Electronic Voting Compliance in Australia: Standards and Best Practices
Monday, 31 August 2026, 5:12 pm
Electronic voting can make an election, AGM, member ballot or workplace vote significantly easier to manage. But moving a ballot online does not remove the governance responsibilities that sit behind it.
If anything, electronic voting makes some of those responsibilities more visible.
Organisations need to be confident that the right people can vote, that votes are recorded accurately, that personal information is protected, and that the final result can be explained and defended if someone challenges it.
There is also a common misconception that Australia has one national law or certification specifically called an “electronic voting standard”. It doesn’t.
The compliance requirements depend on what type of organisation is voting, what the vote is for, which legislation or constitution applies, and what information the voting system handles.
For a company AGM, the Corporations Act 2001 and the company’s constitution may be central. For a union ballot, enterprise agreement vote, incorporated association election or strata resolution, different rules may apply.
That is why good electronic voting is about more than choosing software.
It is about designing a voting process that is secure, transparent, accessible and consistent with the rules governing the particular vote.
What is electronic voting compliance?
Electronic voting compliance is the process of ensuring that an online or digital voting system and the way it is operated meet the legal, regulatory, constitutional, privacy, security and governance requirements that apply to the vote.
That can include:
The technology is only one part of the equation.
A technically secure voting platform can still be used in a non-compliant way if the organisation supplies an incorrect voter roll, uses the wrong voting method, gives inadequate notice or fails to follow its constitution.
Is electronic voting legal in Australia?
Yes. Electronic and virtual voting can be used in many Australian governance and organisational settings, but there is no single set of rules covering every type of electronic vote.
The relevant requirements depend on the organisation and the nature of the vote.
For companies, for example, the Corporations Act 2001 contains specific provisions dealing with meetings held using virtual meeting technology. Section 249R allows a company meeting to be held at physical venues, at physical venues using virtual meeting technology, or using virtual meeting technology only where this is expressly required or permitted by the company’s constitution.
The Act also requires companies conducting meetings using virtual technology to give members, as a whole, a reasonable opportunity to participate. ASIC explains that this includes appropriate opportunities to ask questions, make comments and vote.
For other organisations, the governing rules may instead come from:
So the first compliance question should not be “Which voting software should we use?”
It should be:
“What rules govern this particular vote?”
The main areas of electronic voting compliance
Although the legal requirements differ between voting situations, there are several areas that should form part of almost every serious electronic voting review.
1. Voter eligibility and authentication
The system needs to establish that the person attempting to vote is entitled to participate.
This is particularly important where a voter roll contains thousands of members, employees, shareholders or other eligible participants.
A well-designed process should answer questions such as:
Authentication does not necessarily mean collecting excessive personal information.
The aim is to establish voting entitlement while collecting only the information that is reasonably necessary for the process.
2. Ballot secrecy and voter privacy
For many elections and ballots, knowing who voted is different from knowing how they voted.
A voting system may therefore need to separate voter authentication information from ballot selections.
For example, a system might verify that Jane Smith is entitled to vote, allow her to submit a ballot, and then store the ballot in a way that prevents administrators from linking Jane’s identity to her individual choices.
The precise design will depend on the type of vote and its rules.
This is particularly important for:
A provider should be able to explain, in plain English, what information is collected, what is linked, who can access it and when it is separated or deleted.
Privacy obligations and the Australian Privacy Principles
Privacy is one of the most significant compliance considerations for electronic voting.
The Australian Privacy Principles (APPs), contained in the Privacy Act 1988, establish requirements for organisations covered by the Act when handling personal information.
APP 11 requires an APP entity to take reasonable steps to protect personal information from misuse, interference and loss, as well as unauthorised access, modification or disclosure.
The OAIC’s current guidance makes clear that security is not simply an IT issue. Reasonable steps can involve governance, policies, staff training, ICT security, access controls, third-party providers, data breach processes, physical security and appropriate destruction or de-identification.
That matters when selecting an electronic voting provider.
A voting platform may process:
The organisation should understand what happens to that information throughout its lifecycle.
Think about the entire information lifecycle
A useful way to assess a voting platform is to look at five stages:
Collection → Authentication → Voting → Reporting → Retention or destruction
At each stage, ask:
The OAIC specifically recommends considering privacy and security throughout the information lifecycle rather than treating security as something that happens only after information has been collected.
