Voice phishing simulations in New Zealand
New Zealand is permissive about the recording and sharp about the deception. Its criminal law lets someone on the call record it and extends that to a platform recording on your behalf, and its privacy code applies to employees in full. The edge nobody expects is employment law: the parties to an employment relationship must not do anything to mislead or deceive each other, flatly and without qualifier, and a voice phishing simulation is a communication designed to deceive.
Phone numbers
Supplied by Callstrike
Local numbers in New Zealand, after a one-time approval.
Running a simulation
Permitted, and one duty is unresolved
The good-faith duty not to deceive has no qualifier, and no case law on a simulation.
Consent
Notice, with a fairness test on top
Every listed exception excuses the notice principle. None of them excuses fairness.
Getting a phone number in New Zealand
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
New Zealand asks for the least of any country in this region, and one line in the table below is unlike every neighbour's. The business address may be anywhere in the world: there is no requirement that it sit inside the area the number's own prefix covers, which is the constraint that shapes procurement everywhere else in Asia Pacific. A post office box is still not accepted. The other line is your business name, evidenced by a commercial register excerpt or a business registration, and the same document will usually carry the address.
What is worth knowing before you plan the display number is that no New Zealand statute binds your choice of it. The telecommunications statute was loaded end to end and searched: calling line identification, caller, numbering and spoofing all return nothing, with number portability returning ten as the control that proves the search worked. Numbering lives in a private industry deed that allocates code blocks to carriers and does not bind end-user callers, and the only instrument addressing caller identity labels itself a voluntary code for operators who choose to sign up. The constraint here is therefore contractual and operational, your carrier's acceptable use terms and the blocking practices of the operators that signed that code, and this page will not describe it as a statutory prohibition.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in New Zealand is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Business name | Excerpt from the commercial register, Business registration |
| Business addressMay be anywhere in the world; a PO Box is not acceptable. | Excerpt from the commercial register showing the local address, Business registration showing the local address, Utility bill, Tax notice, Rent receipt, Title deed |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in New Zealand?
The position in short, before your counsel reads the detail below.
Yes, and the privacy code applies in full, which is worth establishing positively rather than by failing to find an exemption. The statute's definition of an agency carries an exhaustive list of exclusions and no employer or employee-record entry appears in it. Better than that, the Parliamentary Service exclusion is drafted with an express carve-back for personal information about its own employees in their capacity as employees, so Parliament pulled employee records back into scope for the one body it exempted. That settles the question far better than silence would.
The principle that decides a deception-based exercise is fairness, and the structure around it is what people miss. Information may be collected only by a lawful means, and by a means that in the circumstances is fair and does not intrude to an unreasonable extent upon the person's personal affairs. Of the listed grounds for not complying, only the one about compliance prejudicing the purposes of the collection is available to you, and the law-enforcement ground is confined to the public sector. Every one of those exceptions excuses the notification principle only. None excuses fairness. So a validly unannounced test still has to be a fair means of collection, and the regulator's gloss sets the bar: covert collection is unfair unless there is a particularly strong reason for not telling people what you are doing. The onus of proving an exception falls on the defendant, so the written record of why it applied is the evidence rather than the filing.
Recording is genuinely clean here and the definition solves a design problem while it is at it. Intentionally intercepting a private communication by means of an interception device is an offence carrying up to two years, but it does not apply where the person intercepting is a party to that communication, and the definition of a party extends beyond the two people speaking to anyone who, with the express or implied consent of an originator or intended recipient, intercepts it. That last limb covers a platform recording on the caller's behalf, which is why a New Zealand architecture needs none of the endpoint care that Australia's federal statute forces. The consequence nobody plans for is on the other side: the person recorded may request a copy, so recordings have to be individually retrievable and retention-scoped from the start rather than pooled.
The unresolved question is the one this page opened with, and we are not going to resolve it in either direction. The parties to an employment relationship must deal with each other in good faith and must not, directly or indirectly, do anything to mislead or deceive each other or anything likely to mislead or deceive. There is no qualifier, no purpose element and no proportionality clause. We searched the employment case material and the privacy regulator's case notes for New Zealand authority on whether a simulated phishing or vishing exercise engages that duty and found none, and a page telling you the point is settled would be inventing comfort. What is available is the employment regulator's own practical advice, which is that a workplace policy explaining why and when this happens should be developed, comply with both the employment and privacy statutes, be consulted on with employees and any union, and be known to staff before the programme starts.
