Electronic Voting Compliance in Australia: Standards and Best Practices

Monday, 31 August 2026, 5:12 pm

Electronic Voting Compliance in Australia Standards and Best Practices
BlogElections

Electronic voting can make an election, AGM, member ballot or workplace vote significantly easier to manage. But moving a ballot online does not remove the governance responsibilities that sit behind it.

If anything, electronic voting makes some of those responsibilities more visible.

Organisations need to be confident that the right people can vote, that votes are recorded accurately, that personal information is protected, and that the final result can be explained and defended if someone challenges it.

There is also a common misconception that Australia has one national law or certification specifically called an “electronic voting standard”. It doesn’t.

The compliance requirements depend on what type of organisation is voting, what the vote is for, which legislation or constitution applies, and what information the voting system handles.

For a company AGM, the Corporations Act 2001 and the company’s constitution may be central. For a union ballot, enterprise agreement vote, incorporated association election or strata resolution, different rules may apply.

That is why good electronic voting is about more than choosing software.

It is about designing a voting process that is secure, transparent, accessible and consistent with the rules governing the particular vote.

What is electronic voting compliance?

Electronic voting compliance is the process of ensuring that an online or digital voting system and the way it is operated meet the legal, regulatory, constitutional, privacy, security and governance requirements that apply to the vote.

That can include:

Confirming who is entitled to vote.
Preventing unauthorised voting.
Preventing duplicate votes.
Protecting voter information.
Maintaining ballot secrecy where required.
Accurately recording preferences.
Applying the correct voting method.
Preserving appropriate records.
Providing an audit trail.
Ensuring members have a reasonable opportunity to participate.
Managing technical failures.
Handling complaints or challenges.
Securely disposing of information when it is no longer required.

The technology is only one part of the equation.

A technically secure voting platform can still be used in a non-compliant way if the organisation supplies an incorrect voter roll, uses the wrong voting method, gives inadequate notice or fails to follow its constitution.

Is electronic voting legal in Australia?

Yes. Electronic and virtual voting can be used in many Australian governance and organisational settings, but there is no single set of rules covering every type of electronic vote.

The relevant requirements depend on the organisation and the nature of the vote.

For companies, for example, the Corporations Act 2001 contains specific provisions dealing with meetings held using virtual meeting technology. Section 249R allows a company meeting to be held at physical venues, at physical venues using virtual meeting technology, or using virtual meeting technology only where this is expressly required or permitted by the company’s constitution.

The Act also requires companies conducting meetings using virtual technology to give members, as a whole, a reasonable opportunity to participate. ASIC explains that this includes appropriate opportunities to ask questions, make comments and vote.

For other organisations, the governing rules may instead come from:

The organisation’s constitution or rules.
Incorporated association legislation.
Strata legislation.
Industrial relations legislation.
Enterprise agreement requirements.
Union rules.
Sector-specific regulations.
Contractual requirements.
Applicable privacy legislation.

So the first compliance question should not be “Which voting software should we use?”

It should be:

“What rules govern this particular vote?”

The main areas of electronic voting compliance

Although the legal requirements differ between voting situations, there are several areas that should form part of almost every serious electronic voting review.

1. Voter eligibility and authentication

The system needs to establish that the person attempting to vote is entitled to participate.

This is particularly important where a voter roll contains thousands of members, employees, shareholders or other eligible participants.

A well-designed process should answer questions such as:

Who is eligible to vote?
How is eligibility determined?
How is a voter authenticated?
Can the same voter vote twice?
Can voting credentials be shared?
What happens if a voter cannot access their credentials?
Can an administrator manually change a voter’s status?
Are those administrative actions recorded?

Authentication does not necessarily mean collecting excessive personal information.

The aim is to establish voting entitlement while collecting only the information that is reasonably necessary for the process.

2. Ballot secrecy and voter privacy

For many elections and ballots, knowing who voted is different from knowing how they voted.

A voting system may therefore need to separate voter authentication information from ballot selections.

