Designing a voting system so coercion simply cannot work
In North Macedonia in 2025, someone was keeping a list of who showed up to vote — and that list was the whole point.
It is a Tuesday in late 2025, and a public-sector worker somewhere in North Macedonia is doing a quiet calculation. Her employer — a municipal office, a state enterprise, it doesn't much matter — wants her to vote. Not just to vote: to vote correctly, and to be seen doing it. She knows that others have been asked, informally, whether they turned out. She knows someone has been noting things down.
She does not know that international observers are watching too.
The OSCE's election-monitoring body, ODIHR, deployed a mission for North Macedonia's 2025 local elections. Its final report, published 7 April 2026, documented what the monitors found: allegations of vote-buying, pressure on public-sector employees and voters, and — the detail that matters most for this piece — instances of voter tracking on and around election day. Not rumor. Not opposition complaint. Documented observation by one of the world's most experienced independent election-monitoring bodies.
That phrase, "voter tracking," sounds almost bureaucratic. It is not. It is the operational spine of coercion.
The spreadsheet that makes a threat real
Here is how voter tracking works in practice. Before an election, someone compiles a list: employees of a state company, residents of a village, members of a community tied to a patron. On election day, a watcher — formal or informal — records who comes and goes from the polling station. After the polls close, the list of who-voted is compared against the employer's list of who-should-have-voted.
The comparison is the threat. You don't need to know how someone voted to punish them for not voting "right" — you just need to know they didn't show. And if someone did show, the implicit assumption is that they complied.
This is coercion made systematic. No individual confrontation required. No cash changing hands at the polling booth. Just a list, a checkmark, and the well-understood social fact that non-compliance has consequences.
ODIHR found the same basic pattern documented in multiple countries in recent years. In Georgia — the country in the Caucasus — observers recorded something even more granular during the October 2024 parliamentary elections. Their final report noted that issues with vote secrecy were observed in over 30 percent of polling-station observations: voters marking ballots in positions where others could see them, ballots being held up in ways that exposed choices before they reached the box, polling-station layouts that gave no real private space. That is not a rounding error. In nearly one in three observed stations, someone other than the voter could plausibly see the vote.
Those two findings, North Macedonia's tracking and Georgia's broken secrecy, point to a single design failure. And the fix is not better poll-worker training.
Why 'the ballot is secret' is not enough
The secret ballot was invented specifically to defeat what North Macedonia is still experiencing. The Australian Electoral Commission records that the "Australian ballot" — the state-printed, privately-marked ballot adopted in the 1850s — was implemented precisely because public voting "left voters vulnerable to intimidation and coercion." The British Parliament followed suit with the Ballot Act 1872, ending the era when a landlord could watch his tenants file past the poll and note how each one declared.
The insight was structural, not sentimental. A vote no one can observe is a vote no one can buy or coerce — not because people became more honest, but because the transaction became unenforceable. You can pressure someone all you like, but if you cannot verify what they actually did behind the curtain, the threat has no teeth.
That structural insight has a corollary that democracies have been slow to absorb: the secret ballot is a security property, and like all security properties, it can be defeated by the wrong system design.
The U.S. Court of Appeals for the First Circuit spelled the mechanism out plainly in Rideout v. Gardner (2016). The case was about ballot selfies — whether voters could photograph their own marked ballots. The state argued the ban protected against vote-buying, because a photo lets a voter prove how they voted to whoever paid them. The court acknowledged the history directly: secret-ballot reforms were adopted to "combat widespread vote buying and voter intimidation," practices that depend on a buyer or coercer being able to verify the vote. The logic is airtight. Secrecy defeats coercion by destroying the proof of delivery. Anything that restores that proof — a camera, a receipt, a visible mark — reopens the market.
And voter tracking exploits a cruder version of the same vulnerability. If you can establish that someone entered a polling station on election day, and the implicit social contract is that entering means compliance, you have half a proof. It is a blurry, probabilistic proof — but in an environment of sustained pressure on employees, blurry is enough.
The question for system designers is: how do you make even that blurry proof impossible to construct?
The gap that surveillance exploits
Modern voting systems — even well-designed ones — tend to solve a different problem than the one North Macedonia and Georgia illustrate. They focus on whether the count is accurate: did the machine record what the voter marked? Did the tally software add correctly? These are important questions, and we spend a great deal of space on this blog examining them.
But coercion does not primarily attack the count. It attacks the voter before the ballot ever reaches the box.
