The secret ballot is a security feature, not a courtesy
The secret ballot wasn't invented to protect your privacy — it was invented to make buying and threatening you pointless, and a phone camera in the booth quietly undoes it.
In 2023, international observers watched a national election inside the European Union and wrote down something blunt. Across the Republic of Bulgaria's early parliamentary elections that April, the OSCE's election-monitoring body recorded "longstanding concerns over vote-buying and controlled voting." Their observers saw the secrecy of the ballot compromised in 7 per cent of the polling-place observations they made, and noted indications of vote-buying happening outside polling stations. When they asked law enforcement about it, the answer was telling: getting evidence is hard, and most cases never make it past the pre-trial stage.
This is not a story about a fragile young democracy in some distant century. It is a contemporary, court-and-monitor-documented account of what happens when the secret ballot stops being secret. A vote you can be watched casting — or that you can later prove you cast — is a vote that can be bought, rented, or coerced.
That is the whole point of ballot secrecy. It was never a privacy courtesy. It is a security mechanism. And it is quietly failing in ways most voters never think about.
Why secrecy is the security feature
Start with the mechanism, stated plainly.
Vote-buying works like a contract: I pay you, you vote the way I want. But a contract you cannot enforce is worthless. If I have no way to verify how you actually voted, I cannot know whether you held up your end — so the rational move is not to pay at all. Coercion runs the same logic in reverse: if I threaten you but can never confirm what you did in the booth, my threat is empty air.
Secrecy is what makes the bribe and the threat unenforceable. Remove it, and both become rational again.
This is exactly why the secret ballot was invented in the first place. The Australian Electoral Commission records that until the 1850s people "voted publicly, which left them vulnerable to intimidation and coercion" — so an independent electoral body was created and the "so-called 'Australian ballot', otherwise now known as the secret ballot, was implemented." A uniform, state-printed ballot, marked alone, that no employer or landlord or party boss could observe. The idea spread across democracies over the following decades because it worked: it made the foreman's stare and the landlord's instructions impossible to enforce.
So when an audit of an election system turns up a "ballot is not truly secret" finding, that is not a footnote about privacy. It is a structural failure with a documented price.
The phone in your pocket reopened the market
Here is the modern twist, and a U.S. federal court laid it out with unusual clarity.
In Rideout v. Gardner (2016), the U.S. Court of Appeals for the First Circuit reviewed a New Hampshire law that banned voters from photographing their own marked ballots — "ballot selfies." The state's defense went straight to the security logic: the ban existed to "preserve the secrecy of the ballot" against vote-buying and coercion, because a photo lets a voter prove how they voted. The court agreed about the history, noting that secret-ballot reforms were originally adopted to "combat widespread vote buying and voter intimidation" — practices that only function when a buyer or coercer can verify the vote.
Read that again, because it is the crux of this entire piece: the proof is the problem. A marked-ballot photograph is, functionally, a receipt — and a receipt is exactly what a vote-buyer needs to enforce the deal.
The court still struck the ban down, on free-speech grounds, ruling it was not narrowly tailored because the state hadn't shown recent evidence that ballot photos had actually driven vote-buying. You can argue the speech question both ways. But notice what the case settled and what it didn't: it confirmed the mechanism — secrecy defeats vote-buying, and a photo undoes secrecy — while leaving the door open for the camera to walk right back into the booth.
That door is now open in much of the world. Everyone carries a high-resolution camera. The technology the secret ballot was designed to defeat — provable voting — is back in every pocket, and Bulgaria 2023 is what it looks like when the proof gets used.
It doesn't take a hacker. It takes a gap.
The other way the secret ballot dies is even lower-tech: someone else touches your ballot.
After the 2018 election in North Carolina's 9th Congressional District, a candidate appeared to have won. The State Board of Elections refused to certify and investigated. On February 21, 2019, the Board unanimously ordered an entirely new election after finding what it called, in its own words, a "coordinated, unlawful and substantially resourced absentee ballot scheme" in Bladen and Robeson counties. An operative named McCrae Dowless had run a network that collected voters' absentee ballots — some blank, some partly filled — to be completed, submitted, or discarded as needed. A new election was held. A different candidate won. It remains one of the rare times a U.S. House result was thrown out for fraud.
