HomeinetEuropean Elections - Postal Voting: Changes to the IT support system to shield...

European Elections – Postal Voting: Changes to the IT support system to protect personal data

With a fast track direct assignment on May 10, the Ministry of Internal Affairs promoted changes to the IT system, aiming to protect personal data, just one month before the European elections

European Elections - Postal Voting: Changes to the IT support system to protect personal data

These days, in the midst of a pre-election period, the Ministry of Interior (MIA) is taking a move that could well be perceived, if nothing else, as an admission by its political leadership, under Minister Niki Kerameus and Deputy Minister Thodoris Livanios, that there may be gaps and "holes" regarding the protection of personal data in the digital electoral application for domestic and foreign voters via postal voting. Documento brings to light the decision of the Ministry of Interior on May 10, 2024 (no. prot. 40177) to make changes to the IT system supporting postal voting in order to protect personal data.

The new interventions are taking place a month before the European elections on June 9 and after the revelations about the personal data leak scandal, the so-called email-gate – involving former New Democracy MEP Anna-Michelle Asimakopoulou – as well as the recent case of the break-in of the office of the head of the Elections Directorate of the Ministry of the Interior.

On 26 April 2024, the Ministry of Internal Affairs issued a call for expressions of interest for the submission of a financial offer regarding the provision of design services for the updating and optimization of the existing impact study (data protection impact analysis – DPIA) prepared by the ministry’s services for the postal voting support information system. On 10 May (no. pr. 40177) the direct award was made, with the cost amounting to 18,600 including VAT.

As noted in the annex to the agreement, the Ministry of Internal Affairs is responsible for processing applications from Greek citizens who wish to register on the special postal voter lists for the European elections of June 2024 and is obliged to take and continuously maintain the appropriate necessary technical and organizational security measures for the information received. The security measures consist, at a minimum, of recording and monitoring accesses, ensuring traceability and protecting the data in transit from any violation, as well as from deliberate or accidental threats.

All of this is not happening in a vacuum. In fact, the findings of the Personal Data Protection Authority (PDPA) are awaited regarding the scandal of the leak of confidential personal data of voters abroad.

The decision of the Ministry of Interior on May 10, 2024 regarding changes to the IT system supporting postal voting in order to protect personal data (01). The contract of February 9, 2024 signed between the Ministry of Interior and SingularLogic regarding the provision of software development services for the implementation of postal voting and support of the electoral process (02). A month later, the email-gate scandal broke out in which Anna-Michelle Asimakopoulou is involved. The 2020 digital application activation contract between the Ministry of the Interior and SingularLogic for the electoral process regarding overseas voters (03) As documentonews.gr had revealed on April 29, the president of the authority, Konstantinos Menudakos, had requested new memoranda from those involved and had made it clear that he would not use the conclusion of the Internal Audit Unit of the Ministry of the Interior. The argument put forward for the decision was that this is an internal document of the Ministry of the Interior services and the APDPH will issue its own conclusion.

European Elections - Postal Voting: Changes to the IT support system to protect personal data
European Elections – Postal Voting: Changes to the IT support system to protect personal data

The government's responsibilities

Of course, the important thing is that the leadership of the Ministry of Interior sought to define as critical for the leak of data the period of May-June 2023, when there was a caretaker leadership due to the then election period. But whatever may emerge regarding the time of the leak, the ministers of the ND government are not without responsibility. In fact, Kerameos's effort to hastily shield the postal voting system demonstrates this deafeningly.

We recall some contracts with significance in a time series that leads to political assessments regarding the latest moves by the leadership of the Ministry of Internal Affairs to strengthen the protection of personal data. In 2020, shortly after the Mitsotakis government passed Law 4648/16.12.2019 on the vote of expatriates, a digital application for the electoral process regarding voters abroad is activated with contract 19/2020 between the Ministry of Internal Affairs and SingularLogic.

Three years have passed since then. The Mitsotakis government passed a law on postal voting for domestic and foreign voters (Law 5083/2024). On February 9, 2024, contract 2/2024 was signed between the Ministry of Internal Affairs and SingularLogic for the provision of software development services for the implementation of postal voting and support of the electoral process (contract value 1,612,000 euros). They jointly undertake to comply with the obligations arising from the EU and national regulatory framework for the protection of personal data. In early March 2024, the scandal of the leak of emails of expatriates (Asimakopoulou case) breaks out.

Applications for postal voting began on February 15 and the deadline expired on April 29, 2024. Almost a week later, on May 10, the Ministry of Internal Affairs brings the contract to determine whether the data protection measures of the IT system supporting postal voting were complied with and at the same time explores the possibility of improving it to comply with the technical and organizational security measures of the information received.

As an opposition politician points out to Documento, there are various versions: the Ministry of Interior and Prime Minister Kyriakos Mitsotakis are either coming to fill the gaps or the lack of data protection at a later date or are attempting to prevent the publication of the APDPH's findings. It seems that there are indications of deficiencies in the security of personal data, whether the leak of emails from overseas voters is linked to the implementation of the 19/2020 convention for expatriates or to the implementation of postal voting of the 2/2024 convention.

See more here: documentonews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS