Callstrike
Compliance

Voice phishing simulations in Argentina

Phone numbers in ArgentinaProvisioned by Callstrike after approval

Callstrike supplies Argentine phone numbers for voice phishing simulations, and Argentine law permits an authorised internal exercise against your own staff. Your company completes one regulatory approval in the console, and two provisions of the employment statute shape how the campaign is designed rather than whether it runs.

Phone numbers

Supplied by Callstrike

Local numbers in Argentina, after a one-time approval.

Running a simulation

Permitted

Subject to workforce notice and a scope you can justify by role.

Consent

Your evidence, not your permission

Nothing in Argentine law makes it a precondition of placing the call.

Getting a phone number in Argentina

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Argentina requires the holder of a number to be a verified local business, so numbers are not released on demand and there is no list to pick from yourself. Your administrator submits the company's details once through the regulatory clearance form in the console, and Callstrike assigns a dedicated Argentine local number to your workspace once it clears.

The address you give has to fall inside the geographic area covered by the number's prefix, and a post office box is not accepted where a local address is required. That is the one requirement that catches companies out, because a registered office in Buenos Aires does not evidence an address in the province you want the number for.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Argentina is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Commercial registry numberCommercial register
Business nameCommercial register
Business addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable where a local address is required.Commercial register showing local address, Utility bill, Tax notice, Rent receipt, Title deed

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Argentina?

The position in short, before your counsel reads the detail below.

Yes. No Argentine instrument prohibits an employer from testing its own workforce, and the national do-not-call statute puts the question beyond argument by stating its own object in its opening article: it protects telephone subscribers from abuses of contact, publicity, offer, sale and gift of unsolicited goods or services. An internal security exercise publicises nothing and sells nothing, so the register and its thirty-day screening duty do not reach your campaign at all.

Two provisions of the employment statute do apply, and they shape the design rather than prevent it. Your workforce has to know that controls of this kind take place, which is a duty owed to the worker and not to any authority. And the selection of who gets called has to be defensible: the statute speaks of automatic selection directed at the entirety of the personnel, and the labour authority's power is to verify that controls do not manifestly and discriminatorily affect dignity. Testing a help desk because it takes external calls is a role rationale. Selecting named individuals on suspicion is not.

One design decision belongs at the start rather than the end, and it is the one that matters most here. Argentine data protection law prohibits the collection of personal data by unfair or fraudulent means. A vishing simulation that measures whether an employee would have given up a credential, without ever capturing the credential, is not collecting by unfair means because it is not collecting the thing at all. Callstrike is configured that way by default.

What Argentina does not give you is a balancing test. Its data protection statute predates the European one it gets compared to, and its exceptions are a closed list of five with no legitimate interests entry, so the ground you record is the one about data deriving from the employment relationship and necessary for its development or performance. That is a narrower foundation than a balancing assessment, and it puts the weight on showing the exercise is necessary to the relationship rather than merely useful to you.

What your company needs to do

7 items, in the order you will need them.

  • Record the ground you are relying onThere is no legitimate interests basis in Argentine law, so you rely on the employment relationship itself. Write down why the exercise is necessary to that relationship rather than merely useful to the business. A balancing assessment copied from a European programme does not transfer.
  • Give your workforce notice before the first callThe content is prescribed: the purpose and who the recipients may be, the existence of the file and who is responsible for it, whether answering is obligatory or optional, the consequences of answering or refusing, and how staff exercise access, rectification and deletion rights.
  • Scope the campaign by role, not by individualArgentina-specificYou may and should concentrate on the roles most exposed, and a help desk that takes external calls is a legitimate scope because the reason for choosing it is what the job involves. What the statute is aimed at is arbitrary singling-out. Record the risk rationale for the scope you choose, because the authority's power is to verify that controls do not manifestly and discriminatorily affect a worker's dignity.
  • Keep the credential out of the systemMeasure the behaviour and discard what the pretext asked for. This is the single configuration choice that keeps the programme clear of the prohibition on collecting personal data by unfair or fraudulent means, because a thing that was never collected cannot have been collected unfairly.
  • Control who can replay the recordingsArgentina-specificPublishing a private communication is a separate criminal offence in Argentina, carrying a fine where harm to a third party could follow. The risk here is not the recording, it is the debrief. Keep audio inside the team that needs it and anonymise anything that goes into awareness content.
  • Present a number your own organisation holdsThe national numbering and signalling plans carry no caller identification rule, so there is no telecoms prohibition to point at. Ordinary fraud and impersonation law still applies, so do not display a number belonging to a bank or a public body.
  • Register the database if the duty reaches youArgentina still operates a database registration procedure that most comparable regimes abolished years ago, and the data protection authority runs it as a live trámite. Check whether your existing registration covers the exercise before the campaign runs rather than afterwards.

