← All posts

In a third of polling stations, someone could see how people voted

International monitors watched more than a third of Georgia's polling stations in 2024 and found that in every one of them, someone could have seen how you voted.

It is the morning of October 26, 2024, and in a polling station somewhere in Georgia — the country, not the state — a voter steps up to mark a ballot. There is no private booth. Or there is one, but it faces the wrong way. Or the voter marks the ballot on a surface that anyone standing nearby can see. Or the ballot, once folded, unfolds itself on the way to the box.

The voter does not know they are being watched. They may not know it matters.

Trained OSCE/ODIHR election observers do know. And when they tabulated what they had seen that day across hundreds of polling stations, the number was striking: potential compromises to the secrecy of the vote were recorded in over 30 percent of their observations.

Not at a few poorly-run stations on the edge of the map. In more than one in three.


The number, broken down

The OSCE/ODIHR Election Observation Mission published its final report on Georgia's 26 October 2024 parliamentary elections on 20 December 2024. The headline finding on ballot secrecy is precise and worth reading slowly.

Observers recorded potential compromises to vote secrecy in 24 percent of observations due to how ballots were inserted into ballot boxes. In 12 percent of observations, the problem was how voters marked their ballots. In 7 percent, it was inadequate polling-station layout.

These three categories overlap — a voter might face both a poorly sited marking table and a poorly designed ballot box — which is why the total exceeds any single figure. The mission concluded that issues with secrecy of the vote were noted in over 30 percent of observations.

The report did not conclude these were all deliberate. Some were design failures. Some were procedural carelessness. Some were the result of layouts nobody had thought to check against a simple test: could a third party see what this voter is doing?

But here is the thing. It does not matter whether the watcher in the room is malicious. The ballot secrecy problem exists the moment the vote can be seen.


Why secrecy is a security control, not a courtesy

There is a tendency to think of ballot privacy as a nicety — something you might want for your own comfort, but not a structural requirement of democracy. The history of elections says otherwise.

In 1872, the UK Parliament passed the Ballot Act — not to make voters more comfortable, but to make it impossible for landlords and employers to verify how their tenants and workers had voted. Before the act, voting was public. You declared your choice aloud, it was written in a book, and the book was published. The result was systematic bribery and intimidation, because coercion only requires one thing: proof. Proof of the vote purchased, proof of the vote defied.

The secret ballot solved this with a structural mechanism, not a legal prohibition. You cannot buy what you cannot verify.

The Australian ballot — uniform, state-printed, marked in a private compartment — was not adopted because voters asked for privacy. It was adopted because it made vote-buying architecturally impossible. The Australian Electoral Commission's own history is direct: people "voted publicly, which left them vulnerable to intimidation and coercion," and the secret ballot was the engineered fix.

Remove the secrecy, and the market for votes reopens.

The OSCE/ODIHR findings in Georgia are not just an administrative embarrassment. They describe the partial collapse of a security mechanism that democracies spent two centuries building.


What breaks secrecy in practice

The Georgia 2024 findings point to three distinct physical failure modes, and each one is instructive.

Ballot insertion. If a box's slot faces a room at large, or if ballots are fed into machines in a way that exposes the marked face, anyone nearby — a party agent, a relative, an employer's operative, a candidate's representative with a mobile phone — can see the choice. Twenty-four percent of observations caught this failure. It is a hardware problem with a hardware solution: the box or machine should be positioned so no one but the voter can see what goes in.

Ballot marking. If the marking area — a table, a booth, a curtain — can be observed from behind or from the side, the moment of decision is exposed. Twelve percent of observations. This is partly a layout problem and partly a design problem: booths that are too open, cubicles without side panels, voters who choose to mark on a flat table rather than a private surface because no other option is offered.

Station layout. In seven percent of observations, the overall arrangement of the station — where the registration table sits, how queues form, where party agents stand, how ballots flow from issuance to box — was itself inadequate. This is the whole-room failure: even if individual components are correct, the traffic pattern through a badly designed room creates sightlines that undermine everything else.