For example, a system might verify that Jane Smith is entitled to vote, allow her to submit a ballot, and then store the ballot in a way that prevents administrators from linking Jane’s identity to her individual choices.

The precise design will depend on the type of vote and its rules.

This is particularly important for:

Union ballots.
Employee ballots.
Director elections.
Member elections.
Sensitive workplace votes.
Political or policy resolutions within organisations.

A provider should be able to explain, in plain English, what information is collected, what is linked, who can access it and when it is separated or deleted.

Privacy obligations and the Australian Privacy Principles

Privacy is one of the most significant compliance considerations for electronic voting.

The Australian Privacy Principles (APPs), contained in the Privacy Act 1988, establish requirements for organisations covered by the Act when handling personal information.

APP 11 requires an APP entity to take reasonable steps to protect personal information from misuse, interference and loss, as well as unauthorised access, modification or disclosure.

The OAIC’s current guidance makes clear that security is not simply an IT issue. Reasonable steps can involve governance, policies, staff training, ICT security, access controls, third-party providers, data breach processes, physical security and appropriate destruction or de-identification.

That matters when selecting an electronic voting provider.

A voting platform may process:

Names.
Email addresses.
Telephone numbers.
Membership information.
Employee information.
Shareholder information.
Voting eligibility.
Voting records.
Proxy information.
Election results.

The organisation should understand what happens to that information throughout its lifecycle.

Think about the entire information lifecycle

A useful way to assess a voting platform is to look at five stages:

Collection → Authentication → Voting → Reporting → Retention or destruction

At each stage, ask:

What information is collected?
Why is it needed?
Who can access it?
How is it protected?
How long is it retained?
When and how is it destroyed or de-identified?

The OAIC specifically recommends considering privacy and security throughout the information lifecycle rather than treating security as something that happens only after information has been collected.

Security standards: where does ISO 27001 fit?

One of the recognised standards organisations may encounter when assessing an electronic voting provider is ISO/IEC 27001.

In Australia, Standards Australia lists AS/NZS ISO/IEC 27001:2023 as the Australian adoption of ISO/IEC 27001:2022. The standard specifies requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS).

ISO 27001 is not an “electronic voting certification”.

Rather, it is a broader information security management standard.

That distinction matters.

An ISO 27001-certified provider is not automatically compliant with every law, constitution or rule that may apply to a particular ballot. Certification should instead be viewed as evidence that the organisation has an independently assessed information security management system within the certified scope.

Standards Australia also explains that formal certification is not mandatory simply to implement the standard. Certification provides independent verification to stakeholders or customers.

For organisations procuring voting services, this makes ISO 27001 a useful question to ask:

Is the voting provider independently certified, and what is actually included within the certification scope?

What about the Essential Eight?

The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) recommends the Essential Eight as a baseline set of mitigation strategies for protecting organisations against common cyber threats.

The Essential Eight includes measures such as:

Application control.
Patching applications.
Configuring Microsoft Office macro settings.
User application hardening.
Restricting administrative privileges.
Patching operating systems.
Multi-factor authentication.
Regular backups.

The Essential Eight is a cybersecurity framework rather than an electronic voting standard.

It can nevertheless be useful when assessing the security maturity of a voting provider or an organisation operating its own voting infrastructure.

The ACSC’s maturity model also addresses backup security and restoration, illustrating why resilience and recoverability matter alongside preventative controls.

For a procurement team, the useful question is not simply:

“Are you Essential Eight compliant?”

Instead, ask the provider to explain its security controls, testing, monitoring, access management, backup strategy and incident response arrangements.

Audit trails are a core part of trustworthy electronic voting

One of the biggest differences between a basic online form and a properly managed electronic ballot is the quality of the audit trail.

If a result is challenged six weeks after an election, an organisation should be able to reconstruct what happened.

