Privacy Policy
Last updated: 8 September 2026
The protection of personal data, voter confidentiality and ballot secrecy are fundamental principles of e-vote.online.
This Privacy Policy explains which personal data may be processed when using www.e-vote.online and the electronic voting services provided by e-vote.online, for what purposes, on what legal basis, for how long such data may be retained and which rights data subjects may exercise.
This Privacy Policy is drafted in accordance with Regulation (EU) 2016/679 of 27 April 2016, the General Data Protection Regulation (“GDPR”), as well as the applicable Belgian data protection legislation.
1. Identity and contact details
e-vote.online SRL
Private limited liability company incorporated under Belgian law
Registered office: Avenue de Foestraets 9, box 1 – 1180 Brussels, Belgium
Company number (BCE/KBO): BE 1001.030.397
VAT number: BE 1001.030.397
Register of Legal Entities (RLE/RPR): Brussels
E-mail: legal@e-vote.online
Telephone: +32 2 374 52 52
2. Role of e-vote.online
The role of e-vote.online depends on the processing activity concerned.
2.1. Processing in connection with an election or vote
Where an organisation uses e-vote.online to organise an election, vote or consultation, that organisation generally determines:
- the purpose of the vote;
- who is entitled to vote;
- which personal data are necessary;
- which electoral colleges or categories apply;
- which rules govern the vote;
- how the voting process is organised and supervised.
That organisation generally acts as the data controller within the meaning of the GDPR.
e-vote.online processes the personal data required for the vote in principle as a data processor, on behalf of and according to the documented instructions of the organiser, in accordance with Article 28 GDPR.
The identity and contact details of the organiser are communicated to voters in the information relating to the relevant vote.
2.2. Processing for which e-vote.online is itself responsible
e-vote.online acts as a data controller for processing activities for which it determines the purposes and essential means itself, including in particular:
- operation of the website;
- handling of contact requests;
- commercial relationships with clients and prospective clients;
- contract management;
- invoicing and accounting;
- security of its own IT systems;
- technical logging;
- incident management;
- compliance with legal obligations.
3. What personal data may be processed?
The personal data actually processed depend on the nature and configuration of the vote.
3.1. Identification data
This may include:
- surname;
- first name;
- voter number or another unique voter identifier;
- employee or membership number;
- date of birth;
- identity card number;
- Belgian National Register number, where its use is legally permitted;
- any other data required to establish a voter’s identity or voting entitlement.
Not all of these data are necessarily used for every vote.
3.2. Contact details
This may include:
- e-mail address;
- telephone number;
- postal address, where required for the organisation of the vote.
3.3. Data relating to voting entitlement
Depending on the vote, the following data may be processed:
- electoral college;
- constituency;
- staff or professional category;
- branch, site or organisational unit;
- entitlement to participate in one or more votes;
- registration status;
- the fact that a voter has exercised his or her voting right.
Certain elections may involve data which directly or indirectly reveal political opinions, trade union membership, religious or philosophical beliefs or other special categories of personal data within the meaning of Article 9 GDPR.
Such data are subject to enhanced protection.
4. Data minimisation
e-vote.online applies the principle of data minimisation.
Only personal data that are necessary for the organisation, security, supervision and proper conduct of the relevant vote are processed.
Personal data processed in connection with a vote are not used by e-vote.online for unrelated or incompatible purposes.
5. Separation between voter identity and ballot
The technical architecture of e-vote.online is designed to maintain a clear separation between:
- personal data required to identify and authenticate the voter and establish voting entitlement; and
- the ballot containing the voter’s selections.
The voter profile may be used in particular to:
- verify voting entitlement;
- authenticate the voter;
- record that the right to vote has been exercised.
The contents of the ballot are stored separately.
e-vote.online does not create or retain any mapping table linking the identity of a voter to his or her ballot.
The ballot contains no name, identification number or other directly identifying personal data of the voter.
6. Cryptographic identification of the ballot
Each ballot is assigned a cryptographic identifier generated locally on the voter’s device, within the voter’s browser.
This identifier is calculated from a combination of:
- a unique identification item belonging to the voter, such as an identity card number or, where legally permitted, the Belgian National Register number;
- a password known only to the voter;
- the unique identifier of the relevant vote.
The cryptographic calculation is performed locally using SHA-256.
The voter’s password is never transmitted to e-vote.online servers, is never stored by e-vote.online and is not known to the organiser of the vote.