The attack surface is the linkage between a person's identity and their voting behavior. In the North Macedonia case, that linkage was partially established just by tracking physical presence. In Georgia, it was established by observers — official or not — watching the moment of marking. In Bulgaria, OSCE/ODIHR documented that ballot secrecy was compromised in 7 percent of observations and found indications of vote-buying outside polling stations — a reminder that the coercion ecosystem extends beyond the booth itself.
Albania's 2021 elections saw ODIHR document "widespread" allegations of vote-buying by political parties, with the monitors recommending that the state guarantee "the right to a free and secret vote and preventing any form of pressure on voters to disclose whether and how they voted." Kyrgyzstan's 2017 presidential election produced a parallel recommendation from the same body: "guarantee the right to a free and secret choice and to prevent any form of pressure on voters to disclose how they voted."
Country after country. Continent after continent. The pattern is not an aberration. Wherever a vote can be linked to a voter — however imperfectly, however probabilistically — a market for coercion opens.
The current toolkit — curtained booths, folded ballots, instructions not to photograph your choices — was designed for a world where the primary threat was a landlord watching you walk to the poll book. It was not designed for systematic employee-tracking spreadsheets, phone cameras, or the social infrastructure of organized workplace pressure.
Anonymity-by-design: a security requirement, not a preference
Here is the design goal stated plainly: a voter's choice must be provably unlinkable to their identity. Not just unlinkable in policy. Not just unlinkable in the absence of a corrupt official willing to dig through records. Unlinkable by construction — so that no one, including the election authority itself, can perform the linkage even if they wanted to.
This is the same language software engineers use when they talk about "privacy by design" in data systems. It means the architecture makes the breach impossible, not just against the rules.
What does that require?
First, physical anonymization at the moment of deposit. The act of placing a ballot in a box must be severed from the identity of the person placing it. Polling-station layouts that give observers sightlines to the marking moment fail this requirement. Transparent or labeled ballot envelopes fail it. A booth that faces a wall of glass fails it. This is a physical engineering problem, and it has known, inexpensive solutions — opaque booths, consistent folding, the universal ballot envelope — that Georgia's polling stations, in over 30 percent of observed instances, were not implementing.
Second, no traceable receipt the voter can be pressured to produce. One of the more counterintuitive results in voting-system design is that voter-verifiable receipts — the kind a voter takes home to confirm their ballot was counted — can, if they cryptographically prove how the voter voted, become coercion tools. The Rideout court saw the simpler version of this with phone cameras. The cryptographic version is subtler but real: a receipt that a voter can use to prove their choice to a third party reopens the vote-buying market. The right design gives the voter confidence their ballot was included in the tally without giving them — or anyone else — a linkable proof of how they voted.
Third, and most importantly: the election authority itself must not be able to reconstruct the link. This is where traditional systems, even well-run ones, fall short. If the authority holds the mapping between ballot number and voter identity, a corrupt or coerced official can reconstruct it. The architectural solution is to ensure that the mapping is never held — that the process of anonymization is irreversible and happens before the ballot enters any system that knows who cast it.
This is not a theoretical aspiration. Cryptographic voting research has produced protocols — mixnets, homomorphic tallying, blind signature schemes — specifically designed to sever this link while still producing a verifiable aggregate count. The tools exist. The question is whether election systems are built to use them.
What 'verifiable' has to mean on both sides of the equation
Most of this blog's coverage of verifiability focuses on the counting end: can the public confirm that the aggregate total reflects the individual ballots? That is a critical question, and the cases are grim — from Kenya's Supreme Court annulling a presidential election because result forms could not be traced to polling stations, to Malawi's courts voiding a presidential election over correction-fluid alterations to tally sheets, to Georgia (USA) running a full hand count of five million ballots to confirm a machine tally that, to its credit, held up.
But verifiability has a second dimension that is less discussed: can a voter confirm that their ballot was included without revealing to anyone — including themselves, for forensic purposes — how they voted?
These two requirements are in tension. Full transparency of individual ballots would make counting perfectly verifiable but would destroy anonymity and hand coercers a perfect audit trail. Zero linkage between ballots and voters protects anonymity but, in naive implementations, removes the ability to catch ballot stuffing or suppression.
The entire point of modern cryptographic voting design is to resolve this tension. A system built on verifiable anonymization — where the shuffle of ballots through a mixing process can be mathematically checked without anyone being able to reverse the shuffle — gives you both: public confidence in the aggregate result and no linkable proof for any coercer to demand.
The Swiss Post case from 2019 is instructive here, though for a cautionary reason: researchers Sarah Jamie Lewis, Olivier Pereira, and Vanessa Teague found that the mixnet's shuffle proof relied on a cryptographic trapdoor, meaning an authority with the right values could generate a proof that appeared valid while having altered votes. The lesson is not that cryptographic approaches fail — it is that they must be open to independent scrutiny. The flaw was found precisely because Swiss Post published the code. A closed, certified system would have sailed through unchallenged.
