Voice phishing simulations in Argentina
Callstrike supplies Argentine phone numbers for voice phishing simulations, and Argentine law permits an authorised internal exercise against your own staff. Your company completes one regulatory approval in the console, and two provisions of the employment statute shape how the campaign is designed rather than whether it runs.
Phone numbers
Supplied by Callstrike
Local numbers in Argentina, after a one-time approval.
Running a simulation
Permitted
Subject to workforce notice and a scope you can justify by role.
Consent
Your evidence, not your permission
Nothing in Argentine law makes it a precondition of placing the call.
Getting a phone number in Argentina
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Argentina requires the holder of a number to be a verified local business, so numbers are not released on demand and there is no list to pick from yourself. Your administrator submits the company's details once through the regulatory clearance form in the console, and Callstrike assigns a dedicated Argentine local number to your workspace once it clears.
The address you give has to fall inside the geographic area covered by the number's prefix, and a post office box is not accepted where a local address is required. That is the one requirement that catches companies out, because a registered office in Buenos Aires does not evidence an address in the province you want the number for.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Argentina is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Commercial registry number | Commercial register |
| Business name | Commercial register |
| Business addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable where a local address is required. | Commercial register showing local address, Utility bill, Tax notice, Rent receipt, Title deed |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in Argentina?
The position in short, before your counsel reads the detail below.
Yes. No Argentine instrument prohibits an employer from testing its own workforce, and the national do-not-call statute puts the question beyond argument by stating its own object in its opening article: it protects telephone subscribers from abuses of contact, publicity, offer, sale and gift of unsolicited goods or services. An internal security exercise publicises nothing and sells nothing, so the register and its thirty-day screening duty do not reach your campaign at all.
Two provisions of the employment statute do apply, and they shape the design rather than prevent it. Your workforce has to know that controls of this kind take place, which is a duty owed to the worker and not to any authority. And the selection of who gets called has to be defensible: the statute speaks of automatic selection directed at the entirety of the personnel, and the labour authority's power is to verify that controls do not manifestly and discriminatorily affect dignity. Testing a help desk because it takes external calls is a role rationale. Selecting named individuals on suspicion is not.
One design decision belongs at the start rather than the end, and it is the one that matters most here. Argentine data protection law prohibits the collection of personal data by unfair or fraudulent means. A vishing simulation that measures whether an employee would have given up a credential, without ever capturing the credential, is not collecting by unfair means because it is not collecting the thing at all. Callstrike is configured that way by default.
What Argentina does not give you is a balancing test. Its data protection statute predates the European one it gets compared to, and its exceptions are a closed list of five with no legitimate interests entry, so the ground you record is the one about data deriving from the employment relationship and necessary for its development or performance. That is a narrower foundation than a balancing assessment, and it puts the weight on showing the exercise is necessary to the relationship rather than merely useful to you.
What your company needs to do
7 items, in the order you will need them.
- Record the ground you are relying onThere is no legitimate interests basis in Argentine law, so you rely on the employment relationship itself. Write down why the exercise is necessary to that relationship rather than merely useful to the business. A balancing assessment copied from a European programme does not transfer.
- Give your workforce notice before the first callThe content is prescribed: the purpose and who the recipients may be, the existence of the file and who is responsible for it, whether answering is obligatory or optional, the consequences of answering or refusing, and how staff exercise access, rectification and deletion rights.
- Scope the campaign by role, not by individualArgentina-specificYou may and should concentrate on the roles most exposed, and a help desk that takes external calls is a legitimate scope because the reason for choosing it is what the job involves. What the statute is aimed at is arbitrary singling-out. Record the risk rationale for the scope you choose, because the authority's power is to verify that controls do not manifestly and discriminatorily affect a worker's dignity.
- Keep the credential out of the systemMeasure the behaviour and discard what the pretext asked for. This is the single configuration choice that keeps the programme clear of the prohibition on collecting personal data by unfair or fraudulent means, because a thing that was never collected cannot have been collected unfairly.
- Control who can replay the recordingsArgentina-specificPublishing a private communication is a separate criminal offence in Argentina, carrying a fine where harm to a third party could follow. The risk here is not the recording, it is the debrief. Keep audio inside the team that needs it and anonymise anything that goes into awareness content.
- Present a number your own organisation holdsThe national numbering and signalling plans carry no caller identification rule, so there is no telecoms prohibition to point at. Ordinary fraud and impersonation law still applies, so do not display a number belonging to a bank or a public body.
- Register the database if the duty reaches youArgentina still operates a database registration procedure that most comparable regimes abolished years ago, and the data protection authority runs it as a live trámite. Check whether your existing registration covers the exercise before the campaign runs rather than afterwards.
The controls that do the work
How Callstrike is configured, and which provision in Argentina each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
This is the control that answers art 4.2, which prohibits collecting personal data by unfair or fraudulent means and is the provision that sits most squarely on a deception exercise. The call ends the moment an employee begins to give up a credential, so no personal data is acquired by the pretext. The provision is not engaged, because the collection it describes never happens. Read with art 4.1's requirement that data be adequate, pertinent and not excessive, it is what makes the Argentine position comfortable rather than merely arguable.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
LCT art 70 requires controls to safeguard the worker's dignity and to be practised with discretion, and art 72 gives the labour authority a power to verify exactly that. A call that ends in immediate education, from a second voice that breaks character on the spot, is a much harder thing to characterise as an affront to dignity than one that ends with a caught employee and no explanation until a report circulates weeks later.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
LCT art 71 owes notice to the worker, and Ley 25.326 prescribes what that notice has to contain. Neither asks the worker to agree, so this is not the basis you rely on. What it produces is the evidence that the notice was given and the record of the scope you attested to, both dated before the campaign ran rather than assembled afterwards when somebody asks.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Where the telephone route is unattractive, this is the fallback that still teaches. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, and a call a person initiates in their own browser is not a telephone call, so Ley 26.951 and the numbering plans have nothing to bite on. It means there is an Argentine answer even for a workforce you would rather not cold-call.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.