Electronic voting (e-voting) presents a significant opportunity to enhance electoral administration, voter inclusion, and post-election auditability.177 However, it simultaneously introduces constitutional, legal, and technical risks that, if not carefully managed, may undermine public confidence, electoral legitimacy, and the fundamental right to vote. In the Ghanaian context, the introduction of e-voting must be approached with heightened sensitivity to inclusivity, particularly for persons with disabilities, including voters who are blind, visually impaired, deaf, hard of hearing, or physically mobility-restricted. Traditional paper-based voting methods in Ghana have historically posed challenges to these groups, often forcing reliance on third-party assistance that compromises ballot secrecy and voter autonomy.178 Any electronic voting framework that fails to address these shortcomings would merely digitize exclusion rather than remedy it.
This document treats accessibility and inclusion as core constitutional design requirements, grounded in the principles of equality, dignity, and universal suffrage. The proposed e-voting framework therefore integrates accessibility considerations at both the policy level and the technical architecture level, ensuring that:
Voters with disabilities can cast ballots independently and secretly.
Assistive technologies are embedded by design rather than added as afterthoughts; and
The transition from manual to electronic processes does not disadvantage any voter category.
Beyond inclusion, the purpose of this document is to propose a Ghana-appropriate, legally defensible, and technically resilient e-voting framework that:
preserves constitutional principles of ballot secrecy, transparency, and electoral fairness.
aligns with Ghana’s electoral, cybersecurity, and data protection legal regimes.
acknowledges infrastructural disparities across regions; and
adopts a phased, hybrid deployment model that prioritizes trust, auditability, and national stability.
Ghana-Specific Design Considerations
The design of any electronic voting system must be context aware. In Ghana, electoral processes operate within a complex environment shaped by scale, uneven infrastructure development, socio-political diversity, and episodic electoral conflict.179 These factors impose concrete constraints on the feasibility, reliability, and legitimacy of e-voting and must therefore inform system architecture from the outset.
Scale of the Electorate and Administrative Complexity
Ghana conducts national elections for an electorate exceeding eighteen million registered voters, distributed across two hundred and sixty-one (261) administrative districts and forty thousand six hundred and forty-eight stations.180 Electoral operations must accommodate:
High-volume voter throughput in densely populated urban centres;
Dispersed and low-turnout polling stations in rural and Island communities; and
Simultaneous nationwide voting within constitutionally fixed timeframes.
This scale renders centralized, real-time digital dependency inherently risky. Any e-voting design for Ghana must therefore support horizontal scalability, decentralized operation at the polling station level, and offline-first functionality, ensuring that voting can proceed even in the absence of continuous network connectivity. Systems that presume uninterrupted broadband access or cloud availability would be structurally incompatible with Ghana’s electoral scale.
Infrastructure Gaps and Digital Inequality
Despite significant progress in digital infrastructure, Ghana continues to experience:
Inconsistent mobile data coverage in rural and peri-urban areas.
intermittent power supply in selected districts.
varying levels of digital literacy among voters and temporary electoral staff.
These infrastructure gaps create a risk that purely digital or remote voting systems could systematically disadvantage certain voter populations, thereby violating principles of electoral equality. From a design perspective, this necessitates:
Reliance on physically supervised polling environments as the default voting channel.
Local device-level resilience, including battery-backed operation and local data buffering; and
Minimal dependence on voter-owned devices, which vary widely in capability and security.
Importantly, infrastructure gaps disproportionately affect persons with disabilities in rural areas, who may already face mobility and accessibility barriers.181 An e-voting system that assumes private, personal device access would therefore compound existing inequalities rather than resolve them.
Conflict-Sensitive and High-Risk Electoral Zones
Certain regions and districts in Ghana, including parts of the Upper East and Northern corridors, periodically experience heightened electoral tension, communal conflict, or heavy security deployment during elections.182 In such environments, electoral processes are vulnerable to:
Voter intimidation and coercion.
