Callstrike
Compliance

Voice phishing simulations in South Africa

Phone numbers in South AfricaSelf-provisioned after approval

In South Africa the governing instrument for a voice phishing simulation is criminal law rather than data protection law. The exercise is lawful, but the conditions that make monitoring your own telephone system lawful are cumulative, and one missing advance notice produces two offences at once, each carrying up to ten years. Underneath sits an objection right stronger than Europe's, under which one employee can end their own inclusion in the programme.

Phone numbers

Supplied by Callstrike

Local and mobile numbers in South Africa, after a one-time approval.

Running a simulation

Permitted on four conditions

The business-monitoring conditions are cumulative, and one miss is two offences.

Consent

Not the ground, and an objection ends it

A reasoned objection stops processing outright, with no override of the European kind.

Getting a phone number in South Africa

One approval per country, completed in the console.

Self-provisioned after approval

Your company files its regulatory details once for this country. Once that is approved, your team provisions numbers directly from available inventory. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

South African onboarding asks for more than anywhere else in this portal, and the reason is not that the carrier is being cautious. Almost all of it is a criminal-law duty imposed on the carrier, which has no discretion to waive any of it: failing the contracting requirements is an offence at up to five million rand, and failing the activation requirements carries up to a hundred thousand rand for every day the failure continues. A per-day criminal fine is why there is no commercial route around a single line of the table below.

What that table asks for is a company registration document or a certified letterhead carrying the registration number, a government-issued photo identity document for your authorised representative, and proof of the business address, which will take a bank statement, a municipal rates or tax invoice, a recent telephone account statement or a new motor vehicle licence. The address is the line that catches companies out, because for a geographic number it has to sit inside the area that number's own prefix covers rather than merely somewhere in the country, and a post office box is not accepted. If you go on to activate a mobile number, the carrier additionally has to hold a letter of authority or affidavit establishing that your representative may bind the company, and that is the document people forget to budget for.

On what the person sees, present a number legitimately assigned to you and nothing else. The regulator defines calling line identification as the transmission of the calling party's assigned number and requires licensees to prohibit transmitting an inaccurate one, and although that duty is written as an obligation on the licensee rather than as an offence against a caller, the enforcement is real: in June 2026 the regulator fined an operator three million rand per contravention for using numbers not allocated to it, barred and withdrew the affected resources and imposed two years of monthly compliance reporting. A subscriber to whom a number has been legitimately assigned may enjoy its beneficial use freely, which is the authority for presenting it.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03Search the inventory and rent your numberYour team
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Proof of business nameOfficial CIPC issued document showing business name, Certified business letterhead
Proof of business registrationDocument must include CIPC issued Business Registration NumberOfficial CIPC issued document showing business name, Certified business letterhead
Proof of business addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable.Bank statement, Municipal rates or tax invoice, Recent telephone account statement, New motor vehicle license
Proof of authorized representative nameGovernment-issued photo ID
Proof of identity document numberGovernment-issued photo ID

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in South Africa?

The position in short, before your counsel reads the detail below.

Yes, and the block that decides it is criminal law rather than data protection law. The interception statute prohibits intentionally intercepting any communication, and intercept is defined widely enough to cover ordinary call recording. The clean route for the simulated call itself is the party provision: a person who is a party to the communication may intercept it, unless the interception is for the purpose of committing an offence. There is no notification duty on the face of that section and nothing needed from the other side, and the platform calling on your behalf is a party to the call. For the call your own system places, South Africa is a one-party jurisdiction and the all-party framing that applies elsewhere is simply the wrong analysis.

Monitoring your own telephone system is a different section, and it is where programmes go wrong, because it carries four cumulative conditions rather than one. The interception must be effected by or with the consent of the system controller, which for a company means the chief executive or someone that officer has duly authorised. It must be for one of the listed purposes, of which investigating or detecting unauthorised use of the system is the relevant one. The system must be provided for use wholly or partly in connection with the business, which is what puts an employee's own personal handset outside the section entirely. And the system controller must have made all reasonable efforts to inform in advance anyone intending to use the system that communications transmitted by means of it may be intercepted.

