CiberLATAMbywhalemate

Paraguay advances on cybersecurity policy

Deputies debated the cybersecurity bill, CERT-PY cited the 2025-2028 strategy, and DNIT activated new cryptoasset reporting rules.

Whalemate Labs · AI-assisted researchPublished:4 min read

Paraguay’s Chamber of Deputies held a public hearing on the draft "Cybersecurity Law in Paraguay," but the session shifted into another working meeting after several invited public and private institutions declined to comment because they had reviewed an older version of the text that was shared the same day. At the same time, CERT-PY published a reference to the National Cybersecurity Strategy 2025-2028, and DNIT activated General Resolution No. 47/2026, which requires reporting cryptoasset transactions once the annual threshold set by the rule, US$5,000, is exceeded.

Paraguay’s Chamber of Deputies held a public hearing on the draft "Cybersecurity Law in Paraguay," but the session ended up being redirected into another working meeting after, according to ABC Color, several public and private institutions declined to comment because they had reviewed an earlier version of the text that was shared with them that same day. At the same time, CERT-PY published a reference to the National Cybersecurity Strategy 2025-2028, and DNIT activated General Resolution No. 47/2026, which requires reporting cryptoasset transactions once the annual threshold set by the rule, US$5,000, is exceeded.

What happened to the cybersecurity bill?

The public hearing surfaced technical objections to the draft and showed that the discussion was still far from closed. ABC Color reported that most of the invited participants chose not to speak because the review had been based on an older version of the bill, which pushed the debate back into another working session.

ABC Color’s coverage also said specialists questioned the bill over technical weaknesses and the absence of a legal definition of critical infrastructure. In the same vein, Miguel Ángel Gaspar said the text mixes cybersecurity, cyber defense, cybercrime, cyber incidents, and enforcement bodies without clear boundaries, and he called for a deep technical review before the bill moves forward in Congress.

What sectors were at the center of the debate?

Gaspar said the main weakness is that the bill does not legally define what counts as critical infrastructure. In his explanation, he pointed to hydroelectric plants, power distribution, water supply, the health system, and state databases as core strategic sectors.

An opinion analysis in La Tribuna went further, describing the draft "Cybersecurity Law of the Republic of Paraguay" (Exp. D-2585561) as trying to cover critical infrastructure protection, fee regulation, military doctrine, artificial intelligence, and nanotechnology at the same time. That text also criticized the inclusion of social media regulation under the principle of territoriality and the citation of Multidomain Operations (MDO) military doctrine, borrowed from U.S. military language without adaptation to Paraguay’s civilian context.

What institutional signal appeared at the same time?

CERT-PY posted a reference on its website to the National Cybersecurity Strategy 2025-2028. The update comes as legislative debate over the bill remains open and adds an official signal about the cybersecurity framework the country is seeking to organize in the coming years.

What changed for cryptoasset operators?

Paraguay’s DNIT activated General Resolution No. 47/2026, which requires reporting cryptoasset operations once the annual threshold of US$5,000 is exceeded, according to ABC Color. Specialized coverage clarified that the rule requires reporting the date and time of each transaction, the type of asset, amounts traded, gross value in dollars, fees and other costs, as well as the hash, source and destination addresses, and wallet type when possible.

Those reports also make clear that the US$5,000 threshold is used to determine who must report their operations and does not automatically create a new tax for crossing that amount. The obligation applies to owners, administrators, and operators of crypto platforms working in Paraguay, as well as to individuals, companies, and entities resident or incorporated in the country that exceed that annual amount, even if they operate without intermediaries or through foreign platforms.

The first filing under General Resolution No. 47/2026 will correspond to fiscal year 2026 and must be submitted in March 2027 through the Marangatu system, after the 959-DJI Cryptoassets obligation is added to the RUC. Late filing carries a fine of G. 1,000,000, without prejudice to other administrative sanctions.

What recommendations are circulating for bank users?

La Nación Paraguay reported that specialists recommended not opening unknown links, verifying web addresses, avoiding transactions on public Wi-Fi, and keeping phones free of questionable apps amid a rise in bank fraud. The warning was issued as cybercriminal tactics shift toward bank accounts.

Sources

View all