Disruption of polling activities.
Politicization of technological failures or delays.
For these zones, unrestricted remote e-voting presents heightened risks. Remote voting environments reduce visibility, weaken institutional safeguards, and make it difficult to detect coercion or organized vote manipulation.183 This framework treats conflict-sensitive zones as requiring enhanced procedural control rather than expanded technological autonomy.
Design responses appropriate to such contexts include:
mandatory in-person electronic voting at supervised polling stations.
strengthened authentication and re-voting safeguards.
enhanced audit logging and post-election forensic review capabilities.
Technology in these zones must function as a stabilizing instrument, reinforcing transparency and institutional presence, rather than as a disruptive innovation.
2.4 Implications for System Design
Ghana’s scale, infrastructure disparities, and conflict dynamics compel the adoption of a hybrid e-voting model that prioritizes:
physical polling stations as the primary voting environment.
digital systems that augment, rather than replace, existing electoral safeguards; and
differential deployment rules based on regional risk profiles.
Recommended Hybrid e-Voting Model
In light of Ghana’s electoral scale, infrastructural disparities, and security considerations, this framework recommends a hybrid electronic voting model that combines digitally assisted in-person voting with narrowly defined remote voting channels. This model rejects both extremes fully manual elections and unrestricted remote e-voting in favour of a controlled, rights-preserving, and auditable middle ground
3.1 In-Person Electronic Voting as the Primary Channel
The cornerstone of the proposed model is in-person electronic voting conducted at designated polling stations. Under this approach, voters physically attend polling stations, but ballots are cast using secure electronic voting devices rather than paper ballots.
This model preserves critical electoral safeguards already familiar to the Ghanaian electorate, including
Physical verification of voter presence.
Supervision by trained electoral officers.
Observation by party agents and accredited observers; and
The symbolic and procedural transparency of election day activities.
From a constitutional perspective, in-person electronic voting maintains continuity with existing electoral practices while allowing technology to improve accuracy, speed, and auditability without altering the social contract underpinning Ghana’s elections.
3.2 Design of Polling-Station Electronic Voting
Polling-station voting devices are designed to operate in offline or semi-offline mode, ensuring that:
Voting continues uninterrupted during network outages.
Ballots are securely stored locally until transmission is available; and
No real-time external interference can occur during voting hours.
Authentication, ballot casting, and confirmation occur locally, with encrypted vote data synchronized to central systems only after polls close or when secure connectivity is restored. This design directly addresses infrastructure unreliability and reduces attack surfaces.
For persons with disabilities, polling-station environments provide the controlled conditions necessary to deploy assistive technologies such as audio ballots, tactile interfaces, and sign-language-assisted workflows without exposing voters to coercion or compromising secrecy.
3.3 Restricted Remote Voting Channels
Remote electronic voting is treated as an exceptional accommodation, not a general alternative to in-person voting. Its availability is limited to clearly defined voter categories, such as:
Persons with severe disabilities for whom physical attendance is impracticable.
Ghanaian diplomatic staff and accredited officials stationed abroad; and
Other narrowly defined categories approved by regulation.
Remote voting is subject to enhanced safeguards, including multi-factor authentication, re-voting protections, and anomaly detection, recognizing the elevated risks of coercion, impersonation, and vote buying in unsupervised environments.
3.4 Justification for Restricting Remote Voting
Unrestricted remote voting introduces systemic risks that are particularly acute in the Ghanaian context, including:
Difficulty detecting third-party influence or coercion.
Increased vulnerability to organized vote buying.
Challenges in proving the voluntariness of voter choice; and
Heightened suspicion of technological manipulation in contested elections.
By confining remote voting to exceptional cases, the hybrid model balances accessibility obligations with electoral integrity imperatives, ensuring that inclusion does not come at the expense of legitimacy.