The controls that do the work

How Callstrike is configured, and which provision in Argentina each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

This is the control that answers art 4.2, which prohibits collecting personal data by unfair or fraudulent means and is the provision that sits most squarely on a deception exercise. The call ends the moment an employee begins to give up a credential, so no personal data is acquired by the pretext. The provision is not engaged, because the collection it describes never happens. Read with art 4.1's requirement that data be adequate, pertinent and not excessive, it is what makes the Argentine position comfortable rather than merely arguable.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

LCT art 70 requires controls to safeguard the worker's dignity and to be practised with discretion, and art 72 gives the labour authority a power to verify exactly that. A call that ends in immediate education, from a second voice that breaks character on the spot, is a much harder thing to characterise as an affront to dignity than one that ends with a caught employee and no explanation until a report circulates weeks later.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

LCT art 71 owes notice to the worker, and Ley 25.326 prescribes what that notice has to contain. Neither asks the worker to agree, so this is not the basis you rely on. What it produces is the evidence that the notice was given and the record of the scope you attested to, both dated before the campaign ran rather than assembled afterwards when somebody asks.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

Where the telephone route is unattractive, this is the fallback that still teaches. Callstrike's vishing simulator can deliver the same deepfake voice through a web call the learner starts themselves after working through the module, and a call a person initiates in their own browser is not a telephone call, so Ley 26.951 and the numbering plans have nothing to bite on. It means there is an Argentine answer even for a workforce you would rather not cold-call.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

A closed list of five, and a rule about unfair means

The statute in force is the one enacted in 2000, and that needs saying because a replacement is frequently described as though it had happened. The data protection authority's own page describes the modernisation as a bill going through a participatory drafting process. It is a bill. The articles relied on below carry no amendment note at all in the official consolidated text.

Processing personal data is unlawful where the data subject has not given free, express and informed agreement, recorded in writing or by an equivalent means. Agreement is not necessary in five cases: data from unrestricted public sources; data collected for the exercise of State functions or under a legal obligation; lists confined to name, identity or tax number, occupation, date of birth and address; data deriving from a contractual, scientific or professional relationship of the data subject and necessary for its development or performance; and certain financial institution operations.

To say it plainly, because the answer differs from most of this portal: Argentine data protection law contains no legitimate interests basis. The phrase legitimate interest appears in the statute, in the article on assignment, but as a qualifier on the purposes of an assignment that still requires the data subject's prior agreement. It is not a standalone ground and reaching for it as one would be importing a structure the statute does not contain. Argentina holds a European adequacy decision, which is a finding about transfers into the country and imports nothing into the closed list either.

So an employer works from the fourth exception, resting on the employment relationship and on necessity for its development or performance. That is a narrower foundation than a balancing test, and it puts the weight on being able to show that the exercise is necessary to the relationship rather than merely useful to the employer.

The provision that most directly touches a deception exercise is not about the ground at all, and it is the one that gets missed. Data must be accurate, adequate, pertinent and not excessive in relation to the scope and purpose for which it was obtained. And collection may not be carried out by unfair or fraudulent means, or in a manner contrary to the provisions of the statute. That is a direct textual constraint on how the call acquires whatever it acquires, and the answer to it is the same design answer that works elsewhere: an exercise that measures whether an employee would have complied, without collecting the credential or the data itself, is not collecting by unfair means because it is not collecting the thing at all.

