LESSONS ON THE USE OF TECHNOLOGY IN ELECTIONS the election process without delaying the process and compromising the integrity of the data. During the 2021 general elections, one of the competing parties alleged fraud relating to anomalies observed in the digitized tally sheets and requested that the Comptroller investigate the issues and recount of more than 27,000 ballot boxes. In response, the prosecutor launched a preliminary investigation and obtained a court authorization to search and retain a copy of the records, but the hardware was not taken physically from the National Electoral Council’s (CNE) computer server. The Comptroller made a request to the CNE to carry out an audit of the computer system, but the CNE objected to this action until after the elections had concluded — believing that these actions would amount to unlawful interference in the ongoing election process and would delay the pending second round and jeopardize the electoral calendar. 62,63 The CNE’s concerns that these requests amounted to undue interference in the election process were echoed by the EU Election Expert Mission and the OAS EOM. 64 The Ecuadoran Congress subsequently brought impeachment proceedings against the Comptroller. 65 If the prosecutor had sought to enforce the court order, the CNE could risk being in contempt of court. If the CNE had complied with the prosecutor’s request, they could have risked delay in the election process and may have compromised the data’s integrity. If limited audits or forensic audits are ordered by the courts, they should be conducted according to clear rules to ensure chain of evidence is respected and evidence is not tampered with during the audit process. To avoid such tensions and a potential political crisis, it is crucial for the EMB and courts to cooperate prior to elections to familiarize judges with the operational and technical challenges of investigating election irregularities during an ongoing election process. 66 Issue 7: Data Protection and Privacy The need for security of election technology is not only vital to the integrity of the election process. It also affects the privacy and data protection rights of all individuals whose data is held by the EMB, including voters, candidates, observers, party representatives and polling officials. International standards emphasize the need for election technology to be secure. 67 While most election data belong to the public domain, there can be a tension between the need for public and stakeholder scrutiny of election data and ensuring the privacy of voters. In the Philippines, punitive measures were imposed on the Commission on Elections (COMELEC) for negligence in data protection in 2016. This followed hackers taking over COMELEC’s website and releasing extensive voter information, including fingerprints. The National Privacy Commission recommended criminal charges against the COMELEC Chairperson Andrés Bautista for negligence. 68 While this case did not result in election court proceedings, it established a 62 EU Expert Mission Report on the 2021 Ecuador Elections, p. 30. In the end, the requested actions did not take place, as Pachakutik agreed with the CNE to carry out a limited number of recounts, which did not change the overall first round result. When the alleged discrepancies were investigated, only a few were well-founded, and were due to problems in filling in the forms, rather than problems in the electronic system. 64 The OAS Election Observation Mission Report on the General Elections in Ecuador 2021, pp. 13-15 (in English) and pp. 141-142 (in Spanish). 65 Testimonies in the impeachment of the exComptroller have begun, El Comercio, July 18, 2021 (in Spanish). 66 For further discussion on institutional coordination, and the development of investigations plans, see IFES’ Election Investigations Guidebook (2020), https://www.ifes.org/publications/election-investigations-guidebook. 67 The Venice Commission Code of Good Practice on Electoral Matters 2002 provides at paragraph 43, “Electronic voting methods must be secure and reliable. They are secure if the system can withstand deliberate attack; they are reliable if they can function on their own, irrespective of any shortcomings in the hardware or software.” The Council of Europe’s Guidelines on use of ICT in electoral processes, February 2022, sets out the responsibility for ensuring the integrity and authenticity of the information, including by continuous risk management of the ICT solutions. The Council of Europe’s Recommendation on Standards for E-Voting CM/Rec (2017)5, section VIII provides that the EMB shall be responsible for compliance with all security requirements even in the case of failures and attacks. 68 Privacy Commission recommends criminal prosecution of Bautista over “Comeleak” » National Privacy Commission, January 5, 2017. 63 24

Select target paragraph3