Soberania Digital
Cloud
LGPD
Geopolítica
Dados

Digital sovereignty: when where your data lives becomes a strategic decision

Choosing a cloud provider is also a geopolitical choice, and leaders who treat it as a technical issue are delegating a decision that should be executive.

Most Brazilian companies that migrated to the cloud in the last ten years made an implicit decision that was never presented as a decision: that their customer data, contracts, operations and strategy should live on American servers, under United States laws, subject to the orders of a court that their legal experts do not know about. This decision was made in the checklist of an infrastructure RFP, between cost per gigabyte and availability SLA. Nobody called it geopolitics.

The problem is that she is exactly that. And the environment has changed enough that ignoring this dimension is, in many sectors, a risk that the board of directors would need to be aware of.

What digital sovereignty actually means

Digital sovereignty is not a single concept — it is a spectrum of control over data, infrastructure and technological capacity. At the most basic level, it's knowing where the data physically is and what laws apply to it. At the most advanced level, it is ensuring that a nation-state or company has the ability to operate its critical technological systems independently of decisions by third parties — be they other governments, private providers or foreign regulators.

For private companies, the real terrain lies between these extremes. It's not about building your own infrastructure like a central bank, but understanding that contracting with an American cloud provider puts data within the reach of the CLOUD Act — an American law that allows the US government to demand access to data stored by American providers, even on servers outside the US. This is not a theoretical hypothesis; has already been exercised. And no clause in your SaaS contract changes that fact.

LGPD, GDPR and regulation as a vector of sovereignty

The General Data Protection Law was the most visible turning point for the discussion of digital sovereignty in Brazil. It established that Brazilians' personal data has treatment rules that need to be respected regardless of where the company is headquartered or where the servers are. International data transfers now require adequate guarantees.

The European GDPR went further and earlier. What Europe has built with the General Data Protection Regulation is, in effect, an assertion that European citizens' data is not subject to American jurisdiction — and that companies that thought they were using Privacy Shield as a shortcut were surprised when the European Court of Justice struck down that agreement twice. Each takedown forced companies to review their data architectures.

The standard that emerges from these regulations is not just protection of individual privacy. It is the construction of a regulatory infrastructure that defines where data can go and under what conditions. This directly affects system architecture decisions.

The industry's answer: sovereign cloud

The cloud market responded with a new category: sovereign cloud. The premise is simple — offering the same elasticity and services as a public cloud, but with guarantees that the data remains within a specific jurisdiction, operated by local entities, without access from foreign governments.

In Europe, the Gaia-X project is the most ambitious attempt: a federation of European providers building a data infrastructure with open interoperability standards and shared governance among member countries. OVHcloud is the most visible example of a European cloud provider that has explicitly positioned itself as a sovereign alternative to American big tech.

In Brazil, the scenario is still fragmented. There are local providers like Ascenty, Localweb and braziliancloud.com; there is the presence of international providers with local regions (AWS São Paulo, Google Cloud São Paulo, Azure Brasil Sul) — which offer geographic locality of data but do not eliminate American jurisdiction. The difference between "data in Brazil" and "data under Brazilian law with national operation" is real and underestimated.

How a leader should look at this

The first move is to stop treating digital sovereignty as a compliance issue and place it on the strategic risk agenda. LGPD Compliance is the floor, not the ceiling. The important thing is to answer: if tomorrow the commercial or diplomatic relationship with the country of our main cloud provider becomes complicated, what is our exposure?

For companies in regulated industries — healthcare, finance, defense, critical infrastructure — this question has answers with concrete consequences. For companies in other sectors, the answer informs architectural decisions that change the risk level of the business. The distinction between data that can be in an international cloud and data that needs additional jurisdictional protection should exist in every serious data strategy.

The second movement is to understand that digital sovereignty has gradations, and the decision does not need to be binary between "everything in the American AWS" and "everything in its own data center in Brazil". There are hybrid architectures where more sensitive data resides in providers with local jurisdiction guarantees, and less critical workloads use the elasticity of international clouds. This intentional segmentation is more honest—and more defensible—than a single architecture that treats all data as equivalent.

The third dimension, rarely discussed in Brazilian companies, is technological dependence as an operational risk. When your entire stack of data, AI, communication and collaboration passes through five American companies, your ability to operate depends on the continuity of those business relationships. It is a position that deserves to be known by the board, not just the CTO.

Also read