That last condition is more workable than it first looks, and the wording is why. What has to be said in advance is that communications may be intercepted. Not that a particular call will be, and not why. A standing policy-level notice that calls on company systems may be monitored and recorded satisfies it without announcing that a test is coming. The reason to get it exactly right is that a miss compounds: contravening the business-monitoring section is a standalone offence and it simultaneously removes the protection that section gives against the general unlawful interception offence, so one missing notice produces two, each carrying a fine of up to two million rand or ten years.

The data protection layer is where the commercially significant surprise sits. The ground for an authorised internal test is processing necessary for pursuing your own legitimate interests, and that provision carries no balancing clause in its own words; the balance enters through the objection right instead. An employee may object at any time on reasonable grounds relating to their particular situation, and the statute then says you may no longer process their personal information. Flat, with no compelling-grounds override of the kind European employers have and no escape on the face of the provision except where legislation provides for the processing. Build the programme knowing that one reasoned objection ends that person's inclusion in it. The marketing rule, by contrast, does not reach you at all, because its own scope is confined to promoting or offering goods or services or requesting a donation. Be precise about that reason: the prohibition simply does not describe the activity, and nothing about it relaxes anything else on this page. Note too that a human-dialled marketing call is inside that rule as well, so putting a live operator on the line moves nothing here.

What your company needs to do

7 items, in the order you will need them.

  • Put the standing notice in place before the first call, and keep itSouth Africa-specificAll reasonable efforts to inform, in advance, anyone intending to use the system that communications transmitted by means of it may be intercepted. A policy-level notice does it; a notice written after the campaign does not. This is the single condition whose absence turns one mistake into two offences, so treat it as a gate on launching rather than as a document to tidy up afterwards.
  • Get the system controller's authorisation, and make it one documentSouth Africa-specificThe interception statute wants the chief executive or someone that officer has duly authorised. The cybercrime offences are each qualified by the word unlawfully, and what negates unlawfulness is the authority of the person entitled to give it, which is the same officer. One written authorisation, scoped to the systems in question, does both jobs.
  • Plan for individual objections rather than treating them as edge casesSouth Africa-specificThe objection right has no override, so a single employee's reasoned objection ends their inclusion. Decide in advance how the programme handles that: how an objection is received, who assesses whether the grounds relate to that person's particular situation, and how the target list is amended without the exclusion itself becoming visible to their colleagues.
  • Keep personal handsets out of scopeSouth Africa-specificThe business-monitoring section applies to a system provided for use wholly or partly in connection with the business, which is exactly what an employee's own personal phone and personal number are not. If your target list includes personal numbers, that part of the campaign is outside the section you were relying on and needs its own analysis.
  • Run the impact assessment, because nothing has to trigger itSouth Africa-specificThe obligation is in the Regulations rather than the Act, and it differs from Europe's in two ways worth planning around: there is no risk threshold, so it applies regardless, and no content, form or methodology is prescribed at all. It is a real duty with no prescribed shape, which means the shape is your decision and should be recorded as one.
  • Decide whether failing carries disciplinary consequences before you buyWhere a workplace forum exists, changes in the organisation of work are consultation and you may implement after exhausting the procedure, but disciplinary codes are joint decision-making, where consensus is required and failure to reach it goes to arbitration. A forum exists only where a majority union has applied at more than a hundred employees, so in most private workplaces there is no counterparty at all.
  • Scope so that no real credential is captured and no real prejudice is possibleThe cyber fraud and forgery offences require an intention to defraud and actual or potential prejudice, and an authorised assurance purpose lacks the intention, which is an element rather than a defence. No South African decision or prosecution guideline has applied the Act to authorised security testing, so that is a reading of an element. Designing out the prejudice is the control that makes the reading safe to rely on.

