The 'public' in public elections: a legal idea worth reviving
In 2009, Germany's highest court ruled that if ordinary citizens can't check the vote count themselves—without expertise—it isn't really a democratic election at all.
It is the morning of March 3, 2009, and eight judges in Karlsruhe have just issued a ruling that most of the world's election administrators will never read — and probably should.
The case before the German Federal Constitutional Court was, on its face, a technical dispute about voting machines. Specifically: the Nedap electronic voting machines used in Germany's 2005 federal election. Critics had complained that these machines stored votes only in electronic memory. No independent record. No way for a voter — or a poll watcher, or a journalist, or a curious citizen who simply showed up — to look at anything after the fact and confirm the count was right.
The Court agreed. And then it said something that cuts much deeper than the machines themselves.
The essential steps of the voting process and of the determination of the result must be able to be examined by the citizen reliably and without any specialist knowledge of the subject.
That sentence, from joined cases 2 BvC 3/07 and 2 BvC 4/07, is not a technical recommendation. It is a statement about what an election is. Not what it should aspire to be. What it must be, constitutionally, to count as a democratic act at all.
The machines failed that test. And so they were gone.
The principle is older than the machines
It is easy to read the German ruling as a story about voting computers — a quaint early-2000s drama, now safely resolved. That would be a mistake.
The Court was not really arguing about Nedap machines. It was recovering a principle it called the Öffentlichkeit der Wahl — the public nature of elections — embedded in Articles 38, 20.1, and 20.2 of Germany's Basic Law. The idea is this: in a democracy, sovereignty belongs to the people. The count that determines who exercises power on the people's behalf must therefore be observable by the people. Not by their proxies. Not by experts they have to trust. By them, directly, with their own eyes.
Paper ballots and open counting rooms were not invented because paper is romantic. They were invented because anyone could walk in, watch a human sort a stack of ballots into piles, and see a number written on a form. The chain of custody was, in principle, something a grandparent with no technical background could follow.
Electronic voting broke that chain. And the Court named exactly why that matters: when the essential steps happen inside a sealed box only an engineer can interrogate, the public has been quietly excluded from the process that is supposed to represent them.
This is not an argument against technology. It is an argument for what any technology used in elections must deliver: results the public can check independently, without asking permission, without needing a computer science degree.
What 'checkable by the public' actually demands
Let's make this concrete. Because 'public verifiability' can sound like a slogan until you ask what it requires in practice.
A voter walks into a polling station. She marks a paper ballot. The ballot goes into a sealed box. At the end of the day, workers open the box, sort the ballots, and write down a number on a form that is signed and posted on the door of the polling station. Any observer present can count along. Any passerby can photograph the posted result.
That chain — mark, seal, sort, post — is publicly verifiable in the German court's sense. Every step is humanly observable. No step requires trusting a proprietary algorithm.
Now run the same scenario through a paperless electronic voting machine. The voter touches a screen. Somewhere in the machine's memory, a number changes. At the end of the day, a number prints on a tape. Can the voter confirm her touch was recorded correctly? No. Can the poll watcher confirm the memory holds what the tape says? No. Can anyone — without specialist knowledge — retrace any essential step? No.
The Dutch came to the same conclusion in 2007, when the government's own commission published a report called Stemmen met vertrouwen — "Voting with Confidence." Its criteria for a legitimate election included controleerbaarheid: checkability. There are no secrets in the election process. Questions must be answerable, and the answers checkable and verifiable. The commission concluded that paper ballots counted by hand met this standard. Electronic methods would meet it only if they produced a voter-checkable paper record. The Netherlands dropped its voting machines and has used hand-counted paper ever since.
Ireland reached the same wall from a slightly different angle. Its independent Commission on Electronic Voting examined the Nedap/Powervote system the government had bought — millions of euros of hardware, sitting ready in a warehouse — and concluded it was unable to recommend the use of the proposed system. Not because it had proven the machines were wrong. Because it could not prove to its own satisfaction that they were right. The burden of demonstration falls on the system, not on the skeptic.
The two directions verifiability can fail
There are two distinct ways a voting system can be unverifiable, and they are easy to conflate.
