Online Voting Privacy and Data Security in Australia: What Organisations Need to Know

Friday, 25 September 2026, 9:59 am

Online Voting for Incorporated Associations- A Complete Guide
BlogVoting

Online Voting Privacy and Data Security in Australia: What Organisations Need to Know

When an organisation moves an election, AGM resolution or member ballot online, the obvious concern is whether people can vote successfully.

The less obvious question is what happens to their information along the way.

An online voting process can involve names, email addresses, mobile numbers, membership details, shareholder information, voting entitlements, proxy information and records showing that a person was entitled to participate. Depending on the organisation and the ballot, some of that information may be personal information under Australian privacy law.

That makes online voting privacy and data security a governance issue, not simply an IT issue.

The good news is that organisations do not need to make voting unnecessarily complicated to manage these risks. The strongest approach is usually straightforward: collect only what is needed, restrict who can access it, understand where the data goes, protect it throughout its lifecycle, and have a clear plan for what happens if something goes wrong.

This guide looks at the practical privacy and security considerations Australian organisations should work through when choosing or managing an online voting system.

Practical note: Privacy obligations vary between organisations. The Privacy Act 1988 does not cover every Australian organisation in exactly the same way, and sector-specific or state and territory requirements may also apply. This article provides general governance guidance rather than legal advice.

What information does an online voting system hold?

The answer depends on the organisation and the type of vote.

A company election might involve shareholder information. An association ballot could use member numbers and contact details. A strata vote may involve lot information and voting entitlements. A union ballot may involve member records and eligibility information.

A typical online election may therefore involve:

names
email addresses
mobile telephone numbers
membership or employee numbers
shareholder or holder reference information
voting entitlements
proxy information
candidate or nomination information
ballot participation records
authentication or access records
election results
administrative and audit records

Not all of this information has the same privacy risk.

A useful starting point is to map the information before the election begins.

What information do we actually need to run this vote?

That question often exposes information that has historically been collected simply because a database contained it.

The Australian Privacy Principles (APPs) include requirements around the collection, use, disclosure, quality, security and retention of personal information. APP 3, for example, deals with the collection of solicited personal information, while APP 10 requires reasonable steps to ensure personal information is accurate, up to date and complete. (OAIC)

Does the Privacy Act apply to online voting?

It can, but the answer depends on the organisation and its circumstances.

The Privacy Act 1988 (Cth) generally regulates Australian Government agencies and many private sector organisations, although there are exemptions. Most small businesses with annual turnover of $3 million or less are not covered unless an exception applies. The OAIC specifically identifies exceptions including certain health service providers, organisations that trade in personal information and Commonwealth contractors. (OAIC)

That distinction matters for organisations such as incorporated associations, clubs and smaller not-for-profits. The fact that an organisation is conducting an election does not, by itself, determine whether the Privacy Act applies.

There may also be other obligations.

For example, a company needs to consider its constitution, the Corporations Act and the rules governing the particular vote. A registered organisation or union may have additional requirements under industrial legislation. Strata schemes are subject to state or territory legislation.

So the right compliance question is not simply:

“Is online voting legal?”

It is:

“What rules apply to this organisation, this voter register and this particular ballot, and does the voting process support them?”

The privacy principles that matter most for online voting

For organisations covered by the Privacy Act, several APPs are particularly relevant to an online voting process.

APP 1: Be open and transparent

Organisations covered by the APPs need to manage personal information in an open and transparent way and maintain an up-to-date privacy policy.

That means voters should be able to understand, in appropriate circumstances, what information is being collected and how it is handled.

For an online election, practical questions include:

What information is being collected?
Why is it needed?
Who will receive it?
Is a third-party voting provider involved?
Is information disclosed overseas?
How can a voter make a privacy enquiry or complaint?

The OAIC says APP entities must take reasonable steps to implement practices, procedures and systems that ensure compliance with the APPs. (OAIC)

APP 3: Only collect what is reasonably necessary

More information does not automatically make an election more secure.

