Voter-data security & breach notification
Is the data security regime for the voter registry (encryption requirements, breach notification, access logs) codified in statute?
Scoring rule
{
"type": "binary"
}Jurisdiction scores
| Jurisdiction | Score | Rationale & evidence | Source |
|---|---|---|---|
| Floridaus-fl | 1/1100.0% | § 97.0585 codifies voter-data confidentiality and exempts protected registration information from public-records disclosure. § 98.093 governs official information-sharing for roll integrity. “The following information held by an agency, as defined in s. 119.011 , and obtained for the purpose of voter registration is confidential and exempt from s. 119.07 (1)” | § view source claude-opus-4-7 2026-05-15 |
| Illinoisus-il | 1/1100.0% | 10 ILCS 5/1A-25 codifies the HAVA-compliant centralized statewide voter registration list. Security is HAVA-mandated by reference. Specific IL-level breach-notification language was not surfaced as a separate provision. “The centralized statewide voter registration list required by Title III, Subtitle A, Section 303 of the Help America Vote Act of 2002 shall be created and maintained by the State Board of Elections as provided in this Section” | § view source claude-opus-4-7 2026-05-13 |
| Bulgariabg | 0.5/150.0% | Чл. 86 codifies municipal commission transparency duties: public website publication of decisions, full minutes, results, scanned section protocols, but specifying 'при спазване изискванията за защита на личните данни' (data protection compliance). Partial security framework — public access carve-outs codified, no specific encryption/breach-notification standards. | § view source claude-opus-4-7 2026-05-12 |
| Denmarkdk | 0.5/150.0% | § 51 codifies impartiality + non-disclosure obligations for officials conducting voting (criminally penalized under § 106). § 62 codifies parallel for postal-vote receivers. § 104 (not in FTS top-5 for this datapoint) codifies retention of voter materials with statutory destruction after complaint period and GDPR-compliant research use. § 2 codifies extension to citizens abroad. § 49 codifies disability-assistance confidentiality. Voter-data security partially codified within the Act; full data-protection framework is in Databeskyttelsesloven (separate). | § view source claude-opus-4-7 2026-05-19 |
| Estoniaee | 0.5/150.0% | § 48⁸ and § 48⁶ codify a detailed data-security regime for the electronic voting system and the voter data within it — encryption, access logging, anonymisation and timed destruction — but breach notification for the voter registry as such sits in general data-protection law outside the election acts. “the authenticity of the data must be ensured and unauthorised modification of the data must be prevented by taking appropriate security measures, such as encryption of files or digital signing.” | § view source claude-opus-4-7 2026-05-21 |
| Georgiaus-ga | 0.5/150.0% | § 21-2-225 codifies confidentiality of original registration applications + limitations on data availability. § 21-2-225.1 codifies address confidentiality for protected electors. Voter-data security codified; breach-notification specifics live in Georgia's Personal Identity Protection Act (separate instrument). | § view source claude-opus-4-7 2026-05-19 |
| Greecegr | 0.5/150.0% | Ν. 4648/2019 Άρθρο 4(2) codifies special identity-verification + antifraud protections for the electronic diaspora-registration application (credentials from the Independent Public Revenue Authority). Specific to diaspora context, not a generalized voter-data security regime. “Η διαδικασία πρόσβασης στην ειδική εφαρμογή λαμβάνει ειδική μέριμνα για την ταυτοποίηση του εκλο- γέα και την αποτροπή κακόβουλης χρήσης αυτής” | § view source claude-opus-4-7 2026-05-13 |
| Kentuckyus-ky | 0.5/150.0% | KRS 116.095 codifies confidentiality of voter-registration data: a county clerk who permits inspection of registration records must redact Social Security numbers, and KRS 116.155 governs the registration form's contents. Confidentiality of sensitive registration data is codified, but no encryption mandate or data-breach-notification regime is codified. | § view source claude-opus-4-7 2026-05-20 |
| Minnesotaus-mn | 0.5/150.0% | § 201.1615 codifies information-sharing rules + restricted use of Social Security numbers in the statewide voter registration system. § 201.022 codifies the statewide registration system. § 201.081 codifies registration files. Voter-data security partially codified; breach notification lives in Minn. Stat. § 13.055 (Government Data Practices Act, separate instrument). | § view source claude-opus-4-7 2026-05-20 |
| Montanaus-mt | 0.5/150.0% | § 13-2-108 directs the Secretary of State to adopt rules on the technical security and information security of the statewide voter registration system (including shielding driver's-license and social-security numbers); the specifics — encryption, breach notification, access logs — are left to rule rather than codified in statute. | § view source claude-opus-4-7 2026-05-22 |
| New Yorkus-ny | 0.5/150.0% | § 3-103 codifies state board promulgation of minimum standards for computerized record-keeping systems maintained by county boards of elections (including security/access controls implicit in HAVA-compliant systems). § 5-614 codifies the statewide list. Voter-data security is codified but breach-notification specifics live in the NY SHIELD Act (separate instrument). | § view source claude-opus-4-7 2026-05-18 |
| North Dakotaus-nd | 0.5/150.0% | § 16.1-02-13 codifies central-voter-file pollbook generation with confidentiality of certain records. § 16.1-02-15 codifies availability for election-related uses with specified restrictions. § 16.1-02-11 codifies SoS rule-making for maintenance. § 16.1-07-10 codifies ballot custody. Voter-data security framework codified through chapter 16.1-02. | § view source claude-opus-4-7 2026-05-19 |
| Ohious-oh | 0.5/150.0% | ORC 3503.13 codifies the public-records status of the voter registration database with enumerated exemptions (SSN, DL, telephone, e-mail, citizenship proof, confidential records). Partial security: access carve-outs codified, not breach-notification per se. | § view source claude-opus-4-7 2026-05-12 |
