Mechanism
Decreto Supremo 5309 operationalises Article 77 of Bolivia's Ley 164 (Telecomunicaciones y TIC), which has since 2011 directed the state to prioritise free software and open standards "within the framework of sovereignty and national security." Prior implementation attempts (Decreto Supremo 3251/2017, DS 3900/2019) failed to set enforceable migration deadlines; DS 5309 repairs this by imposing a hard 12 January 2030 migration cut-off on all public entities (Executive, Legislative, Judicial, and Electoral bodies at all tiers of government).
Two instruments in one decree:
1. Free software / open-standards mandate — public entities must progressively replace proprietary software (Microsoft 365, Oracle, SAP, Adobe) with FOSS equivalents by 2030. Migration plans must be submitted to AGETIC within 90 days of the decree's publication.
2. Data-localization clause — "non-public" state data and content may only be stored on: - Infrastructure operated directly by the public entity, or - Cloud services operated by the State, located within national territory.
This effectively bars use of AWS, Azure, Google Cloud, or any foreign-hosted SaaS for government workloads carrying non-public data. Bolivia has no significant domestic hyperscaler; the practical implication is on-premises or a future state-run cloud.
Implementation architecture: AGETIC was given 15 business days from promulgation to publish the Plan de Implementación de Software Libre y Estándares Abiertos (PISLEA). This was done via Decreto Supremo 5322 (23 January 2025), which approved the PISLEA roadmap document.
Downstream implications
- Market-access barrier for US/EU software vendors and hyperscalers — Microsoft, Google, AWS, SAP, and Oracle lose addressable government workloads in a market of ~12 million people. Bolivia's public IT spend is modest (~USD 50–100M/yr estimated), so absolute revenue impact is small.
- No direct private-sector mandate — the decree applies only to public entities. Bolivian private companies and foreign subsidiaries are unaffected; this is not a cross-economy data-localization regime like Vietnam's Cybersecurity Law.
- Precedent value — Bolivia is the first Latin American state to combine a comprehensive FOSS mandate with a formal data-localization clause for government workloads. If implemented, it may influence similar efforts in Ecuador (where the 2021 constitution references digital sovereignty) or Venezuela.
- Enforcement risk — Bolivia's prior FOSS mandates (2017, 2019) went largely unenforced. AGETIC's capacity to audit 200+ public entities across nine departments is limited. The 2030 deadline creates political accountability but operational failure is the base case without dedicated funding.
- Companion decree to watch — Decreto Supremo 5322 (23 Jan 2025) approved the PISLEA implementation plan. Monitor AGETIC portal for annual progress reports; audit triggers if >30% of entities miss the 2026 interim milestone.
Open questions
- Does the data-localization clause cover data at rest only, or also data in transit (cross-border API calls)?
- Which categories of data qualify as "non-public"? The decree does not publish a classification framework — AGETIC may issue secondary regulation.
- Will a state-operated cloud (e.g., on ENTEL infrastructure) actually be stood up before 2030, or will the localization clause force agency-level on-premises deployments?
- Any carve-outs for defence/intelligence entities operating under separate security classifications?