A useful audit trail can help establish:

When the ballot opened.
When it closed.
Which voter records were eligible.
When voting credentials were issued.
Whether credentials were used.
When votes were submitted.
Whether invalid votes were rejected.
Whether administrators changed ballot settings.
When results were generated.
Who had administrative access.
What actions were taken during the ballot.

There is a balance here.

Auditability does not mean exposing individual voting choices.

A good system should provide sufficient evidence to verify the integrity of the process while maintaining the confidentiality or anonymity required by the particular ballot.

This is one reason a proper voting system should be assessed as a complete process rather than as a simple web form.

Electronic voting and AGM compliance

AGMs are one of the most common situations where organisations consider electronic voting.

For companies, ASIC states that virtual and hybrid meetings must provide members, as a whole, with a reasonable opportunity to participate. The technology must allow appropriate participation, including asking questions, making comments and voting.

This has a practical consequence:

A livestream is not necessarily a compliant virtual meeting solution.

ASIC specifically explains that a webcast that only allows members to watch proceedings does not, by itself, provide the participation required for a hybrid meeting.

For an electronic AGM voting process, consider whether members can:

Authenticate themselves.
Access the meeting.
Ask questions where they have the right to do so.
Participate in discussion.
Vote on resolutions.
Receive clear voting instructions.
Understand when voting opens and closes.
Obtain appropriate confirmation that their vote was submitted.

ASIC also recommends testing virtual meeting technology in advance, considering expected usage, conducting rehearsals and preparing contingency arrangements for technical problems.

That is good practice for electronic voting generally.

Electronic voting does not remove the need to follow the constitution

This is one of the most common mistakes organisations make.

An organisation may purchase an excellent online voting platform and still run a defective election.

Why?

Because the platform cannot override the organisation’s governing rules.

Before configuring the ballot, check:

Who is eligible to vote.
How notice must be provided.
Minimum notice periods.
Quorum requirements.
Voting entitlements.
Proxy rules.
Nomination requirements.
Voting method.
Preferential voting requirements.
Majority thresholds.
Tie-breaking provisions.
Scrutineer or returning officer requirements.
Requirements for recording results.

For companies, ASIC reminds organisations that meetings and resolutions must comply with the Corporations Act as well as the company’s constitution or applicable replaceable rules. Failure to follow the relevant rules can affect the validity of a resolution.

The same basic principle applies elsewhere:

Technology should implement the governing rules, not replace them.

Common electronic voting mistakes

Treating a survey tool as an election platform

A survey tool may be excellent for gathering opinions.

That does not automatically make it suitable for a formal election or ballot.

Formal voting may require authentication, eligibility controls, ballot secrecy, preferential voting, proxy handling, auditability and formal result reporting.

Assuming encryption alone makes a ballot secure

Encryption protects information in transit and, depending on the implementation, at rest.

It does not by itself answer:

Who can vote?
Can someone vote twice?
Who has administrator access?
Can votes be altered?
Can voter identities be linked to selections?
Are changes logged?
What happens during an outage?

Security is layered.

Keeping voter information indefinitely

More data is not necessarily better.

The OAIC’s guidance states that APP 11 includes an obligation to take reasonable steps to destroy or de-identify personal information when it is no longer needed for permitted purposes, subject to relevant exceptions.

A good retention policy should therefore be established before the ballot starts.

Forgetting the human side of voting

A secure system that voters cannot use is not a successful voting system.

Instructions should be clear, mobile-friendly and tested with ordinary users.

Consider accessibility, language, device compatibility and what support is available if a voter gets stuck.

Having no contingency plan

What happens if:

The voting platform becomes unavailable?
An email delivery problem affects voters?
A voter loses their credentials?
A meeting loses internet connectivity?
The voting deadline needs to be extended?
An incorrect voter list is discovered?

These questions should be answered before the ballot opens.

Best practices for compliant electronic voting

A practical electronic voting framework can be built around the following principles.

1. Start with the rules

Identify the legislation, constitution, rules, agreement or other instrument governing the vote.

Do this before configuring the ballot.