| Pennsylvaniaus-pa | 0.5/150.0% | § 1309 codifies that absentee-ballot files are public records with 2-year retention BUT 'no proof of identification shall be made public, nor shall information concerning a military elector be made public which is expressly forbidden by the Department of Defense because of military security' — partial security/confidentiality codification. | § view source claude-opus-4-7 2026-05-12 |
| South Dakotaus-sd | 0.5/150.0% | § 12-4-9 codifies that 'an individual's social security number, driver license number, South Dakota nondriver identification number, or month and day of birth is not open to public inspection.' § 12-4-37.1 codifies historical-archive availability with PII restrictions. § 12-4-5.4 codifies registration information protection. Voter-data security partially codified; breach notification lives in SDCL 22-40-19 to 22-40-26 (separate). | § view source claude-opus-4-7 2026-05-19 |
| Swedense | 0.5/150.0% | 5 kap. 1 § codifies that 'for elections the central election authority shall, for each polling district, establish a list of those eligible to vote in the election (electoral roll).' 5 kap. 2 § codifies external-residency tracking. 5 kap. 10 § codifies duplicate voter card procedure. Voter-data security is governed by Sweden's Data Protection Act (Dataskyddslagen) implementing GDPR — separate instrument. | § view source claude-opus-4-7 2026-05-19 |
| Texasus-tx | 0.5/150.0% | § 13.103 codifies physical security of the voter-registration files — they 'shall be kept in the registrar's office at all times in a place and manner ensuring their security' — and § 13.004 codifies confidentiality of sensitive voter data (social security, driver's license, and protected residence addresses) and bars posting it on a website. No encryption mandate or data-breach-notification regime is codified, so the data-security regime is only partially codified. | § view source claude-opus-4-7 2026-05-20 |
| United Statesus | 0.5/150.0% | 52 USC § 21083 codifies the statewide voter registration list including 'unique identifier' and 'safeguards' for integrity, security, confidentiality; partial security framework without specific encryption or breach-notification standards. | § view source claude-opus-4-7 2026-05-12 |
| Vermontus-vt | 0.5/150.0% | § 2154 codifies access controls on the statewide voter checklist: the Secretary of State must limit each town clerk to editing only that municipality's portion of the checklist and must limit access to the checklist. Access security is codified, but no encryption mandate or data-breach-notification regime is codified. | § view source claude-opus-4-7 2026-05-21 |
| Alabamaus-al | 0/10.0% | Section 17-11-43 addresses only the confidentiality of *voted ballots*, not voter registry data security, encryption standards, or breach notification procedures. While it imposes a duty to protect ballot confidentiality, it does not establish a data security regime for the voter registry, does not enumerate encryption requirements, and does not define breach notification procedures. The statute is focused on overseas ballot request procedures rather than registry data protection. “(c) The absentee election manager and the staff of the absentee election manager shall ensure the confidentiality of all voted ballots, including voted ballots received by facsimile.” | § view source claude-haiku-4-5 2026-06-09 |
| Alaskaus-ak | 0/10.0% | This section designates certain voter data as confidential and restricts disclosure, but does not codify encryption requirements, breach notification procedures, or access logging for the voter registry. The statute addresses confidentiality and authorized disclosure pathways, not the technical security regime or breach response obligations. “in compliance with federal law, information made confidential by this section may be released by the division to a local, state, or federal government agency, including to the child support services agency created in AS 25.27.010 or the child support enforcement agency of another state; the agency receiving information under this paragraph may use the information only for governmental purposes authorized under law” | § view source claude-haiku-4-5 2026-06-15 |
| Argentinaar | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Article 88 governs the right to vote and the mechanics of accepting or rejecting voters at the poll based on registry status and presentation of civic documents. It contains no provisions addressing data security, encryption, breach notification, access logs, or any other element of voter-data security infrastructure. The criterion asks whether data security requirements are codified in statute; this section deals only with voting eligibility and poll-site procedures. | § view source claude-haiku-4-5 2026-06-10 |
| Arizonaus-az | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Section 16-165 governs voter registration cancellation procedures—when and how to remove voters from the rolls—but contains no provisions addressing voter-data security, encryption requirements, breach notification procedures, or access logging for the voter registry. The criterion requires statutory codification of data security and breach notification regimes; this section addresses registration status changes only. | § view source claude-haiku-4-5 2026-06-04 |
| Arkansasus-ar | 0/10.0% | The statute addresses confidentiality of certain voter data for domestic violence victims but does not codify a comprehensive data security regime. It does not enumerate encryption requirements, breach notification procedures, or access logging standards for the voter registry. Instead, it delegates implementation details to the Secretary of State through administrative rulemaking (subsection (d)). | § view source claude-haiku-4-5 2026-06-08 |
| Armeniaam | 0/10.0% | No candidate sections returned by FTS. | no FTS match claude-opus-4-7 2026-05-17 |
