Brazil
Latin America
Brazil regulates telecom cybersecurity primarily through Anatel Resolution 767/2020. The LGPD (data-protection law) applies to subscriber data. Together they set the operator security baseline.
Regulator: Anatel + ANPD
Primary frameworks: Anatel Res. 767/2020, LGPD, Anatel 5G rules, Marco Civil da Internet
Resolution 767 on cybersecurity
The resolution requires operators to have a cybersecurity policy, incident-response capability, risk assessment, and reporting of significant incidents to Anatel. Signaling security falls under general risk-management obligations.
5G auction conditions
Brazil's 5G auction embedded security commitments including a Standalone-Only Private Network for federal-government use and cybersecurity-conditioned commercial spectrum.
LGPD interplay
Subscriber data protection sits with ANPD under LGPD. Signaling-security incidents that expose subscriber data trigger LGPD notification alongside Anatel reporting.
Key takeaways
- Res. 767 is principles-based; operators translate it into internal control specifications.
- The 5G Private Network requirement created a unique parallel-network security scope.
- Dual reporting to Anatel and ANPD requires coordinated incident playbooks.