Voice phishing simulations in South Africa
In South Africa the governing instrument for a voice phishing simulation is criminal law rather than data protection law. The exercise is lawful, but the conditions that make monitoring your own telephone system lawful are cumulative, and one missing advance notice produces two offences at once, each carrying up to ten years. Underneath sits an objection right stronger than Europe's, under which one employee can end their own inclusion in the programme.
Phone numbers
Supplied by Callstrike
Local and mobile numbers in South Africa, after a one-time approval.
Running a simulation
Permitted on four conditions
The business-monitoring conditions are cumulative, and one miss is two offences.
Consent
Not the ground, and an objection ends it
A reasoned objection stops processing outright, with no override of the European kind.
Getting a phone number in South Africa
One approval per country, completed in the console.
Self-provisioned after approval
Your company files its regulatory details once for this country. Once that is approved, your team provisions numbers directly from available inventory. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
South African onboarding asks for more than anywhere else in this portal, and the reason is not that the carrier is being cautious. Almost all of it is a criminal-law duty imposed on the carrier, which has no discretion to waive any of it: failing the contracting requirements is an offence at up to five million rand, and failing the activation requirements carries up to a hundred thousand rand for every day the failure continues. A per-day criminal fine is why there is no commercial route around a single line of the table below.
What that table asks for is a company registration document or a certified letterhead carrying the registration number, a government-issued photo identity document for your authorised representative, and proof of the business address, which will take a bank statement, a municipal rates or tax invoice, a recent telephone account statement or a new motor vehicle licence. The address is the line that catches companies out, because for a geographic number it has to sit inside the area that number's own prefix covers rather than merely somewhere in the country, and a post office box is not accepted. If you go on to activate a mobile number, the carrier additionally has to hold a letter of authority or affidavit establishing that your representative may bind the company, and that is the document people forget to budget for.
On what the person sees, present a number legitimately assigned to you and nothing else. The regulator defines calling line identification as the transmission of the calling party's assigned number and requires licensees to prohibit transmitting an inaccurate one, and although that duty is written as an obligation on the licensee rather than as an offence against a caller, the enforcement is real: in June 2026 the regulator fined an operator three million rand per contravention for using numbers not allocated to it, barred and withdrew the affected resources and imposed two years of monthly compliance reporting. A subscriber to whom a number has been legitimately assigned may enjoy its beneficial use freely, which is the authority for presenting it.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03Search the inventory and rent your numberYour team
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Proof of business name | Official CIPC issued document showing business name, Certified business letterhead |
| Proof of business registrationDocument must include CIPC issued Business Registration Number | Official CIPC issued document showing business name, Certified business letterhead |
| Proof of business addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable. | Bank statement, Municipal rates or tax invoice, Recent telephone account statement, New motor vehicle license |
| Proof of authorized representative name | Government-issued photo ID |
| Proof of identity document number | Government-issued photo ID |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in South Africa?
The position in short, before your counsel reads the detail below.
Yes, and the block that decides it is criminal law rather than data protection law. The interception statute prohibits intentionally intercepting any communication, and intercept is defined widely enough to cover ordinary call recording. The clean route for the simulated call itself is the party provision: a person who is a party to the communication may intercept it, unless the interception is for the purpose of committing an offence. There is no notification duty on the face of that section and nothing needed from the other side, and the platform calling on your behalf is a party to the call. For the call your own system places, South Africa is a one-party jurisdiction and the all-party framing that applies elsewhere is simply the wrong analysis.
Monitoring your own telephone system is a different section, and it is where programmes go wrong, because it carries four cumulative conditions rather than one. The interception must be effected by or with the consent of the system controller, which for a company means the chief executive or someone that officer has duly authorised. It must be for one of the listed purposes, of which investigating or detecting unauthorised use of the system is the relevant one. The system must be provided for use wholly or partly in connection with the business, which is what puts an employee's own personal handset outside the section entirely. And the system controller must have made all reasonable efforts to inform in advance anyone intending to use the system that communications transmitted by means of it may be intercepted.
That last condition is more workable than it first looks, and the wording is why. What has to be said in advance is that communications may be intercepted. Not that a particular call will be, and not why. A standing policy-level notice that calls on company systems may be monitored and recorded satisfies it without announcing that a test is coming. The reason to get it exactly right is that a miss compounds: contravening the business-monitoring section is a standalone offence and it simultaneously removes the protection that section gives against the general unlawful interception offence, so one missing notice produces two, each carrying a fine of up to two million rand or ten years.