What your company needs to do
8 items, in the order you will need them.
- Write the monitoring and testing policy and consult on it firstNew Zealand-specificThe employment regulator's advice is specific: develop a workplace policy explaining why and when this will happen, make sure it complies with both statutes, consult with employees and unions if applicable, and make sure employees know about the policy and why it is needed. That consultation is where the unresolved good-faith duty is answered in practice, so it belongs before the first campaign rather than after the first complaint.
- Write down the fairness assessment, with the strong reason in itNew Zealand-specificThe regulator's position is that covert collection is unfair unless you have a particularly strong reason for not telling people what you are doing. Record what yours is, why a warned test would not measure the thing you need measured, and why the intrusion is not unreasonable. The fairness principle survives every exception, so this is the assessment that does not go away.
- Record why the prejudice-to-purpose exception applies, and to whatNew Zealand-specificIt is the only listed ground available to a private employer, and the onus of proving an exception falls on the defendant. That makes the written reasoning the evidence you would have to produce, not a note for the file. It excuses the notification principle and nothing else.
- Decide whether per-individual results are necessary at allWhere the lawful purpose for which information is collected does not require identifying information, the agency may not require it. That is a real question for a programme that scores individuals rather than measuring a population, and answering it deliberately is cheaper than defending it afterwards.
- Make recordings individually retrievable and retention-scopedNew Zealand-specificThe regulator is explicit that the person recorded is entitled to request copies of the recordings involving them. A pooled archive that cannot be filtered by subject turns a routine access request into an incident, so build the retrieval in at the start rather than when the first request arrives.
- Check your own marketing copy, not just your use of the productNew Zealand-specificIt is an offence to deal in a device where the person holds it out as being useful for the surreptitious interception of private communications, whether or not they also hold it out as useful for other purposes. That limb bites on how a product is described rather than on how it is used, which makes marketing copy a compliance surface here in a way it is not elsewhere.
- Re-check any New Zealand notice guidance written before mid-2026An indirect-collection notification principle came into force on 1 May 2026 and does not apply to information collected before that date. Anything written earlier is describing a smaller set of obligations than the one that exists now, which is an easy way to end up short.
- Do not cite the outsourcing policy as a testing mandateIt is a resolvability instrument rather than a security one, binding through conditions of registration on large locally incorporated registered banks, and its only testing requirements concern annual testing of the separation plan and back-up arrangements. Training, awareness, phishing, social engineering and simulation each return zero across its twenty-seven pages.
The controls that do the work
How Callstrike is configured, and which provision in New Zealand each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
Say plainly what this does not do in New Zealand: it does not answer the good-faith duty, because that duty bites on the deception itself rather than on what the deception obtains. What it does answer is the two privacy principles that decide the collection. The means must be fair in the circumstances and must not intrude to an unreasonable extent, and where the lawful purpose does not require identifying information you may not require it. A call that ends the moment an employee begins to give up a credential collects the least the purpose can be served by, which is the shape both principles ask for and the easiest fairness assessment to write.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
This is the control that speaks to New Zealand's unresolved question, and it is the only one that does. The duty is about misleading or deceiving, and a second voice that breaks character the moment the call ends, with vishing training in writing the same day, means the deception is undone inside the same minute rather than left standing until a report circulates. It also answers the regulator's separate warning about misleading staff as to what information will be used for, because the explanation arrives before anyone has had time to wonder.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Three dated artefacts here, and each one answers a different instrument. The workplace policy the employment regulator asks for, consulted on with employees and any union and in place before the programme starts. The programme notice carrying the checklist the notification principle prescribes, from the fact of collection through to the access and correction rights. And the record of why the prejudice-to-purpose exception applied, which matters more here than elsewhere because the onus of proving an exception is on the person relying on it.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Telephony was never New Zealand's obstacle, and a drafting decision from 2007 settles it: the spam statute excludes voice calls from the definition of an electronic message by name and defines a voice call to include one involving a recorded or synthetic voice. The obstacle is the good-faith duty, and this is the one delivery where nobody is deceived at all. Callstrike's vishing simulator carries the same deepfake voice into a web call the learner opts into after working through the module, so the exercise the duty is asked about is one the person chose to enter. The privacy code still governs whatever it collects, and New Zealand imposes no synthetic-voice disclosure duty for the module to satisfy.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.