3.5 Uniformity of the Ballot and Tally
Regardless of the voting channel used, all ballots are:
cryptographically identical.
processed through the same tallying and audit mechanisms; and
subject to identical verification and dispute-resolution procedures.
This guarantees that no class of voter receives preferential treatment in vote counting, preserving the principle of equal suffrage.
3.6 Trust, Legitimacy, and Public Confidence
Public trust is not derived solely from technical correctness but from perceived fairness and visibility.184 In-person electronic voting ensures that elections remain a public civic exercise, while restricted remote voting addresses genuine access needs without transforming elections into a private, unverifiable activity.
Integrated Legal-Technical Approach
A core premise of this framework is that electronic voting systems must not merely comply with the law in operation but must be legally constituted by design. In other words, statutory duties under Ghanaian law must be translated into enforceable technical constraints within the system architecture. This section maps key obligations under the Cybersecurity Act, 2020 (Act 1038) and the Data Protection Act, 2012 (Act 843) directly onto the proposed e-voting system design.
4.1 Cybersecurity Act, 2020 (Act 1038): Critical Information Infrastructure by Design
Act 1038 establishes a legal regime for the protection of Critical Information Infrastructure (CII), defined to include systems whose disruption would have a debilitating impact on national security, public order, or economic stability.185 A national e-voting system squarely falls within this category.
4.1.1 Legal Obligation
Under Act 1038, operators of CII are required to:
implement appropriate technical and organizational cybersecurity measures.
ensure system availability, integrity, and resilience.
report cybersecurity incidents; and
submit to regulatory oversight and audits.
4.1.2 Architectural Translation
To satisfy these obligations, the e-voting system is designed as follows:
CII classification by default: The core voting infrastructure, authentication services, and tallying systems are explicitly designated as CII components.
Active–active redundancy: Geographically separated data centres operate concurrently to eliminate single points of failure.
Fail-secure design: In the event of system disruption, voting devices default to secure offline operation rather than shutdown.
Continuous security monitoring: Intrusion detection, integrity checks, and incident logging are embedded as mandatory system services.
4.2 Data Protection Act, 2012 (Act 843): Privacy and Data Minimization
Act 843 establishes principles governing the lawful processing of personal data, including its lawfulness, purpose limitation, data minimization, and security safeguards.186 In an electoral context, these principles are particularly sensitive given the scale and political significance of voter data.
4.2.1 Legal Obligation
The Act requires that:
Personal data is collected only for specified and lawful purposes.
Processing should be limited to what is necessary.
Appropriate security safeguards be applied; and
Data subjects’ rights be respected.
4.2.2 Architectural Translation
The system operationalizes these obligations through:
Strict separation of identity and ballot data: Voter authentication occurs in a logically and physically separate subsystem from vote recording and tallying.
Token-based eligibility confirmation: Once eligibility is verified, the system issues a non-identifying cryptographic token rather than storing personal or biometric data within the voting ledger.
Ephemeral biometric handling: Biometric data used for authentication is processed transiently and never written to persistent voting records.
Purpose-bound data flows: Data collected for eligibility verification is technically prevented from being repurposed for profiling, surveillance, or vote inference.
4.3 Legal Separation of Roles and Responsibilities
Both Acts implicitly require clarity in accountability. The system enforces role separation aligned with legal mandates:
The Electoral Commission oversees electoral processes but cannot access decrypted ballots.
Cybersecurity oversight bodies monitor infrastructure integrity without access to voter identity data.
Data protection authorities audit compliance without interfering in electoral outcomes.
These separations are encoded into access controls and cryptographic thresholds, ensuring that no single institution can exceed its lawful authority.
4.4 Auditability and Legal Admissibility of Electronic Evidence
Both Act 1038 and Act 843 anticipate the need for reliable electronic records. The system, therefore:
generates cryptographically signed logs.
applies tamper-evident storage mechanisms; and
timestamps all critical events using trusted time sources.
