International Foundation for Electoral Systems object to e-voting generally, but ruled that the relevant legislation was not specific enough on the duties of the Election Commission, the specifications of the technology to be used, and the protection of the principles of secrecy and publicity. Although there was no evidence of malfeasance, the law left open the possibility of tampering. A CD-ROM with the election data stored on it that could be used to print the data at any point was found insufficient as a paper record. The court noted that electoral principles require public access to the system used and the underlying software, including the source code. Because the e-vote was remote, regulations therefore had to be at least as stringent as regulation of postal voting. Austrian law requires that student elections are held Tuesday through Thursday, and evoting was available from the preceding Monday through Friday. The court ruled that this also violated the law. The ruling was in 2011, after the terms of the representatives elected in the 2008 election had expired, so no election was annulled. Ensuring Cybersecurity in Elections While not enshrined in case law, punitive measures imposed on the EMB in the Philippines in 2016 are instructive in terms of the EMB’s responsibility for cybersecurity in elections. In March 2016, the Philippines Commission on Elections (COMELEC) was hacked by a group called Anonymous Philippines. The hackers took over COMELEC’s website, which was temporarily shut down in the aftermath, and released extensive voter information, including fingerprints. Following the attack, the National Privacy Commission recommended criminal charges against COMELEC Chairperson Andres Bautista for negligence. In its decision of December 28, 2016, the commission stated that “the willful and intentional disregard of his duties as head of agency, which he should know or ought to know, is tantamount to gross negligence. The lack of a clear data governance policy, particularly in collecting and further processing of personal data, unnecessarily exposed personal and sensitive information of millions of Filipinos to unlawful access.”76 The commission did not find Bautista guilty of helping with the attack, but did establish a precedent of holding EMBs and their leadership accountable for information security failures and data breaches in elections. The commission ordered COMELEC to implement new security measures, conduct a privacy assessment, appoint a Data Protection Officer, and establish a Privacy Management Program and a Breach Management Program. Less than a month later, a computer was stolen from the Office of the Election Officer (OEO) in Lanao Del Sur, which the National Privacy Commission noted was “COMELEC’s second large-scale data breach in a span of less than a year.”77 The computer contained biometric records of registered voters. Chairperson Bautista was impeached in October 2017 and resigned that month. Bautista was accused of mishandling the data hack, receiving payment from the company whose voting machines were used in the 2016 elections, and failing to disclose his assets. As of the time of writing, a Senate inquiry is ongoing. The Philippines case is a compelling example of potential institutional and personal liability for EMBs and election officials with 76 National Privacy Commission, “Privacy Commission recommends criminal prosecution of Bautista over “Comeleak,” January 5, 2017, https://www.privacy.gov.ph/2017/01/privacy-commission-finds-bautista-criminallyliable-for-comeleak-data-breach/. 77 National Privacy Commission, “NPC starts probe into COMELEC’s 2nd large scale data breach; issues compliance order,” February 20, 2017, https://www.privacy.gov.ph/2017/02/npc-starts-probe-comelecs-2nd-large-scale-databreach-issues-compliance-order/. 18

Select target paragraph3