Voice phishing simulations in the Philippines
The Philippines is permissive about the call and the strictest jurisdiction in this portal about recording it. A voice phishing simulation runs here on six co-equal statutory grounds and an unusually wide employment proviso, but the wiretapping statute requires the authority of every party and the Supreme Court has held that someone on the call who records it is a violator. So the first decision here is whether the programme produces audio at all.
Phone numbers
Supplied by Callstrike
Local numbers in the Philippines, after a one-time approval.
Running a simulation
Permitted, and the audio is the hard part
Six co-equal grounds and a wide employment proviso; all-party authority for any recording.
Consent
Not the ground, and the recording needs everyone's
Legitimate interests carries the processing. Only the audio needs authority from all parties.
Getting a phone number in the Philippines
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
The Philippine table below is short and one of its three lines is unlike anything else in this region. Proof of the local business address is a mayor's permit, which is a municipal document issued by the city or municipality itself rather than an extract from a national register, and the address it shows has to fall inside the locality covered by the number's own prefix. A company whose registered office sits in a different city has to obtain the permit for the place the number belongs to, and that is a local errand rather than a download.
The other two lines are the ordinary ones and come from the same national body: a certificate of registration of business name from the Department of Trade and Industry, and a certificate showing your business registration number. The console form asks you to type the business name and the corporate registration number alongside them.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in the Philippines is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Proof of identity | Certificate of registration of business name department of trade & industry phillipines, Certificate of registration of business name department of trade & industry phillipines |
| Proof of business registration number | Certificate of registration showing the business registration number |
| Proof of local business addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable where a local address is required. | Mayors permit showing local address |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in the Philippines?
The position in short, before your counsel reads the detail below.
Yes, and the Philippine structure is more generous than most of this region. The data privacy statute does not put agreement first: processing is permitted where at least one of six conditions exists, agreement being the first and legitimate interests the sixth. Note the last five words of the override when you quote it, because a reader trained on European material skips them: the interests are overridden by fundamental rights and freedoms which require protection under the Philippine Constitution. The override is anchored domestically, and the three principles the whole assessment should be written against are transparency, legitimate purpose and proportionality.
The provision that makes an unannounced test workable is a proviso most summaries omit entirely. The notification duty does not apply where collection and processing are for obvious purposes, including where necessary or desirable in the context of an employer-employee relationship between the collector and the data subject. Necessary or desirable is wider than anything comparable in this region, and it means the Philippines does not force the awkward reliance on a prejudice-to-purpose exception that several other countries do. It does not remove the transparency principle, so a standing policy remains the right design rather than an optional one.
Recording is where the page turns. It is unlawful for any person not authorised by all the parties to a private communication to secretly overhear, intercept or record it, and the Supreme Court has closed the argument that someone on the call is outside that: the statute penalises any unauthorised person, and even a person privy to a communication who records their conversation without the other's knowledge qualifies as a violator. Two further paragraphs make it harder. Knowingly possessing the record, replaying it, communicating its contents or furnishing transcripts is independently criminal, for any person, whether a participant or not, so a supplier holding the audio commits its own offence. And anything obtained in violation is inadmissible in any judicial, quasi-judicial, legislative or administrative hearing or investigation.
Read those two consequences together, because they arrive at the same moment and they decide the design. An unlawfully recorded simulation call exposes everyone who touches it to six months to six years, and is simultaneously unusable in the very human resources or disciplinary process it was made to feed. The only route in the statute runs through a peace officer with a court order for an enumerated list of offences beginning with treason, so there is no business purpose, employer or security-testing route anywhere in it. Either obtain genuine advance authorisation from every employee who might be called, covering recorded security test calls, or build the exercise so its outputs are events and outcomes rather than audio.
What your company needs to do
8 items, in the order you will need them.
- Decide whether the programme produces audio or eventsPhilippines-specificThis is the Philippine decision and it belongs at design time. Events and outcomes, who answered and who complied, carry no wiretapping question at all. Audio requires genuine advance authorisation from every party, obtained and filed before the first call, and exposes your supplier to a separate offence for holding it.
