GDPR and online voting: how voter data is actually protected

GDPR and online voting: how voter data is actually protected

As soon as online voting comes up, one question returns in every RFP, often asked by the DPO or the workers' representatives: "what happens to the voter list, and can anyone find out how each person voted?" That is the right question. Here is how the data is actually protected, in plain terms, with no marketing jargon.

The basic principle: the necessary minimum

The GDPR requires data minimisation: you only process what is strictly necessary for the vote. For an election, that comes down to two things:

  • voter identity, to check who is entitled to vote and prevent double voting,
  • login credentials, to secure access.

You do not collect union membership, opinions, or any data unrelated to running the vote. The less data you hold, the less risk there is.

The heart of the system: separating identity from ballot

This is the point everyone wants to understand. In a serious online vote, the attendance list (who voted) is kept strictly separate from the electronic ballot box (the ballots). So the system knows that you voted, to stop you voting twice, but it does not know how.

Technically, this separation is guaranteed by the architecture and encryption: the two sets of data cannot be cross-referenced to reconstruct a person's choice. It is exactly the digital equivalent of the paper vote's booth and sealed box, where your name is ticked off a list at the entrance, but your ballot drops anonymously into the box.

Encryption and hosting

Data is encrypted, at rest and in transit. Hosting and the location of the servers are among the questions to ask the vendor: for a Belgian client, hosting within the European Union is a legitimate and common criterion. These are elements to put in writing in the contract.

Retention: keep, then delete

The GDPR requires a limited retention period. In practice:

  • identification data is used for the duration of the vote and any appeal period,
  • anonymised ballots are kept for as long as the verifiability of the result requires, then deleted.

All of this follows a retention policy defined in advance, not a deletion left to circumstance. Knowing when the data disappears is as important as knowing how it is protected.

Who is responsible for what

A crucial legal point, often misunderstood: the employer organising the election is the data controller. The voting vendor is the processor. This relationship must be framed by a data processing agreement (DPA) that specifies what the vendor may do with the data, where it is hosted, how it is secured, and what happens at the end of the contract. A vendor that does not offer a clear DPA is a warning sign.

The questions to ask your vendor

If you are preparing for 2028, here are the useful questions to ask, the ones we are asked and answer gladly:

  • Exactly what data is collected, and why?
  • How is identity separated from the ballot?
  • Where is the data hosted, and is it encrypted?
  • What is the retention period, and how is deletion proven?
  • Is a DPA provided, and what does it say about the end of the contract?

In short

A GDPR-compliant online vote rests on four pillars: minimisation (process only identity and access), strict separation between who voted and how, encryption with controlled hosting, and a clear retention policy with deletion. All framed by a data processing agreement between the employer (controller) and the vendor (processor). Confidentiality is not a promise: it is an architecture.

To understand in detail how ballot secrecy is guaranteed, read Ballot secrecy online: how nobody can know how you voted. And if your DPO has questions about our setup, let's talk.

More Articles

E-voting abroad: what Estonia, Switzerland and France teach Belgium

Estonia, Switzerland, France: three e-voting models, three lessons. What worked, what failed, and what transfers to Belgian social elections…

Read all

The legal requirements for electronic voting in social elections

The WC/CPPW agreement, system requirements, secrecy guarantees: what the law requires to vote electronically in social elections, and what t…

Read all

Witnesses and observers: who actually keeps the election honest?

Who can be a witness at social elections, what they can see and do, and how that oversight works with electronic voting. The role explained…

Read all

Interview: an HR director looks back on the 2024 social elections

An HR director in the Belgian services sector looks back on the 2024 social elections: the mistakes, the underestimated deadlines and what s…

Read all

Voting without a work email: how to reach deskless workers

How to let workers without a work email vote online: printed personal codes, SMS, on-site kiosks, hybrid setups. The practical guide for ind…

Read all

Social elections in the non-profit sector: the special rules

Hospitals, care homes, non-profits: how to count headcount, draw the TBU and run the 2028 social elections in a sector with huge, part-time…

Read all