Security standards: where does ISO 27001 fit?
One of the recognised standards organisations may encounter when assessing an electronic voting provider is ISO/IEC 27001.
In Australia, Standards Australia lists AS/NZS ISO/IEC 27001:2023 as the Australian adoption of ISO/IEC 27001:2022. The standard specifies requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS).
ISO 27001 is not an “electronic voting certification”.
Rather, it is a broader information security management standard.
That distinction matters.
An ISO 27001-certified provider is not automatically compliant with every law, constitution or rule that may apply to a particular ballot. Certification should instead be viewed as evidence that the organisation has an independently assessed information security management system within the certified scope.
Standards Australia also explains that formal certification is not mandatory simply to implement the standard. Certification provides independent verification to stakeholders or customers.
For organisations procuring voting services, this makes ISO 27001 a useful question to ask:
Is the voting provider independently certified, and what is actually included within the certification scope?
What about the Essential Eight?
The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) recommends the Essential Eight as a baseline set of mitigation strategies for protecting organisations against common cyber threats.
The Essential Eight includes measures such as:
The Essential Eight is a cybersecurity framework rather than an electronic voting standard.
It can nevertheless be useful when assessing the security maturity of a voting provider or an organisation operating its own voting infrastructure.
The ACSC’s maturity model also addresses backup security and restoration, illustrating why resilience and recoverability matter alongside preventative controls.
For a procurement team, the useful question is not simply:
“Are you Essential Eight compliant?”
Instead, ask the provider to explain its security controls, testing, monitoring, access management, backup strategy and incident response arrangements.
Audit trails are a core part of trustworthy electronic voting
One of the biggest differences between a basic online form and a properly managed electronic ballot is the quality of the audit trail.
If a result is challenged six weeks after an election, an organisation should be able to reconstruct what happened.
A useful audit trail can help establish:
There is a balance here.
Auditability does not mean exposing individual voting choices.
A good system should provide sufficient evidence to verify the integrity of the process while maintaining the confidentiality or anonymity required by the particular ballot.
This is one reason a proper voting system should be assessed as a complete process rather than as a simple web form.
Electronic voting and AGM compliance
AGMs are one of the most common situations where organisations consider electronic voting.
For companies, ASIC states that virtual and hybrid meetings must provide members, as a whole, with a reasonable opportunity to participate. The technology must allow appropriate participation, including asking questions, making comments and voting.
This has a practical consequence:
A livestream is not necessarily a compliant virtual meeting solution.
ASIC specifically explains that a webcast that only allows members to watch proceedings does not, by itself, provide the participation required for a hybrid meeting.
For an electronic AGM voting process, consider whether members can:
ASIC also recommends testing virtual meeting technology in advance, considering expected usage, conducting rehearsals and preparing contingency arrangements for technical problems.
That is good practice for electronic voting generally.
Electronic voting does not remove the need to follow the constitution
This is one of the most common mistakes organisations make.
An organisation may purchase an excellent online voting platform and still run a defective election.
Why?
Because the platform cannot override the organisation’s governing rules.
Before configuring the ballot, check:
For companies, ASIC reminds organisations that meetings and resolutions must comply with the Corporations Act as well as the company’s constitution or applicable replaceable rules. Failure to follow the relevant rules can affect the validity of a resolution.
The same basic principle applies elsewhere:
Technology should implement the governing rules, not replace them.
Common electronic voting mistakes
Treating a survey tool as an election platform
A survey tool may be excellent for gathering opinions.
That does not automatically make it suitable for a formal election or ballot.
Formal voting may require authentication, eligibility controls, ballot secrecy, preferential voting, proxy handling, auditability and formal result reporting.
Assuming encryption alone makes a ballot secure
Encryption protects information in transit and, depending on the implementation, at rest.
It does not by itself answer:
Security is layered.
Keeping voter information indefinitely
More data is not necessarily better.
The OAIC’s guidance states that APP 11 includes an obligation to take reasonable steps to destroy or de-identify personal information when it is no longer needed for permitted purposes, subject to relevant exceptions.
A good retention policy should therefore be established before the ballot starts.
Forgetting the human side of voting
A secure system that voters cannot use is not a successful voting system.
