Continental Postal Services of Hebland

Serpro’s 376M biometric database underpins Brazil’s sovereign identity strategy


Brazil’s digital identity transformation has been decades in the making.

The country is moving from fragmented identity databases and point-in-time biometric verification toward shared national infrastructure connecting identity, authoritative government data and population-scale biometrics. Its next ambition goes further: continuous authentication running on infrastructure and data kept under Brazilian control.

At the center is Serpro, Brazil’s state-owned Federal Data Processing Service. Founded in 1964, Serpro operates critical technology infrastructure and thousands of systems for the federal government.

The largest biometric database operated by Serpro has now expanded to 376 million faces, with duplicates raising the total beyond Brazil’s total population, domestic outlet Mobile Times reports.

Brazil’s journey can broadly be divided into three phases.

Phase 1: Siloed identity and 1:1 verification

Brazil has used the CPF taxpayer identifier for decades, but civil identity historically remained decentralized. States issued their own identity cards and maintained separate databases, while citizens accumulated different identifiers across government, driving, elections and other services.

Brazil also had substantial biometric coverage. Large repositories already existed for elections, driver’s licenses and civil identification, with much of the biometric verification focused on 1:1 identity checks.

The problem was not the absence of biometrics. It was fragmentation.

Siloed databases created duplicate and inconsistent records. Government agencies maintained separate infrastructure and integrations. Private companies seeking authoritative verification faced multiple sources and processes, while citizens could repeatedly provide information already held elsewhere.

Brazil needed common identity infrastructure.

Phase 2: Building national identity infrastructure

The transformation accelerated in 2019.

Gov.br created a common digital gateway to government services. CPF increasingly became the common identifier, culminating in Law 14.534/2023, which established it as the single identification number in public-service databases. The Carteira de Identidade Nacional (CIN) national ID card subsequently created a common national identity framework around CPF.

But one identifier and one document were not enough.

Brazil also needed infrastructure capable of establishing uniqueness across previously fragmented databases, moving beyond 1:1 verification to population-scale 1:N identification and deduplication.

AIBio: the biometric platform

To support this model, Serpro developed AIBio, its centralized biometric platform.

AIBio provides 1:1 verification, 1:N identification and deduplication, biometric quality checks, liveness detection and fraud detection. It supports face, voice and fingerprint biometrics and leverages large repositories that already existed across government, including electoral, driver’s-license and digital-government systems.

Serpro previously reported an ecosystem containing approximately 220 million facial images and two billion fingerprints. The database has now reached 376 million with the integration of the CNH (driver’s license), CIN and biometric records from the TSE (voter ID).

Centralization therefore addressed several problems simultaneously. Duplicate identities could be detected, expensive biometric capabilities could be built once and reused, integrations could be simplified, fraud detection could improve and citizens could receive a more consistent experience.

Creating an authoritative identity source

Centralization also created something valuable beyond government: an authoritative identity source that private companies could use for identity verification.

This is where Datavalid comes in.

Datavalid is Serpro’s identity-validation service that allows authorized organizations to validate customer-provided information against authoritative Brazilian government databases. Through APIs, businesses can check biographical information, CPF and driver’s-license data, as well as face and fingerprint biometrics.

The distinction is important: AIBio provides the biometric capabilities, while Datavalid makes government-backed identity validation consumable by businesses.

And adoption shows the model is operating at scale. Serpro said in June 2026 that Datavalid had completed nearly two billion validations for thousands of companies in Brazil and internationally. Companies including Uber and 99 have used Serpro’s identity-validation infrastructure, while financial institutions use it for remote customer verification.

Datavalid V5 further simplifies integration by combining checks such as registration information, facial biometrics, fingerprints and driver’s-license validation. It also adds greater purpose declaration, traceability and citizen visibility into how identity data is used.

In effect, Brazil is turning parts of government identity infrastructure into an identity utility for the broader digital economy.

Efficiency also creates concentration risk

Centralization brings efficiency, but it also concentrates risk.

A national biometric infrastructure becomes an attractive cyber target, while compromised biometrics cannot simply be replaced like passwords. Population-scale 1:N matching also makes accuracy and demographic performance particularly important.

There is also the risk of function creep as infrastructure built for government authentication expands into banking, transportation, travel and other services.

The more useful the infrastructure becomes, the more important security, purpose limitation, transparency and citizen control become.

Phase 3: Sovereign and continuous trust

Brazil’s next phase involves two important transitions.

The first is digital sovereignty.

Serpro’s sovereign-cloud strategy goes beyond storing Brazilian data in Brazil. Critical infrastructure can be located in the country, operated by Serpro personnel and governed by the Brazilian state, with sensitive data remaining under Brazilian jurisdiction without international transfer or external management.

That means sovereignty across three dimensions: data, infrastructure and operations.

The objective is ultimately citizen trust. If Brazilians are expected to use common identity infrastructure across more public and private services, they need confidence in who controls their sensitive data and the systems processing it.

Sovereignty could also help localize fraud intelligence, allowing Brazilian identity, device, transaction and attack patterns to inform fraud detection specific to the country’s digital ecosystem.

The second transition is from point-in-time verification toward continuous authentication.

Serpro has been experimenting with behavioral biometrics, according to Mobile Time. The agency began working on analyzing how users interact with devices — including typing, mouse and touchscreen behavior — to identify anomalies and potential fraud after initial authentication with its Gov.br app. Datavalid also uses behavioral analysis to identify devices associated with fraud risk.

Combined with device intelligence, physical biometrics and transaction context, identity could evolve from a one-time decision into a continuously evaluated trust signal.

Blockchain or other tamper-evident technologies could eventually provide additional capabilities around auditability, credential integrity and verifiable records.

Brazil is simultaneously extending the sovereignty philosophy beyond identity into AI, cloud and computing infrastructure, with plans for domestic AI compute, sovereign models, data infrastructure and longer-term capabilities around critical hardware.

Is this what the next generation of national identity infrastructure looks like?

Brazil suggests the answer may be yes — but with an important qualification.

The emerging model combines a common identifier, authoritative government data, population-scale biometrics, reusable public and private verification services, fraud intelligence and continuous authentication, supported by infrastructure increasingly kept under national control.

In that sense, Brazil offers a glimpse of identity becoming a shared national infrastructure rather than a collection of independent verification systems.

But every layer added also concentrates more trust and risk. The same infrastructure that makes fraud easier to detect and services easier to access can magnify the consequences of a breach, biometric error, function creep or misuse.

The real test for the next generation of national identity will therefore be whether countries can combine scale, interoperability and continuous trust with sovereignty, security, privacy, transparency and meaningful citizen control.

Brazil is attempting to build both sides of that equation — and may offer an early blueprint for countries considering what comes next.

Article Topics

 |   |   |   |   |   |   |   | 

Latest Biometrics News


 

  NIST has completed the first phase of its vendor engagements under the Fast Capture (FastCap) program for evaluating contactless…


 

Sri Lanka has taken another step toward introducing biometric passports after the Cabinet approved a new Immigration Bill that establishes…


 

The Gulf Cooperation Council is often viewed as a single digital identity market, but verification providers expanding across the region…


 

The United Nations Relief and Works Agency for Palestinian Refugees in the Near East (UNRWA) is using its eUNRWA digital…


 

For many of us of a certain vintage, our first encounter with biometrics was probably on screen – specifically, in…


 

Interoperability is a key issue identified by the OpenID Foundation in its response to the Australian Government’s Department of Finance…





Source link

Leave A Reply

Your email address will not be published.