The controls that do the work

How Callstrike is configured, and which provision in South Africa each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

The sourced position below asks for exactly this control by name, and the reason is the cybercrime statute rather than the privacy one. Acquiring or using a password or access code for the purpose of unlawfully accessing a system is an offence carrying up to ten years, and cyber fraud requires an intention to defraud together with actual or potential prejudice. The call ends the instant an employee begins to give up a credential, so nothing the pretext asked for is ever acquired and no real prejudice becomes possible. Both offences are built around a thing that does not happen, which is a stronger position than arguing about intention after the fact.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

Two South African features make how the exercise ends a commercial question rather than a courtesy. The first condition for lawful processing requires you not to infringe privacy in an excessive way, and the objection right lets any employee stop their own inclusion for reasons relating to their situation. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is both the answer to excessiveness and the difference between a programme people accept and one they opt out of individually.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Agreement is the wrong ground here for the reason it is wrong everywhere: it cannot be freely given by someone who reports to you, and asking destroys the test. What this produces is the two notices South Africa actually demands, dated and evidenced. The privacy statute wants people made aware of the purpose before information is collected. The interception statute wants all reasonable efforts to inform system users in advance that communications may be intercepted, and that is the notice whose absence produces two offences, so a signed and timestamped record of it is worth more here than anywhere else in this portal.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

The South African friction is the onboarding rather than the law, and this route has none of it. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, so there is no service-provider contract to enter, no five documents to certify and no number to have assigned. The business-monitoring conditions are written about a telecommunication system provided in connection with the business, and a session a learner opens in their own browser is not one. The privacy statute still governs whatever either route records, and South Africa imposes no synthetic-voice disclosure duty for the module to satisfy.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

The POPIA basis, and the objection right that has no override

South Africa's data protection statute is POPIA, and it does not have a list of legal bases in the European sense. It has eight conditions for lawful processing, and the grounds sit inside the second of them. The ground for an authorised internal test is section 11(1)(f), processing necessary for pursuing the legitimate interests of the responsible party. Note that section 11(1)(f) carries no balancing clause in its own words, unlike its European counterpart; the balance enters through the objection right and through the first condition, which requires processing to be lawful and not to infringe privacy in an excessive way.

Then read section 11(3) and (4) together, because this is the most commercially significant difference between South Africa and Europe and almost nobody covers it. An employee may object at any time, on reasonable grounds relating to their particular situation, to processing carried out on the legitimate interests ground. If they do, section 11(4) says the responsible party may no longer process the personal information. Flat. There is no compelling legitimate grounds override of the kind Article 21 of the GDPR gives a European employer, and the only escape on the face of the provision is where legislation provides for the processing. So build your programme knowing that a single named employee's reasoned objection ends their inclusion in it.

Consent is the wrong ground here for the same reason it is wrong everywhere: it cannot be freely given by someone who reports to you, and asking destroys the test. Note that POPIA reaches a foreign supplier too. It applies where the responsible party is not domiciled in South Africa but uses automated or non-automated means inside the country, unless those means only forward information through it.

Transparency is section 18, and it requires you to make people aware of the purpose of collection before the information is collected. Two provisions carry the programme-level design. Section 18(3) says that where you have already given the information, you comply for subsequent collection of the same kind of information where the purpose stays the same, and section 18(4)(d) removes the duty where compliance would prejudice a lawful purpose of the collection. We are quoting those provisions rather than concluding from them: no South African decision, regulator guidance or enforcement notice has applied section 18(4)(d) to security testing, so it is the provision your argument runs through and it has not been tested here.

The impact assessment obligation exists but it is not in the Act. Regulation 4(1)(b) of the 2018 Regulations requires the information officer to ensure a personal information impact assessment is done, and the Information Regulator restates it as a live duty. Two differences from Europe worth planning around: it is not triggered by a risk threshold, so it applies regardless, and the Regulations prescribe no content, form or methodology at all. It is a real obligation with no prescribed shape.

On consultation, South Africa has no works council. It has the workplace forum, and a forum exists only where a majority union has applied to the CCMA in a workplace of more than one hundred employees. An employer cannot be made to create one, so in most private-sector workplaces there is no statutory counterparty at all. Where a forum does exist, the position splits: changes in the organisation of work are consultation, where the employer must attempt consensus and may implement after exhausting the procedure, but disciplinary codes are joint decision-making, where consensus is required and a failure to reach it goes to arbitration rather than to unilateral implementation. So if failing a simulation is to carry disciplinary consequences, that is the stronger track. One honest limit: we verified the wording of these sections as unamended only to 2002, because later amendment Acts could not be obtained in machine-readable form.

RICA, and the four conditions you cannot afford to miss

This is the block that decides whether the programme is lawful in South Africa, and it is criminal law rather than data protection law. RICA prohibits intentionally intercepting any communication, and intercept is defined widely enough to cover ordinary call recording: the aural or other acquisition of the contents of a communication so as to make them available to someone other than the sender or the intended recipient.

The cleanest route for recording the simulated call itself is section 4. A person who is a party to the communication may intercept it, unless the interception is for the purpose of committing an offence. There is no notification duty on the face of section 4 and no agreement needed from the other side. The caller, or the platform calling on the caller's behalf, is a party to the call. So for the call your own operator or system places, South Africa is a one party jurisdiction and the all party framing that applies elsewhere is simply the wrong analysis.

Monitoring your own telephone system is section 6, and section 6 is where programmes go wrong, because it carries four cumulative conditions rather than one. The interception must be effected by or with the consent of the system controller, which for a company means the chief executive or someone that officer has duly authorised. It must be for one of the listed purposes, of which investigating or detecting unauthorised use of the system is the relevant one. The telecommunication system must be provided for use wholly or partly in connection with the business, which is what puts an employee's own personal handset and personal number outside section 6 entirely. And the system controller must have made all reasonable efforts to inform in advance anyone who intends to use the system that communications transmitted by means of it may be intercepted.

Read that last condition carefully, because it is more workable than it first looks. What has to be said in advance is that communications may be intercepted. Not that a particular call will be, and not why. A standing policy-level notice that calls on company systems may be monitored and recorded satisfies the condition without announcing that a test is coming.

The reason to get this exactly right is that a miss compounds. Contravening section 6(2) is a standalone offence, and it simultaneously puts you outside the carve-out that protects you from the general unlawful interception offence. So one missing advance notice produces two offences, each carrying a fine of up to two million rand or ten years. The practical instruction is short: obtain the system controller's authorisation and put the advance notice in place in writing before the first call, and keep both.

Two things that are not the case. The Information Regulator has published no guidance note on call recording, workplace surveillance or employee monitoring at all, so the statute is genuinely all there is and quoting it beats paraphrasing it. And although you may read that RICA has been found unconstitutional, that litigation concerns the state surveillance chapters. The party and business exceptions above carry no amendment annotation and are not in doubt.

An AI voice, a live operator, and a rule scoped to marketing

POPIA section 69 is the provision people expect to bite, and it names the technology directly: it prohibits processing personal information for the purpose of direct marketing by any form of electronic communication, including automatic calling machines, which subsection (5) defines as a machine able to do automated calls without human intervention. So the definition is about how the call is placed, not about how the voice is produced.

The scope words settle it. Direct marketing is defined in the Act as approaching someone for the direct or indirect purpose of promoting or offering to supply goods or services, or requesting a donation. An employer-authorised test of its own workforce promotes nothing, offers nothing and asks for nothing. Section 69 is therefore not engaged, and it is important to be precise about why: the prohibition's own scope does not reach the activity. That is not a carve-out and not an exemption, and nothing about it relaxes any of the other obligations on this page.

The same answer comes back from the other two candidate rules. The Consumer Protection Act's right to restrict unwanted approaches is scoped to communications primarily for the purpose of direct marketing, on materially the same definition. The Electronic Communications and Transactions Act's unsolicited communications provision is scoped twice over, to commercial communications and to consumers. Neither reaches an employer testing its own staff.

Now the thing to be careful about, because it cuts the other way. Section 69 applies to any form of electronic communication used for direct marketing, and the Information Regulator's own guidance lists the telephone alongside automatic calling machines as examples. A human-dialled marketing call is inside section 69 too. So putting a live operator on the line does not move the section 69 line at all. It reduces exposure under other headings, and it is a live call rather than an automated one, but it is not a route past a rule.

What South Africa does not have is worth stating, because a reader arriving from our American page will look for it. There is no South African equivalent of the TCPA, no artificial or prerecorded voice rule outside the direct marketing frame, and no rule requiring disclosure that a voice is generated by AI. The absence is more useful to know than an invented equivalent would be.

Presenting a number, and who the rule actually binds

ICASA defines calling line identification as a facility permitting the transmission of accurate originating caller identification information, being the calling party's assigned number, and requires licensees to prohibit the transmission of an inaccurate one. Numbers are a national resource and are not owned either by the licensee they are allocated to or by the subscriber they are assigned to, and a licensee may not use numbers that have not been allocated to it.

