Callstrike
Compliance

Voice phishing simulations in the Philippines

Phone numbers in the PhilippinesProvisioned by Callstrike after approval

The Philippines is permissive about the call and the strictest jurisdiction in this portal about recording it. A voice phishing simulation runs here on six co-equal statutory grounds and an unusually wide employment proviso, but the wiretapping statute requires the authority of every party and the Supreme Court has held that someone on the call who records it is a violator. So the first decision here is whether the programme produces audio at all.

Phone numbers

Supplied by Callstrike

Local numbers in the Philippines, after a one-time approval.

Running a simulation

Permitted, and the audio is the hard part

Six co-equal grounds and a wide employment proviso; all-party authority for any recording.

Consent

Not the ground, and the recording needs everyone's

Legitimate interests carries the processing. Only the audio needs authority from all parties.

Getting a phone number in the Philippines

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

The Philippine table below is short and one of its three lines is unlike anything else in this region. Proof of the local business address is a mayor's permit, which is a municipal document issued by the city or municipality itself rather than an extract from a national register, and the address it shows has to fall inside the locality covered by the number's own prefix. A company whose registered office sits in a different city has to obtain the permit for the place the number belongs to, and that is a local errand rather than a download.

The other two lines are the ordinary ones and come from the same national body: a certificate of registration of business name from the Department of Trade and Industry, and a certificate showing your business registration number. The console form asks you to type the business name and the corporate registration number alongside them.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in the Philippines is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Proof of identityCertificate of registration of business name department of trade & industry phillipines, Certificate of registration of business name department of trade & industry phillipines
Proof of business registration numberCertificate of registration showing the business registration number
Proof of local business addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable where a local address is required.Mayors permit showing local address

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in the Philippines?

The position in short, before your counsel reads the detail below.

Yes, and the Philippine structure is more generous than most of this region. The data privacy statute does not put agreement first: processing is permitted where at least one of six conditions exists, agreement being the first and legitimate interests the sixth. Note the last five words of the override when you quote it, because a reader trained on European material skips them: the interests are overridden by fundamental rights and freedoms which require protection under the Philippine Constitution. The override is anchored domestically, and the three principles the whole assessment should be written against are transparency, legitimate purpose and proportionality.

The provision that makes an unannounced test workable is a proviso most summaries omit entirely. The notification duty does not apply where collection and processing are for obvious purposes, including where necessary or desirable in the context of an employer-employee relationship between the collector and the data subject. Necessary or desirable is wider than anything comparable in this region, and it means the Philippines does not force the awkward reliance on a prejudice-to-purpose exception that several other countries do. It does not remove the transparency principle, so a standing policy remains the right design rather than an optional one.

Recording is where the page turns. It is unlawful for any person not authorised by all the parties to a private communication to secretly overhear, intercept or record it, and the Supreme Court has closed the argument that someone on the call is outside that: the statute penalises any unauthorised person, and even a person privy to a communication who records their conversation without the other's knowledge qualifies as a violator. Two further paragraphs make it harder. Knowingly possessing the record, replaying it, communicating its contents or furnishing transcripts is independently criminal, for any person, whether a participant or not, so a supplier holding the audio commits its own offence. And anything obtained in violation is inadmissible in any judicial, quasi-judicial, legislative or administrative hearing or investigation.

Read those two consequences together, because they arrive at the same moment and they decide the design. An unlawfully recorded simulation call exposes everyone who touches it to six months to six years, and is simultaneously unusable in the very human resources or disciplinary process it was made to feed. The only route in the statute runs through a peace officer with a court order for an enumerated list of offences beginning with treason, so there is no business purpose, employer or security-testing route anywhere in it. Either obtain genuine advance authorisation from every employee who might be called, covering recorded security test calls, or build the exercise so its outputs are events and outcomes rather than audio.

What your company needs to do

8 items, in the order you will need them.