The first is when you cannot check what the machine recorded. This is the Nedap problem. The German court problem. The Sarasota County, Florida problem, where 18,000 votes disappeared into paperless touchscreen machines in a race decided by 369, and the GAO could find no malfunction — but also had no voter-marked paper to examine. The machine's word was the only word, and the machine could not be cross-examined.
The second is when a paper record exists but the artifact actually counted is not the one the voter can read. This is subtler and more modern. In 2020, a federal court in Georgia examined the state's Dominion ballot-marking device system. Expert testimony, including from Professor J. Alex Halderman, described how the machines print a paper ballot — which looks checkable — but what is actually tabulated is a QR code on that same paper. A QR code the voter cannot read without a separate device. The court found the system "does not provide a verifiable and auditable ballot record because it relies on the QR code for vote tabulation and that code itself cannot be read and verified by the voter." Paper existed. Verifiability, in the German court's sense, did not.
A system whose paper record carries a machine-readable summary the voter cannot personally inspect has moved the opacity from silicon to ink. The principle is the same: the step that matters happens somewhere the citizen cannot follow.
'The audit confirmed it' is not the same as 'you could verify it'
Here is where official reassurances most consistently mislead.
After a contested count, election authorities routinely announce that an audit has confirmed the result. Sometimes this is meaningful. Georgia's 2020 statewide audit took the form of a full hand count of roughly five million presidential ballots — a genuine, large-scale exercise in checking machine output against voter-marked paper. The variation was about a tenth of one percent. That is a real data point.
But notice what made it real: the existence of voter-marked paper ballots that could be re-examined by humans, independently of the machines. The paper was the verifiability. The hand count was only possible because the artifact the voter actually touched still existed and could be read by anyone.
Now ask a harder question. In a jurisdiction that uses ballot-marking devices with unreadable QR codes, what does a "hand count" audit? It audits the paper record — which reflects the QR code's output, not the voter's independent mark. If the machine translated touches into QR codes incorrectly, the paper is wrong, and the hand count faithfully reproduces the wrong answer.
'The audit confirmed it' is only meaningful if the thing being audited is something a voter independently marked — not something a machine produced on their behalf.
And "the Secretary of State says the audit confirmed it" is not proof of anything. It is a claim. The question is always: can you check it yourself, without trusting the person making the claim?
What first principles actually require
Step back from the individual cases and the specific technologies and ask what a legitimately public election must have, if the German court's principle is taken seriously.
First: every voter must be able to confirm, with their own senses, that their choices were recorded as they intended. Not by trusting a machine's display. Not by taking a vendor's word. By inspecting a human-readable artifact they themselves created — a marked paper ballot they can read before it leaves their hands.
Second: the artifact the voter marks must be the same artifact that is counted. Not a machine-generated translation of that artifact. Not a barcode derived from it. The thing itself, or a transparent and human-readable copy of it.
Third: anyone — without specialist knowledge — must be able to observe the process by which individual artifacts aggregate into a final total. In a hand count, this is visible in the room. In a machine count, it requires that the software performing the aggregation be published and independently verifiable, and that the machine's output be checkable against the physical artifacts.
Fourth: the published result must be granular enough that any observer can do their own arithmetic. Precinct-level totals, available in machine-readable format, from the moment they are final. Not because observers distrust officials, but because the ability to independently verify is what makes trust rational rather than compelled.
These are not utopian demands. Paper ballots, open counts, posted precinct totals, and published risk-limiting audits already deliver most of them in jurisdictions that have chosen to implement them. Colorado ran the first statewide risk-limiting audit in 2017. The method is not exotic: it samples ballots statistically, checking more of them when a race is closer, until the probability of having missed a wrong outcome drops below a defined threshold. The public can inspect the methodology. The paper can be re-examined.
What no jurisdiction has fully delivered — yet — is a system in which the cryptographic proof of a correct count is published and verifiable by any member of the public without trusting any official or vendor. That would be the German court's principle fully realized in software: not paper on a wall, but a mathematical record anyone can check with open tools, without needing to attend the count in person or request a copy from an authority.
The villain is not a machine. It is opacity.
It is important to be precise here, because the German ruling gets misread in two directions.
