← Tous les articles

Where votes have a price: what monitors keep finding in Europe

In Albania's 2021 election, OSCE monitors found vote-buying so widespread it triggered criminal investigations — and it only works if the buyer can verify the purchase.

It is the morning of April 26, 2021, and somewhere in a constituency office in Albania, a transaction is being completed. Not at a ballot box — well before that. Money or favors change hands. The understanding is clear: vote as instructed. But there is a problem, the same problem every vote-buyer faces. Once the voter walks into that polling booth alone, how does the buyer know they kept their end of the deal?

That question — how does a buyer confirm delivery? — is not an abstract puzzle. It is the central engineering problem of political corruption. And the answer to it explains why ballot secrecy is not a courtesy. It is a security feature. Destroy secrecy, and you have built a market. Restore it, and the transaction collapses.

OSCE/ODIHR observers documented what they found in Albania's April 25, 2021 parliamentary elections in a final report that pulls no punches. Allegations of vote-buying by political parties were widespread during the campaign, leading to a number of criminal investigations. The mission also raised concerns about misuse of state resources and pressure on voters. Among its recommendations: guarantee the right to a free and secret vote, prevent any form of pressure on voters to disclose whether and how they voted, and intensify efforts to identify, investigate, and prosecute vote-buying.

Those words — identify, investigate, prosecute — represent the law-enforcement response to the problem. They are necessary. They are also, by themselves, nowhere near sufficient.

Here is why.


The buyer's problem — and why secrecy solves it

Think of vote-buying as a contract. The buyer offers value (cash, a job, a bag of groceries). The voter promises to deliver a specific ballot. For the contract to hold, the buyer needs enforcement: some way to verify that the voter performed.

That verification is the entire mechanism. Remove it, and the market dries up instantly. A buyer who cannot confirm delivery is just handing out cash. Some voters will take the money and vote however they like. The buyer has no recourse, and rational buyers stop paying.

The secret ballot was invented precisely to destroy this verification mechanism.

The Australian Electoral Commission records that before the 1850s, people "voted publicly, which left them vulnerable to intimidation and coercion," and that the "so-called 'Australian ballot', otherwise now known as the secret ballot, was implemented" as a direct remedy. The UK Parliament made the same move in the Ballot Act 1872 — replacing open voting with a private compartment and a sealed box — to stop what had been, in some English constituencies, a near-open market for votes.

The U.S. Court of Appeals for the First Circuit traced this history explicitly in Rideout v. Gardner (2016), explaining that secret-ballot reforms were adopted to "combat widespread vote buying and voter intimidation," practices that "depend on a buyer or coercer being able to verify the vote." When a voter can prove how they voted — with a photograph, a receipt, a traceable ballot — the market reopens. Take the proof away, and the purchase becomes an unenforceable bet.

So secrecy is not just about the voter's privacy. It is the structural mechanism that makes a vote unsaleable.


What happens when that mechanism fails in practice

Albania's 2021 case is one data point on a map that OSCE/ODIHR has been filling in across Europe for years.

In Georgia's October 2024 parliamentary elections, ODIHR's mission observed potential compromises to ballot secrecy in over 30 percent of their observations — in 24 percent of cases due to how ballots were inserted into ballot boxes, in 12 percent due to how voters marked their ballots, and in 7 percent due to inadequate polling-station layouts. The mission found that pressure on voters combined with election-day practices compromised the ability of some voters to cast their vote without fear of retribution.

That is not a rogue official. That is not an isolated county. That is a pervasive, systemic exposure of the mechanism that is supposed to make coercion impossible — playing out in a European election in 2024.

In Bulgaria's April 2023 parliamentary elections, the same monitoring body recorded "longstanding concerns over vote-buying and controlled voting," present and reported to the observation mission, with secrecy of the ballot compromised in 7 percent of their election-day observations. Law-enforcement agencies told ODIHR that "obtaining evidence of vote-buying remains challenging and that most cases do not progress past the pre-trial stage."

Read that last sentence twice. The very thing that makes vote-buying hard to prosecute — the secrecy of individual transactions — is also, in its absence, what makes them easy to enforce. When the ballot is secret, the buyer can't prove the purchase. When the vote can be observed or proven, the buyer can enforce the deal, but prosecutors still can't catch it because the victim often won't cooperate.

This is the trap. And no law-enforcement agency, by itself, can prosecute their way out of it.

In Kyrgyzstan's 2017 presidential election, ODIHR again documented cases of pressure on voters, vote-buying, and misuse of public resources, and again recommended that authorities "guarantee the right to a free and secret choice and to prevent any form of pressure on voters to disclose how they voted." In North Macedonia's 2025 local elections, the mission flagged vote-buying, pressure on public-sector employees, and voter tracking — recording who showed up, monitoring compliance.

Voter tracking is the operational infrastructure of both vote-buying and workplace coercion. If someone is noting which employees turned up to vote, and which way, the secrecy rule is already dead in practice. Defeating it requires more than a legal guarantee. It requires processes where a voter's choice is provably unlinkable to their identity — anonymity by design, not anonymity by policy.


The court cases that named the mechanism clearly

Courts have been direct about this in a way that politicians rarely are.

In Rideout v. Gardner, the First Circuit upheld the principle even while striking down New Hampshire's particular ballot-selfie ban. The logic was unambiguous: a photograph of a marked ballot gives the voter the means to prove their choice to a third party. That proof is the thing vote-buyers need. The court's reasoning is essentially a design specification: a voting system should produce no artifact — no receipt, no image, no traceable record — that lets a voter demonstrate to a buyer how they voted.