  • Decide whether the programme produces audio or eventsPhilippines-specificThis is the Philippine decision and it belongs at design time. Events and outcomes, who answered and who complied, carry no wiretapping question at all. Audio requires genuine advance authorisation from every party, obtained and filed before the first call, and exposes your supplier to a separate offence for holding it.
  • If you record, obtain and file all-party authorisation in advancePhilippines-specificAll the parties, not one and not the caller. It has to be genuine, informed and documented, covering the possibility of recorded security test calls, from every employee who might be called. The design of a simulation means it cannot be obtained at call time, so it is obtained at programme time or not at all.
  • Write the scope of authority narrowly, and date itPhilippines-specificIllegal access is access without right, and without right is statutorily defined to include conduct undertaken without or in excess of authority. Exceeding the agreed scope re-criminalises the act, so the document should name the systems, the population, the pretexts permitted and the pretexts excluded. It is the single load-bearing document on this page.
  • Keep a standing privacy notice covering security testingThe transparency principle survives the obvious-purposes proviso even though the per-collection notification duty does not, so the notice is what carries it. It also gives you something dated to point at if anyone later asks what employees were told and when.
  • Present a number you genuinely hold, and keep the intent recordsPhilippines-specificSpoofing here is a fraud offence rather than a numbering-rights rule: transmitting misleading information about the source with intent to defraud, cause harm or wrongfully obtain anything of value. An authorised training exercise meets none of those, but the exemption list is closed and contains no testing limb, so you are relying entirely on the absence of intent and that has to be evidenced from your own documentation.
  • Design so no live financial credential can ever be capturedPhilippines-specificThe financial account scamming offence describes a pretexting call almost exactly, and the only thing keeping an authorised simulation outside it is the result element: the scheme has to result in unauthorised access and control over a financial account. A single element is doing the whole exculpatory job, which is a reason to design the capture out rather than to argue about it.
  • Do not cite a privacy commission advisory opinion as a ruleThe commission's own index states that an opinion provides guidance to the requesting party and the general public but is not a standing rule binding on the commission regardless of the similarity of the facts. There is no opinion on phishing simulation, vishing simulation or security awareness testing, so nobody can say the regulator has blessed the practice.
  • Take the Labor Code position to local employment counselThis page makes no claim about company rules and regulations, about due process before disciplining an employee, or about any consultation duty, because we did not retrieve the Labor Code or its implementing rules. It does not say there is none either. If you intend to act on results, that is the gap to close first.

The controls that do the work

How Callstrike is configured, and which provision in the Philippines each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

The financial account scamming legislation is the reason this control matters here. Its social engineering limb covers obtaining sensitive identifying information through deception by misrepresenting yourself as acting for an institution, which is a description of a pretext call, and the only thing keeping an authorised simulation outside the offence is the result element: the scheme must result in unauthorised access and control over the person's financial account. One element doing the whole exculpatory job is a thin margin to rely on. The call ending the moment an employee begins to give up a credential means the result the offence requires can never arrive, which converts an argument into a fact about the system.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The Philippines is the one country in this portal where the recording is worth less than the teaching, and the statute is why: audio obtained without all-party authority is inadmissible in any hearing or investigation, so it cannot feed the disciplinary process it would elsewhere justify. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, delivers the entire value of the exercise inside the call itself, where no evidentiary rule reaches it.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Two separate jobs here, and they are owed to different provisions. The standing notice is what carries the transparency principle past the obvious-purposes proviso, dated before the campaign rather than reconstructed afterwards. And where the programme records, the genuine advance authorisation from every party is not evidence of anything: it is the thing that makes the audio lawful to make, lawful for your supplier to hold and admissible if it is ever needed. Per employee, dated, and collected long before the call.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

Be precise about what this route does and does not solve in the Philippines, because the sharpest rule here is not a telephony one. Callstrike's vishing simulator carries the same deepfake voice into a web call the learner opens themselves after working through the module, which removes the spoofing offence's intent question entirely, since no number is presented at all. The wiretapping statute is written about a private communication rather than about a telephone call, so the all-party question travels with the audio into either delivery and this route does not answer it. What the module changes is the pretext and the number, not the recording.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

Six co-equal bases, and a proviso built for employment

The Philippine data privacy statute does not put consent first, and getting that right changes the whole shape of a Philippine programme.

Processing personal information is permitted only if not otherwise prohibited by law and when at least one of six conditions exists. Consent is the first of them and legitimate interests is the sixth: processing is permitted where it is necessary for the purposes of the legitimate interests pursued by the controller or by a third party to whom the data is disclosed, except where such interests are overridden by fundamental rights and freedoms of the data subject which require protection under the Philippine Constitution.

Note the last five words. The override in the Philippines is anchored to domestic constitutional rights, not to any external charter, and a reader trained on European material will skip past them. They belong in any quotation of the provision.

The statute's general principles sit alongside: processing is allowed subject to compliance with the Act and adherence to the principles of transparency, legitimate purpose and proportionality. Those three words are the frame a Philippine assessment should be written against.

The provision that makes an unannounced test workable is a proviso most summaries omit entirely. The Act's notification duty does not apply where the personal information is needed pursuant to a subpoena, or when the collection and processing are for obvious purposes, including when it is necessary for the performance of or in relation to a contract or service, or when necessary or desirable in the context of an employer-employee relationship between the collector and the data subject, or when the information is being collected and processed as a result of a legal obligation.