| Australiaau | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Section 90 addresses only the manner and form in which Electoral Commission may provide access to electoral rolls (electronic vs. paper, public inspection vs. distribution). It contains no statutory codification of data security requirements, encryption standards, breach notification procedures, or access logging. The section grants discretion to the Commission regarding presentation format but is silent on the security regime itself. | § view source claude-haiku-4-5 2026-06-08 |
| Austriaat | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: § 25 NRWO establishes procedural rules for voter-registry inspection, publication, and access (including online access via qualified electronic signature), but contains no statutory codification of data security, encryption requirements, breach notification obligations, or access-logging regimes. The section addresses transparency and public inspection mechanisms, not the underlying security architecture that would satisfy the criterion. | § view source claude-haiku-4-5 2026-06-16 |
| Belarusby | 0/10.0% | No candidate sections returned by FTS. | no FTS match claude-opus-4-7 2026-05-18 |
| Belgiumbe | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: This section addresses the procedural mechanics of electoral-dispute resolution (decision-making, appeal declaration, and finality of rulings), but contains no data-security provisions, encryption requirements, breach-notification duties, or access-control specifications. The section does not codify any voter-registry security regime. | § view source claude-haiku-4-5 2026-06-13 |
| Brazilbr | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Article 107 is a repealing clause that revokes specific provisions from prior electoral laws. It contains no substantive provisions regarding voter-data security, encryption requirements, breach notification procedures, or access logs. The section does not establish or codify any data security regime. | § view source claude-haiku-4-5 2026-06-02 |
| Californiaus-ca | 0/10.0% | No candidate sections returned by FTS. | no FTS match claude-opus-4-7 2026-05-17 |
| Canadaca | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Section 45 governs the distribution and format of voter lists to MPs and registered parties, specifying what information must be included and how it is arranged. It contains no provisions regarding data security, encryption requirements, breach notification procedures, or access logging for the voter registry. The procedural clarity required by the criterion — statutory codification of security measures — is entirely absent from this section. | § view source claude-haiku-4-5 2026-06-05 |
| Chinacn | 0/10.0% | No matching sections in corpus. | no FTS match no-fts-match 2026-06-01 |
| Coloradous-co | 0/10.0% | The statute mandates confidentiality of SSNs and requires development of 'appropriate security measures,' but does not codify specific technical requirements (encryption standards, access logs, audit trails) or a defined breach notification procedure. The obligation to develop measures is delegated to county clerk discretion rather than enumerated in statute. | § view source claude-haiku-4-5 2026-06-03 |
| Connecticutus-ct | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: § 9-50d addresses confidentiality and nondisclosure of certain voter registration data elements (date of birth, ID numbers, names in safety cases), but it does not codify a data security regime. The statute does not specify encryption requirements, breach notification procedures, access logs, or other security measures for the voter registry system. Confidentiality rules and security protocols are distinct procedural elements. | § view source claude-haiku-4-5 2026-06-15 |
| Croatiahr | 0/10.0% | No matching sections in corpus. | no FTS match no-fts-match 2026-06-16 |
| Czechiacz | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Section 28 addresses the procedural steps for EU citizens to request inclusion in the Czech voter registry for European Parliament elections. It specifies submission deadlines, required documentation, acceptable submission methods, and notification timelines, but contains no provisions governing data security, encryption, breach notification protocols, or access logging for the voter registry. The section is entirely procedural with respect to voter registration requests, not data protection or security infrastructure. | § view source claude-haiku-4-5 2026-06-14 |
| Delawareus-de | 0/10.0% | §1303 provides statutory prohibition on unauthorized disclosure of confidential addresses and breach notification after disclosure (subsection (b)(2)), but does NOT codify encryption requirements, systematic access logs, or a comprehensive data security regime for the voter registry generally. The section addresses confidentiality protections for a specific subset of voter data (confidential addresses) rather than the broad data-security infrastructure—encryption standards, breach-reporting timelines for other data types, audit trails, etc.—that the criterion requires. “It shall be unlawful for any person knowingly to obtain or disclose any address from voter records that is rendered confidential for any use not permitted under this section.” | § view source claude-haiku-4-5 2026-06-15 |
| Finlandfi | 0/10.0% | No candidate sections returned by FTS. | no FTS match claude-opus-4-7 2026-05-20 |
| Francefr | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Article L560 addresses only eligibility criteria for participation in a territorial consultation — specifically that registered voters on the territorial electoral list may participate. It contains no language whatsoever regarding data security, encryption, breach notification, access logs, or any cyber-protection regime for voter registries. The section is purely substantive about who may vote, not procedural about how voter data is protected. | § view source claude-haiku-4-5 2026-06-12 |
