Voice phishing simulations in Mexico
Mexico replaced its data protection statute outright in March 2025 and dissolved the authority that used to enforce the old one, so a voice phishing simulation here is planned against a law barely a year old. Numbers are cleared once and then assigned to your workspace. The decision that shapes everything else is whether anything happens to an individual who fails, because that is what pulls in a workplace rulebook drafted jointly with your workers and published for anyone to read.
Phone numbers
Supplied by Callstrike
Local numbers in Mexico, after a one-time approval.
Running a simulation
Permitted, on the relationship
No balancing ground exists. The route is the obligations the employment relationship creates.
Consent
Tacit by default, so it is the notice
Agreement is tacit where the privacy notice reached the person and they did not object.
Getting a phone number in Mexico
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Mexican numbers are not released from open inventory, so your administrator clears the country once in the console and Callstrike then provisions a dedicated Mexican number against that clearance. The form is short. Your business name is typed in, and then two things are evidenced: that the name is yours, and that you have an address. Those are the two lines of the table below, and the tax status certificate does double duty because it is accepted for each.
That certificate is worth starting early even though nothing else here is slow. It is issued by the tax administration through its own portal, so the person who can produce it quickly usually sits in finance rather than in security. The address it evidences has to fall inside the locality or region covered by the number's own prefix and a post office box will not do, which means the prefix you want and the address you can prove are one decision rather than two.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Mexico is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Proof of business nameThe Constancia de Situación Fiscal (Tax Status Certificate) can be obtained through the SAT portal. | Constancia de situación fiscal |
| Proof of business addressMust be within locality or region covered by the phone number's prefix; a PO Box is not acceptable. | Constancia de situación fiscal, Utility bill, Government communication |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in Mexico?
The position in short, before your counsel reads the detail below.
Yes, and the first thing to get right is which statute you are reading. One decree published in March 2025 enacted an entirely new federal data protection law for the private sector, abrogated the 2010 statute it replaced and took effect the following day, and the same wave of reform dissolved the national institute that enforced it and moved its functions to a ministry. Any Mexican guidance built on the old article numbers is describing a repealed law, and this is the country in the portal where reading a stale source does the most damage.
On substance Mexico gives you no balancing ground. Processing needs the person's agreement except in a closed list of seven cases, and the one open to you is data needed to exercise a right or to comply with obligations arising from a legal relationship. Then comes the provision that inverts the intuition most readers arrive with: agreement is tacit as a general rule where the privacy notice has been made available and the person does not say otherwise. You are not chasing signatures in Mexico. You are getting the notice right, in its full and simplified forms, and a voice channel counts as a sound means, so decide in advance how the simplified notice reaches your workforce.
The heavier obligation is a labour one and it is triggered by consequences rather than by the exercise. Nothing makes the programme itself subject to joint drafting. But if you want a disciplinary consequence to rest on the internal work rulebook, everything that attaches to that instrument attaches to you: it is drawn up by a joint commission of worker and employer representatives, deposited with the federal conciliation and registration centre within eight days of signature, effective only from deposit, printed, distributed and posted at the workplace, and published in full for anyone to consult. A worker also has the right to be heard before a sanction is applied. So whatever you write there about a testing programme is a public document, and a programme that attaches no consequence to any individual is a much lighter proposition.
Two more provisions bear on design. There is a right to object to processing intended to evaluate, without human intervention, personal aspects including professional performance, reliability and behaviour, which is a reason to keep a human decision point between a result and anything that happens to a person. And processing personal data by deception, taking advantage of the error the person is in, is punishable by six months to five years, but only where it is done to obtain an undue profit. That element is what keeps an authorised internal exercise outside the offence, which is the reason to document the programme as assurance work before it runs rather than afterwards when somebody asks what it was for.
What your company needs to do
6 items, in the order you will need them.
- Check every article number against the 2025 statuteMexico-specificA Mexican memo written before March 2025 cites a law that no longer exists and an authority that no longer exists, and both look entirely normal on the page. If a supplier or an adviser hands you a Mexican analysis, the first question is which statute it is numbered against.
- Write the privacy notice in both forms before the first callMexico-specificThe contents are prescribed rather than left to judgement: who you are and where, what data and which of it is sensitive, the purposes with those needing agreement distinguished, how use can be limited, how access, rectification, cancellation and objection rights are exercised, and how changes will be communicated. Where data is collected by a sound means the simplified notice is what does the work, so decide the route it travels.
- Decide now whether anything happens to an individual who failsMexico-specificThis is the Mexican decision. Consequences resting on the internal work rulebook bring the joint commission, the deposit, the posting, the publication and the right to be heard with them. A programme that reports at team level and attaches nothing to a named person does not go near any of it.
- Keep a person between the result and the consequenceThe objection right is aimed at evaluation carried out without human intervention, and a programme that automatically scores named employees on how they handled a call is exactly what it describes. It is a right the individual exercises rather than a prohibition on you, and a human decision point answers it cheaply.
- Record the relationship route, not a balancing assessmentThere is no legitimate interests entry in the closed list, so an assessment imported from a European programme is answering a question Mexican law does not ask. Write down instead why the exercise is necessary to obligations arising from the employment relationship.
- Take the caller identity question to a Mexican carrierWe could not read the fundamental numbering plan or the successor regulator's current guidance, and we would rather say so than tell you Mexico has no rule. Present a number your own organisation holds and can be reached on, and settle the question with the carrier that will have to carry the traffic before a campaign rather than after one.
The controls that do the work
How Callstrike is configured, and which provision in Mexico each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
The provision this sits closest to is the criminal one on processing personal data by deception. Be precise about the work each thing does: what keeps an authorised internal exercise outside that offence is its undue profit element, which is a fact about your purpose rather than about your call design. What this control does is remove the object. The call ends the moment an employee starts to give up a credential, so the pretext obtains no personal data at all, and it is also the cleanest answer to the statute's minimisation duty, since the shortest privacy notice to write is the one for data you never collect.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
Mexico's heavy procedural route exists for consequences, so a programme that ends in vishing training rather than in a sanction stays clear of it by design. A second voice breaks character as the call ends and explains what just happened, and a follow-up email repeats it in writing. That is an awareness exercise on its face, and it is a very different thing from a result that arrives as a disciplinary matter under an instrument the whole workforce can read.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Mexican agreement is tacit where the privacy notice has been made available, which sounds easy until somebody asks you to prove availability. This is what produces that proof: a dated, per-employee record that the notice actually reached a person before the campaign ran, rather than a claim that it was published somewhere. It is not the ground you are processing on, and this page does not present it as one.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Two Mexican questions are open rather than answered: whether any synthetic voice disclosure duty is in force, and what the numbering plan we could not read actually says. A web call the learner starts themselves after working through the module does not wait on either, because you are not originating a telephone call to anybody. Callstrike's vishing simulator delivers the same deepfake voice that way, which means there is a Mexican answer even while those two questions stay open.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.