Necessary or desirable in the context of an employer-employee relationship is a wider formulation than most of this portal's jurisdictions offer, and it is the statutory hook for not announcing each individual test. It does not remove the transparency principle, and a standing policy remains the right design, but it means the Philippines does not force the awkward reliance on a prejudice-to-purpose exception that several other countries do.

One caution about the regulator's material. The privacy commission publishes advisory opinions, and the index page states in terms that an opinion serves to provide guidance to the requesting party and the general public but shall not be used in the nature of a standing rule binding on the commission regardless of the similarity of the facts. Portal pages routinely cite those opinions as if they were rules. They are not, and the commission says so on the index itself. We reviewed the opinion index back through 2025 and found none on phishing simulation, vishing simulation or security awareness testing, so nobody should claim the regulator has blessed the practice.

Every party must authorise it, and a participant is not enough

This is the section that decides whether a Philippine programme can record at all, and the answer is the strictest in this portal.

It is unlawful for any person, not being authorised by all the parties to any private communication or spoken word, to tap any wire or cable, or by using any other device or arrangement, to secretly overhear, intercept or record such communication or spoken word by using a device commonly known as a dictaphone, walkie-talkie or tape recorder, or however otherwise described.

All the parties. Not one, not the caller, all of them. And the Supreme Court has closed the argument that a participant is outside it. The provision clearly and unequivocally makes it illegal for any person not authorised by all the parties to record secretly, the Court held; the law makes no distinction as to whether the party sought to be penalised ought to be a person other than or different from those involved in the communication, and the statute's intent to penalise all unauthorised persons is underscored by the use of the qualifier any. So even a person privy to a communication who records their private conversation with another without the knowledge of the latter qualifies as a violator.

Read that against a simulation. The entire design is that the person on the other end does not know what the call is, so all-party authorisation cannot be obtained at call time. Recording therefore requires genuine advance, informed, documented authorisation from every employee who might be called, covering the possibility of recorded security test calls, or it requires not recording at all.

Two further paragraphs make the position harder still. The same section independently criminalises, for any person, be he a participant or not, knowingly possessing any such record or copy of it, replaying it for any other person, communicating its contents verbally or in writing, or furnishing transcriptions. A vendor holding recordings commits a separate offence from the person who made them. And the penalty is imprisonment of not less than six months and not more than six years, with perpetual absolute disqualification from public office for a public official and deportation proceedings for an alien.

Then the provision that removes the reason you wanted the recording. Any communication or spoken word, or its existence, contents, substance, purport, effect or meaning, or any information contained in it, obtained in violation of the Act shall not be admissible in evidence in any judicial, quasi-judicial, legislative or administrative hearing or investigation. So an unlawfully recorded simulation call is unusable in the internal disciplinary or human resources proceeding it would feed. The legal exposure and the loss of the artefact's purpose arrive at the same moment.

The only escape route in the statute is unavailable to an employer. It permits the acts solely for a peace officer authorised by a written order of the court, and only for an enumerated list of offences beginning with treason, espionage and provoking war. There is no business-purpose exception, no employer exception and no security-testing exception anywhere in the Act.

The practical design conclusion is short. In the Philippines, either obtain and file genuine advance all-party authorisation, or build the exercise so that its outputs are events and outcomes rather than audio.

No disclosure duty exists, and that is a finding not a permission

There is no Philippine rule requiring a caller to disclose that a voice is AI-generated, and no Philippine automated-calling regime of the European kind. We counted five statutes through rather than inferring it: the data privacy act, the cybercrime act, the electronic commerce act, the subscriber registration act and the financial account scamming act. Social engineering, phishing, voice phishing and simulation return zero in all five, and spoofing appears only in the registration act, where it is defined and penalised.

That is an honest absence rather than a permission, and the difference matters. No instrument tells you a synthetic voice must be announced. Equally, no instrument gives you a safe harbour for using one, and the general offences described in the rest of this page apply to a synthetic caller exactly as they apply to a human one.

One statute is worth reading because it looks threatening and is not. The electronic commerce act defines hacking as unauthorised access into or interference in a computer system or information and communication system, or any access in order to corrupt, alter, steal or destroy using a computer or other similar device, without the knowledge and consent of the owner of the computer or information and communications system. Without the knowledge and consent of the owner is the operative phrase, and an employer testing its own systems with its own authorisation does not satisfy it.