Instructions should be clear, mobile-friendly and tested with ordinary users.
Consider accessibility, language, device compatibility and what support is available if a voter gets stuck.
Having no contingency plan
What happens if:
These questions should be answered before the ballot opens.
Best practices for compliant electronic voting
A practical electronic voting framework can be built around the following principles.
1. Start with the rules
Identify the legislation, constitution, rules, agreement or other instrument governing the vote.
Do this before configuring the ballot.
2. Define voter eligibility
Create and approve the voter roll.
Document who is entitled to vote and the source of the eligibility information.
3. Use appropriate authentication
Select an authentication method proportionate to the risk of the vote.
For higher-risk elections, stronger authentication controls may be appropriate.
4. Separate identity from ballot choice where required
If the ballot needs to be anonymous, ensure the technical architecture supports that requirement rather than relying on an administrator’s promise not to look at the data.
5. Use strong access controls
Administrative access should be restricted to authorised personnel.
Use multi-factor authentication where appropriate and maintain logs of privileged activity.
6. Maintain a defensible audit trail
Record important events without compromising ballot secrecy.
The objective is to be able to demonstrate that the process operated as intended.
7. Test the complete process
Do not test only whether the ballot page loads.
Test:
8. Reconcile the results
After voting closes, reconcile the number of eligible voters, participation records and ballots received where the voting rules permit and require this.
Unexpected discrepancies should be investigated before results are declared.
9. Have an incident process
Know who makes decisions if something goes wrong.
Document the escalation path and criteria for pausing, extending, restarting or otherwise managing a ballot.
10. Manage data after the vote
Do not treat the end of voting as the end of information security obligations.
Determine what must be retained, why it must be retained and when information can be securely destroyed or de-identified.
What should you ask an electronic voting provider?
A procurement checklist should go beyond asking whether the platform is “secure”.
Ask the provider:
Governance
Security
Voting integrity
Privacy
Auditability
These questions are much more useful than simply asking whether a platform has “bank-level security”.
Where Vero Voting can assist
Electronic voting becomes particularly complex when there are formal eligibility rules, large voter populations, multiple voting channels or sensitive results.
Vero Voting’s online voting services are designed for formal ballots, elections and governance processes rather than simply collecting survey responses.
Vero Voting supports voting processes including elections, AGMs, enterprise agreement ballots and other organisational votes, with voter authentication, automated vote counting and voting receipts forming part of its online voting offering.
For organisations running elections, Vero Voting’s election voting services can support processes from nominations through to results, including board, committee, association and office-bearer elections.
For AGMs and member meetings, Vero Voting’s AGM voting services cover voting processes including nominations, elections, proxy voting and preferential voting.
From a security perspective, Vero Voting states that it is ISO/IEC 27001:2022 certified and SOC 2 Type II audited. Its online voting information also describes voter authentication, duplicate-vote prevention, separate handling of submitted voting data and voting receipts.
That does not mean a provider’s certification replaces the organisation’s own legal or governance responsibilities. The organisation still needs to ensure that the ballot itself follows the applicable legislation, constitution, rules or agreement.
That distinction is worth keeping clear.
A practical compliance framework
For most organisations, the following sequence provides a sensible starting point:
1. Identify the governing rules
What legislation, constitution, agreement or rules apply?
2. Define the voting process
Who votes, what are they voting on and what voting method applies?
3. Establish the voter roll
Confirm eligibility before credentials are issued.
4. Assess privacy and security
Determine what information will be collected and how it will be protected.
5. Select the technology
Choose a platform that can implement the actual voting rules.
6. Test the ballot
Test normal voting and unusual scenarios before opening.
7. Communicate clearly
Give voters straightforward instructions and support information.
8. Monitor the process
Track participation and technical issues without compromising ballot secrecy.
9. Close and reconcile
Secure the ballot, verify the results and produce the required reports.
10. Retain or dispose of information appropriately
Follow the organisation’s retention requirements and applicable privacy obligations.
This approach makes compliance part of the voting design rather than something checked after the result has already been announced.
Key takeaways
Electronic voting compliance in Australia is not about finding one magic certification or ticking a single compliance box.
The strongest voting processes bring several things together:
The best electronic voting systems are not simply easy to use.
They are defensible.