Notice who that duty falls on. It is written as an obligation on the licensee, not as an offence against the caller. We looked for a South African statutory offence of caller identification spoofing and there is not one: the Cybercrimes Act offences are framed around computer systems and data rather than around presenting a telephone number. The regulator's mechanism against a misused number is barring it, and the regulator uses it: in June 2026 ICASA's Complaints and Compliance Committee fined an operator three million rand per contravention for using numbers not allocated to it, ordered it to cease, barred and withdrew the affected numbering resources and imposed two years of monthly compliance reporting.

So the practical rule is short. Present a number legitimately assigned to you by a South African licensee for the service in question, and do not present one that is not. A subscriber to whom a number has been legitimately assigned may enjoy its beneficial use freely and without hindrance, which is the authority for presenting it in the first place.

What the country matrix holds for South Africa

Number types:
Local, Mobile
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Five documents, and why nobody can waive them

South African onboarding asks for more than anywhere else we operate, and the reason is not that the carrier is cautious. Almost all of it is a criminal-law duty imposed on the carrier by RICA, and the carrier has no discretion at all.

Before a service provider enters into a contract with a company, RICA requires it to obtain the representative's full names, identity number and address, the business name and address and registration number, a certified photocopy of the representative's identification document, and a certified photocopy of the business letterhead, and then to verify each against the underlying document. For a mobile number, a provider may not activate a SIM at all until it has recorded the authorised representative's details and the company's name, address and registration number, verified by an identification document, by a registration document or founding statement or revenue service document, by an address document no older than three months, and by a letter of authority or affidavit establishing the representative's authority.

That last one is worth naming separately, because it is the fifth document and it is the one people forget. It is not the representative's identification; it is the instrument proving that this particular person may bind the company.

The enforcement is what removes the discretion. A provider that fails to comply with the contracting requirements commits an offence carrying a fine of up to five million rand, and one that fails to comply with the SIM activation requirements faces a fine of up to one hundred thousand rand for each day the failure continues. A per-day criminal fine is why there is no commercial route around any of it. The documents are not the carrier's policy. They are the carrier's criminal liability.

Two precision points, because our own description of this has not always been exact. RICA never names the companies commission: the statute asks for a registration number and accepts a registration document, a founding statement, a revenue service document or any other similar document, and the commission's certificate is simply how a South African company satisfies that. And the telecoms regulator imposes only one requirement of its own, which is that a geographic number be assigned only where the subscriber provides a business or postal address in the geographic area matching the number's first three digits. Not merely somewhere in the country: a Cape Town number needs a Cape Town area address. Mobile numbers carry no address condition in the numbering rules at all, and the regulator imposes no company registration or photo identification requirement on a subscriber anywhere in them.

Adversarial simulation, mandated, plus an offence nobody mentions

In financial services South Africa has the strongest requirement of any country in this tranche. Joint Standard 2 of 2024, made by the Financial Sector Conduct Authority and the Prudential Authority and effective from 1 June 2025, requires a financial institution to carry out regular scenario-based simulation exercises which must include, but are not limited to, an adversarial attack and defence simulation exercise, and to design those exercises using threat intelligence relevant to the institution's own environment so as to identify the threat actors most likely to pose a threat and the tactics, techniques and procedures most likely to be used. Alongside it sits a duty to run a comprehensive awareness training programme with refresher training at least annually.

Be precise about the limit of that. The Joint Standard does not use the words phishing, vishing or social engineering anywhere in its text. What it mandates is adversarial simulation designed from threat intelligence. For a South African financial institution, voice social engineering plainly sits inside that description, but the accurate sentence is the first one and not the second.

The overlay almost nobody covers is the Cybercrimes Act, and it deserves a paragraph because a simulation touches several of its offences. Unlawfully and intentionally accessing a computer system, intercepting data, interfering with data, or acquiring or using a password or access code for the purpose of doing any of those things are all offences carrying up to ten years. Every one of them is qualified by the word unlawfully, and the Act does not define it, so it carries its ordinary criminal law meaning and the authority of the person entitled to give it is what negates unlawfulness. For those offences the person entitled is the employer, as owner of the systems and the data, which means a written authorisation from the right officer, scoped to the systems in question, is what makes the conduct lawful. It is the same officer RICA requires, so make it one document.

