International Foundation for Electoral Systems
object to e-voting generally, but ruled that the relevant legislation was not specific enough on the duties
of the Election Commission, the specifications of the technology to be used, and the protection of the
principles of secrecy and publicity. Although there was no evidence of malfeasance, the law left open
the possibility of tampering. A CD-ROM with the election data stored on it that could be used to print
the data at any point was found insufficient as a paper record. The court noted that electoral principles
require public access to the system used and the underlying software, including the source code.
Because the e-vote was remote, regulations therefore had to be at least as stringent as regulation of
postal voting. Austrian law requires that student elections are held Tuesday through Thursday, and evoting was available from the preceding Monday through Friday. The court ruled that this also violated
the law. The ruling was in 2011, after the terms of the representatives elected in the 2008 election had
expired, so no election was annulled.
Ensuring Cybersecurity in Elections
While not enshrined in case law, punitive measures imposed on the EMB in the Philippines in 2016 are
instructive in terms of the EMB’s responsibility for cybersecurity in elections. In March 2016, the
Philippines Commission on Elections (COMELEC) was hacked by a group called Anonymous Philippines.
The hackers took over COMELEC’s website, which was temporarily shut down in the aftermath, and
released extensive voter information, including fingerprints. Following the attack, the National Privacy
Commission recommended criminal charges against COMELEC Chairperson Andres Bautista for
negligence. In its decision of December 28, 2016, the commission stated that “the willful and intentional
disregard of his duties as head of agency, which he should know or ought to know, is tantamount to
gross negligence. The lack of a clear data governance policy, particularly in collecting and further
processing of personal data, unnecessarily exposed personal and sensitive information of millions of
Filipinos to unlawful access.”76 The commission did not find Bautista guilty of helping with the attack,
but did establish a precedent of holding EMBs and their leadership accountable for information security
failures and data breaches in elections. The commission ordered COMELEC to implement new security
measures, conduct a privacy assessment, appoint a Data Protection Officer, and establish a Privacy
Management Program and a Breach Management Program. Less than a month later, a computer was
stolen from the Office of the Election Officer (OEO) in Lanao Del Sur, which the National Privacy
Commission noted was “COMELEC’s second large-scale data breach in a span of less than a year.”77 The
computer contained biometric records of registered voters. Chairperson Bautista was impeached in
October 2017 and resigned that month. Bautista was accused of mishandling the data hack, receiving
payment from the company whose voting machines were used in the 2016 elections, and failing to
disclose his assets. As of the time of writing, a Senate inquiry is ongoing. The Philippines case is a
compelling example of potential institutional and personal liability for EMBs and election officials with
76
National Privacy Commission, “Privacy Commission recommends criminal prosecution of Bautista over
“Comeleak,” January 5, 2017, https://www.privacy.gov.ph/2017/01/privacy-commission-finds-bautista-criminallyliable-for-comeleak-data-breach/.
77
National Privacy Commission, “NPC starts probe into COMELEC’s 2nd large scale data breach; issues compliance
order,” February 20, 2017, https://www.privacy.gov.ph/2017/02/npc-starts-probe-comelecs-2nd-large-scale-databreach-issues-compliance-order/.
18