If a voting provider can authenticate an eligible member using an existing membership number and registered contact information, there may be no reason to collect a copy of a passport or driver’s licence.

The OAIC’s guidance says an APP entity must not collect personal information unless it is reasonably necessary for one or more of its functions or activities, with additional requirements applying to sensitive information. (OAIC)

This is particularly relevant when organisations are designing voter verification.

Verify what you need. Don’t collect everything you can.

APP 5: Tell people what is happening with their information

When personal information is collected, APP 5 requires APP entities to take reasonable steps to notify or ensure individuals are aware of specified matters, including the purpose of collection and relevant disclosures.

For an online ballot, this information can be addressed through the organisation’s privacy notice, election documentation and voting instructions, depending on the circumstances. (OAIC)

APP 6: Use and disclosure need a purpose

Personal information collected for an election should not simply become a general-purpose database for unrelated activities.

APP 6 governs when an APP entity may use or disclose personal information it holds.

That makes it worth checking what a voting provider, administrator or other service provider is actually permitted to do with voter information. (OAIC)

APP 8: Check where information goes

This is an area organisations sometimes overlook when choosing cloud-based software.

If an APP entity discloses personal information to an overseas recipient, APP 8 can impose additional requirements. In general, the entity must take reasonable steps to ensure the overseas recipient does not breach the APPs, subject to exceptions. The Australian entity can also remain accountable for certain acts or practices of the overseas recipient. (OAIC)

That does not mean every overseas cloud service is prohibited.

It means organisations need to understand where personal information is being disclosed and what contractual and technical protections apply.

When assessing an online voting provider, ask:

Where is voter information stored?
Where is it processed?
Are any overseas service providers involved?
Are subcontractors used?
What contractual privacy protections are in place?
What happens to information after the election?

These are reasonable due diligence questions.

APP 11: The core security obligation

For online voting, APP 11 is one of the most important provisions to understand.

Where an APP entity holds personal information, it must take reasonable steps to protect it from misuse, interference and loss, as well as unauthorised access, modification or disclosure.

The OAIC’s current guidance makes clear that “reasonable steps” include both technical and organisational measures. It also says security should be considered across the information lifecycle, from collection through to destruction or de-identification. (OAIC)

This is a useful way to think about online voting.

Security is not one feature on a product page.

It is the whole process.

What does reasonable security look like?

There is no single checklist that makes every organisation compliant.

The appropriate controls depend on factors including the organisation, the amount and sensitivity of the information, the way it is handled and the potential consequences of a breach.

The OAIC identifies areas including:

governance and staff training
internal policies and procedures
ICT security
access security
third-party providers
data breach response
physical security
destruction and de-identification
relevant standards

The OAIC also recommends a layered approach rather than relying on a single security measure. (OAIC)

That principle translates well to online elections.

You don’t want one password standing between an unauthorised person and an entire voter database.

Access controls: who can actually see the voter data?

Access control is often where privacy and security meet.

A voting platform may contain information that an ordinary administrator does not need to see.

For example, someone responsible for meeting logistics may need to know how many people have voted. They may not need unrestricted access to the full voter register.

Likewise, a person helping a voter recover access should not necessarily have access to the person’s ballot choices.

A sensible access model follows the principle of least privilege: people receive the access necessary to perform their role, rather than broad access by default.

Consider separating access between:

election administrators
meeting administrators
technical support staff
vote counters or scrutineers
organisation executives
external providers

Access should also be reviewed when roles change.

A committee member who helped administer last year’s election should not automatically retain the same permissions for the next one.

Multi-factor authentication and administrator security

Voter authentication and administrator authentication are different problems.

A member might receive a one-time code to verify access to a ballot. An administrator, meanwhile, may have access to the underlying voter records or election configuration.

The administrator account can therefore be particularly valuable to an attacker.

Australian Government cybersecurity guidance recommends multi-factor authentication as part of the Essential Eight, including for online services that process, store or communicate sensitive organisational data. The Australian Cyber Security Centre’s current guidance also includes requirements around MFA for privileged and unprivileged users at relevant maturity levels. (Cyber.gov.au)

For organisations selecting an online voting provider, useful questions include:

Is MFA available for administrator accounts?
Is MFA enforced rather than merely offered?
How are privileged accounts controlled?
Are administrator activities logged?
Can access be revoked promptly?
Are administrative permissions separated by role?