The data protection layer is where the commercially significant surprise sits. The ground for an authorised internal test is processing necessary for pursuing your own legitimate interests, and that provision carries no balancing clause in its own words; the balance enters through the objection right instead. An employee may object at any time on reasonable grounds relating to their particular situation, and the statute then says you may no longer process their personal information. Flat, with no compelling-grounds override of the kind European employers have and no escape on the face of the provision except where legislation provides for the processing. Build the programme knowing that one reasoned objection ends that person's inclusion in it. The marketing rule, by contrast, does not reach you at all, because its own scope is confined to promoting or offering goods or services or requesting a donation. Be precise about that reason: the prohibition simply does not describe the activity, and nothing about it relaxes anything else on this page. Note too that a human-dialled marketing call is inside that rule as well, so putting a live operator on the line moves nothing here.
What your company needs to do
7 items, in the order you will need them.
- Put the standing notice in place before the first call, and keep itSouth Africa-specificAll reasonable efforts to inform, in advance, anyone intending to use the system that communications transmitted by means of it may be intercepted. A policy-level notice does it; a notice written after the campaign does not. This is the single condition whose absence turns one mistake into two offences, so treat it as a gate on launching rather than as a document to tidy up afterwards.
- Get the system controller's authorisation, and make it one documentSouth Africa-specificThe interception statute wants the chief executive or someone that officer has duly authorised. The cybercrime offences are each qualified by the word unlawfully, and what negates unlawfulness is the authority of the person entitled to give it, which is the same officer. One written authorisation, scoped to the systems in question, does both jobs.
- Plan for individual objections rather than treating them as edge casesSouth Africa-specificThe objection right has no override, so a single employee's reasoned objection ends their inclusion. Decide in advance how the programme handles that: how an objection is received, who assesses whether the grounds relate to that person's particular situation, and how the target list is amended without the exclusion itself becoming visible to their colleagues.
- Keep personal handsets out of scopeSouth Africa-specificThe business-monitoring section applies to a system provided for use wholly or partly in connection with the business, which is exactly what an employee's own personal phone and personal number are not. If your target list includes personal numbers, that part of the campaign is outside the section you were relying on and needs its own analysis.
- Run the impact assessment, because nothing has to trigger itSouth Africa-specificThe obligation is in the Regulations rather than the Act, and it differs from Europe's in two ways worth planning around: there is no risk threshold, so it applies regardless, and no content, form or methodology is prescribed at all. It is a real duty with no prescribed shape, which means the shape is your decision and should be recorded as one.
- Decide whether failing carries disciplinary consequences before you buyWhere a workplace forum exists, changes in the organisation of work are consultation and you may implement after exhausting the procedure, but disciplinary codes are joint decision-making, where consensus is required and failure to reach it goes to arbitration. A forum exists only where a majority union has applied at more than a hundred employees, so in most private workplaces there is no counterparty at all.
- Scope so that no real credential is captured and no real prejudice is possibleThe cyber fraud and forgery offences require an intention to defraud and actual or potential prejudice, and an authorised assurance purpose lacks the intention, which is an element rather than a defence. No South African decision or prosecution guideline has applied the Act to authorised security testing, so that is a reading of an element. Designing out the prejudice is the control that makes the reading safe to rely on.
The controls that do the work
How Callstrike is configured, and which provision in South Africa each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
The sourced position below asks for exactly this control by name, and the reason is the cybercrime statute rather than the privacy one. Acquiring or using a password or access code for the purpose of unlawfully accessing a system is an offence carrying up to ten years, and cyber fraud requires an intention to defraud together with actual or potential prejudice. The call ends the instant an employee begins to give up a credential, so nothing the pretext asked for is ever acquired and no real prejudice becomes possible. Both offences are built around a thing that does not happen, which is a stronger position than arguing about intention after the fact.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
Two South African features make how the exercise ends a commercial question rather than a courtesy. The first condition for lawful processing requires you not to infringe privacy in an excessive way, and the objection right lets any employee stop their own inclusion for reasons relating to their situation. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is both the answer to excessiveness and the difference between a programme people accept and one they opt out of individually.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Agreement is the wrong ground here for the reason it is wrong everywhere: it cannot be freely given by someone who reports to you, and asking destroys the test. What this produces is the two notices South Africa actually demands, dated and evidenced. The privacy statute wants people made aware of the purpose before information is collected. The interception statute wants all reasonable efforts to inform system users in advance that communications may be intercepted, and that is the notice whose absence produces two offences, so a signed and timestamped record of it is worth more here than anywhere else in this portal.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
The South African friction is the onboarding rather than the law, and this route has none of it. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, so there is no service-provider contract to enter, no five documents to certify and no number to have assigned. The business-monitoring conditions are written about a telecommunication system provided in connection with the business, and a session a learner opens in their own browser is not one. The privacy statute still governs whatever either route records, and South Africa imposes no synthetic-voice disclosure duty for the module to satisfy.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.