Security in electronic voting Privacy and Data Protection Policy
Privacy by design: voter roll data is used only to verify the voter's identity and is certifiably deleted once the process concludes.
Privacy is not optional: it is part of the design
The Privacy by Design principle means that the protection of personal data is not added as a later layer, but is integrated into the system architecture from the ground up.
Strictly limited use of information
Voter roll data is used for a single purpose: authenticating the voter's identity and validating their right to participate.
- Single purpose: no personal data from the voter roll is used for commercial or marketing purposes, nor shared with third parties.
- Minimum access: only staff directly responsible for the process may access the data, under documented roles and permissions.
- No profiling: the platform does not build electoral behaviour profiles of participants.
Certified deletion of sensitive data
Once results are ratified and validated, formal deletion protocols are executed for all sensitive personal data.
- Documented protocol: deletion follows a formal, recordable and auditable procedure under the ISO 27001 ISMS controls.
- Data that persists: only encrypted votes (which cannot be linked to individuals) and result certificates are kept, necessary for any potential challenges.
- AWS infrastructure: data is stored on Amazon Web Services with the highest levels of security, redundancy and regional isolation.
Data protection from start to finish
Four concrete guarantees on how personal information is handled.
ISO 27001
Personal data handling is governed by the controls of the certified ISMS.
No profiling
We do not build profiles or cross-reference participation data with other sources.
Certified deletion
Personal data is formally deleted at the end of the process, with an auditable record.
AWS
World-class infrastructure with the highest standards of security and redundancy.