Two more duties complete the file. Collection carries a prescribed notice: the purpose and who the recipients may be, the existence of the file or database and the identity and address of the person responsible, whether answering is obligatory or optional, the consequences of providing the data or refusing, and the ability to exercise access, rectification and deletion rights. And Argentina still operates a database registration duty, run by the authority as a live procedure, which most comparable regimes abolished years ago. Sanctions run from a warning through suspension and fines to closure or cancellation of the file.

A reading rather than a carve-out, and publication is its own offence

Argentina is the one country in its region that does not answer the participant question in enacted text, and we would rather tell you that than borrow a neighbour's answer.

The criminal code punishes, with fifteen days to six months of imprisonment, a person who improperly opens or accesses an electronic communication, letter, sealed packet or telegraphic, telephone or other dispatch that is not directed to them, or who improperly takes such a communication, or who improperly suppresses or diverts one not directed to them. The same penalty applies to a person who improperly intercepts or captures electronic communications or telecommunications originating from any private or restricted-access system. The penalty rises to one month to one year where the person also communicates the content to another or publishes it.

The reading that a party to the call is outside all of that rests on the words rather than on authority. The first limb is confined to a communication not directed to the actor, and a call the operator is on is directed to them. The second limb requires the conduct to be improper, and interception in its ordinary sense presupposes a third party. We found no Argentine case law confirming that reading and we are not going to present it as settled. It is a textual argument, it is a reasonable one, and it is weaker than the statutory answers available in Brazil and Mexico.

The provision to design around, though, is a different one, and it survives regardless of how the first question resolves. A person in possession of a communication not intended for publication who improperly causes it to be published commits a separate offence carrying a fine, where the act causes or could cause harm to third parties, with an exemption for someone who acted with the unequivocal purpose of protecting a public interest. So the Argentine risk is not the recording. It is the debrief. Replaying a named employee's call to an audience, circulating the audio, or using it in an awareness session is the conduct the statute describes, and the mitigation is to anonymise, to aggregate, and to keep the audio inside the small group that needs it.

One further provision is worth a line for a programme that touches personal data systems: knowingly and unlawfully accessing a personal database, or doing so in breach of confidentiality and data security systems, carries one month to two years.

The do-not-call statute says what it is for, and it is not this

Argentina's do-not-call regime is scoped by purpose in its own opening article, which makes the answer short.

The statute states its object as protecting holders and authorised users of telephone services from abuses of the procedure of contact, publicity, offer, sale and gift of unsolicited goods or services. Its operative prohibition is addressed to those who publicise, offer, sell or give away goods or services using telephone services as the means of contact: they may not address anyone registered, and they must consult the registrations and removals every thirty days.

An employer running an internal exercise against its own staff publicises nothing, offers nothing, sells nothing and gives nothing away. It is outside the object of the statute and outside the class the prohibition addresses, so the register and the thirty-day screening duty do not reach it. Nothing in the statute turns on whether a person or a system is speaking, and its exceptions, which cover public interest campaigns, emergency calls, electoral campaigns, calls by those in a live contractual relationship confined to its object, and calls the registrant has expressly permitted, are not needed to reach that conclusion.

One administrative point that catches people reading the original text: the authority named in the statute as enacted no longer runs the register. It was substituted in 2017 and the register is now operated by the access to public information agency, which is also the data protection authority. So the same body sits behind both halves of this page.

On synthetic voice we assert nothing in either direction. We did not establish whether any Argentine instrument requires a caller to disclose that a voice is generated, because the official legislative search would not accept a usable query and we would not report a negative we had not tested. Treat it as an open question. What is not open is the data protection side: a synthetic voice does not change the ground, the notice, or the rule against collection by unfair means, all of which apply to the exercise however it is delivered.