This ensures that electronic evidence produced by the system meets standards of integrity, authenticity, and non-repudiation, making it suitable for judicial scrutiny in election petitions and related disputes.
4.5 Effect of the Integrated Approach
By mapping statutory obligations directly into system architecture, this framework eliminates the risk of “paper compliance” where systems appear lawful on paper but violate rights in practice. Instead, legal norms are transformed into technical constraints, making unlawful operation structurally impossible.
This integrated legal technical approach ensures that Ghana’s adoption of e-voting strengthens, rather than strains its constitutional and regulatory order.
5. Eligibility and National Identification Authority (NIA) Register Integration Policy
5.1 Policy Objective
The objective of the Eligibility and NIA Register Integration Policy is to ensure that only duly qualified voters participate in electronic voting, while simultaneously safeguarding voter privacy, preventing double voting, and maintaining strict separation between voter identity and ballot choice.187
This policy recognizes that voter eligibility verification is a pre-voting function, not a component of vote casting itself, and must therefore be architecturally and legally isolated from the voting and tallying processes.
5.2 Legal Basis and Institutional Alignment
This policy is grounded in:
the constitutional requirement that voting rights be exercised only by eligible persons.
the statutory mandate of the Electoral Commission to compile and maintain the voters’ register; and
the lawful authority of the National Identification Authority to maintain a national biometric identity database.
Integration between electoral systems and the NIA register is therefore permitted solely for eligibility verification purposes and must not extend to ballot attribution or vote inference.
5.3 Scope of NIA Integration
The e-voting system shall integrate with the NIA register under the following strict limitations:
Eligibility Confirmation Only
The NIA interface shall be used exclusively to confirm:
Identity authenticity; and
Voting eligibility status.
No Transfer of Biometric Templates
Biometric data (including fingerprints and facial templates) shall not be stored, cached, or replicated within the e-voting system.
One-Time Verification Per Voting Session
Eligibility verification occurs once per voter per election cycle, preventing multiple voting attempts.
5.4 Token-Based Eligibility Architecture
Upon successful verification against the NIA register, the system issues a cryptographically generated, non-identifying eligibility token. This token:
confirms that the voter is eligible.
carries no personal or biometric data; and
cannot be reverse engineered to identify the voter.
The eligibility token is the only artefact permitted to cross the boundary between the identity verification subsystem and the ballot casting subsystem.
5.5 Separation of Identity and Ballot
To preserve ballot secrecy:
Identity verification systems are logically and physically segregated from voting systems.
Voting devices do not store names, NIA numbers, or biometric identifiers; and
No system component is capable of linking a cast ballot to a verified identity.
5.6 Handling of Persons with Disabilities
The eligibility verification process shall accommodate voters with disabilities by:
supporting alternative biometric modalities where standard capture is impracticable.
permitting assisted authentication without revealing ballot choices; and
ensuring that disability-related accommodations do not result in enhanced data capture or reduced privacy protections.
No voter shall be excluded or subjected to inferior secrecy protections on the basis of disability.
5.7 Fraud Prevention and Audit Controls
To prevent impersonation and multiple voting:
Each eligibility token is single-use and time-bound.
Token issuance and consumption events are immutably logged; and
Anomalous authentication patterns are flagged for post-election audit without exposing voter identities.
5.8 Prohibited Practices
The following are expressly prohibited:
storage of biometric data within voting or tallying systems.
reuse of eligibility data for profiling, surveillance, or political analysis.
any architectural linkage capable of correlating voter identity with ballot content.
5.9 Effect of the Policy
This policy ensures that voter eligibility verification is:
accurate without being intrusive.
secure without being over-centralized; and
legally compliant without undermining ballot secrecy.
6. Ballot Secrecy and Threshold Cryptography Policy
6.1 Policy Objective
The objective of the Ballot Secrecy and Threshold Cryptography Policy is to ensure that no person, institution, or system component can determine how an individual voter voted, whether during the election, after the election, or under compulsion. Ballot secrecy is treated not merely as an administrative rule but as a non-negotiable constitutional invariant enforced by cryptographic design.