None of these require a conspiracy. They require inattention to an engineering requirement that most people never think about: polling station design is a security control, and it should be evaluated as one.


The mechanism that makes it dangerous

A voter who can be watched casting a ballot is a voter who can be made to prove their vote.

The U.S. Court of Appeals for the First Circuit laid this out cleanly in Rideout v. Gardner in 2016, a case about whether New Hampshire could ban ballot selfies. The court traced the history directly: secret-ballot reforms were adopted to "combat widespread vote buying and voter intimidation," practices that depend on the buyer or coercer being able to verify the vote. A photograph of a marked ballot functions as proof. And proof is what transforms a preference into a transaction.

The same logic extends to polling-station observation. If you can be watched — or if you know you might be watched — the secret vote is no longer functionally secret. Even if no one is actually looking, the credible possibility that someone could look is enough to change behavior. A voter who fears their employer's operative is watching the queue will not vote their conscience. A voter who knows their family will see which box they approach has already lost the protection that 150 years of electoral reform was designed to provide.

The OSCE observers in Georgia also recorded instances of vote-buying, double-voting, physical violence, and intimidation. They found that pressure on voters "combined with election-day practices compromised the ability of some voters to cast their vote without fear of retribution."

Secrecy failures and coercion failures are not two separate problems. They are the same problem at different stages of the same transaction.


This is not a problem unique to Georgia

Georgia 2024 is the lead case here because the monitoring data is precise and recent. But the underlying pattern is documented across multiple jurisdictions by the same monitoring body.

In Bulgaria's April 2023 parliamentary elections, the same OSCE/ODIHR reported that ballot secrecy was compromised in 7 percent of their observations, with vote-buying present and reported — inside an EU member state.

In Albania's 2021 parliamentary elections, ODIHR documented widespread vote-buying allegations and recommended that authorities guarantee the right to a free and secret vote, and prevent any form of pressure on voters to disclose whether and how they voted.

In Kyrgyzstan's 2017 presidential election, ODIHR recommended guaranteeing the right to a free and secret choice and preventing pressure on voters to disclose how they voted.

In North Macedonia's 2025 local elections, ODIHR flagged voter tracking — recording who voted and monitoring compliance — as a live concern alongside vote-buying and pressure on public employees.

The geography spans Europe, Central Asia, the Caucasus. The mechanism is identical in every case: where someone can observe or prove how you voted, a market or a coercive relationship can operate. Close the observation gap, and the transaction collapses.


What 30 percent actually means for a close race

Thirty percent sounds like a process problem. In a tight election, it is a result problem.

Here is the arithmetic. Suppose a parliamentary district has 50,000 voters, spread across 100 polling stations. If secrecy is compromised in 30 of those stations — on average, as the monitoring data suggests — and if a party with resources is systematically exploiting sightlines to verify compliance, the number of votes that can be reliably purchased or coerced is not incidental. It is structural.

You do not need to buy every vote. You need to buy enough, in the right stations, in the right districts. And you can only buy votes you can verify.

This is why courts have repeatedly voided elections over secrecy failures that were not accompanied by any direct proof of fraud. Austria's Constitutional Court annulled the 2016 presidential run-off — a race decided by roughly 30,000 votes — because postal ballot procedures were violated in ways affecting 77,000 votes, even though no evidence of actual manipulation was found. The court's reasoning was explicit: safeguards against manipulation must be so robust that fraud demonstrably could not have occurred — not merely that it probably did not.

Procedural failures that create the possibility of observation or interference are sufficient reason to treat a result as unverifiable. That is not an extreme standard. It is the minimum that makes a result trustworthy.


Design requirements, not policy wishes

So what does it actually take to make a polling station a secure environment?