2. Define voter eligibility

Create and approve the voter roll.

Document who is entitled to vote and the source of the eligibility information.

3. Use appropriate authentication

Select an authentication method proportionate to the risk of the vote.

For higher-risk elections, stronger authentication controls may be appropriate.

4. Separate identity from ballot choice where required

If the ballot needs to be anonymous, ensure the technical architecture supports that requirement rather than relying on an administrator’s promise not to look at the data.

5. Use strong access controls

Administrative access should be restricted to authorised personnel.

Use multi-factor authentication where appropriate and maintain logs of privileged activity.

6. Maintain a defensible audit trail

Record important events without compromising ballot secrecy.

The objective is to be able to demonstrate that the process operated as intended.

7. Test the complete process

Do not test only whether the ballot page loads.

Test:

Voter authentication.
Eligibility.
Duplicate-vote prevention.
Voting rules.
Invalid responses.
Mobile devices.
Accessibility.
Result calculations.
Administrator permissions.
Reporting.
Contingency procedures.

8. Reconcile the results

After voting closes, reconcile the number of eligible voters, participation records and ballots received where the voting rules permit and require this.

Unexpected discrepancies should be investigated before results are declared.

9. Have an incident process

Know who makes decisions if something goes wrong.

Document the escalation path and criteria for pausing, extending, restarting or otherwise managing a ballot.

10. Manage data after the vote

Do not treat the end of voting as the end of information security obligations.

Determine what must be retained, why it must be retained and when information can be securely destroyed or de-identified.

What should you ask an electronic voting provider?

A procurement checklist should go beyond asking whether the platform is “secure”.

Ask the provider:

Governance

How do you support different voting rules and constitutions?
Can the voting method be configured for the specific ballot?
Who is responsible for configuring the election?
Is an independent returning officer available?

Security

Is the organisation ISO/IEC 27001 certified?
What is the scope of the certification?
Are security controls independently assessed?
Is multi-factor authentication available for administrators?
How is privileged access controlled?
How are security incidents detected and managed?

Voting integrity

How do you prevent duplicate voting?
How is voter eligibility checked?
How are invalid votes handled?
How are results calculated?
Can administrators alter submitted votes?
How are changes to ballot configuration recorded?

Privacy

What personal information is collected?
Where is it stored?
Who can access it?
Is voter identity separated from ballot selections?
How long is information retained?
What happens when the retention period ends?
Are third-party service providers involved?

Auditability

What audit logs are generated?
Can the organisation obtain a complete election report?
Can the process be independently reviewed after the vote?
How are technical incidents documented?

These questions are much more useful than simply asking whether a platform has “bank-level security”.

Where Vero Voting can assist

Electronic voting becomes particularly complex when there are formal eligibility rules, large voter populations, multiple voting channels or sensitive results.

Vero Voting’s online voting services are designed for formal ballots, elections and governance processes rather than simply collecting survey responses.

Vero Voting supports voting processes including elections, AGMs, enterprise agreement ballots and other organisational votes, with voter authentication, automated vote counting and voting receipts forming part of its online voting offering.

For organisations running elections, Vero Voting’s election voting services can support processes from nominations through to results, including board, committee, association and office-bearer elections.

For AGMs and member meetings, Vero Voting’s AGM voting services cover voting processes including nominations, elections, proxy voting and preferential voting.

From a security perspective, Vero Voting states that it is ISO/IEC 27001:2022 certified and SOC 2 Type II audited. Its online voting information also describes voter authentication, duplicate-vote prevention, separate handling of submitted voting data and voting receipts.

That does not mean a provider’s certification replaces the organisation’s own legal or governance responsibilities. The organisation still needs to ensure that the ballot itself follows the applicable legislation, constitution, rules or agreement.

That distinction is worth keeping clear.

A practical compliance framework

For most organisations, the following sequence provides a sensible starting point:

1. Identify the governing rules

What legislation, constitution, agreement or rules apply?