| Georgiage | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Article 8 covers election-commission rules of operation generally. No specific voter-registry data-security regime (encryption, breach notification) codified in surfaced corpus. | § view source claude-opus-4-7 2026-05-18 |
| Germanyde | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: § 21 BWO addresses the physical and procedural access to the voter registry (viewing times, location, device operation), but contains no codification of data security elements such as encryption requirements, breach notification procedures, or access logging. The statute specifies only that automated systems may be used and that a public official must operate any viewing device; it does not establish the security regime required for the criterion. | § view source claude-haiku-4-5 2026-06-07 |
| Greenlandgl | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: The section addresses voter-list publication requirements and includes a minimal data-protection constraint (prohibition on including personal ID numbers in published lists), but it does not codify any statutory data-security regime for the voter registry itself—no encryption requirements, breach-notification procedures, access-log mandates, or security standards are enumerated. | § view source claude-haiku-4-5 2026-06-06 |
| Hawaiius-hi | 0/10.0% | The statute designates certain voter data as confidential and invokes chapter 91 (administrative rulemaking), but does not itself codify specific data security measures (encryption, breach notification, access logs). Instead, it delegates security rules to the chief election officer's discretion within chapter 91, leaving the core procedural requirements undefined in statute. “A voter's full name, district/precinct designation, and voter status shall be public; but all other personal information, as provided on the voter registration affidavit, shall be confidential except for election or government purposes in accordance with rules adopted by the chief election officer, pursuant to chapter 91.” | § view source claude-haiku-4-5 2026-06-15 |
| Icelandis | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Article 30 addresses publication and public inspection of electoral registers, but contains no statutory codification of data security measures (encryption, access controls, audit logs) or breach notification procedures. The section permits ministerial regulations to detail publication rules, but does not itself establish security requirements or notification protocols. Data security governance is conspicuously absent from the text. | § view source claude-haiku-4-5 2026-06-06 |
| Idahous-id | 0/10.0% | The statute delegates security requirements to administrative discretion ('such security measures necessary') without specifying encryption standards, breach-notification procedures, or access-log requirements. While data security is mentioned, the procedural details are not enumerated in statute, leaving implementation to the Secretary of State's administrative judgment. “The office of the secretary of state shall use such security measures necessary to ensure the accuracy and integrity of an electronically submitted voter registration application.” | no FTS match claude-haiku-4-5 2026-06-01 |
| Indianaus-in | 0/10.0% | The section imposes confidentiality obligations and limits use of voter-data information, but does not codify encryption requirements, access logs, or breach-notification procedures. The statute addresses information handling and public-records redaction but lacks the technical and operational security measures required by the criterion. | § view source claude-haiku-4-5 2026-06-12 |
| Iowaus-ia | 0/10.0% | The statute delegates the core data security regime—encryption requirements, breach notification procedures, and access logs—to administrative rules rather than codifying them in statute itself. While § 47.7(2)(d) mandates that the registrar 'prescribe by rule' certain safeguards and breach protocols, the actual specifications are left to regulatory discretion, not statutorily enumerated. This fails the procedural-clarity test: neither a left-leaning nor right-leaning election scholar would deem unspecified rule-making authority a sufficient statutory codification of security requirements. | § view source claude-haiku-4-5 2026-06-06 |
| Irelandie | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Section 95 addresses the establishment and maintenance of a pending elector list for 16–17-year-olds, specifying content, confidentiality, and transfer procedures. It contains no provisions regarding data security, encryption, breach notification, or access logs for the voter registry. The section is procedurally focused on age-based registration mechanics, not on the security regime required by ROLL.1. | § view source claude-haiku-4-5 2026-06-03 |
| Kansasus-ks | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Section 25-2309 prescribes voter registration application procedures and required data elements but does not address data security, encryption requirements, breach notification protocols, or access logging for the voter registry. The statute focuses on what information must be collected and how applications are processed, not how that collected data is secured or how breaches are reported. | § view source claude-haiku-4-5 2026-06-06 |
| Kazakhstankz | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Article 27 addresses pre-election campaign procedures, restrictions, and conduct — it does not contain any provisions regarding voter-data security, encryption requirements, breach notification protocols, or access logs for the voter registry. The section is entirely focused on campaign speech and behavior regulation, not data governance. | § view source claude-haiku-4-5 2026-06-02 |
| Latvialv | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: FTS surfaced candidate-data-processing and signature-collection provisions; the data-security regime for the electoral register sits in Latvia's separate Electoral Register Law and the general data-protection law, outside this corpus. | § view source claude-opus-4-7 2026-05-22 |
