Cybersecurity in Elections: Developing a Holistic Exposure and Adaptation Testing (HEAT) Process for Election Management Bodies accountability requires that the system be open to audits and that EMBs maintain responsibility for ensuring compliance with security requirements “even in the case of failures and attacks.”14 Some countries establish their own voluntary standards or legislation. For example, the U.S. Electoral Assistance Commission maintains a set of voluntary guidelines to help election authorities test whether their systems meet certain functionality, accessibility and security standards. Many U.S. jurisdictions have adopted these standards as obligatory.15 Certification of election technologies has also been captured in the Council of Europe’s guidelines for certifying e-voting systems, which focused on selecting certification bodies, renewing certification, and conducting cost-benefit analyses.16 The privacy of the individuals whose data is collected is another integral aspect of data management that has become particularly prominent with the recent passage of the European Union’s (EU) General Data Protection Regulation (GDPR),17 which went into effect in May 2018. This regulation governs personal data of EU residents that companies and organizations collect, store or process, and requires more openness about what data they have and who they share it with.18 The UN has adopted various general resolutions on data privacy19 to ensure the privacy of individuals or groups whose data is collected. Collectively, these principles aim to ensure transparency in the collection of data to protect the use of this data and offer the opportunity to determine whether information is accurate and nondiscriminatory. For the sake of transparent elections, it is important to allow access to certain types of data to voters, political parties, and civil society organizations. For example, access to preliminary voter lists is important in order to verify details and to challenge registrants who are not eligible, and access to final voter lists is important so these can be used by party agents on Election Day and for voters to know which polling station to go to. Limitations on data access are typically imposed, such as limited access for political parties to the full voter register or its signed version.20 In 2011, 75 countries signed the Open Government Declaration, committing themselves to advancing transparency and openness within 14 Council of Europe, CM-Rec. (2017)5, Appendix I, sec. VIII. “Voluntary Voting System Guidelines,” Voting Equipment, U.S. Election Assistance Commission (EAC), https://www.eac.gov/voting-equipment/voluntary-voting-system-guidelines/. 16 Council of Europe, Certification of e-voting systems, 2011. 17 Regulation (EU) 2016/679, https://eur-lex.europa.eu/legalcontent/EN/TXT/?qid=1532348683434&uri=CELEX:02016R0679-20160504. 18 “What does the General Data Protection Regulation (GDPR) govern?”, European Commission, https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-does-general-data-protection-regulationgdpr-govern_en. 19 G.A. res. 44/132, 44 U.N. GAOR Supp. (No. 49) at 211, U.N. Doc. A/44/49 (1989). See also General Assembly resolutions 68/167 of December 18, 2013 and 69/166 of December 18, 2014, as well as Human Rights Council resolutions 28/16 of March 26, 2015, on the right to privacy in the digital age and 32/13 of July 1, 2016 on the promotion, protection and enjoyment of human rights on the Internet. 20 Ed. Michael Yard, Civil and Voter Registries: Lessons Learned from Global Experiences, IFES, 2011, 15. 15 7

Select target paragraph3