The answer is mostly physical engineering and procedural checklist, not technology. A private marking compartment with adequate side panels and no rear sightlines. A ballot box or scanner positioned so that the ballot's marked face is never visible to anyone but the voter at the moment of insertion. A room layout that prevents crowding near the marking area. Entry and exit flows that do not expose which box or queue a voter approaches. Party agents seated where they can observe the process without observing individual ballots.

None of this is difficult. All of it can be audited on arrival, before a single voter enters the room. A trained observer with a clipboard and ten minutes can check every sightline.

The fact that over 30 percent of stations failed this check in Georgia in 2024 is not a reflection of technical difficulty. It is a reflection of the absence of an enforceable design standard treated as a security control — the same category of absence that allows hardware and procedural failures to silently undermine the integrity of everything downstream.

And this is where the problem connects to a wider one. A badly designed polling station is an opaque system: you do not know, after the fact, which votes were observed, by whom, or with what effect. The secrecy failure is undetectable from the results alone. No audit of the count will find it. No machine recount will surface it.

The Philippines Supreme Court, upholding the disqualification of a mayor-elect for vote-buying in Nolasco v. COMELEC in 1997, framed the underlying principle precisely: the criminal offense is the offer, not just the execution. But the court also recognized that prosecution alone cannot scale to a mass market. The decisive defense is architectural — if a vote cannot be proven to a buyer, the purchase cannot be enforced, and the transaction collapses.

Criminal penalties for vote-buying are a last resort. A truly secret ballot is a first-line structural defence.


The verifiability problem that counting cannot fix

There is a temptation to treat election integrity as a counting problem. Build a better machine. Audit the tallies. Run a risk-limiting audit. Publish the results faster.

These things matter enormously — but they operate downstream of the ballot box. They verify that the votes recorded were counted accurately. They cannot verify that the votes recorded were cast freely.

A perfectly audited count of coerced votes is still a coerced count.

This is the gap that polling-station design failures open: an upstream vulnerability that no downstream audit can close. If 30 percent of your polling stations allow observation of the vote, and you run the most rigorous post-election hand count in history, you have verified the arithmetic of a potentially compromised input.

The chain of custody for a free election does not begin at the ballot box. It begins the moment a voter steps into a private space to mark a ballot — and that space must be private by design, not by assumption.

The OSCE/ODIHR mission in Georgia concluded that the secrecy failures "negatively impacted the integrity of the elections and eroded public trust." That is diplomatically measured language. What it means in plain terms is that a significant portion of the 2024 parliamentary elections took place in conditions where the foundational security property of the secret ballot — the property that makes vote-buying and coercion architecturally impossible — was not reliably present.

And that is a fact no official statement can audit away.


What would make this checkable

Here is what remains unknown, and what would make it verifiable.

We do not know — because it cannot be known from observer data alone — how many of the observed secrecy compromises were exploited. We do not know whether the sightlines were used, by whom, or to what effect. We do not know, station by station, whether the physical failures correlated with anomalous vote patterns. We cannot reconstruct, from the count, which ballots were cast under observation.

What would make this checkable is a combination of things that currently do not exist together in most jurisdictions:

Enforceable physical design standards for polling stations, auditable on arrival by any accredited observer, with a public checklist and a public record of compliance per station.

Precinct-level results published immediately and in machine-readable form, so that any analyst can test whether stations with documented secrecy failures show distributional anomalies compared to stations where secrecy was intact.

An independent body with standing to require remediation, not merely to note concerns in a post-election report that arrives two months after the ballots are counted.

None of this requires new cryptography or new voting technology. It requires treating the room where voting happens as a designed security environment — and publishing enough data that anyone can check whether the design held.

Until that exists, "the secrecy of the ballot was potentially compromised in over 30 percent of polling stations" is a finding, not a verdict. But it is the kind of finding that, in a close race, a functioning democracy should not be able to leave unresolved.


Interested in how this gap appears across different countries? See the global picture on our atlas. Or read the two-minute version of the ballot-secrecy gap.

For a broader look at the gaps between what election systems promise and what they can prove, start here.


Sources