A secure voter experience is of limited value if an administrator account can bypass the controls.

Encryption: ask what is actually protected

“Encrypted” is not a sufficiently detailed answer when assessing a voting platform.

Organisations should understand what encryption is used for and where.

For example:

Is information encrypted in transit?
Is stored information protected?
How are encryption keys managed?
Who can access decrypted information?
Are backups protected?
Are administrative connections secured?

The OAIC’s Guide to Securing Personal Information discusses encryption and other technical and organisational measures as part of securing personal information. (OAIC)

The practical lesson is simple: don’t stop at a security badge or marketing statement. Ask the provider to explain the control.

Voter privacy and ballot secrecy are not the same thing

This distinction is particularly important in elections.

Privacy concerns the protection of personal information.

Ballot secrecy concerns whether an individual’s voting choices can be associated with them.

An election system may need to verify that a person is eligible to vote while ensuring that their actual voting selections remain confidential.

Those are separate requirements.

A well-designed election process should therefore consider how voter authentication, participation records and ballot data interact.

For a secret ballot, the organisation should be able to establish that an eligible person voted without creating an unnecessary record showing how that person voted.

This should be discussed with the voting provider before the election is configured, rather than discovered during the count.

Vero Voting describes its platform as separating voter verification from voting choices and supporting confidential voting processes where applicable. Its published security information also describes authentication, auditability and access controls as components of its approach to online voting. (Vero Voting)

Data retention: don’t keep voter information forever

An election ends.

The privacy risk does not necessarily end at the same moment.

After the ballot closes, ask what information actually needs to be retained and for how long.

There may be legitimate reasons to retain certain election records. For example, an organisation may need evidence of the voting process, results or compliance with its governing rules.

But retaining every piece of personal information indefinitely creates a larger pool of information that could be exposed later.

APP 11.2 requires APP entities, in certain circumstances, to take reasonable steps to destroy or de-identify personal information when it is no longer needed for a permitted purpose, subject to specified exceptions such as legal retention requirements. (OAIC)

A practical retention review should ask:

1. What records must be retained?
2. Why must they be retained?
3. Who needs access?
4. Can unnecessary personal information be removed?
5. When can information be securely destroyed or de-identified?

This should be agreed before the election, particularly when a third-party voting provider is involved.

What happens if the voting provider uses overseas services?

This deserves specific attention.

Modern online platforms can rely on a number of cloud, communications, hosting and infrastructure providers. Those services may operate in different countries.

If an organisation covered by the APPs discloses personal information to an overseas recipient, APP 8 may apply. The OAIC says organisations should consider factors including the sensitivity of the information, potential consequences of mishandling, existing technical and operational safeguards and the relationship with the overseas recipient. (OAIC)

Before appointing a provider, ask for enough information to understand the data flow.

A useful procurement question is:

“Please explain where our voter information is stored, processed and accessed, including any overseas service providers or subcontractors.”

That single question can reveal a surprising amount about the provider’s operating model.

Third-party voting providers: what should organisations check?

Using a specialist voting provider can reduce administrative workload, but outsourcing does not mean outsourcing governance responsibility.

The OAIC’s APP 11 guidance specifically identifies third-party providers, including cloud computing, as an area organisations should consider when protecting personal information. (OAIC)

Before engaging a provider, consider asking for:

Security controls

What security framework does the provider use?
Is the organisation independently audited or certified?
How is access controlled?
How is information encrypted?
How are vulnerabilities managed?
How are security incidents detected?

Privacy controls

What personal information is collected?
Why is it collected?
Where is it stored?
Who can access it?
Are overseas recipients involved?
What happens after the election?

Election controls

How are voters authenticated?
How is duplicate voting prevented?
How is ballot secrecy maintained?
What audit records are produced?
Can administrators change voter eligibility?
What happens if a voter loses access?