The plans where the rule should live do not contain one

Argentina's answer on caller identity is a negative, and it is worth being precise about how wide a negative it is.

We read the national fundamental numbering plan in the form the communications regulator serves it today. It contains no caller identification provision and no anti-spoofing provision. Every occurrence of the word for the calling party in it belongs to the calling-party-pays dialling modality and its prefix, and the single occurrence of identification is about the long distance operator code structure. The rest is dialling procedure. We also read the national fundamental signalling plan in its current form, which deals with signalling point codes and says nothing about calling line identification either.

Those two are where such a rule would most naturally sit, and neither has one. What we could not do is confirm that no separate regulator resolution exists on the subject: the regulator's numbering pages returned its own not-found message throughout, and its regulations index exposes only a handful of topical links, none on caller identification. So the negative is confined to the two plans we actually read, and we are not extending it into a claim that Argentina has no such rule anywhere.

The practical consequence is unchanged by that uncertainty. In the absence of a sourced permission, presenting a number your own organisation holds and can be reached on is the position that needs no argument, and it is what an Argentine carrier will expect in any event. Presenting a number belonging to a real third party, particularly a bank or a public body, raises ordinary fraud and impersonation questions that have nothing to do with telecoms regulation and do not depend on the plans.

This is also the section where the labour rule described further down does more work than the telecoms rules do. A control system applied to the whole workforce by automatic selection is a different campaign shape from one aimed at a chosen list, and the number you display is a smaller design question than who you call.

What the country matrix holds for Argentina

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Tell the worker, test everybody, and file nothing

The Argentine employment file is short, and the most common description of it is fifty years out of date. We will give the correction first and then the rule.

The original 1974 statute did contain an approval duty. Control systems in all cases had to have the approval of the labour authority, which was to consult the trade association that signed the collective agreement governing the employment relationship. That article did not survive the 1976 consolidated text and there is no equivalent of it in the law in force. Any source describing an Argentine filing or approval duty for a monitoring system is reading a repealed provision.

What is in force is three articles and they say something different. Personal control systems intended to protect the employer's property must always safeguard the worker's dignity, must be practised with discretion, and are to be carried out by means of automatic selection directed at the entirety of the personnel. The controls referred to, and those relating to the worker's activity, must be known to the worker. And the authority of application is empowered to verify that the control systems used do not manifestly and discriminatorily affect the worker's dignity.

So notice runs to the worker, not to the authority, and the authority has an inspection power rather than a permission to grant. The article about knowledge was substituted in 2016 and its current wording is unambiguous on that point.

The requirement about automatic selection directed at the entirety of the personnel is the sharpest practical constraint on this page and it has no counterpart elsewhere in this portal. Read it with two qualifiers that summaries of it usually lose. The article is scoped to control systems intended to protect the employer's property, so whether it reaches a security awareness exercise at all is arguable rather than settled. And the authority's verification power is framed against controls that manifestly and discriminatorily affect dignity, which is the standard a scope has to survive. What the provision is aimed at is arbitrary singling-out, not risk-based coverage: concentrating on a team because its job involves taking external calls is a role rationale, while selecting named individuals because somebody suspects them is not. The workable Argentine shape is a scope defined by role with the sample drawn automatically inside it, and the risk rationale recorded when the campaign is designed rather than reconstructed afterwards.

Where discipline is in view, the general disciplinary article permits measures proportionate to the demonstrated failings, and gives the worker thirty running days from notification of the measure to challenge it. That window is a reason to record the evidence from an exercise carefully and to keep the link between the call and any consequence documented.

The Argentine file, then: the notice required at collection, given to workers before the programme runs and as part of how it is known to them; a record of the employment relationship route rather than a balancing assessment that has no basis in the statute; the necessity and non-excessiveness analysis, written around what the exercise deliberately does not collect; the database registration where it applies; and a sampling design that is automatic and workforce-wide.