The only other place a Philippine statute comes close to describing this activity is in the financial account scamming legislation, and the margin is narrower than anyone would like. A social engineering scheme is committed by a person who obtains sensitive identifying information of another person, through deception or fraud, resulting in unauthorised access and control over the person's financial account, by misrepresenting themselves as acting on behalf of an institution or making false representations to solicit the information, or by using electronic communications to obtain it.

Read the first of those limbs on its own and it describes a pretexting call almost exactly. What keeps an authorised simulation outside the offence is the result element: the scheme must result in unauthorised access and control over a financial account. A test that captures no credential and touches no account does not complete it. That is a single element doing the entire exculpatory job, and it is worth stating rather than glossing, because a simulation that genuinely captured live banking credentials would be arguing about it.

A fraud offence rather than a numbering-rights rule

Most countries in this portal regulate caller identity as a question of who holds the number. The Philippines made it a fraud offence instead, which is more permissive for an honest test and more dangerous at the edges.

Spoofing is defined as the act of transmitting misleading or inaccurate information about the source of the phone call or text message, with the intent to defraud, cause harm, or wrongfully obtain anything of value. The offence carries imprisonment of no less than six years, or a fine of two hundred thousand pesos, or both, for anyone who causes such information to be transmitted with that intent.

So the prohibition is not framed as a right-of-use rule at all. It bites on misleading information about the source plus an intent element, and an authorised internal security test conducted for training, with no intent to defraud, to cause harm or to wrongfully obtain anything of value, does not meet that element on its face.

But read the exemptions before relying on that, because they are what a cautious buyer will ask about. The offence does not apply where the transmission is exempted in connection with authorised activities of law enforcement agencies, or a court order specifically authorising the use of caller identification manipulation. That list is closed and it contains no security-testing limb.

The consequence is a materially thinner position than an express carve-out would give. An operator presenting a misleading number in the Philippines is relying entirely on the absence of intent, which is a state of mind that has to be evidenced from the programme's own documentation, rather than on a provision saying the activity is permitted. That is a reason to present a number the employer genuinely holds, and to keep the authorisation and purpose records that show what the intent was.

What the country matrix holds for the Philippines

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

The scope document is what makes the access lawful

The Philippines does not give you a monitoring statute with a documentation checklist. What it gives you is a definition, and that definition makes one document load-bearing.

Illegal access under the cybercrime act is the access to the whole or any part of a computer system without right, and illegal interception is interception made by technical means without right of any non-public transmission of computer data to, from or within a computer system. The statute then defines the phrase that does all the work: without right refers to either conduct undertaken without or in excess of authority, or conduct not covered by established legal defenses, excuses, court orders or justifications.

Written authority from the system owner, properly scoped, is what converts the activity from without right into lawful conduct. And the words in excess of authority mean the scope document is not a formality: exceeding the agreed scope re-criminalises the act. That is the single most important documentation point for a Philippine programme, and it argues for a narrow, explicit, dated authorisation naming the systems, the population, the pretexts permitted and the pretexts excluded.

The exposure if it goes wrong is not trivial. Aiding or abetting, and attempting, are separately punishable; offences under the revised penal code committed through information and communications technologies have their penalty raised by one degree; and the principal offences carry imprisonment of prision mayor or a fine of at least two hundred thousand pesos, or both.

We counted the cybercrime act through for phishing, voice phishing, social engineering and simulation. All four return zero. There is no express authorised-testing or research exemption anywhere in it: the entire defence lives in the words without right, which is why the paperwork carries the weight.

One honest gap, and we would rather name it than fill it. We did not retrieve the Labor Code or its implementing rules, so this page makes no claim about company rules and regulations, about due process requirements before disciplining an employee, or about any consultation duty. It does not say the Philippines has no such duty either. The only employment-specific provision we can source is the privacy statute's proviso described earlier. A Philippine programme that intends to discipline on the results should take the Labor Code position to local employment counsel.

What we can say about the remaining paperwork follows from the earlier sections rather than from a checklist. A standing privacy notice covering security testing, because the transparency principle survives the notification proviso. Genuine advance all-party authorisation for any recording, or a design that produces no recording. And a record of purpose and intent good enough to answer the spoofing offence's intent element if the campaign presents anything other than the employer's own number.

The central bank tests people by definition, not by naming it

The claim that the Philippine central bank expressly requires social engineering testing circulates widely and is false as stated. We checked three issuances in full text. Social engineering appears zero times in the 2017 guidelines on information security management and zero times in the 2022 amendments on information technology risk management; it appears once in a 2025 circular, purely as a rationale for limiting one-time passwords sent by text. Publishing the stronger claim would be a checkable error on a public page.

