Cybersecurity in Elections:
Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies
accountability requires that the system be open to audits and that EMBs maintain responsibility for
ensuring compliance with security requirements “even in the case of failures and attacks.”14
Some countries establish their own voluntary standards or legislation. For example, the U.S. Electoral
Assistance Commission maintains a set of voluntary guidelines to help election authorities test whether
their systems meet certain functionality, accessibility and security standards. Many U.S. jurisdictions
have adopted these standards as obligatory.15 Certification of election technologies has also been
captured in the Council of Europe’s guidelines for certifying e-voting systems, which focused on
selecting certification bodies, renewing certification, and conducting cost-benefit analyses.16
The privacy of the individuals whose data is collected is another integral aspect of data management
that has become particularly prominent with the recent passage of the European Union’s (EU) General
Data Protection Regulation (GDPR),17 which went into effect in May 2018. This regulation governs
personal data of EU residents that companies and organizations collect, store or process, and requires
more openness about what data they have and who they share it with.18 The UN has adopted various
general resolutions on data privacy19 to ensure the privacy of individuals or groups whose data is
collected. Collectively, these principles aim to ensure transparency in the collection of data to protect
the use of this data and offer the opportunity to determine whether information is accurate and nondiscriminatory.
For the sake of transparent elections, it is important to allow access to certain types of data to voters,
political parties, and civil society organizations. For example, access to preliminary voter lists is
important in order to verify details and to challenge registrants who are not eligible, and access to final
voter lists is important so these can be used by party agents on Election Day and for voters to know
which polling station to go to. Limitations on data access are typically imposed, such as limited access
for political parties to the full voter register or its signed version.20 In 2011, 75 countries signed the Open
Government Declaration, committing themselves to advancing transparency and openness within
14
Council of Europe, CM-Rec. (2017)5, Appendix I, sec. VIII.
“Voluntary Voting System Guidelines,” Voting Equipment, U.S. Election Assistance Commission (EAC),
https://www.eac.gov/voting-equipment/voluntary-voting-system-guidelines/.
16
Council of Europe, Certification of e-voting systems, 2011.
17
Regulation (EU) 2016/679, https://eur-lex.europa.eu/legalcontent/EN/TXT/?qid=1532348683434&uri=CELEX:02016R0679-20160504.
18
“What does the General Data Protection Regulation (GDPR) govern?”, European Commission,
https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-does-general-data-protection-regulationgdpr-govern_en.
19
G.A. res. 44/132, 44 U.N. GAOR Supp. (No. 49) at 211, U.N. Doc. A/44/49 (1989). See also General Assembly
resolutions 68/167 of December 18, 2013 and 69/166 of December 18, 2014, as well as Human Rights Council
resolutions 28/16 of March 26, 2015, on the right to privacy in the digital age and 32/13 of July 1, 2016 on the
promotion, protection and enjoyment of human rights on the Internet.
20
Ed. Michael Yard, Civil and Voter Registries: Lessons Learned from Global Experiences, IFES, 2011, 15.
15
7