No machine was hacked. No foreign power was involved. The mechanism was a clipboard and a basket.
The chain of custody is the secret ballot. The moment your unmarked or partly-marked ballot passes into a third party's hands, the protection is already gone — not because the paper changed, but because someone other than you now knows, and controls, what it says. North Carolina is the clearest modern proof that buying and coercing votes doesn't require sophistication. It requires only a gap between the voter and the ballot.
The machine version of the same wound
There is a subtler way the link between voter and vote breaks, built into some electronic systems.
Certain ballot-marking devices print a barcode. You make your choices on a touchscreen; the machine prints a ballot showing a human-readable summary and a barcode; and when the ballot is tallied, the scanner reads the barcode, not the text you checked. You are invited to "verify" your ballot by reading the summary. Almost nobody verifies the barcode, because almost nobody carries a barcode reader into a polling place.
What gets counted is the barcode. What you checked is a printed summary. In principle those two things can differ — and you would have no way to know.
This is the secret-ballot failure from a different direction. Here the danger isn't that your vote is traceable back to you; it's that the vote recorded on your behalf may not be the one you cast. The voter's intent is severed from the record. A related failure lurks wherever ballot serial numbers or printing order can be cross-referenced against check-in logs: if a ballot can be matched to a name through any accessible record, the secret ballot is over. Not hypothetically. Structurally.
The trap in "just give voters a receipt"
If proof is the problem, you might think the cure is to let every voter keep proof their vote was counted. It's the obvious instinct, and it is a trap.
Any system that lets a voter walk out with proof of which way they voted has solved verifiability by recreating the exact vulnerability the secret ballot was built to close. You've handed the voter a receipt they can be forced to show — to an employer, a landlord, a party operative, anyone with leverage. That is the Bulgaria problem manufactured at scale, by design.
So the real engineering question in election security is harder than "can we verify the count?" It is: can we let anyone verify the count without letting any individual prove their specific choice? These two goals are in genuine tension, and pretending they aren't is how systems get built that quietly sacrifice one for the other.
This is the problem end-to-end verifiable (E2E) voting has worked on for decades: give every voter mathematical proof that their encrypted vote was included in the tally, without ever revealing — even to the voter, even to a coercer standing over their shoulder — what that vote was. The cryptography is real and the approach is sound. It is also not yet how most people vote. Most voters use systems that have never even named the trade-off, let alone resolved it.
What no press release can tell you
Here is what no official statement, audit summary, or Secretary-of-State assurance can currently confirm for you, as an independent citizen:
- That no ballot in your jurisdiction was completed or altered by a third party before it was counted.
- That no ballot-marking device encoded a choice in its barcode different from the one shown on screen.
- That no serial number or sequence record exists anywhere that could link your ballot to your name.
- That the mathematics of the system — not merely its policies — make it impossible to trace your vote back to you, or to sell a provable one.
These are not accusations. They are gaps. And gaps don't close because an official is trustworthy; they close when a system is built so that independent verification is possible without trusting anyone. A vote no one can prove is a vote no one can buy. A count anyone can check is a count no one has to take on faith.
That is the work. Not reassurance — architecture.
"You cannot pay someone for a vote you cannot verify. Hand the voter a way to prove it — a camera, a receipt, a traceable serial number — and the bribe becomes rational again."
See where the 'ballot not truly secret' gap shows up across election systems →
Explore the full global atlas of election-integrity gaps →
Read the 2-minute version of this issue →
Sources
- Australian Electoral Commission — A short history of voting and the secret ballot
- U.S. Court of Appeals for the First Circuit — Rideout v. Gardner, No. 15-2021 (opinion, Sept. 28, 2016)
- OSCE/ODIHR — Republic of Bulgaria, Early Parliamentary Elections 2 April 2023, Final Report (Warsaw, 27 July 2023)
- NC State Board of Elections — State Board Unanimously Orders New Election in 9th Congressional District