Brazil digital sovereignty

Brazil's Sovereign Cloud Gets One Thing Right: Sovereignty Is Measured by Control, Not by Where the Servers Sit

Serpro's graded test of data, operations and technology, with foreign providers kept in, beats a location rule. Its weights and the cost of its tests still need scrutiny.

Brazil's Sovereign Cloud by the Numbers People of Internet Research · Brazil ~500 Verification tests Up from about 70 in Serpro's metho… 40% Weight on operations Data and technology are weighted 3… 5,000+ Government systems hosted Hosted on Serpro's existing Govern… 15 Technical sovereignty criteria Listed in Serpro's August 21 relea… peopleofinternet.com
Brazil's Sovereign Cloud by the Number… People of Internet Research · Brazil ~500 Verification tests 40% Weight on operations 5,000+ Government systems hosted 15 Technical sovereignty crit… peopleofinternet.com

Key Takeaways

A definition that rejects the binary

In early September, Serpro, Brazil's federal data-processing company, published its account of the first market hearing for the "Brazilian Cloud" (Nuvem Brasileira). The initiative is coordinated by the Ministry of Management and Innovation in Public Services (MGI) with Serpro, the industrial development agency ABDI and the development bank BNDES. Serpro's president, Wilton Mota, told the hearing that "sovereignty in cloud environments cannot be reduced to a binary classification". His point was that where a server sits does not settle whether a state controls what runs on it.

This is a healthier starting point than most sovereign-cloud debates. Much of that debate has treated data residency as the whole question, which lets a vendor call a product sovereign because a rack sits inside national borders while the keys, the administrators and the update pipeline stay elsewhere.

What Serpro is proposing

According to Serpro, the methodology grades a cloud environment on three dimensions: data, operations and technology. The tests ask who holds the encryption keys, who administers the environment, which jurisdictions apply, what external dependencies exist, and whether services survive an interruption. Serpro describes a "disconnection test": a solution is placed in a laboratory and its external connectivity is cut, to see whether essential services keep running and the environment stays manageable.

Serpro's page describes a weighted gradient, with 30% for data, 40% for operations and 30% for technology. It says the test battery has grown from about 70 to roughly 500 checks. An earlier Serpro release, dated August 21, lists 15 technical criteria including key custody, foreign-jurisdiction exposure, licensing independence, open standards and supply-chain diversification. The two figures are not necessarily in conflict, since criteria and individual tests are different units. They do show that the design is still moving.

The initiative also builds on the existing Government Cloud and does not demand full self-sufficiency. Serpro's page says the proposal expressly allows integration of external technologies while national control is kept over critical operational elements. The page adds that Serpro has operated technologies from multiple public cloud providers since 2019.

The strongest case for something stricter

Sovereignty advocates have a serious argument. A gradient is easier to game than a bright line. Foreign providers can be compelled by their home governments, and a single dependency, such as a proprietary control plane or a licence that can be revoked, can undo an otherwise strong score. Brazil also has recent reason for caution about concentrated dependencies. Serpro's president has said that, on his account, no big tech initially delivered a solution with the operational control the government required. He also said that Google, AWS and Microsoft have since expressed interest, and that their interest does not by itself guarantee sovereignty in practice. A residency-only rule would be simple to audit, and simplicity has real value in public procurement.

Why the graded approach is still better

A location rule fails on its own terms. It certifies the wrong thing, and it pushes a country toward duplicating capabilities that global providers have spent billions building. A test built on key custody, jurisdictional exposure and continuity under disruption points at the actual failure modes. Those are the risks that matter when a health registry or a tax system has to keep running during a sanctions dispute or a cable cut.

Keeping access to foreign providers is also the pro-innovation choice. Government agencies that must serve a large share of the population need managed AI services, modern databases and security tooling. Mota's own figures for the Government Cloud illustrate the scale: more than 5,000 hosted systems, and roughly 160 million people registered on Gov.br. A mandate to build every layer domestically would likely slow those services and raise their cost, with no gain in resilience.

The EFF's recent essay on the topic makes a useful warning that applies here. It argues that digital sovereignty should not mean replacing U.S. dominance with a handful of giants based elsewhere, and it favours open-source tools, interoperability and data portability. Brazil's stated criteria on open standards and licensing independence point the same way. The test is whether they carry real weight when procurement decisions are made.

Where the risks lie

Three issues deserve scrutiny as the initiative moves toward tenders.

The context matters as well. Brazil is implementing a new intermediary-liability regime after the Supreme Court's 2025 ruling and a June 2026 clarification, which the EFF has warned carries risks of enforcement overreach. A sovereign cloud that centralises government data should come with matching safeguards on access, logging and oversight.

The bottom line

Brazil's approach treats sovereignty as a spectrum of controls that can be tested, and it avoids both isolationism and blind reliance on any one vendor. That is a defensible, evidence-based way to buy cloud services. The remaining work is to make the scoring transparent, the testing independent and the encryption commitments explicit before the first contracts are awarded.

Sources & Citations

  1. Serpro: Soberania sem isolamento (Sept 4, 2026)
  2. Serpro: 'Soberania sem isolamento' — Nuvem Brasileira sovereignty criteria (Sep 4, 2026)
  3. EFF: Digital Sovereignty: What It Is, What It Could Be
  4. EFF: Intermediary Liability in Brazil
  5. MobileTime: Serpro sovereign cloud (May 11, 2026)