- If you record, obtain and file all-party authorisation in advancePhilippines-specificAll the parties, not one and not the caller. It has to be genuine, informed and documented, covering the possibility of recorded security test calls, from every employee who might be called. The design of a simulation means it cannot be obtained at call time, so it is obtained at programme time or not at all.
- Write the scope of authority narrowly, and date itPhilippines-specificIllegal access is access without right, and without right is statutorily defined to include conduct undertaken without or in excess of authority. Exceeding the agreed scope re-criminalises the act, so the document should name the systems, the population, the pretexts permitted and the pretexts excluded. It is the single load-bearing document on this page.
- Keep a standing privacy notice covering security testingThe transparency principle survives the obvious-purposes proviso even though the per-collection notification duty does not, so the notice is what carries it. It also gives you something dated to point at if anyone later asks what employees were told and when.
- Present a number you genuinely hold, and keep the intent recordsPhilippines-specificSpoofing here is a fraud offence rather than a numbering-rights rule: transmitting misleading information about the source with intent to defraud, cause harm or wrongfully obtain anything of value. An authorised training exercise meets none of those, but the exemption list is closed and contains no testing limb, so you are relying entirely on the absence of intent and that has to be evidenced from your own documentation.
- Design so no live financial credential can ever be capturedPhilippines-specificThe financial account scamming offence describes a pretexting call almost exactly, and the only thing keeping an authorised simulation outside it is the result element: the scheme has to result in unauthorised access and control over a financial account. A single element is doing the whole exculpatory job, which is a reason to design the capture out rather than to argue about it.
- Do not cite a privacy commission advisory opinion as a ruleThe commission's own index states that an opinion provides guidance to the requesting party and the general public but is not a standing rule binding on the commission regardless of the similarity of the facts. There is no opinion on phishing simulation, vishing simulation or security awareness testing, so nobody can say the regulator has blessed the practice.
- Take the Labor Code position to local employment counselThis page makes no claim about company rules and regulations, about due process before disciplining an employee, or about any consultation duty, because we did not retrieve the Labor Code or its implementing rules. It does not say there is none either. If you intend to act on results, that is the gap to close first.
The controls that do the work
How Callstrike is configured, and which provision in the Philippines each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
The financial account scamming legislation is the reason this control matters here. Its social engineering limb covers obtaining sensitive identifying information through deception by misrepresenting yourself as acting for an institution, which is a description of a pretext call, and the only thing keeping an authorised simulation outside the offence is the result element: the scheme must result in unauthorised access and control over the person's financial account. One element doing the whole exculpatory job is a thin margin to rely on. The call ending the moment an employee begins to give up a credential means the result the offence requires can never arrive, which converts an argument into a fact about the system.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The Philippines is the one country in this portal where the recording is worth less than the teaching, and the statute is why: audio obtained without all-party authority is inadmissible in any hearing or investigation, so it cannot feed the disciplinary process it would elsewhere justify. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, delivers the entire value of the exercise inside the call itself, where no evidentiary rule reaches it.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Two separate jobs here, and they are owed to different provisions. The standing notice is what carries the transparency principle past the obvious-purposes proviso, dated before the campaign rather than reconstructed afterwards. And where the programme records, the genuine advance authorisation from every party is not evidence of anything: it is the thing that makes the audio lawful to make, lawful for your supplier to hold and admissible if it is ever needed. Per employee, dated, and collected long before the call.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Be precise about what this route does and does not solve in the Philippines, because the sharpest rule here is not a telephony one. Callstrike's vishing simulator carries the same deepfake voice into a web call the learner opens themselves after working through the module, which removes the spoofing offence's intent question entirely, since no number is presented at all. The wiretapping statute is written about a private communication rather than about a telephone call, so the all-party question travels with the audio into either delivery and this route does not answer it. What the module changes is the pretext and the number, not the recording.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.