2. Define the voting process

Who votes, what are they voting on and what voting method applies?

3. Establish the voter roll

Confirm eligibility before credentials are issued.

4. Assess privacy and security

Determine what information will be collected and how it will be protected.

5. Select the technology

Choose a platform that can implement the actual voting rules.

6. Test the ballot

Test normal voting and unusual scenarios before opening.

7. Communicate clearly

Give voters straightforward instructions and support information.

8. Monitor the process

Track participation and technical issues without compromising ballot secrecy.

9. Close and reconcile

Secure the ballot, verify the results and produce the required reports.

10. Retain or dispose of information appropriately

Follow the organisation’s retention requirements and applicable privacy obligations.

This approach makes compliance part of the voting design rather than something checked after the result has already been announced.

Key takeaways

Electronic voting compliance in Australia is not about finding one magic certification or ticking a single compliance box.

The strongest voting processes bring several things together:

Legal compliance — follow the legislation and rules governing the particular vote.
Governance — follow the constitution, election rules and approved procedures.
Voter integrity — ensure only eligible people vote and prevent duplicate voting.
Privacy — protect personal information throughout its lifecycle.
Security — use appropriate technical and organisational controls.
Ballot secrecy — separate voter identity from voting choices where required.
Auditability — maintain sufficient evidence to demonstrate how the process operated.
Accessibility — make the voting process practical for the people entitled to participate.
Resilience — plan for technical failures and unexpected events.
Independent assurance — consider certifications, audits and other evidence when assessing providers.

The best electronic voting systems are not simply easy to use.

They are defensible.

If a member, employee, shareholder, regulator or other stakeholder asks, “How do you know this result is accurate?”, the organisation should have a clear answer backed by evidence.

If your organisation is planning an online election, AGM poll or member ballot and needs help designing the voting and compliance process, contact Vero Voting to discuss your requirements or request a demonstration.

Sources

Australian Government and regulators

Standards and industry authorities

Vero Voting

Editorial note: This article provides general governance and compliance information and is not legal advice. Organisations should confirm the specific legislative, constitutional or regulatory requirements applicable to their particular vote.


Frequently Asked Questions

Is electronic voting legal in Australia?

Yes. Electronic voting and virtual meeting technology can be used in many Australian contexts, but the rules depend on the type of organisation and vote. For companies, the Corporations Act 2001 contains specific requirements for meetings using virtual technology, including reasonable opportunities for members to participate. Other organisations may be governed by different legislation, constitutions, rules or agreements.

Is there an Australian standard for electronic voting?

There is no single Australian standard that makes every electronic voting system compliant. Organisations should consider the rules governing their particular vote alongside privacy, cybersecurity, information security, governance and audit requirements. Standards such as AS/NZS ISO/IEC 27001:2023 can provide a recognised information security framework, but ISO 27001 is not itself an electronic voting law or certification.

Does online voting need to be anonymous?

Not every vote needs to be anonymous. The requirement depends on the rules and nature of the ballot. Where a secret ballot is required or appropriate, the system should be designed so that voter authentication can occur without unnecessarily exposing an individual’s voting choices to administrators.

What should an electronic voting audit trail contain?

An audit trail should provide enough evidence to reconstruct and verify the voting process. Depending on the ballot, this may include ballot configuration, voter authentication events, voting activity, administrative actions, system events, result calculations and final reports. The audit trail should not undermine ballot secrecy or disclose individual voting choices where confidentiality is required.

Is ISO 27001 enough to make an online voting platform compliant?

No. ISO/IEC 27001 addresses information security management and can provide valuable independent assurance, but it does not determine whether a particular election complies with the Corporations Act, a constitution, enterprise agreement, union rules or other applicable requirements. Compliance is broader than information security certification.

Need support with your next Elections?

Contact Us

Subscribe to our blog

Stay up to date on the latest topics for voting solutions

[stc-subscribe]



    Subscribe

    If you want to personalise your subscription, click here