The only regulator anywhere here that says the word, and it says teach it

The Argentine central bank is the one financial regulator across this region's pages that uses the word for this attack in a binding norm, and what it requires is not what a vendor would like it to require.

Its communication on minimum requirements for managing technology and information security risk obliges institutions to have an annual, measurable and verifiable information security awareness and training programme, whose contents address all internal and external needs in the use, knowledge, prevention and reporting of incidents, escalation and responsibility for the electronic channels they operate. Annual, measurable and verifiable is unusually concrete for an awareness obligation, and it is the part that makes a Argentine institution ask how the programme is evidenced.

Then the content requirement, which names the attack. The contents of the awareness and training programme must include techniques for detecting and preventing the appropriation of personal data and credentials by attacks of the social engineering, phishing and vishing types and others of similar characteristics. Voice phishing is named in a supervisory norm, which happens nowhere else in this cluster.

But the reading has to be exact, and here the term count is the finding rather than colour. The word for simulation occurs zero times in the seventy-six page document. The obligation is that the attack be taught, not that it be staged. The only testing language in the instrument sits in the continuity section and refers to a programme of exercises and testing aligned with those carried out in cyber incident management, which is about response rather than about staff.

So the honest statement for an Argentine bank is that a vishing exercise is an unusually good way to make the programme measurable and verifiable, and to evidence that the named content landed, and that no Argentine regime examined mandates running one. That is a better argument than a false claim of obligation, and it survives contact with a supervisor.

Outside financial services we found no Argentine sector instrument bearing on this activity, and we did not read the data protection authority's own security measures resolution, whose page would not load. The statutory security duty in the data protection law applies regardless: the person responsible must adopt the technical and organisational measures necessary to guarantee the security and confidentiality of personal data.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in ARGENTINA. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance and the programme is covered by our security testing policy.

Verify or correct each proposition below against primary Argentine sources, and tell me specifically what our company must document before the first call:

1. Ley 25.326 art 5.2 is a closed list of five exceptions containing no legitimate-interests ground, and art 5.2(d) is the route open to an employer.
2. Art 4.2's prohibition on collection by unfair or fraudulent means is not engaged where the exercise never collects the credential.
3. LCT art 70 is scoped to controls intended to protect the employer's property. Assess whether it reaches an awareness exercise at all, and whether a risk-based scope limited to customer-facing roles is consistent with art 72's "manifestly and discriminatorily" standard.
4. LCT art 71 owes notice to the worker; art 72 confers verification only; no filing or approval duty survives the t.o. 1976.
5. A participant may lawfully record (CP art 153), but CP art 155 makes publishing the recording a separate offence.
6. Ley 26.951 is purpose-scoped and does not reach an internal exercise.
7. The art 21 database registration duty is still operated by the AAIP as a live procedure, and whether our existing registration covers this.

Flag anything that has changed since September 2026, and identify any provincial or collective-agreement obligation this analysis omits.

Common questions

Do we have to notify the Argentine labour authority?
No. That duty was in the 1974 statute and did not survive the 1976 consolidated text. The law in force requires the controls to be known to the worker, and gives the authority only a power to verify that control systems do not manifestly and discriminatorily affect a worker's dignity.
Can we choose which employees get tested in Argentina?
By role, yes; by individual, no. The labour statute wants automatic selection across the personnel and the authority verifies that controls do not manifestly and discriminatorily affect dignity. Testing a help desk because it takes external calls is a role rationale. Record why you scoped it that way.
Is there a legitimate interests ground in Argentine law?
No. The statute predates the European one it gets compared to, and its exceptions are a closed list of five with no balancing entry. An employer works from the exception for data deriving from the employment relationship and necessary for its development or performance.
Does the central bank require vishing simulations?
It requires them to be taught, not staged. The awareness and training programme must be annual, measurable and verifiable, and its contents must cover social engineering, phishing and vishing by name. The word for simulation appears nowhere in the seventy-six page document.

Elsewhere in the Americas

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.