If a member, employee, shareholder, regulator or other stakeholder asks, “How do you know this result is accurate?”, the organisation should have a clear answer backed by evidence.
If your organisation is planning an online election, AGM poll or member ballot and needs help designing the voting and compliance process, contact Vero Voting to discuss your requirements or request a demonstration.
FAQ Section
Electronic Voting Compliance in Australia
Electronic Voting Compliance in Australia
Electronic Voting Compliance in Australia
Electronic Voting Compliance in Australia
Electronic Voting Compliance in Australia
Electronic Voting Compliance in Australia
Electronic Voting Compliance in Australia
Electronic Voting Compliance in Australia
Electronic Voting Compliance in Australia
Electronic Voting Compliance in Australia
Is electronic voting legal in Australia?
Yes. Electronic voting and virtual meeting technology can be used in many Australian contexts, but the rules depend on the type of organisation and vote. For companies, the Corporations Act 2001 contains specific requirements for meetings using virtual technology, including reasonable opportunities for members to participate. Other organisations may be governed by different legislation, constitutions, rules or agreements.
https://www.verovoting.com.au/wp-admin/media-upload.php?post_id=5499&type=image&TB_iframe=1
Is there an Australian standard for electronic voting?
There is no single Australian standard that makes every electronic voting system compliant. Organisations should consider the rules governing their particular vote alongside privacy, cybersecurity, information security, governance and audit requirements. Standards such as AS/NZS ISO/IEC 27001:2023 can provide a recognised information security framework, but ISO 27001 is not itself an electronic voting law or certification.
Does online voting need to be anonymous?
Not every vote needs to be anonymous. The requirement depends on the rules and nature of the ballot. Where a secret ballot is required or appropriate, the system should be designed so that voter authentication can occur without unnecessarily exposing an individual’s voting choices to administrators.
What should an electronic voting audit trail contain?
An audit trail should provide enough evidence to reconstruct and verify the voting process. Depending on the ballot, this may include ballot configuration, voter authentication events, voting activity, administrative actions, system events, result calculations and final reports. The audit trail should not undermine ballot secrecy or disclose individual voting choices where confidentiality is required.
Is ISO 27001 enough to make an online voting platform compliant?
No. ISO/IEC 27001 addresses information security management and can provide valuable independent assurance, but it does not determine whether a particular election complies with the Corporations Act, a constitution, enterprise agreement, union rules or other applicable requirements. Compliance is broader than information security certification.
Sources
Australian Government and regulators
Standards and industry authorities
Vero Voting
Editorial note: This article provides general governance and compliance information and is not legal advice. Organisations should confirm the specific legislative, constitutional or regulatory requirements applicable to their particular vote.
Frequently Asked Questions
Is electronic voting legal in Australia?
Yes. Electronic voting and virtual meeting technology can be used in many Australian contexts, but the rules depend on the type of organisation and vote. For companies, the Corporations Act 2001 contains specific requirements for meetings using virtual technology, including reasonable opportunities for members to participate. Other organisations may be governed by different legislation, constitutions, rules or agreements.
Is there an Australian standard for electronic voting?
There is no single Australian standard that makes every electronic voting system compliant. Organisations should consider the rules governing their particular vote alongside privacy, cybersecurity, information security, governance and audit requirements. Standards such as AS/NZS ISO/IEC 27001:2023 can provide a recognised information security framework, but ISO 27001 is not itself an electronic voting law or certification.
Does online voting need to be anonymous?
Not every vote needs to be anonymous. The requirement depends on the rules and nature of the ballot. Where a secret ballot is required or appropriate, the system should be designed so that voter authentication can occur without unnecessarily exposing an individual’s voting choices to administrators.
What should an electronic voting audit trail contain?
An audit trail should provide enough evidence to reconstruct and verify the voting process. Depending on the ballot, this may include ballot configuration, voter authentication events, voting activity, administrative actions, system events, result calculations and final reports. The audit trail should not undermine ballot secrecy or disclose individual voting choices where confidentiality is required.
Is ISO 27001 enough to make an online voting platform compliant?
No. ISO/IEC 27001 addresses information security management and can provide valuable independent assurance, but it does not determine whether a particular election complies with the Corporations Act, a constitution, enterprise agreement, union rules or other applicable requirements. Compliance is broader than information security certification.