This policy recognizes that in electronic voting systems, secrecy cannot rely on trust in officials or procedures alone; it must be rendered technically and structurally irreversible.
6.2 Constitutional and Democratic Basis
The secrecy of the ballot underpins:
voter autonomy and freedom of choice.
protection against intimidation, retaliation, and vote buying; and
the legitimacy of electoral outcomes.
Any electronic voting system that allows, theoretically, the reconstruction of voter choices from system records would violate these foundational principles and undermine public confidence.
6.3 Threshold Cryptography as a Secrecy Mechanism
To enforce ballot secrecy, the system adopts threshold cryptography for vote encryption and tally decryption.
Under this approach:
ballots are encrypted immediately upon casting.
the cryptographic key required to decrypt or tally votes is mathematically split into multiple independent key shares; and no single authority holds sufficient information to decrypt ballots or partial results.
Only when a legally defined quorum of independent key holders cooperates can decryption occur, and only for the purpose of generating aggregated tallies.
6.4 Distribution of Cryptographic Trust
Key shares are distributed among institutionally and functionally independent entities, such as:
the Electoral Commission.
an independent judiciary-designated custodian.
accredited independent auditors or civil society representatives; and
a national cybersecurity oversight authority.
6.5 Prohibition of Individual Ballot Decryption
The system is expressly designed such that:
individual ballots cannot be decrypted at any point.
decryption operations apply only to aggregated datasets; and
Partial tallies cannot be generated before lawful close of polls.
Even during dispute resolution or forensic audits, verification relies on cryptographic proofs rather than revealing ballot contents.
6.6 Ballot Lifecycle and Irreversibility
Once a ballot is cast:
It is encrypted on the voting device.
It is stripped of any session or device identifiers.
It is committed to an append-only vote ledger, and
It becomes mathematically unlinkable to the voter.
At no stage does the system retain or generate a reversible mapping between voter identity and ballot content.
6.7 Interaction with Accessibility and Assisted Voting
For voters requiring assistance, including blind or mobility-impaired voters, assistive interfaces and helpers may facilitate ballot selection, but:
The encryption and submission of the ballot remain automated.
Assistants cannot view or retain the final encrypted vote; and
No additional metadata is introduced that could weaken secrecy guarantees.
Accessibility accommodations shall not dilute cryptographic protections.
6.8 Auditability Without Disclosure
Ballot secrecy does not preclude transparency. The system therefore enables:
public verification that all encrypted ballots are included in the final tally.
mathematical proof that tallies are correctly computed; and
independent validation without access to plaintext votes.
Transparency is achieved through verifiability, not disclosure.
6.9 Prohibited Practices
The following are strictly prohibited:
storage of unencrypted ballots at any stage.
possession of full decryption keys by any single entity.
generation of voter-specific receipts that reveal vote choices; and
debugging or diagnostic modes capable of exposing ballot contents.
6.10 Effect of the Policy
By embedding threshold cryptography into the core of the voting system, this policy ensures that ballot secrecy is not dependent on trust, discretion, or good faith, but is instead guaranteed by mathematical constraints.
The secrecy of the vote is thus preserved even in adversarial conditions, institutional failure, or post-election legal disputes.
7. Multi-Factor Authentication (MFA) and Anti-Fraud Policy
The electronic voting system shall employ mandatory multi-factor authentication to ensure that only eligible voters participate in the election and that each voter is able to vote only once. Authentication is treated strictly as a pre-voting gatekeeping function and is architecturally separated from ballot casting and tallying processes to preserve ballot secrecy. Authentication shall combine biometric verification, a one-time cryptographic token issued for the voting session, and contextual controls such as physical presence at a polling station or authorized remote voting environment. No single authentication factor shall be sufficient on its own, and all authentication credentials shall be time-bound and single-use to prevent replay or impersonation attacks.