| Lithuanialt | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: FTS surfaced candidate-rights provisions; the data-security regime for the Voter List sits in the Population Register law and general data-protection law, outside this election-law corpus. | § view source claude-opus-4-7 2026-05-23 |
| Louisianaus-la | 0/10.0% | This section establishes statutory restrictions on access to and disclosure of certain voter data categories (SSN, DOB, email, etc.) and procedures for copying records, but does not codify encryption requirements, breach notification procedures, or access logging requirements. The statute enumerates data elements to protect but lacks the technical security specifications and incident-response procedures necessary to satisfy the criterion. | § view source claude-haiku-4-5 2026-06-08 |
| Luxembourglu | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Article 30 addresses procedural transfer of electoral files from district commissioner to peace court on September 1st and certification of electoral lists for litigation purposes. It contains no provisions regarding data security, encryption, breach notification, access logs, or any data protection regime for the voter registry. The section is entirely administrative process-focused and does not codify any data security requirements. | § view source claude-haiku-4-5 2026-06-16 |
| Madagascarmg | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Article 21 addresses voter verification procedures and inscription challenges but contains no provisions regarding data security, encryption requirements, breach notification protocols, or access logs for the voter registry. The section is exclusively procedural regarding voter verification deadlines and attestations, not data protection or security regime. | § view source claude-haiku-4-5 2026-06-10 |
| Maineus-me | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: This section delegates authority to the Secretary of State to adopt administrative rules regarding voter data security and confidentiality, but does not codify specific data security requirements (encryption, breach notification procedures, access logs) in statute itself. The criterion requires the regime to be codified in statute, not left to administrative rule-making. While the statute authorizes confidentiality and use limitations, the concrete procedural requirements for security and breach notification are delegated to future rulemaking without statutory enumeration. | § view source claude-haiku-4-5 2026-06-15 |
| Maltamt | 0/10.0% | The statute mandates that the Commission ensure security procedures and control over voter data access and processing, but does not codify specific technical requirements (encryption, breach notification, access logs) in statute. The provision delegates implementation to the Commission without enumerated safeguards, failing the dual-scholar test for procedural clarity and statutory specificity. “The Commission is to ensure that there is full observance of procedures of control and security, especially with regards to access of terminals, the introduction, use and processing of information and in the printing of documents of identification.” | § view source claude-haiku-4-5 2026-06-16 |
| Marylandus-md | 0/10.0% | The section establishes a statutory breach notification procedure (7-day reporting requirement) and defines security violations by reference to state policy, but does not codify encryption requirements, access-log standards, or retention rules. It addresses notification timing and reporting path but leaves the substantive data-security regime to Department of Information Technology policy rather than statute. “Within 7 days after becoming aware of a security violation or significant attempted security violation, the State Administrator shall submit to the Department of Information Technology and the appropriate persons a report on each security violation and significant attempted security violation involving an election system” | § view source claude-haiku-4-5 2026-06-15 |
| Massachusettsus-ma | 0/10.0% | The statute requires the state secretary to adopt regulations that include 'data security protocols,' but it delegates the actual codification of security requirements to regulations rather than enumerating them in the statute itself. There is no statutory specification of encryption, breach notification procedures, or access logs—only a directive to adopt regulations covering these matters. This satisfies the procedural requirement to have rules, but not the EAI standard that such rules be statutorily grounded and enumerated. “The state secretary shall adopt regulations governing such transmission, which shall include, but not be limited to: (i) provisions requiring electronic transmission; (ii) the frequency and nature of such transmissions; (iii) data security protocols; and (iv) integration with the online portals established pursuant to section 33A.” | § view source claude-haiku-4-5 2026-06-10 |
| Mexicomx | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Article 279 addresses voting procedures at the polling place (ballot marking, ballot casting, credential marking, and indelible ink application), but contains no provisions regarding voter registry data security, encryption requirements, breach notification, or access logs. The criterion concerns the data security regime for the voter registry itself, which is distinct from the mechanics of the voting transaction described in this section. | § view source claude-haiku-4-5 2026-06-07 |
| Michiganus-mi | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: The section delegates security features entirely to administrative discretion ('determined appropriate by the secretary of state') and contains no statutory requirements for encryption, breach notification, or access logs. | § view source claude-opus-4-7 2026-05-12 |
