or a business registration, and the same document will usually carry the address.

What is worth knowing before you plan the display number is that no New Zealand statute binds your choice of it. The telecommunications statute was loaded end to end and searched: calling line identification, caller, numbering and spoofing all return nothing, with number portability returning ten as the control that proves the search worked. Numbering lives in a private industry deed that allocates code blocks to carriers and does not bind end-user callers, and the only instrument addressing caller identity labels itself a voluntary code for operators who choose to sign up. The constraint here is therefore contractual and operational, your carrier's acceptable use terms and the blocking practices of the operators that signed that code, and this page will not describe it as a statutory prohibition.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in New Zealand is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Business nameExcerpt from the commercial register, Business registration
Business addressMay be anywhere in the world; a PO Box is not acceptable.Excerpt from the commercial register showing the local address, Business registration showing the local address, Utility bill, Tax notice, Rent receipt, Title deed

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in New Zealand?

The position in short, before your counsel reads the detail below.

Yes, and the privacy code applies in full, which is worth establishing positively rather than by failing to find an exemption. The statute's definition of an agency carries an exhaustive list of exclusions and no employer or employee-record entry appears in it. Better than that, the Parliamentary Service exclusion is drafted with an express carve-back for personal information about its own employees in their capacity as employees, so Parliament pulled employee records back into scope for the one body it exempted. That settles the question far better than silence would.

The principle that decides a deception-based exercise is fairness, and the structure around it is what people miss. Information may be collected only by a lawful means, and by a means that in the circumstances is fair and does not intrude to an unreasonable extent upon the person's personal affairs. Of the listed grounds for not complying, only the one about compliance prejudicing the purposes of the collection is available to you, and the law-enforcement ground is confined to the public sector. Every one of those exceptions excuses the notification principle only. None excuses fairness. So a validly unannounced test still has to be a fair means of collection, and the regulator's gloss sets the bar: covert collection is unfair unless there is a particularly strong reason for not telling people what you are doing. The onus of proving an exception falls on the defendant, so the written record of why it applied is the evidence rather than the filing.

Recording is genuinely clean here and the definition solves a design problem while it is at it. Intentionally intercepting a private communication by means of an interception device is an offence carrying up to two years, but it does not apply where the person intercepting is a party to that communication, and the definition of a party extends beyond the two people speaking to anyone who, with the express or implied consent of an originator or intended recipient, intercepts it. That last limb covers a platform recording on the caller's behalf, which is why a New Zealand architecture needs none of the endpoint care that Australia's federal statute forces. The consequence nobody plans for is on the other side: the person recorded may request a copy, so recordings have to be individually retrievable and retention-scoped from the start rather than pooled.

The unresolved question is the one this page opened with, and we are not going to resolve it in either direction. The parties to an employment relationship must deal with each other in good faith and must not, directly or indirectly, do anything to mislead or deceive each other or anything likely to mislead or deceive. There is no qualifier, no purpose element and no proportionality clause. We searched the employment case material and the privacy regulator's case notes for New Zealand authority on whether a simulated phishing or vishing exercise engages that duty and found none, and a page telling you the point is settled would be inventing comfort. What is available is the employment regulator's own practical advice, which is that a workplace policy explaining why and when this happens should be developed, comply with both the employment and privacy statutes, be consulted on with employees and any union, and be known to staff before the programme starts.

What your company needs to do

8 items, in the order you will need them.