To mitigate electoral fraud, the system shall implement automated controls to detect abnormal authentication patterns, repeated failed attempts, and statistically anomalous voting behaviours.
These controls shall operate on anonymized event data and shall not enable identification of voter choices or linkage between voter identity and ballot content. Enhanced authentication requirements shall apply to any authorized remote voting channels, recognizing the heightened risks associated with unsupervised voting environments. At all times, authentication data shall not be stored with ballot data, embedded in ballot metadata, or accessible to tallying systems.
The MFA framework shall be designed to accommodate voters with disabilities by providing accessible alternatives to standard biometric modalities, without weakening security controls or diminishing voter privacy. Under no circumstances shall authentication mechanisms result in traceability of votes, retention of biometric data beyond the voting session, or creation of evidence that could be used to prove how a voter voted.
WCAG 2.2 Accessibility and Inclusion Policy (Blind and Deaf Voters)
The electronic voting system shall be designed and operated in full alignment with WCAG 2.2 accessibility standards and persons with disability Act,2006 (Act 715)188 ensuring that voters who are blind, visually impaired, deaf, hard of hearing, or otherwise disabled can exercise their right to vote independently, secretly, and with dignity. Accessibility is seen as a basic constitutional requirement, not as an extra or optional part of the system.
Voting interfaces at polling stations shall support assistive technologies, including screen readers, audio-guided ballots delivered through secure personal headsets, tactile or simplified input controls, and adjustable visual contrast and text scaling. For deaf and hard-of-hearing voters, the system shall provide clear visual instructions, text-based prompts, and non-audio confirmation mechanisms without reliance on spoken guidance.
Where voter assistance is required, such assistance shall be limited strictly to facilitating interaction with the interface and shall not extend to influencing, observing, or recording the voter’s ballot choice. The system shall ensure that encryption, submission, and confirmation of the ballot occur automatically, preventing assistants or officials from accessing vote content.
Remote or assisted voting accommodations for persons with disabilities shall not result in weaker authentication, reduced ballot secrecy, or enhanced data capture. No disability-related metadata shall be attached to ballots or voting records, and no accessibility accommodation shall create a distinguishable voting pattern capable of indirect identification.
By embedding WCAG 2.2 compliance directly into system design, this policy ensures that electronic voting enhances democratic inclusion while preserving equality of suffrage, ballot secrecy, and public confidence in the electoral process.
9. Transparency and "Public Bulletin Board" Policy
To ensure public confidence, verifiability, and institutional accountability, the electronic voting system shall incorporate a publicly accessible digital bulletin board that enables independent verification of the integrity of the election without revealing voter identities or ballot choices. Transparency is achieved through cryptographic verifiability rather than disclosure of sensitive information.189 The public bulletin board shall publish, in near real time or at legally prescribed intervals, non-identifying election artifacts, including encrypted ballot hashes, proofs of ballot inclusion, system integrity attestations, and final tally verification data. These records shall be immutable, append-only, and protected against alteration or deletion, ensuring that all published information remains permanently auditable.
No information published on the bulletin board shall contain personal data, biometric identifiers, device identifiers, or metadata capable of linking a ballot to an individual voter. The bulletin board shall not support search, filtering, or correlation functions that could enable indirect inference of voting behaviour.
Access to the bulletin board shall be open to political parties, accredited observers, civil society organizations, the media, and the general public. Independent experts shall be able to verify that all recorded ballots are included in the final tally and that the tally has been correctly computed, without requiring privileged system access. The bulletin board shall function as the primary mechanism for post-election transparency, enabling electoral stakeholders and courts to independently assess the credibility of election results while preserving the secrecy and integrity of the ballot.
10. Dispute Resolution and Electronic Evidence Policy
The electronic voting system shall be designed to support timely, fair, and legally defensible resolution of electoral disputes by generating electronic records that meet standards of integrity, authenticity, and reliability required for judicial proceedings. Dispute resolution is treated as a core system function rather than a post-election administrative activity.