| Mississippius-ms | 0/10.0% | The statute delegates security requirements to the Secretary of State's discretionary rulemaking authority (subsection 4), rather than codifying them directly in statute. While subsection 4(c)–(e) envision security measures, they are stated as requirements for administrative rules, not statutory mandates. Critically, there is no mention of encryption requirements, breach notification procedures, or access logging—key elements of data security governance. The procedural clarity is insufficient because the actual security specifications are left to administrative discretion. | § view source claude-haiku-4-5 2026-06-09 |
| Missourius-mo | 0/10.0% | The statute requires the Secretary of State to implement 'adequate technological security measures' but does not enumerate specific requirements (encryption, access logs, etc.) or establish a breach notification procedure. The provision delegates detailed security standards to administrative discretion rather than codifying them statutorily, failing the procedural-clarity requirement. “The secretary of state shall provide adequate technological security measures to prevent the unauthorized access to the system established pursuant to this section.” | § view source claude-haiku-4-5 2026-06-08 |
| Moldovamd | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Article 61 establishes the composition, content, distribution, and procedural timeline for electoral rolls, but contains no statutory provisions regarding data security, encryption requirements, breach notification procedures, or access logging for the voter registry. The section delegates rule-making on 'establishment, administration, dissemination and updating' to the Central Electoral Commission (subsection 1), but does not codify security standards in statute itself. Data protection is left to administrative regulation rather than statutory enumeration. | § view source claude-haiku-4-5 2026-06-09 |
| Nebraskaus-ne | 0/10.0% | The statute requires breach notification to officials 'without delay,' providing a clear mandatory disclosure procedure. However, it does not codify encryption requirements, access-logging protocols, or specific security standards for data storage and protection. The statute addresses only the notification consequence of a breach, not the preventive security measures themselves. “Any person who acquires a list of registered voters under subsection (2) of this section shall, following discovery or notification of a breach in the security of the storage of the information, disclose the breach in security to the Secretary of State, election commissioner, or county clerk without delay.” | § view source claude-haiku-4-5 2026-06-05 |
| Netherlandsnl | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: This section addresses the handling of candidate lists and supporting declarations by the central electoral bureau and local administrators—specifically their transmission, public inspection, and destruction. It contains no provisions concerning voter-data security, encryption requirements, breach notification procedures, or access logging for the voter registry. The section is about electoral materials management, not voter-data protection. | § view source claude-haiku-4-5 2026-06-08 |
| Nevadaus-nv | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: NRS § 293.558 addresses disclosure restrictions and confidentiality of specific voter data elements (SSN, driver's license number, email address), but contains no provisions regarding data security infrastructure, encryption requirements, breach notification procedures, or access logging. The section is focused on what information may or may not be released to the public, not on how the registry itself is secured or how breaches are handled. | § view source claude-haiku-4-5 2026-06-01 |
| New Hampshireus-nh | 0/10.0% | The statute mandates a centralized voter database and requires 'safeguards' to prevent erroneous removal of voter records, but does not enumerate specific security requirements (encryption, access logs, breach notification procedures) or establish a statutory cure/notification regime. The word 'safeguards' is vague and delegates implementation to administrative discretion without statutory specification of what those safeguards must be. “The system shall contain safeguards to ensure that the names of properly registered voters are not removed in error.” | § view source claude-haiku-4-5 2026-06-15 |
| New Jerseyus-nj | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: This section addresses provisional ballot handling and custody procedures—specifically how voted provisional ballots are placed in envelopes, sealed, and transferred to the district board. It contains no provisions addressing voter registry data security, encryption requirements, breach notification procedures, or access logging. The section's scope is ballot chain-of-custody during voting, not the statutory codification of voter-data protection regimes. | § view source claude-haiku-4-5 2026-06-15 |
| New Mexicous-nm | 0/10.0% | The statute requires the secretary of state to ensure security and confidentiality of online voter registration systems, but it does not codify specific procedural requirements: no encryption standards are enumerated, no breach notification protocol is established, and no access-log or audit-trail requirements are specified. The mandate is aspirational and delegated to the secretary of state's discretion rather than set forth in statute with defined procedures. | § view source claude-haiku-4-5 2026-06-04 |
| North Carolinaus-nc | 0/10.0% | The statute mandates that guidelines include 'protecting and securing the data,' but this delegates the actual security regime (encryption, access logs, breach notification protocols) to State Board discretion rather than codifying it in statute. The section provides no enumerated security standards, encryption requirements, breach notification timelines, or access-control specifications that would constitute a clear statutory procedure. “Protecting and securing the data.” | § view source claude-haiku-4-5 2026-06-15 |
| North Koreakp | 0/10.0% | No matching sections in corpus. | no FTS match no-fts-match 2026-06-01 |