  • Write the monitoring and testing policy and consult on it firstNew Zealand-specificThe employment regulator's advice is specific: develop a workplace policy explaining why and when this will happen, make sure it complies with both statutes, consult with employees and unions if applicable, and make sure employees know about the policy and why it is needed. That consultation is where the unresolved good-faith duty is answered in practice, so it belongs before the first campaign rather than after the first complaint.
  • Write down the fairness assessment, with the strong reason in itNew Zealand-specificThe regulator's position is that covert collection is unfair unless you have a particularly strong reason for not telling people what you are doing. Record what yours is, why a warned test would not measure the thing you need measured, and why the intrusion is not unreasonable. The fairness principle survives every exception, so this is the assessment that does not go away.
  • Record why the prejudice-to-purpose exception applies, and to whatNew Zealand-specificIt is the only listed ground available to a private employer, and the onus of proving an exception falls on the defendant. That makes the written reasoning the evidence you would have to produce, not a note for the file. It excuses the notification principle and nothing else.
  • Decide whether per-individual results are necessary at allWhere the lawful purpose for which information is collected does not require identifying information, the agency may not require it. That is a real question for a programme that scores individuals rather than measuring a population, and answering it deliberately is cheaper than defending it afterwards.
  • Make recordings individually retrievable and retention-scopedNew Zealand-specificThe regulator is explicit that the person recorded is entitled to request copies of the recordings involving them. A pooled archive that cannot be filtered by subject turns a routine access request into an incident, so build the retrieval in at the start rather than when the first request arrives.
  • Check your own marketing copy, not just your use of the productNew Zealand-specificIt is an offence to deal in a device where the person holds it out as being useful for the surreptitious interception of private communications, whether or not they also hold it out as useful for other purposes. That limb bites on how a product is described rather than on how it is used, which makes marketing copy a compliance surface here in a way it is not elsewhere.
  • Re-check any New Zealand notice guidance written before mid-2026An indirect-collection notification principle came into force on 1 May 2026 and does not apply to information collected before that date. Anything written earlier is describing a smaller set of obligations than the one that exists now, which is an easy way to end up short.
  • Do not cite the outsourcing policy as a testing mandateIt is a resolvability instrument rather than a security one, binding through conditions of registration on large locally incorporated registered banks, and its only testing requirements concern annual testing of the separation plan and back-up arrangements. Training, awareness, phishing, social engineering and simulation each return zero across its twenty-seven pages.

The controls that do the work

How Callstrike is configured, and which provision in New Zealand each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

Say plainly what this does not do in New Zealand: it does not answer the good-faith duty, because that duty bites on the deception itself rather than on what the deception obtains. What it does answer is the two privacy principles that decide the collection. The means must be fair in the circumstances and must not intrude to an unreasonable extent, and where the lawful purpose does not require identifying information you may not require it. A call that ends the moment an employee begins to give up a credential collects the least the purpose can be served by, which is the shape both principles ask for and the easiest fairness assessment to write.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

This is the control that speaks to New Zealand's unresolved question, and it is the only one that does. The duty is about misleading or deceiving, and a second voice that breaks character the moment the call ends, with vishing training in writing the same day, means the deception is undone inside the same minute rather than left standing until a report circulates. It also answers the regulator's separate warning about misleading staff as to what information will be used for, because the explanation arrives before anyone has had time to wonder.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Three dated artefacts here, and each one answers a different instrument. The workplace policy the employment regulator asks for, consulted on with employees and any union and in place before the programme starts. The programme notice carrying the checklist the notification principle prescribes, from the fact of collection through to the access and correction rights. And the record of why the prejudice-to-purpose exception applied, which matters more here than elsewhere because the onus of proving an exception is on the person relying on it.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

Telephony was never New Zealand's obstacle, and a drafting decision from 2007 settles it: the spam statute excludes voice calls from the definition of an electronic message by name and defines a voice call to include one involving a recorded or synthetic voice. The obstacle is the good-faith duty, and this is the one delivery where nobody is deceived at all. Callstrike's vishing simulator carries the same deepfake voice into a web call the learner opts into after working through the module, so the exercise the duty is asked about is one the person chose to enter. The privacy code still governs whatever it collects, and New Zealand imposes no synthetic-voice disclosure duty for the module to satisfy.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

Fairness is the principle, and the exceptions do not reach it

New Zealand applies its privacy code to employees in full, and it is worth establishing that positively rather than by not finding an exemption.