What is verifiable is better than nothing and is arguably more useful, because it reaches people by definition rather than by vocabulary. The 2017 guidelines define penetration testing as subjecting a system or network to simulated or real-world attacks that exploit vulnerabilities under controlled conditions, and say that depending on the test objectives and scope the institution may use penetration testing to assess potential business impact, the level of security, risk management processes and controls, as well as the knowledge of concerned personnel in the organisation in identifying, detecting and responding to attacks. For institutions providing digital or electronic financial services, vulnerability assessment and penetration testing should be performed by an external party at least annually.

The knowledge of concerned personnel in identifying, detecting and responding to attacks. That is a people-testing mandate arrived at through the definition of penetration testing rather than through the phrase social engineering, and it is the accurate way to state the Philippine financial-sector position. The same guidelines separately define a red-teaming exercise as a more in-depth type of penetration testing that continually challenges the organisation's defences and controls, conducted by highly-trained specialists acting in adversarial mode who may be the institution's own independent employees or third-party experts.

So the honest sentence for a Philippine buyer is that the central bank mandates annual external vulnerability assessment and penetration testing for institutions offering digital financial services, and defines penetration testing so as to include assessing personnel knowledge. It does not name social engineering testing, and a vendor quoting it as if it did is overreaching.

One currency note. The 2017 guidelines carry a transition to the end of 2022 referencing a 2022 circular, and a 2025 circular still amends the same manual architecture, which confirms the framework is live. There is an internal date discrepancy between the resolution date and the issuance date of the 2022 circular; the issuance date is the one to cite.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in the PHILIPPINES. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. A standing privacy notice covers security testing.

Verify or correct each proposition below against primary Philippine sources, and tell me whether we can record:

1. ⚠⚠ RA 4200 s 1 requires authorisation by ALL the parties, and Ramirez v Court of Appeals (G.R. No. 93833, 28 September 1995) holds that a person privy to the communication who records it qualifies as a violator. Confirm both, and confirm no business, employer or security-testing exception exists in the Act.
2. ⚠ s 1's SECOND paragraph independently criminalises possessing, replaying, transcribing or communicating the contents «be he a participant or not», so our VENDOR commits a separate offence. Confirm.
3. ⚠ s 4 makes the material inadmissible «in any judicial, quasi-judicial, legislative or administrative hearing or investigation», which removes its value in our own HR process. Confirm.
4. RA 10173 s 12(f) is a genuine legitimate-interests ground whose override is anchored to «fundamental rights and freedoms ... which require protection under the Philippine Constitution», and s 16's notification duty is disapplied for «obvious purposes ... necessary or desirable in the context of an employer-employee relationship».
5. ⚠ RA 10175 s 3(h): «without right» includes conduct «without or in excess of authority». Advise on how narrowly our written scope of authority must be drawn, and what it must name.
6. ⚠ RA 12010 s 4(b)(1) reads almost exactly like a pretext call; the RESULT element («resulting in unauthorised access and control over a Financial Account») is the only thing keeping us outside it. Confirm that reading.
7. RA 11934 s 3(g) defines spoofing by INTENT, and its s 19(e) exemptions are a closed list with no security-testing limb, so we rely entirely on absence of intent.
8. ⚠ NOT COVERED: the Labor Code on company rules and regulations, and on due process before discipline. What does it require of us if we act on results?

⚠ NPC advisory opinions are self-declared non-binding and none addresses this practice. Disini v Secretary of Justice struck down parts of RA 10175 and was not checked. Flag anything that has changed since September 2026.

Common questions

Can we record a simulation call in the Philippines?
Only with genuine advance authorisation from every party. The wiretapping law requires the authority of all parties, the Supreme Court has held a participant who records is a violator, possessing or replaying the recording is a separate offence, and the result is inadmissible in any proceeding.
Does the privacy law require us to announce each test?
No. The notification duty does not apply where collection and processing are for obvious purposes, including where necessary or desirable in the context of an employer-employee relationship. The transparency principle survives, so a standing policy is still the right design.
What single document matters most here?
The written scope of authority. The cybercrime offence turns on acting without right, which the statute defines to include conduct undertaken without or in excess of authority. Exceeding the agreed scope re-criminalises the act, so the scope document is load-bearing rather than a formality.
Does the central bank require social engineering testing?
Not in those words, and the claim that it does is false. What it requires is annual external vulnerability assessment and penetration testing for institutions offering digital financial services, with penetration testing defined to include assessing personnel knowledge in detecting and responding to attacks.

Elsewhere in Asia Pacific

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.