Only the result of the cryptographic calculation is transmitted to the system and used as the ballot identifier.
SHA-256 is a cryptographic hash function standardised by the National Institute of Standards and Technology (NIST). It is designed so that, from the hash value alone, directly reconstructing the original input data is computationally infeasible.
Because the unique vote identifier is included in the calculation, the same voter using the same identification data and the same password in different votes will nevertheless obtain different ballot identifiers.
7. Password used to verify the ballot
The password used to generate the cryptographic ballot identifier must contain at least 15 characters.
The creation and assessment of this password take place in the voter’s browser.
e-vote.online implements technical controls designed to reduce the use of insufficiently strong or predictable passwords, including:
- a visual indication of password strength;
- analysis of length and predictability;
- rejection of commonly used or compromised passwords;
- encouragement to use a long, unique and difficult-to-guess passphrase.
Password assessment does not rely solely on formal composition rules such as mandatory upper-case letters, lower-case letters, digits or special characters.
Checking compromised passwords
The selected password is checked against a database of passwords known to have appeared in previous data breaches.
This check is carried out using a mechanism designed to preserve the confidentiality of the password.
A hash of the password is calculated locally in the browser. Only a limited part of that hash is used to query the verification service.
The password itself and the complete hash of the password are not disclosed to the external service.
The final comparison is performed locally in the browser.
A password identified as compromised is rejected.
8. Individual verification by the voter
A voter who has access to:
- his or her unique identification data;
- the self-selected password;
- the identifier of the relevant vote,
can reproduce the cryptographic calculation locally.
This enables the voter to regenerate the identifier of his or her ballot and verify:
- that the ballot is present;
- and that its contents correspond to the vote cast.
This verification capability does not rely on any secret key or mapping retained by e-vote.online.
e-vote.online does not possess the password required to perform this verification on behalf of the voter.
9. Anonymity of ballots
Once submitted, ballots are separated from the personal data used to identify voters.
e-vote.online does not retain any mapping table that would allow a particular ballot to be identified from the identity of a voter.
The secret information enabling the voter to locate his or her own ballot is never disclosed to e-vote.online.
Ballots separated in this way from identifying personal data are treated as anonymous ballots.
The architecture is designed to achieve, at the same time:
- ballot secrecy;
- anonymity of the ballot;
- individual verifiability by the voter;
- integrity of the voting process;
- the possibility of recount or audit.
10. Technical logs and security data
To ensure the security, availability and integrity of the service, e-vote.online may record certain technical data, including:
- IP address;
- date and time of connection;
- authentication events;
- access attempts;
- browser used;
- operating system;
- technical session identifiers;
- application errors;
- administrative actions;
- security events.
Technical logs do not contain the contents of ballots and are not used to determine how a specific voter voted.
11. Purposes of processing
Personal data may be processed for the following purposes:
- creating and managing electoral rolls;
- determining voting entitlement;
- registering voters;
- authenticating voters;
- providing practical information about the vote;
- preventing unauthorised voting;
- recording that voting rights have been exercised;
- receiving and recording ballots;
- ensuring the integrity of the vote;
- preventing and detecting fraud or misuse;
- securing the platform;
- counting votes;
- establishing results;
- enabling individual verification;
- enabling recounts or audits;
- providing technical support;
- documenting the proper conduct of the vote.
12. No commercial use of electoral data
Personal data received or generated in connection with a vote:
- are not sold;
- are not rented;
- are not used for advertising;
- are not used for direct marketing;
- are not used to enrich commercial databases;
- are not used to build political or trade union profiles of voters;
- are not used to analyse individual voting preferences;
- are not used to train artificial intelligence systems for e-vote.online’s own purposes.
13. Legal basis for processing
13.1. Processing in connection with a vote
The legal basis for the processing is determined by the organiser of the vote in its capacity as data controller.
Depending on the nature of the vote, processing may be based on:
- compliance with a legal obligation;
- performance of a task carried out in the public interest;
- performance of a contract;
- a legitimate interest;
- consent, where consent constitutes a valid legal basis in the circumstances.
Where special categories of personal data within the meaning of Article 9 GDPR are processed, one of the exemptions provided for in that Article must also apply.