The statute's definition of an agency carries an exhaustive list of exclusions covering the Sovereign, the Governor-General, the House of Representatives, members of Parliament, the Parliamentary Service Commission, the Parliamentary Service, an Ombudsman, inquiries and news entities carrying on news activities. No employer or employee-record exclusion appears anywhere in it. And the Parliamentary Service exclusion is drafted with an express carve-back: the Service is excluded except in relation to personal information about any employee or former employee in their capacity as an employee. Parliament went out of its way to pull employee records back into scope for the one body it exempted, which settles the question far better than silence would.

The principles that bite are three. Where the lawful purpose for which information is collected does not require identifying information, the agency may not require it, which is a genuine question for a programme that scores individuals rather than measuring a population. The notification principle supplies a checklist: the fact of collection, the purpose, the intended recipients, the name and address of the collecting and holding agencies, any authorising law and whether supply is voluntary or mandatory, the consequences of not providing it, and the access and correction rights.

The third is the one that decides a deception-based exercise. An agency may collect personal information only by a lawful means, and by a means that in the circumstances is fair and does not intrude to an unreasonable extent upon the personal affairs of the individual concerned.

The timing rules are more helpful than they look. Notification steps must be taken before collection or, if that is not practicable, as soon as practicable afterwards, and they are not required at all where the agency has taken them on a recent previous occasion in relation to collecting the same information or information of the same kind from that individual. That is the hook for a standing programme notice rather than a warning before each call.

The exceptions are narrower than they appear and they matter in a way people miss. Of the listed grounds for not complying, only the one about compliance prejudicing the purposes of the collection is on point here; the law-enforcement ground is confined to public sector agencies and is unavailable to a private employer. And every one of those exceptions excuses the notification principle only. None of them excuses the fairness principle. So even a validly unannounced test still has to be a fair means of collection.

The regulator's gloss on fairness is the most load-bearing sentence in New Zealand law for this activity: covert collection is unfair unless you have a particularly strong reason for not telling people what you are doing, and it is a good idea to seek legal advice before making covert recordings. It also warns that misleading staff about what the information will be used for is an example of unfairness.

One procedural point closes the section. Where the Act excepts or exempts an action from being an interference with privacy, the defendant bears the onus of proving the exception. The written record of why the exception applied is not optional paperwork; it is the evidence you would have to produce.

A currency warning for anyone checking this. An indirect-collection notification principle came into force on 1 May 2026 and does not apply to information collected before that date. Anything written about New Zealand notice duties before the middle of 2026 is describing a smaller set of obligations than exists now.

A party may record, and the platform counts as a party

New Zealand is a genuine one-party jurisdiction on the face of the statute, and the provision that makes it so is worth reading because it also solves a design problem.

It is an offence, punishable by up to two years, intentionally to intercept any private communication by means of an interception device. Intercept is defined broadly to include hearing, listening to, recording, monitoring, acquiring or receiving the communication either while it is taking place or while it is in transit. But the offence does not apply where the person intercepting is a party to that private communication. The called employee's consent is not required by the criminal law.

The definition of a party then extends further than the two people speaking. It covers any originator of the communication and anyone the originator intended to receive it, and also a person who, with the express or implied consent of an originator or an intended recipient, intercepts the communication. That last limb is what covers a platform recording on the caller's behalf, and it is the reason a New Zealand architecture does not need the endpoint gymnastics that Australia's federal statute forces.

The disclosure offence is predicated on the interception having been unlawful in the first place: it applies where a private communication has been intercepted in contravention of the interception provision. Where the party exception applies, that offence is not engaged at all, which is unusually clean by the standards of this portal.

One provision is aimed squarely at vendors rather than at users and is easy to trip over in a brochure. It is an offence to deal in a device where the person knows its sole or principal purpose to be the surreptitious interception of private communications, or where the person holds it out as being useful for surreptitious interception, whether or not they also hold it out as useful for other purposes. The second limb bites on how a product is described, not on how it is used, so marketing copy is a compliance surface in New Zealand in a way it is not elsewhere.

