In early September 2026, Anatel presented "Anatel Protege" to telecom and internet providers. Teletime reported on 4 September that the proposed free service would let any citizen block the opening of new mobile lines under their CPF. The citizen would switch the block on or off through Gov.br, authenticated with facial biometrics. Before activating any line, operators would have to query the list of blocked CPFs through an API. The aim is "subscription fraud", where criminals use someone else's personal data to activate numbers later used in scams. The project is still under study at Anatel, and no launch date has been given.
That last point matters. This is a proposal, not a rule, so the useful question is what a good version looks like.
The strongest case for it
The case for Anatel Protege is strong. Brazil's identity numbers are widely leaked, and a CPF is the main key for opening a line. Today the defrauded person finds out only after the damage, when a number registered in their name is used for a scam. Anatel's consolidated service rules already recognize this. The General Regulation of Telecommunications Services (Resolução Anatel nº 777, published 30 April 2025) requires providers to keep user registries updated and to take "preventive measures against subscription fraud" (Art. 69, VIII). The consumer-rights regulation (Resolução nº 765, of 6 November 2023) contains a parallel duty in Art. 32-A. Those duties put the burden on operators, who cannot see whether the person at the counter owns the data they present. A lock held by the data subject moves the control to the one party who knows the answer.
There is also a working precedent. The Central Bank's BC Protege+ launched in December 2025, and the Bank said it passed 1 million activations on 20 February 2026, just over two months in. That is real voluntary uptake of an opt-in lock on a CPF. Anatel Protege borrows that design: free, reversible at any time, and checked by the institution before it acts.
Why this design beats mandates
Anatel has been adding mandatory friction at the point of sale. Trade press reports that its 2026 rules require facial biometrics, validated against the gov.br/Serpro database, for second chips and number portability. Earlier, from 28 August 2023, portability required an SMS confirmation with a six-hour window, after which the request is cancelled. Operators face fines of up to R$50 million per violation under the same regime, according to that report.
These mandates apply to every customer, whether or not they are at risk. A citizen who never wants a second line pays the same verification cost as one who does. An opt-in lock works the other way: people who face risk, or who simply want certainty, pay a small one-time cost, and everyone else is untouched. That is the proportionate version of fraud policy, and it fits a pro-innovation view. It cuts fraud without forcing every prepaid sale in every corner shop through a heavier identity check.
Where the design could go wrong
Four issues deserve attention before Anatel moves from study to rule.
- Biometric scope. A face match is needed to set the lock, since otherwise a fraudster could unlock it. But the operator's check needs only a yes/no flag on a CPF. The API should return that single bit and nothing else: no photo, no identity attributes, no log of why the query was made. A fraud lock that quietly became a new registry of who is trying to open lines would be a poor trade.
- Query logs. The operator queries the database before every activation. Anatel should state who holds those logs, for how long, and whether they can be used for anything beyond fraud checks.
- Fail-safe behavior. If the API is down, operators must not be left to choose between refusing legitimate customers and skipping the check. A clear rule is needed, with a short, auditable fallback.
- Recovery for victims. People who are already defrauded need a route to lift or contest a wrongly attached line, and to unlock after losing access to their Gov.br account.
The Gov.br dependency is itself a point to watch. Authentication that routes through one federal login concentrates risk: if Gov.br accounts are compromised, so is the lock. BC Protege+ already requires a higher-assurance Gov.br account, and Anatel should state the same assurance level and two-step requirement for the telecom lock.
What the evidence would need to show
The case for the tool will rest on numbers Anatel has not yet published. Useful measures would be activation rates, the share of blocked attempts that were confirmed fraud, the false-block rate for legitimate customers, and the change in complaints about unrecognized lines. Brazil's Central Bank and its institutions have accumulated that data for BC Protege+, and Anatel should publish equivalent metrics for any pilot. If the lock works, there is also a good case for relaxing blanket biometric mandates for customers who have used it, and the regulator should consider that tradeoff openly.
Bottom line
Anatel Protege points toward a better way to deal with identity fraud than adding steps at every counter. It gives the citizen a control, keeps the default open, and uses an API instead of a paper process. The risk lies in the details: data minimization, log retention, outage rules, and recourse. If Anatel writes those into the rule and publishes outcome data, the tool would deserve support. If it treats the lock as an excuse to widen biometric collection, it would not.