| Norwayno | 0/10.0% | § 16-1 codifies grounds for complaint including unlawful breach of preparation rules. Voter-data security is governed primarily by the Norwegian Personal Data Act (Personopplysningsloven, LOV-2018-06-15-38) implementing GDPR — separate instrument. Within Valgloven, data-handling rules live in § 2-3 (Ministry responsibility) and § 2-4 (access to Population Register). | § view source claude-opus-4-7 2026-05-19 |
| Oklahomaus-ok | 0/10.0% | The statute requires that voter registration and motor vehicle license data 'shall be done in a secure manner,' establishing a statutory duty. However, this phrase is vague and does not enumerate specific security measures (encryption standards, access logs, audit trails) or define breach notification procedures. The statute lacks the specificity needed to satisfy the criterion's requirement for a codified data security regime with enumerated technical controls and defined breach-notification pathways. | § view source claude-haiku-4-5 2026-06-07 |
| Oregonus-or | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: ORS § 247.208 addresses voter registration agency designation, services, and procedural requirements under the National Voter Registration Act, but contains no statutory language on data security, encryption, breach notification procedures, or access logs for voter registry data. The section focuses on registration processes and conduct of registration personnel, not the technical or administrative security infrastructure governing voter data. | § view source claude-haiku-4-5 2026-05-31 |
| Polandpl | 0/10.0% | No matching sections in corpus. | no FTS match no-fts-match 2026-05-30 |
| Portugalpt | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Article 51 establishes administrative procedures for copying and accessing voter registry cadernos (poll books) but does not address data security, encryption, breach notification, or access logging. The section specifies *who* may access copies (poll workers and list delegates), *when* (two days before election, anytime for delegates), and *how* (authenticated copies), but contains no statutory codification of encryption standards, breach-notification protocols, or audit trails—the core elements of a data-security regime. | § view source claude-haiku-4-5 2026-06-16 |
| Rhode Islandus-ri | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: The section establishes procedures for electronic voter registration and information sharing between agencies, but contains no statutory codification of data security requirements (encryption standards, breach notification protocols, or access logging requirements). While the statute addresses confidentiality and data use restrictions, it does not enumerate specific security measures or breach-notification procedures that must be followed. The procedural clarity required by the EAI criterion is absent. | § view source claude-haiku-4-5 2026-06-15 |
| Romaniaro | 0/10.0% | No matching sections in corpus (FTS returned 0 candidates) — concept not codified in this jurisdiction's election statute. | no FTS match no-fts-match 2026-05-12 |
| Russiaru | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Article 33 covers candidate-nomination data handling, Article 56 campaign restrictions, Article 53 mass campaigning, Article 59 fund expenditure, Article 40 official-position restrictions. No specific voter-data security/breach regime codified in surfaced corpus. | § view source claude-opus-4-7 2026-05-18 |
| Serbiasr | 0/10.0% | No candidate sections returned by FTS. | no FTS match claude-opus-4-7 2026-05-15 |
| South Africaza | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Section 23 addresses the procedural requirements for conducting a revote when ballot papers are lost, destroyed, or unlawfully removed—a voting-station-level operational matter. It contains no provisions regarding voter-registry data security, encryption, breach notification, access logs, or any aspect of voter-data protection. The criterion evaluates whether data-security safeguards for the voter roll itself are codified in statute; this section is entirely outside that scope. | § view source claude-haiku-4-5 2026-06-09 |
| South Carolinaus-sc | 0/10.0% | The statute imposes a general mandate that voter registration information be protected and requires the State Election Commission to consider federal security standards. However, the procedure is not exhaustively enumerated—'current best practices' is delegated to the SEC's discretion and to external federal standards not codified in statute. Critically, there is no statutory requirement for breach notification procedures, no mandated encryption specifics, no access-log requirements, and no defined cure or appeal path for security violations. The annual certification requirement provides minimal accountability. “The State Election Commission shall ensure that voter registration information, the voting system, and electronic poll books are protected by security measures that meet or exceed current best practices for protecting data integrity.” | § view source claude-haiku-4-5 2026-06-15 |
| Spaines | 0/10.0% | Article 41 establishes statutory restrictions on voter-data access (prohibition on particularized disclosure except by judicial order) and delegates detailed data-security specifications to royal decree (real decreto). While the statute sets a clear policy boundary, it does not itself codify specific encryption requirements, breach notification procedures, or access-logging protocols—these are delegated to subordinate regulation. The criterion requires security specifications to be codified in statute, not deferred to administrative instruments. | § view source claude-haiku-4-5 2026-06-16 |