The cyber fraud and cyber forgery offences need separate handling and we are not going to gloss them. They require an intention to defraud and actual or potential prejudice to another person, and the misrepresentation in a simulation is made to the employee, whose authorisation you do not have. A test conducted for an authorised assurance purpose lacks the intention to defraud, which is an element of the offence, and that is the argument. We found no South African decision, prosecution guideline or regulator statement applying the Act to authorised security testing, so it is a reading of an element rather than settled law. Scoping the exercise so that no real credential is captured and no real prejudice is possible is the control that matters, and it is worth designing for.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in SOUTH AFRICA. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. Staff have been told through policy that communications on company systems may be intercepted.

Verify or correct each proposition below against primary South African sources, and tell me what we must hold before the first call:

1. RICA s.4 permits a PARTY to intercept, with no notification duty on its face, unless the interception is for the purpose of committing an offence. Confirm this covers the call our own platform places.
2. ⚠⚠ RICA s.6 imposes FOUR CUMULATIVE conditions for business monitoring: system controller consent; a listed purpose; a system provided wholly or partly in connection with the business; and all reasonable efforts to inform users IN ADVANCE that communications may be intercepted. Confirm that contravening s.6(2) is a standalone offence AND removes the s.6 protection against the s.2 offence, so one miss is two offences at R2m or 10 years each.
3. Does a standing policy notice that calls MAY be intercepted satisfy s.6(2)(d), without announcing a particular test?
4. ⚠ POPIA s.11(4): once an employee objects on reasonable grounds under s.11(3), the responsible party «may no longer process» the information, with NO compelling-grounds override. Confirm the only escape is legislation providing for the processing.
5. Has s.18(4)(d) («compliance would prejudice a lawful purpose of the collection») ever been applied to security testing by any South African decision, guidance or enforcement notice? We assert it has not.
6. POPIA s.69 is scoped to direct marketing as defined in s.1, so an internal test is outside it; and a HUMAN-dialled marketing call is inside s.69 too, so a live operator changes nothing.
7. ⚠ The five clearance documents are the CARRIER'S RICA ss.39/40 criminal duty, not ICASA's. ICASA imposes exactly one requirement of its own: a business or postal address in the geographic area matching the number's first three digits, for GEOGRAPHIC numbers only. Confirm both halves.
8. Cybercrimes Act ss.2, 3, 5, 7 and 8 are each qualified by «unlawfully», undefined in the Act. Does written authority from the system owner negate it? And does an authorised assurance purpose defeat the intention-to-defraud element of s.8?
9. Joint Standard 2 of 2024 requires «adversarial attack and defence simulation exercise» but never uses the words phishing, vishing or social engineering. Confirm, and advise whether voice social engineering sits inside it for a financial institution.
10. LRA ss.78 to 86: a workplace forum exists only on a majority union's CCMA application above 100 employees, and disciplinary codes are JOINT DECISION-MAKING while work organisation is consultation. ⚠ We verified these sections as unamended only to 2002; check later amendment Acts.

Flag anything that has changed since September 2026.

Common questions

Can we record simulated calls in South Africa?
Yes. A party to a call may intercept it under RICA section 4, so recording your own simulated call is covered. Monitoring the wider system is section 6 instead, and that carries four cumulative conditions, including advance notice to users that communications may be intercepted. Miss one and you commit two offences.
What is the legal basis, and can an employee refuse?
The basis is legitimate interests under POPIA section 11(1)(f). An employee can object at any time on reasonable grounds relating to their situation, and section 11(4) then says processing must stop. There is no compelling grounds override of the kind European employers have, so plan for individual objections.
Why does South African onboarding need so many documents?
Because RICA imposes them on your carrier as a criminal duty, not as policy. Failure to comply with the SIM activation requirements carries a fine of up to one hundred thousand rand for every day it continues, so no carrier will waive any of it. Budget for the letter of authority too.
Does POPIA's automatic calling machine rule stop us?
No, because that rule is scoped to direct marketing, which the Act defines as promoting or offering goods or services or requesting a donation. A test of your own staff is none of those. Note this is about what the rule covers, and it relaxes nothing else in POPIA or RICA.

Elsewhere in the Middle East and Africa

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.