LESSONS ON THE USE OF TECHNOLOGY IN ELECTIONS
the election process without delaying the process and compromising the integrity of the data. During the 2021 general
elections, one of the competing parties alleged fraud relating to anomalies observed in the digitized tally sheets and
requested that the Comptroller investigate the issues and recount of more than 27,000 ballot boxes. In response, the
prosecutor launched a preliminary investigation and obtained a court authorization to search and retain a copy of the
records, but the hardware was not taken physically from the National Electoral Council’s (CNE) computer server. The
Comptroller made a request to the CNE to carry out an audit of the computer system, but the CNE objected to this
action until after the elections had concluded — believing that these actions would amount to unlawful interference
in the ongoing election process and would delay the pending second round and jeopardize the electoral calendar.
62,63
The CNE’s concerns that these requests amounted to undue interference in the election process were echoed
by the EU Election Expert Mission and the OAS EOM. 64 The Ecuadoran Congress subsequently brought
impeachment proceedings against the Comptroller. 65 If the prosecutor had sought to enforce the court order, the CNE
could risk being in contempt of court. If the CNE had complied with the prosecutor’s request, they could have risked
delay in the election process and may have compromised the data’s integrity.
If limited audits or forensic audits are ordered by the courts, they should be conducted according to clear rules to
ensure chain of evidence is respected and evidence is not tampered with during the audit process. To avoid such
tensions and a potential political crisis, it is crucial for the EMB and courts to cooperate prior to elections to familiarize
judges with the operational and technical challenges of investigating election irregularities during an ongoing election
process. 66
Issue 7: Data Protection and Privacy
The need for security of election technology is not only vital to the integrity of the election process. It also affects the
privacy and data protection rights of all individuals whose data is held by the EMB, including voters, candidates,
observers, party representatives and polling officials. International standards emphasize the need for election
technology to be secure. 67 While most election data belong to the public domain, there can be a tension between the
need for public and stakeholder scrutiny of election data and ensuring the privacy of voters. In the Philippines,
punitive measures were imposed on the Commission on Elections (COMELEC) for negligence in data protection in
2016. This followed hackers taking over COMELEC’s website and releasing extensive voter information, including
fingerprints. The National Privacy Commission recommended criminal charges against the COMELEC Chairperson
Andrés Bautista for negligence. 68 While this case did not result in election court proceedings, it established a
62 EU
Expert Mission Report on the 2021 Ecuador Elections, p. 30.
In the end, the requested actions did not take place, as Pachakutik agreed with the CNE to carry out a limited number of recounts,
which did not change the overall first round result. When the alleged discrepancies were investigated, only a few were well-founded, and
were due to problems in filling in the forms, rather than problems in the electronic system.
64 The OAS Election Observation Mission Report on the General Elections in Ecuador 2021, pp. 13-15 (in English) and pp. 141-142 (in
Spanish).
65 Testimonies in the impeachment of the exComptroller have begun, El Comercio, July 18, 2021 (in Spanish).
66 For further discussion on institutional coordination, and the development of investigations plans, see IFES’ Election Investigations
Guidebook (2020), https://www.ifes.org/publications/election-investigations-guidebook.
67 The Venice Commission Code of Good Practice on Electoral Matters 2002 provides at paragraph 43, “Electronic voting methods must
be secure and reliable. They are secure if the system can withstand deliberate attack; they are reliable if they can function on their own,
irrespective of any shortcomings in the hardware or software.” The Council of Europe’s Guidelines on use of ICT in electoral processes,
February 2022, sets out the responsibility for ensuring the integrity and authenticity of the information, including by continuous risk
management of the ICT solutions. The Council of Europe’s Recommendation on Standards for E-Voting CM/Rec (2017)5, section VIII
provides that the EMB shall be responsible for compliance with all security requirements even in the case of failures and attacks.
68
Privacy Commission recommends criminal prosecution of Bautista over “Comeleak” » National Privacy Commission, January 5, 2017.
63
24