One misreading is that it is a vote against electronic voting. It is not. The Court did not say electronic voting is unconstitutional. It said electronic voting is unconstitutional when ordinary citizens cannot check the essential steps. A system with voter-marked paper, publicly auditable aggregation software, and precinct-level published results would satisfy the principle just as well as hand-counted paper — arguably better, if the cryptographic verifiability is rigorous enough.
The second misreading is that it is a vote for any specific alternative. It is not that either. Switching from one unverifiable system to a different unverifiable one accomplishes nothing. The Netherlands switched back to paper — but a paper count that happens behind closed doors, with results reported only in aggregate, with no machine-readable precinct data available for independent reconciliation, would still fail the principle. Form does not matter. Checkability does.
The villain in every case in this archive — the DRC in 2011, where the EU observation mission found results compiled without public visibility; Venezuela in 2017, where even the voting-system vendor disowned the announced turnout; Malawi in 2020, where tally sheets had been overwritten with correction fluid — is not a particular technology. It is opacity. The systematic removal of the count from anyone's ability to independently verify it.
And official assurances do not dissolve opacity. They add a layer on top of it.
What is still not checkable — and what would fix it
Here is what remains true, regardless of what officials say, in most of the world's elections right now.
The software that aggregates precinct results into a county or national total is proprietary in most jurisdictions, inspected by no one outside the vendor and the certification laboratory. The certification laboratory's findings are rarely public in full. The chain from individual ballot to final total passes through multiple steps — scanning, tabulation, upload, canvassing — that are not individually verifiable by any member of the public.
In jurisdictions that use ballot-marking devices rather than hand-marked paper, the artifact being counted is produced by software the voter cannot inspect.
In jurisdictions without risk-limiting audits, the machine count is checked by a fixed-percentage spot check that provides no statistical guarantee about close races.
In jurisdictions without precinct-level machine-readable results published in real time, the public has no way to do independent arithmetic against the official total.
The German court drew the line clearly in 2009. A result that only an expert can verify is not a democratically legitimate result. That line has not yet been crossed — in the direction of full public verifiability — by most of the systems in use today.
What would cross it? Voter-marked paper ballots, counted or scanned in public, with a precinct-level record posted immediately and downloadable in a format any spreadsheet can open. A risk-limiting audit of every close contest, with the sampled ballots and their hand-read totals published. And, for the cryptographically ambitious: an end-to-end verifiable system in which each voter can confirm their ballot was included in the final tally, and any observer can verify the tally's mathematical integrity, without trusting any single authority.
That last item is technically feasible. Switzerland tried to implement it and found a trapdoor in the cryptography — but found it precisely because independent researchers could inspect the published code. The trapdoor was patched. That is the correct outcome: public scrutiny found a flaw that private certification had missed. The answer to a flawed cryptographic verifiability system is not to abandon verifiability. It is to keep the code public until the flaw is gone.
The German court's principle is not satisfied until every essential step is checkable by every citizen who chooses to look.
Most elections, right now, are not there.
See how this gap appears in election systems around the world →
Read the two-minute version of why verifiability matters →
Explore documented cases of unverifiable elections →
Sources
- Bundesverfassungsgericht, Judgment of 3 March 2009, 2 BvC 3/07 and 2 BvC 4/07 (English translation)
- Bundesverfassungsgericht, Press Release No. 19/2009 (English)
- Adviescommissie inrichting verkiezingsproces (Commissie Korthals Altes), 'Stemmen met vertrouwen', 27 September 2007
- Commission on Electronic Voting — Interim Report on the Secrecy, Accuracy and Testing of the Chosen Electronic Voting System (Ireland, 2004)
- Curling v. Raffensperger, No. 1:17-cv-2989-AT, Opinion and Order (N.D. Ga. Oct. 11, 2020)
- U.S. GAO (GAO-08-97T) — Testing of Voting Systems in Florida's 13th Congressional District
- Colorado Secretary of State — A new kind of election audit: Colorado is first to complete it
- Lewis, Pereira, Teague — Ceci n'est pas une preuve (trapdoor commitments in the Scytl-SwissPost Internet voting system), 2019
- Georgia Public Broadcasting — Risk-Limiting Audit Confirms Biden Won Georgia