The German Federal Constitutional Court reached the complementary conclusion about opacity in 2009: the use of voting machines requires that essential steps of voting and counting "can be examined by the citizen reliably and without any specialist knowledge." Closed software fails this. A mixnet whose mathematical proof anyone trained can verify does not.
The problem with reassurance
When ODIHR observers flag voter tracking in North Macedonia, the official response tends to follow a predictable shape: investigations will be conducted, recommendations will be considered, the next election will be better. When Georgia's secrecy problems were documented, officials could point to legal provisions that technically require private marking.
These responses are not lies. But they are reassurances, and reassurances are not architecture.
A voting system that relies on officials choosing not to build a tracking spreadsheet is not a system that defeats coercion. It is a system that hopes officials won't.
The only durable answer is a design in which the spreadsheet is useless — where even perfect tracking of who entered a polling station produces no actionable intelligence for a coercer, because the connection between presence and choice is severed by the process itself. Anonymous ballot deposit. No linkable receipt. An authority that cannot, even if subpoenaed, produce a record of how any individual voted.
That is not the system most democracies currently run. It is the system they should be building toward.
The reassurances in North Macedonia and Georgia are worth exactly what every official reassurance in this space is worth: a claim made by the people who control the system, about the system they control, without a mechanism for anyone else to check it independently.
And in a race — local, parliamentary, presidential — decided by a margin smaller than the pool of people whose employer kept a list, that gap between reassurance and architecture is not theoretical. It is the result.
What would make it checkable — by anyone
Here is what a coercion-resistant, independently verifiable system would allow an ordinary observer to confirm, without special access:
That every cast ballot entered an anonymizing process — a cryptographic mix or equivalent — before it was associated with any tally. This step should be publicly logged and its integrity checkable by anyone with the mathematical proof.
That no receipt exists that a voter could be forced to produce to prove how they voted. This means the verification token a voter receives should confirm inclusion in the count without encoding their specific choice in a form linkable to them.
That the aggregate tally can be verified against the anonymized ballot pool by any independent party who downloads the published data — not by trusting the authority's announcement, but by rerunning the cryptographic check themselves.
None of this exists at scale in any major national election system today. Most systems offer one or two of these properties, partially. The gap between partial and complete is where voter tracking, workplace pressure, and the entire coercion economy lives.
The cases are documented. The tools exist. The design goal is clear: a choice provably unlinkable to a voter's identity is not a privacy nicety — it is the only architecture that makes coercion economically pointless.
What is still not independently checkable, in North Macedonia, in Georgia, in most of the world: whether the ballot cast by the worker who was watched going into the polling station is the same ballot that entered the count, connected to no name, verifiable by no employer, provable to no patron.
Until that is checkable — by math, not by promise — the spreadsheet stays useful.
See how this gap appears across different countries and systems →
Read the two-minute version of the coercion and anonymity problem →
Browse documented cases of vote-buying and broken ballot secrecy →
Sources
- OSCE/ODIHR — North Macedonia, Local Elections 2025: ODIHR EOM Final Report (7 Apr 2026)
- OSCE/ODIHR — Georgia, Parliamentary Elections, 26 October 2024: Final Report (20 Dec 2024)
- OSCE/ODIHR — Republic of Bulgaria, Early Parliamentary Elections 2 April 2023, Final Report
- OSCE/ODIHR — Republic of Albania Parliamentary Elections 25 April 2021, Final Report
- OSCE/ODIHR — Kyrgyz Republic, Presidential Election, 15 October 2017: Final Report
- U.S. Court of Appeals for the First Circuit — Rideout v. Gardner, No. 15-2021 (Sept. 28, 2016)
- Australian Electoral Commission — A short history of voting and the secret ballot
- UK primary legislation — Ballot Act 1872
- Bundesverfassungsgericht, Judgment of 3 March 2009, 2 BvC 3/07 and 2 BvC 4/07 (English translation)
- Supreme Court of Kenya, Presidential Election Petition No. 1 of 2017 (Odinga v IEBC), Judgment of 20 September 2017
- Supreme Court of Appeal of Malawi, Mutharika & Electoral Commission v Chilima & Chakwera, MSCA Constitutional Appeal No. 1 of 2020
- Georgia Public Broadcasting — Risk-Limiting Audit Confirms Biden Won Georgia
- Lewis, Pereira, Teague — Ceci n'est pas une preuve (trapdoor commitments in the Scytl-SwissPost Internet voting system), 2019