Incident response

How will the provider notify the organisation about a suspected breach?
Who is responsible for investigating?
Is there a documented incident response process?
Can relevant logs and records be preserved?

The answers matter more than a long list of security terminology.

Data breaches and online elections

Even well-managed systems can experience security incidents.

Organisations need to know what they will do if voter information is accidentally exposed, accessed without authorisation or otherwise compromised.

For organisations covered by the Notifiable Data Breaches (NDB) scheme, an eligible data breach may trigger notification obligations.

Broadly, the NDB scheme applies where an organisation or agency covered by Australian privacy law experiences an eligible data breach that is likely to result in serious harm to affected individuals. The organisation must take reasonable steps to assess a suspected breach within 30 calendar days after becoming aware of the relevant circumstances. If an eligible data breach is identified, notification obligations can follow. (OAIC)

That is one reason a voting provider’s incident response arrangements should be understood before an election.

The organisation should know:

who gets notified internally
who contacts the provider
who investigates
who determines whether notification is required
what information needs to be preserved
how affected voters would be contacted if necessary

Don’t try to write this process after an incident.

Privacy by design is particularly useful for elections

Privacy is easier to manage when it is considered before the voter register is uploaded.

A practical privacy-by-design process might look like this:

Before the election

Identify the information required and confirm the voting rules.

During configuration

Only provide the provider with information required to conduct the vote.

Before voting opens

Test authentication, access permissions, recovery procedures and administrator controls.

During voting

Monitor the election without giving unnecessary people access to voter information.

After voting closes

Retain required records and securely remove information that is no longer needed, subject to applicable retention requirements.

This is much easier than trying to retrofit privacy controls after a database has already been shared with several systems.

What should organisations ask an online voting provider?

If you’re comparing providers, take a practical approach.

Ask these questions before signing up:

1. What personal information will you require from us? You should be able to understand every field.
2. Where will our information be stored and processed? Ask specifically about overseas providers and subcontractors.
3. Who can access voter information? Ask how access is restricted, monitored and revoked.
4. How are administrator accounts protected? Ask about MFA and privileged access.
5. How is voter authentication handled? Understand the options for email, mobile, OTP, unique links or other controls.
6. Can voter identity be linked to ballot choices? For secret ballots, this is a fundamental question.
7. What happens when a voter loses their invitation? There should be a controlled recovery process rather than an informal administrator workaround.
8. What audit records are produced? Ask what can be demonstrated after the election.
9. How are security incidents handled? Understand the notification and response process.
10. What happens to our data after the election? Ask about retention, deletion and de-identification.

A provider that can answer these questions clearly is much easier to assess than one that simply says the platform is “secure”.

What Vero Voting can offer organisations

Vero Voting provides online voting and election services for Australian organisations, including AGMs, elections, member ballots, enterprise agreement voting and other governance processes.

Its current published information states that Vero Voting is ISO/IEC 27001:2022 certified and SOC 2 Type II audited. These are useful forms of independent assurance, although organisations should still consider whether the provider’s controls and contractual arrangements meet the requirements of their particular election. (Vero Voting)

Vero also describes controls around voter authentication, auditability, access control and separation of voter verification from ballot choices. (Vero Voting)

For organisations, that matters because an online election is not simply a matter of putting a ballot on a website.

The voter register, authentication process, privacy arrangements, administrator permissions, ballot secrecy, audit trail and post-election data handling all form part of the governance process.

A specialist provider can take much of that operational burden away while giving the organisation a clearer process to review and document.

A practical online voting privacy checklist

Before launching your next online ballot, work through this checklist.

Personal information

Have we identified all personal information being collected?
Is every field necessary?
Have we checked the accuracy of the voter register?
Have voters been given appropriate privacy information?

Access

Who can access the voter register?
Are administrator permissions role-based?
Is MFA used for privileged accounts?
Are access events logged?
Can access be revoked promptly?

Voting

How are voters authenticated?
Can unauthorised people obtain ballot access?
How is duplicate voting prevented?
Is ballot secrecy preserved where required?
Is the voting process consistent with the organisation’s governing rules?