The privacy layer sits on top and is not discharged by the criminal-law position. The regulator's answer to whether an employer may record calls is yes, but staff and customers should have been advised at some point that calls are being recorded, because the Act generally requires an agency to tell you when it is collecting your personal information. It then adds an operational consequence people rarely plan for: the client or employee will be entitled to request copies of the recordings involving them. A recording of a test call is subject to an access request by its subject, so recordings have to be individually retrievable and retention-scoped from the start rather than pooled.

A 2007 statute that already knew about synthetic voices

This is the cleanest finding on the page, and it comes from a drafting decision made nineteen years ago.

New Zealand's unsolicited electronic messages statute does not cover voice calls, and it says so by name rather than by implication. Its schedule provides that the listed messages are not electronic messages for the purposes of the Act, and the first item is voice calls made using a standard telephone service or voice over internet protocol. The same schedule then defines a voice call to mean, whether or not the recipient responds by pressing buttons on a handset, a voice call within the ordinary meaning of the expression, or a call that involves a recorded or synthetic voice, or an equivalent call for a recipient with a disability.

A call that involves a recorded or synthetic voice. That phrase was written in 2007 and it answers the question an AI voice agent raises directly, without anyone having to argue by analogy. The administering department states the same scope in its own words: the Act covers email, fax, instant messaging, mobile text and image-based messages of a commercial nature, and does not cover internet pop-ups or voice telemarketing.

There is a second, independent reason the Act does not reach a simulation: it applies to commercial electronic messages, and an internal security test is not one. Either reason would be enough on its own.

On synthetic voice disclosure the answer is a negative and we are stating it as one. There is no New Zealand law in force requiring disclosure that a caller's voice is AI-generated. No artificial intelligence statute exists on the legislation register, and full-text checks of the telecommunications statute and the messages statute found nothing. That is a negative across the sources we checked rather than an exhaustive proof, and we would rather say which it is.

The government's position is strategy rather than law and describes itself that way: New Zealand is taking a light-touch and principles-based approach, relying on existing frameworks in privacy, consumer protection and human rights which are largely principles-based and technology-neutral, and the strategy document carries its own disclaimer that it is a guide only and should not be used as a substitute for legislation or legal advice. The one transparency instruction we found, to be transparent to the public about when and how AI is used, applies to public service agencies and is published as unofficial versioned guidance.

The statute does not contain the word numbering

New Zealand's answer to what binds a caller's choice of presented number is starker than any other country in this portal: nothing does, and we established that by loading the statute in full rather than by failing to find something.

The telecommunications statute was loaded end to end, eight hundred and forty-four thousand characters, with completeness confirmed by the closing amendment history, and searched case-insensitively. Calling line identification returns nothing. Caller returns nothing. Numbering returns nothing. Spoofing returns nothing. Number portability returns ten, which is the control that proves the search was working.

Numbering in New Zealand lives outside legislation entirely, in a private industry deed that establishes the numbering mechanism and an industry body to oversee it. We counted the deed and its rules through as well: calling line identification, right of use, right to use, spoofing and presentation all return nothing across both documents. The deed allocates code blocks to carrier parties and does not bind end-user callers.

The only instrument that addresses caller identity is a telecommunications forum code on scam calling and scam messaging, and it labels itself in its own header as a voluntary code. It applies to retail service providers, network operators and messaging partners that provide services to customers, and the forum's own page describes it as applying to operators who choose to sign up. Across its pages the words mandatory, binding, right of use and authorised to use appear zero times.

So the practical constraint in New Zealand is contractual and operational rather than legal: your carrier's acceptable use terms, and the blocking practices of the operators that have signed the voluntary code. That is a real constraint and it is the one to design around, but it is not a statutory prohibition and this page will not describe it as one.

