The Brazilian regulator, ANATEL, banned permanent roaming and, with Costa Rica, applies a stricter authorisation regime for the provision of IoT/M2M (internet of things, machine-to-machine) connectivity.
This is one of the key findings from Cullen International’s new analysis of the key regulatory issues for the provision of cross-border IoT connectivity in the Americas.
Most of the 11 countries surveyed do not regulate the use of extraterritorial numbering solutions, so that providers of cross-border connectivity do not have to rely on local profiles for each national market.
Similarly, most of the countries exempt the provision of IoT/M2M connectivity from licensing requirements, as long as providers do not enter into a direct contractual relationship with end users and do not own or operate local telecoms infrastructure for their service provision. However, most countries apply stricter authorisation regimes as soon as providers begin to offer consumer-facing IoT applications (such as smart cars) and enable access to the public internet through these applications.
Moreover, once providers start to offer services that fall under the authorisation regime, they must establish a local presence or announce a local representative.

Providers are not normally required to register SIM cards if connectivity is provided in a machine-to-machine context. However, these registration obligations apply if providers enable consumer-facing applications that allow end users to access the public internet via the underlying M2M subscription.
Cullen International’s research focuses on 11 countries, covering the following topics:
- permanent roaming regulations;
- restrictions on the use of extraterritorial numbering solutions;
- licensing and authorisation requirements for cross-border IoT connectivity and service providers;
- requirements for cross-border providers to establish a local presence or to appoint local representatives; and
- SIM card registration obligations specific to IoT applications.
For more information and to access the research, please click 'Access full content' - or 'Request access' if you are not a subscriber to our brand new IoT service.
Interested in other regions? Check these out:
more news
01 June 26
Privacy in the digital age
Our latest benchmark compares data protection laws across 14 jurisdictions. It covers recent legal updates, lawful bases for processing personal data, and extraterritorial applicability. It also examines privacy rules for location, biometric, and children’s data, as well as enforcement practices involving these data types and big tech groups.
01 June 26
Fewer European countries offer local loop unbundling over copper
29 May 26
How are EU member states transposing NIS2?
Our latest benchmark tracks the progress of the Directive on measures for a high common level of cybersecurity across the EU (NIS2) transposition in the 27 EU member states.