When an organization conducts an online vote, it entrusts its technology provider with the most sensitive asset of its democratic process: the electoral roll. Names, email addresses, national ID numbers, and, in many cases, verified membership in a trade union, political party, or specific association.
Launching a digital voting process is not merely a technical usability matter; it entails assuming a strict chain of legal responsibility under the General Data Protection Regulation (GDPR). At Demokratian, we designed our platform placing legal compliance and security at the core of our architecture.
Electoral rolls are not ordinary data (Art. 9 GDPR)
The GDPR distinguishes between standard personal data and special categories of personal data (Art. 9), which mandate heightened protection measures. This includes data revealing political opinions, trade union membership, or religious beliefs.
An electoral roll is not a neutral contact directory. The moment a citizen appears on the electoral roll for a vote held by a union, political party, or sectoral assembly, that context directly discloses their affiliation, political ideology, or membership in that organization. Therefore, this constitutes processing of special category data.
Unlike generic software vendors whose standard terms exclude Article 9 data processing, our platform is legally structured to handle voter rosters with political or trade union implications.
Article 28 guarantees (DPA): your legal compliance
The GDPR establishes that your organization acts as the Data Controller (determining who votes and for what purpose), while the voting platform acts as the Data Processor (processing data strictly under your instructions).
This relationship legally requires a Data Processing Agreement governed by Article 28 of the GDPR. Operating without one constitutes a major infringement subject to administrative fines.
At Demokratian, we do not hide these obligations in fine print. We have integrated Article 28 GDPR commitments directly into our General Terms and Conditions of Use (Clause 13) and Privacy Policy (Clause 5). Upon account creation, the legal framework is automatically executed, defining:
- The purposes of processing.
- Applied technical security measures.
- Data restriction protocols and permanent data destruction following tallying.
Furthermore, our entire infrastructure provider supply chain (servers, databases) is contractually bound to these same legal standards, utilizing EU-located servers.
Infrastructure and backups: 100% within the European Economic Area
For data as sensitive as election records, geographic location control is critical. Utilizing servers that automatically replicate data outside Europe (e.g., US servers without adequate safeguards) can constitute an unlawful international data transfer.
- Guaranteed physical location: both the primary servers hosting the Demokratian platform and automated backup systems are permanently located within the European Economic Area (EEA).
- No cross-border data leakage: none of our infrastructure or auxiliary service providers bypass this geographic restriction.
Advanced technical measures: encryption and audit logs
GDPR compliance is not just paperwork; it requires implementing technical measures to mitigate data breach risks. At Demokratian, we audit our infrastructure to ensure:
- Data encryption at rest: we implement encryption techniques (at both physical storage and database engine levels) ensuring electoral roll data remains inaccessible to unauthorized extraction attempts.
- Isolated architecture (secure multi-tenancy): each client operates on a dedicated database instance. This guarantees total isolation: organizational data is never commingled or exposed to another tenant's activity.
- Access logs and audit trails: we maintain detailed system activity logs. All technical maintenance accesses are fully logged, ensuring complete traceability required during regulatory audits.
The secret ballot by design principle
Beyond voter roster protection, Demokratian's ethical core is the complete dissociation between voter identity and ballot content.
By application design, the system verifies voter eligibility before casting, but once placed into the digital ballot box, it is technically impossible to link a voter's identity with their chosen option. Privacy is enforced directly by system architecture.
Agile incident response
The GDPR requires notification of personal data breaches to competent authorities within 72 hours (Art. 33). At Demokratian, we maintain documented incident response protocols and commit contractually to notify clients immediately of any infrastructure anomalies, enabling timely legal compliance.
If you are evaluating an online voting platform and wish to review our security measures or legal frameworks in our Terms of Use and Privacy Policy, contact us at info@demokratian.org.