The general-law backstop that would presumably catch a fraudulent misuse of caller identity, in the deception offences of the criminal law and in fair trading, is plausible and we did not source it to primary text, so it is not asserted here.

What the country matrix holds for New Zealand

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

A duty not to deceive, with no case law to tell you what it means

Every other page in this portal lands on legal basis and consultation. New Zealand's sharpest question is neither, and it is worth putting first because it is genuinely unresolved.

The parties to an employment relationship must deal with each other in good faith and, without limiting that, must not, whether directly or indirectly, do anything to mislead or deceive each other, or anything that is likely to mislead or deceive each other. There is no qualifier, no purpose element and no proportionality clause attached to it. A vishing simulation is a communication designed to deceive an employee, which is the thing that provision names.

We are not going to tell you that a simulation breaches it, and we are not going to tell you it does not. We searched for New Zealand authority on whether a simulated phishing or vishing exercise engages the duty and found none, in the employment case material and in the privacy regulator's case notes alike. The position is not settled either way, and a page telling a New Zealand buyer that it is settled would be inventing comfort.

What we can say is how the duty is structured around this. The specific information and comment procedure in the same section is tied to a decision that will or is likely to have an adverse effect on the continuation of employment, and introducing a simulation programme is not on its face such a decision, so that procedure is not automatically engaged. But the general duty is expressed to apply to a proposal by an employer that might impact on the employer's employees, and the statute says the listed matters are examples that do not limit the general duty. It also requires the parties to be active and constructive in maintaining a productive relationship in which they are responsive and communicative.

The two regimes stack rather than substitute. The same section preserves the employer's obligations under the Privacy Act, and says so notwithstanding the provision of that Act that would otherwise limit its effect on employment. Satisfying the privacy code does not answer the good-faith question, and satisfying good faith does not answer the fairness principle.

The employment regulator's practical advice is where the design guidance actually comes from, and it is specific. Recording a meeting at work secretly, without the other person knowing, could be considered a breach of good faith. Employers who decide to go ahead should develop a workplace policy explaining why and when this will happen, make sure it complies with both the employment and privacy statutes, consult with employees and unions if applicable, and make sure employees know about the policy and why it is needed.

So the New Zealand file is: a written monitoring and testing policy, consulted on with employees and any union, in place before the programme starts. A programme-level notice covering purpose, recipients, the agency's identity and address, the consequences of not providing information, and the access and correction rights. A recorded rationale for relying on the prejudice-to-purpose exception to withhold notice at the moment of the call, remembering that the onus of proving it falls on you. A recorded decision on whether per-individual results are necessary at all. A fairness assessment that shows the particularly strong reason the regulator's covert-collection test demands. Retrievability and retention of recordings for access requests. And, where a vendor holds the data, the allocation the Act makes: information held for and on behalf of the employer is treated as held by the employer, unless the vendor uses or discloses it for its own purposes.

Guidance that says it is not a checklist, and a statute that is not about security

No New Zealand instrument mandates a vishing simulation, and two of the documents most often cited as if one did are worth correcting individually.

The central bank's cyber resilience guidance is explicit about its own status: it sets out the bank's expectations for its regulated entities and has not been designed as a checklist for cyber resilience minimum requirements. On testing it says only that testing is another integral part of developing strong cyber resilience, whether penetration testing, vulnerability assessments or business impact analyses. On people it says the entity should develop and maintain a programme for continuing cyber resilience training for staff at all levels, and that the training should include current cyber threats, attack tactics and appropriate incident responses.

That last sentence is the closest any New Zealand instrument comes, and it is worth being precise about what it does and does not do. A programme covering attack tactics could be delivered and measured through a simulation. The text does not name one. Counted over the document, phishing, voice phishing, social engineering and simulation each return zero; training returns six and awareness five.