In England in 2015, an Election Court voided the Tower Hamlets mayoral election in Erlam & Ors v Rahman & Anor, finding corrupt and illegal practices including personation, postal-vote fraud, bribery, and treating. The court's findings turned on what happens when votes leave the controlled environment of the polling station: postal and remote ballots can be watched, collected, or coerced in ways that in-person, private-booth votes cannot. The chain of custody that protects secrecy — which materials touch, who handles them, when, with what witnesses — is hardest to maintain precisely where it is most vulnerable to attack.

North Carolina's 9th Congressional District in 2018 is the American version of that same failure. A political operative built a ballot-collection scheme for mail-in absentee ballots in Bladen and Robeson counties. The State Board of Elections unanimously ordered a new election after finding what it called a "coordinated, unlawful and substantially resourced absentee ballot scheme." The operative, McCrae Dowless, was later indicted on felony charges. The lesson is identical to Tower Hamlets: when the ballot leaves the booth, every link in the chain that handles it becomes a potential attack point.


Coercion from above: when the state is the buyer

Vote-buying is usually imagined as a cash transaction between a fixer and a voter. But coercion from above is at least as dangerous and considerably harder to prosecute.

On October 22, 2015, Mexico's Electoral Tribunal of the Judicial Branch of the Federation — the TEPJF — resolved case SUP-JRC-678/2015 and declared the annulment of the gubernatorial election in the state of Colima. The Tribunal found violations of the guiding principles of equity and neutrality through the improper intervention of state-government officials, including the steering of social programmes to benefit a coalition candidate and intimidation connected to arrests of opposition campaign workers. It revoked the certificate of majority issued to the apparent winner and ordered a fresh election, referring the officials' conduct for investigation.

This is vote-buying with the purchasing power of the state. Social programmes aimed at specific communities. Jobs. Permits. Infrastructure. The buyer isn't a fixer with an envelope of cash; it is a government apparatus that can dispense or withhold things people need.

The same dynamic that makes individual vote-buying work makes state coercion work: if the government can monitor who voted and how, it can reward compliance and punish deviation. The structural fix is identical — make every vote genuinely unprovable to any third party, including the government — but the threat model is harder to address because the coercer has both resources and access.


Why verification doesn't fix it — and what actually does

At this point, a reasonable reader might wonder: isn't this the wrong blog for this topic? Isn't TrustVoting about making votes more verifiable?

Here is the tension, and it is real. Everything else on this blog argues that elections need stronger verification — that results should be independently checkable, that code should be open, that paper trails should be auditable. But ballot-secrecy arguments seem to point the other way: less traceability, less provability, less verification.

The resolution is architectural. There are two different things being verified, and they must be kept completely separate.

The first thing to verify is: did the count correctly reflect the ballots? This is the integrity problem — machine errors, software flaws, chain-of-custody breaks, manipulation of tallies. For this, you want maximum transparency. Auditable paper records. Open-source code. Independent hand audits. Publicly checkable precinct-level results. Everything Germany's Constitutional Court demanded in 2009 when it found that voting computers whose internals a citizen could not inspect were unconstitutional — that the "essential steps of the voting and of the determination of the result can be examined by the citizen reliably and without any specialist knowledge."

The second thing to verify is: which voter cast which ballot? For this, you want zero traceability. None. The system should be cryptographically incapable of linking a specific voter to a specific choice — not by policy, not by promise, but by mathematical design.

Modern election cryptography has tools for achieving both simultaneously. Zero-knowledge proofs and verifiable mixnets — the same family of techniques that Switzerland's postal service tried to deploy (before researchers found a cryptographic trapdoor in the implementation) — are designed precisely to let you prove that a set of ballots was counted correctly without revealing which ballot belonged to whom. The system proves the count was honest. It proves nothing about individual voters.

That is the architecture vote-buying cannot survive. The buyer gets no receipt. The coercer gets no compliance record. The tracker gets no list. And the public gets a fully auditable proof that every ballot was counted as cast.


What 'widespread' actually means — and what remains unverifiable

Return to Albania, April 2021. ODIHR's word is "widespread." Not "alleged." Not "reported by one opposition party." Widespread — enough to trigger criminal investigations, enough for an international monitoring mission to make it a headline finding, enough to generate a recommendation to the state that it needs to try harder to prosecute it.

Criminal prosecution is the response after the fact. What ODIHR is describing in Albania — and Bulgaria, and Georgia, and Kyrgyzstan, and North Macedonia — is a live, active, ongoing market for votes. Not a historical curiosity. A present-tense problem inside Europe, documented by monitors with no partisan interest in the finding.

And here is what remains unverifiable from the outside, even with ODIHR's report in hand: how many votes were actually bought? How many were actually delivered? The report describes allegations, investigations, and observations of compromised secrecy. It cannot tell you, because no one can tell you, how many voters took money and voted as instructed. That number is definitionally hidden — which is, structurally, the only thing a vote-buyer cares about.

A system that produces auditable, cryptographically verifiable aggregate results — while maintaining complete voter anonymity — would not answer that question either. But it would do something more important: it would make the delivery confirmation impossible. No receipt. No proof. No market.

Until that architecture is standard, the OSCE will keep writing the same recommendations. And the markets will keep operating.


The shareable version

Vote-buying doesn't fail because it's illegal. It fails when the ballot is genuinely unprovable — cryptographically, architecturally, by design. Every system that lets a voter demonstrate their choice to a third party is a system with a price list.

What we can independently verify right now, from ODIHR's Albania report: vote-buying was widespread enough to open criminal investigations. What we cannot verify: how many transactions completed, how many votes were actually delivered, and whether any race turned on it.

What would make it checkable: election systems built to prove the count is accurate without proving anything about individual voters — verifiable results, genuinely secret ballots, anonymity by architecture rather than by promise.

See how common this verification gap is across elections worldwide →

Read the two-minute version of why ballot secrecy is a security feature →


Sources