| Tennesseeus-tn | 0/10.0% | The statute mandates a unique identifier system and confidentiality protections, but does not codify encryption requirements, breach notification procedures, or access logging standards. These critical data security elements are left unaddressed, making the security regime incomplete and potentially delegated to administrative discretion (the coordinator may 'promulgate policies or rules'). “The online voter registration system shall use a unique identifier for each applicant to prevent unauthorized persons from altering a voter's registration information. Any unique identifier, including driver license and social security numbers, shall be confidential and not subject to the open records law, compiled in title 10, chapter 7.” | § view source claude-haiku-4-5 2026-06-11 |
| Turkeytr | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: No candidate codifies encryption, breach-notification, or access-log requirements specifically for the voter registry. General data-protection law (KVKK 6698) applies but is not in the election-law corpus. | § view source claude-opus-4-7 2026-05-17 |
| Ukraineua | 0/10.0% | Art. III-169 codifies ballot-paper printing procedure (secure printing). Art. II-113 codifies ballot papers. Art. III-176 codifies precinct protocols. Voter-data security is governed by the State Voter Register Law and Ukrainian data-protection laws (Law 'On Protection of Personal Data') — separate instruments. | § view source claude-opus-4-7 2026-05-19 |
| United Kingdomgb | 0/10.0% | No section in the FTS-surfaced candidates satisfies this criterion. Best signal: Section 13 of the Electoral Administration Act 2006 addresses service voter registration, declaration procedures, and arrangements for military personnel to exercise voting rights. It does not establish or codify any data security regime for the voter registry, including encryption requirements, breach notification procedures, or access logs. The section is procedurally focused on eligibility and voting access, not data protection. | § view source claude-haiku-4-5 2026-05-31 |
| Utahus-ut | 0/10.0% | The statute requires data encryption or similar security for shared records (Subsection 2(b)(iii)), establishing a minimal encryption mandate. However, the statute does not codify breach notification procedures, access logging requirements, or comprehensive security standards across the entire voter registration system. These critical security elements are absent from the statutory text, leaving significant gaps in the data security regime. “that the record is secure from unauthorized use by employing data encryption or another similar technology security system” | § view source claude-haiku-4-5 2026-06-02 |
| Virginiaus-va | 0/10.0% | The statute delegates the core data security regime—encryption requirements, breach notification protocols, and access logs—to the State Board to establish through regulation, rather than codifying these requirements in statute itself. While the section mandates that security standards exist and be updated annually, it does not enumerate specific statutory requirements for encryption, breach notification procedures, or access-log standards. The section thus fails the EAI's procedural-clarity test: a dual-scholar review would conclude that actual security specifications are left to administrative discretion rather than grounded in statute. “The State Board shall promulgate regulations and standards necessary to ensure the security and integrity of the Virginia voter registration system” | § view source claude-haiku-4-5 2026-06-15 |
| Washingtonus-wa | 0/10.0% | This section establishes statutory breach-notification obligations and requires intrusion detection systems (subsection 2), but does not enumerate encryption requirements for voter data or mandate access logs. The statute mandates WHO must notify and WHEN, but omits core data-security procedural elements: no specified encryption standards, no required audit logging, no defined cure procedures if a breach occurs, and no appeal mechanism. Breach notification without security architecture requirements leaves the core criterion unsatisfied. “A county auditor or county information technology director of any county, participating in the shared voter registration system operated by the secretary of state under RCW 29A.08.105 and 29A.08.125, or operating a voting system or component of a voting system that is certified by the secretary of state under RCW 29A.12.020 shall disclose to the secretary of state and attorney general any malicious activity or breach of the security of any of its information technology (IT) systems immediately following discovery” | § view source claude-haiku-4-5 2026-05-26 |
| West Virginiaus-wv | 0/10.0% | The statute mandates 'adequate technological security measures' in broad terms, but does not enumerate specific requirements such as encryption standards, breach notification procedures, or access-logging protocols. The language delegates the substance of security implementation to administrative discretion rather than codifying concrete procedural safeguards in statute. “The Secretary of State and the clerks of all county commissions shall provide adequate technological security measures to prevent the unauthorized access to the statewide voter registration database established under this section.” | § view source claude-haiku-4-5 2026-06-14 |
| Wisconsinus-wi | 0/10.0% | No candidate sections returned by FTS. | no FTS match claude-opus-4-7 2026-05-18 |
| Wyomingus-wy | 0/10.0% | The statute establishes confidentiality requirements for sensitive voter data (SSNs, driver's license numbers, birthdates, phone numbers, tribal ID numbers, emails), which creates a baseline data protection classification. However, it does not codify affirmative security requirements (encryption standards, access controls, logging), nor does it establish breach notification procedures. The section defines what must be kept confidential but not how security breaches must be reported or remediated. | § view source claude-haiku-4-5 2026-06-16 |
About this datapoint
Each score is one of: strong, partial, gap, or no codified provision. The evidence quote is a byte-exact substring of the cited statute section at scoring time. If the statute is amended, the old score is preserved with is_current=0 and a new score is inserted on top — never overwritten.