13.2. Processing carried out by e-vote.online for its own purposes
For processing activities for which e-vote.online itself acts as data controller, the legal basis may include:
- performance of a contract;
- pre-contractual measures;
- compliance with legal obligations;
- a legitimate interest, in particular in relation to IT security, business operations and the protection of legal rights;
- consent, where legally required.
14. Use of the Belgian National Register number
The Belgian National Register number is subject to specific legal rules.
Where the National Register number is used in connection with a vote, the organiser is responsible for ensuring that the required legal basis or authorisation exists.
Where the National Register number is disclosed to e-vote.online, it is processed solely:
- on the instructions of the data controller;
- for purposes necessary to the relevant vote;
- within the limits permitted by applicable law.
e-vote.online does not use the National Register number for its own purposes.
15. Hosting
The e-vote.online services are hosted by:
OVH SAS
Société par actions simplifiée, subsidiary of OVH Groupe SA
Share capital: EUR 50,000,000
Registered office: 2 rue Kellermann, 59100 Roubaix, France
RCS Lille Métropole: 424 761 419
APE code: 2620Z
EU VAT number: FR 22 424 761 419
OVH acts as a technical hosting provider and, where it processes personal data on behalf of e-vote.online, as a sub-processor.
16. Other technical service providers
e-vote.online may use technical service providers necessary for the operation of the platform, including for:
- sending e-mails;
- sending SMS messages;
- backups;
- technical monitoring;
- cybersecurity.
Where such a provider processes personal data on behalf of e-vote.online, the contractual safeguards required by the GDPR are implemented.
An up-to-date list of relevant sub-processors may be requested at:
17. Who may access personal data?
To the extent necessary for the performance of their duties, personal data may be accessible to:
- the organiser of the vote;
- persons duly authorised by the organiser;
- authorised e-vote.online staff;
- technical providers necessary for operation of the service;
- authorised auditors and security experts;
- competent public authorities where disclosure is required by law.
Access rights are limited in accordance with the need-to-know principle and the relevant authorisations.
18. Transfers outside the European Economic Area
e-vote.online gives preference to processing and hosting within the European Economic Area.
Where personal data are transferred to a country outside the European Economic Area, such transfer is carried out only in accordance with Articles 44 et seq. GDPR and on the basis of the required safeguards.
19. Retention periods
e-vote.online applies limited retention periods.
19.1. Personal data relating to a vote
Personal data enabling a voter to be identified are retained for a maximum period of one month after the end of the relevant vote.
After this period, the data are deleted unless a legal obligation, court order or legally binding request from a competent authority exceptionally requires longer retention.
19.2. Technical logs
Technical and security logs containing personal data are retained for a maximum period of one month.
They are then deleted, unless longer retention is necessary for:
- investigating a security incident;
- investigating suspected fraud;
- legal proceedings;
- responding to a request from a competent authority;
- complying with a legal obligation.
19.3. Anonymous ballots
Ballots that can no longer be linked to an identified or identifiable natural person are not treated as personal data.
They may be retained for as long as necessary for:
- counting;
- verification of the vote;
- individual verification;
- recount;
- audit;
- evidence of the result in accordance with the rules applicable to the relevant vote.
20. Deletion of personal data
Once the applicable retention period has expired, personal data are deleted using appropriate procedures.
Backup and recovery procedures are organised in such a way as to respect the applicable retention periods and to avoid data whose retention period has expired being permanently reintroduced into production systems.
21. Security
Given the sensitive nature of electronic voting, e-vote.online implements appropriate technical and organisational measures to protect personal data and the voting system.
Depending on the component concerned, these measures may include:
- separation of identification data and ballots;
- access and authorisation management;
- limitation of administrative privileges;
- secure communications;
- cryptographic security mechanisms;
- logging of sensitive operations;
- backups;
- recovery procedures;
- monitoring;
- incident management;
- vulnerability management;
- restricted access to production environments.
For security reasons, e-vote.online does not publish technical information where disclosure could weaken the security of the platform.
22. Personal data breaches
e-vote.online maintains procedures for detecting, analysing and managing security incidents and personal data breaches.
Where e-vote.online acts as a processor, it notifies the relevant data controller of a personal data breach in accordance with the GDPR and the applicable contractual arrangements.
Where e-vote.online itself acts as data controller, it makes the notifications required by law to the competent supervisory authority and, where applicable, to the affected data subjects.