The outsourcing policy that is regularly cited in vendor material as a testing mandate is not a security instrument at all. It is binding, through conditions of registration, on large locally incorporated registered banks, and it is about resolvability: its only testing requirements concern annual testing of the separation plan and of back-up arrangements. Counted over its twenty-seven pages, training, awareness, phishing, social engineering and simulation return zero each. Any claim that it requires or supports a vishing simulation is false.

The statutory position is thinner still. The only network security statute binds network operators by its own application provision and imposes nothing on an employer running a simulation. There is no in-force New Zealand critical infrastructure cyber statute at all: the consultation on creating one opened in February 2026 and closed in April 2026. Anyone describing New Zealand as having a European-style network and information security regime is wrong by about a legislative cycle.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in NEW ZEALAND. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. A monitoring and testing policy was consulted on and issued before the programme began.

Verify or correct each proposition below against primary New Zealand sources, and tell me how exposed we are on the good-faith duty:

1. ⚠⚠ Employment Relations Act 2000 s 4(1)(b): the parties «must not, whether directly or indirectly, do anything to mislead or deceive each other, or that is likely to mislead or deceive each other», with no qualifier and no purpose element. Is there ANY New Zealand authority (Employment Relations Authority, Employment Court, or a Privacy Commissioner case note) on a simulated phishing or voice-phishing exercise? We found none.
2. ⚠ Privacy Act 2020 s 8(b)(vi) excludes the Parliamentary Service EXCEPT as to its own employees' information in that capacity, which affirmatively puts employee records in scope. Confirm there is no employee-records exemption anywhere in the Act.
3. ⚠ IPP 3(4) excuses only IPP 3(1). Confirm nothing excuses IPP 4 (fairness), and that s 101 puts the onus of proving an exception on the DEFENDANT.
4. Crimes Act s 216B(2): the offence does not apply where the interceptor is a party, and s 216A's definition of «party» extends to a person who intercepts with the express or implied consent of an originator or intended recipient. Confirm this covers our platform recording on the caller's behalf.
5. ⚠ Crimes Act s 216D(1)(ii) criminalises dealing in a device a person «holds out as being useful for the surreptitious interception of private communications». Does that reach vendor MARKETING COPY rather than use?
6. ⚠ IPP 3A (indirect collection) came into force 1 MAY 2026 and s 25A excludes information collected before that date. Confirm what it now adds for us.
7. Unsolicited Electronic Messages Act 2007, Schedule cll 1(a) and 2(b): voice calls are excluded from «electronic message» by name, and «voice call» expressly includes «a call that involves a recorded or synthetic voice». Confirm.
8. ⚠ The Telecommunications Act 2001 contains NO occurrence of «numbering», «caller», «calling line identification» or «spoof»; numbering sits in a private industry deed and the only CLI instrument is a self-declared VOLUNTARY TCF code. Confirm nothing binds us as a caller.

⚠ RBNZ BS11 is a resolvability instrument with zero occurrences of training, awareness, phishing, social engineering or simulation, and is regularly miscited as a testing mandate. Flag anything that has changed since September 2026.

Common questions

May a party to the call record it in New Zealand?
Yes. The interception offence does not apply where the person intercepting is a party to the private communication, and the definition of a party extends to someone who intercepts with an originator's consent, which covers a platform recording on the caller's behalf.
Is there an employee-records exemption?
No, and the evidence is affirmative rather than an absence. The statute excludes the Parliamentary Service from the definition of an agency except in relation to information about its own employees in that capacity, which pulls employee records back into scope for the one body Parliament exempted.
What is the biggest legal risk here?
Employment law. The parties to an employment relationship must not do anything to mislead or deceive each other, flatly and without qualifier, and a simulation is designed to deceive. No New Zealand case law resolves what that means for an authorised security test, and this page will not pretend otherwise.
Does the spam law cover an AI voice call?
No, and it says so by name. The schedule excludes voice calls from the definition of an electronic message and defines a voice call to include a call involving a recorded or synthetic voice. That was drafted in 2007 and answers the question directly.

Elsewhere in Asia Pacific

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.