Provider

Have we reviewed the provider’s security controls?
Is independent assurance available?
Where is information stored and processed?
Are overseas recipients involved?
Are subcontractors involved?

After the election

What information must be retained?
What information can be destroyed or de-identified?
Who remains authorised to access the records?
Are audit records preserved?
Do we know how a suspected data breach would be handled?

If you can answer those questions before voting opens, you’re already addressing many of the issues that cause problems later.

A note on privacy reforms coming in December 2026

Australian privacy requirements continue to develop.

From 10 December 2026, new APP 1.7–1.9 provisions introduced by the Privacy and Other Legislation Amendment Act 2024 will create additional privacy-policy transparency requirements for APP entities that arrange for computer programs to use personal information to make, or substantially and directly contribute to, decisions that could reasonably be expected to significantly affect an individual’s rights or interests. (OAIC)

For most ordinary voting platforms, this should not be interpreted as a new general requirement to disclose every piece of software used in an election.

The relevance depends on whether the organisation is an APP entity and whether the particular automated decision-making arrangement falls within the new provisions.

For organisations using automation in voter eligibility, access decisions or other processes that could significantly affect individual rights or interests, it is worth reviewing the position before the December commencement date.

The legislation’s commencement provisions specify 10 December 2026 for the relevant automated decision-making reforms. (Federal Register of Legislation)

Key takeaways

Online voting privacy is about much more than keeping a database behind a password.

A properly managed election should consider the entire information lifecycle:

Collect → verify → access → vote → audit → retain or securely dispose.

For Australian organisations, the practical priorities are:

collect only the personal information you actually need
keep voter information accurate
explain how information will be handled
restrict administrative access
protect privileged accounts with strong authentication
understand where data is stored and processed
assess overseas disclosures where relevant
separate voter authentication from ballot secrecy where a secret ballot is required
maintain appropriate audit records
have a clear data breach response process
review retention and secure disposal after the election

Privacy and security should not be treated as obstacles to online voting.

Done properly, they are part of what makes an election credible.

If you’re planning an AGM, member ballot, board election, union ballot or other online vote and want to work through the privacy and security requirements, contact Vero Voting or request a demonstration. A short discussion before the election can often identify issues that would be much harder to fix once voting has opened.

Sources

The article relies primarily on Australian Government and regulator material. The most relevant authority links are:

The Vero-specific statements can be supported by:


Frequently Asked Questions

Is online voting secure in Australia?

Online voting security depends on how the system is designed and operated. Important controls include voter authentication, administrator access controls, encryption, auditability, ballot secrecy where required, secure data handling and incident response. Australian organisations should also consider applicable privacy and election-specific requirements.

Does the Privacy Act apply to online voting?

It can. The Privacy Act 1988 applies to many Australian organisations and government agencies, but exemptions exist, including for many small business operators. Some small businesses are covered where specific exceptions apply. Organisations should establish whether the Privacy Act applies to their particular circumstances rather than assuming that it does or does not.

What personal information does an online voting platform collect?

This varies according to the election. It may include a voter’s name, email address, mobile number, membership or shareholder number, voting entitlement and authentication information. Organisations covered by the APPs should consider whether each category is reasonably necessary before collecting it.

Can an online voting system know who voted without knowing how they voted?

Yes, a voting system can be designed to verify voter eligibility or record participation while keeping ballot choices separate from voter identity. For a secret ballot, the organisation should specifically confirm how the provider’s technical design prevents an individual’s voting choices from being linked back to them.

What should we ask an online voting provider about data security?

Ask where voter information is stored and processed, who can access it, how administrator accounts are protected, whether MFA is used, what encryption and access controls are in place, whether overseas providers are involved, what audit records are available, how breaches are handled and what happens to personal information after the election.

Need support with your next Voting?

Contact Us

Subscribe to our blog

Stay up to date on the latest topics for voting solutions

[stc-subscribe]



    Subscribe

    If you want to personalise your subscription, click here