23. Rights of data subjects
Subject to the conditions laid down by the GDPR, data subjects may have, among others:
- the right to information;
- the right of access;
- the right to rectification;
- the right to erasure;
- the right to restriction of processing;
- the right to object;
- the right to data portability, where applicable;
- the right to withdraw consent where processing is based on consent;
- rights relating to solely automated individual decision-making.
These rights are not absolute and may be restricted where the GDPR or other applicable legislation so provides.
24. Exercising rights in connection with a vote
Where a request relates to a vote organised by a client of e-vote.online, the data subject should generally contact the organiser of the vote, who acts as data controller.
e-vote.online provides the organiser with the necessary assistance in handling such requests in accordance with its obligations as processor.
For processing activities for which e-vote.online itself acts as data controller, requests may be addressed to:
e-vote.online SRL
Avenue de Foestraets 9, box 1
1180 Brussels
Belgium
E-mail: legal@e-vote.online
Telephone: +32 2 374 52 52
Where necessary to prevent unauthorised access to personal data, e-vote.online may request reasonable additional information to verify the identity of the person making the request.
25. Anonymous ballots and data subject rights
Where a ballot has been permanently separated from the identity of the voter and e-vote.online no longer possesses information enabling the author of the ballot to be identified, e-vote.online cannot locate that ballot on the basis of the voter’s identity.
This technical impossibility results from the system designed to protect ballot secrecy and the anonymity of the ballot.
It does not affect the voter’s rights in relation to other personal data that continue to be processed.
26. No electoral profiling
e-vote.online does not carry out profiling for the purpose of determining or inferring voters’ political, trade union, religious or philosophical beliefs.
Automated vote counting consists of applying predefined rules to the recorded ballots.
It does not constitute individual profiling of voters.
27. Data Protection Impact Assessment
Depending on the nature, scale and sensitivity of a particular vote, a Data Protection Impact Assessment (DPIA) may be required under Article 35 GDPR.
Where e-vote.online acts as a processor, it provides the data controller with the information and reasonable assistance necessary for carrying out such an assessment.
28. Data Protection Officer
e-vote.online has not currently appointed a Data Protection Officer (DPO).
Questions relating to data protection may be addressed to:
e-vote.online periodically reassesses whether, in light of the nature, scope and scale of its processing activities, the appointment of a Data Protection Officer becomes necessary or legally required.
29. Cookies and similar technologies
The e-vote.online website may use cookies and similar technologies.
29.1. Strictly necessary cookies
Certain cookies may be required for:
- technical operation of the website;
- security;
- authentication;
- session management;
- remembering privacy preferences.
Where such cookies are strictly necessary for a service requested by the user, they may be used without prior consent where permitted by applicable law.
29.2. Non-essential cookies and technologies
Cookies and technologies used for audience measurement, analytics, marketing or other non-essential purposes are activated only after consent has been obtained where required by law.
Users must be able to refuse such technologies and subsequently withdraw their consent.
Further information about cookies used by e-vote.online is provided in the separate Cookie Policy.
30. Google Tag Manager and analytics tools
Where e-vote.online uses Google Tag Manager, it is used to manage the activation of technologies on the website.
Technologies that are not strictly necessary are not activated before the required user consent has been obtained.
Analytics tools are not used to:
- determine the contents of a vote;
- link a voter to a specific ballot;
- build an electoral profile;
- analyse individual voting preferences.
31. Complaints to the supervisory authority
A data subject who considers that his or her personal data have been processed in breach of applicable data protection law may lodge a complaint with the competent supervisory authority.
In Belgium:
Belgian Data Protection Authority
Rue de la Presse 35 / Drukpersstraat 35
1000 Brussels
Belgium
Where applicable, the data subject may also lodge a complaint with another competent European supervisory authority in accordance with the GDPR.
32. Contact
For any questions regarding this Privacy Policy or processing activities for which e-vote.online itself acts as data controller:
e-vote.online SRL
Avenue de Foestraets 9, box 1
1180 Brussels
Belgium
E-mail: legal@e-vote.online
Telephone: +32 2 374 52 52
33. Changes to this Privacy Policy
e-vote.online may amend this Privacy Policy, in particular to reflect:
- changes in applicable law or regulations;
- changes to the platform;
- changes in processing activities;
- changes to technical infrastructure;
- changes in service providers;
- recommendations or decisions of competent authorities.
The date at the top of this Privacy Policy indicates when it was last updated.