All critical system events including voter authentication attempts, ballot casting, system configuration changes, data transmissions, and tally operations shall be automatically logged, time-stamped, and cryptographically signed. These records shall be stored in tamper-evident, write-once-read-many (WORM) or equivalently secure storage, ensuring that logs cannot be altered, suppressed, or selectively disclosed. Electronic evidence produced by the system shall be structured to enable independent verification by courts, election tribunals, and authorized experts without requiring access to live election infrastructure or compromising ballot secrecy. Verification shall rely on cryptographic proofs, hash comparisons, and integrity attestations rather than disclosure of voter identities or ballot content.
Access to detailed forensic records shall be restricted to lawful processes initiated by the Electoral Commission, a competent court, or other legally authorized bodies. Public disclosure of dispute-related evidence shall be limited to non-identifying materials necessary to establish procedural compliance and system integrity. No dispute resolution process shall permit reconstruction of individual voting choices or linkage between voters and ballots. Where irregularities are identified, remedies shall focus on procedural correction, system validation, or lawful reruns in affected areas, rather than exposure of individual voter behaviour.
By embedding evidentiary integrity and verifiability into system architecture, this policy ensures that electoral disputes can be resolved through lawful proof rather than conjecture, reinforcing public trust and judicial confidence in electronically assisted elections.
Design Specifications
The technical architecture of the proposed e-voting system is designed to operationalize the legal and policy rules outlined above, translating them into enforceable system components. The architecture follows three guiding principles:
Functional separation (identity, voting, and tallying must not collapse into a single trust domain).
Defense-in-depth (security controls at device, network, service, and cryptographic layers); and
Sovereign control with selective cloud leverage, ensuring national ownership of sensitive electoral assets.
The system is organized around three core components: Voter Channels, Authentication Services, and the Vote Ledger and Public Record
11.1 Voter Channels
Voter channels define the controlled interfaces through which voters interact with the system.190 These channels are deliberately limited, monitored, and standardized to reduce attack surface and coercion risk.
11.1 Supported Voter Channels
Polling-station electronic voting terminals (primary channel);
Web and mobile interfaces for authorized remote voting categories; and
USSD/IVR interfaces for constrained environments, limited to authentication and confirmation flows rather than full ballot interaction.
All voter channels are fronted by global edge infrastructure providing load balancing and distributed denial-of-service (DDoS) protection, while sensitive election operations remain anchored within sovereign infrastructure.
11.2 Security Characteristics
No voter channel stores plaintext ballots.
Device-level encryption is enforced before transmission.
Session identifiers are ephemeral and non-linkable.
Fig 1. Ghana National e-voting system: Hybrid-Sovereign Cloud Architecture
11.2. Authentication and Eligibility Service
The Authentication Service acts as the gatekeeper to the voting system and is strictly separated from ballot creation and tallying components.
11.2.1 Functional Role
The service is responsible for:
verifying voter identity and eligibility.
enforcing multi-factor authentication.
issuing cryptographic eligibility tokens; and
preventing duplicate voting attempts.
Authentication integrates with the national identity infrastructure under a token-based model, ensuring that identity data never enters the voting or tallying subsystems.
11.2.2 Architectural Controls
Authentication services operate within a sovereign Kubernetes cluster.
Hardware Security Modules (HSMs) or secure enclaves protect cryptographic keys.
Mutual TLS and service mesh controls enforce zero-trust communication.
Once an eligibility token is issued, all identity-related context is discarded, and the voter proceeds anonymously to ballot issuance.
11.3. Ballot Creation and Casting Services
Ballot services are responsible for generating, encrypting, and recording votes while preserving secrecy and integrity.
11.3.1 Ballot Issuance
Ballots are dynamically generated after successful authentication.
Ballot definitions are cryptographically signed and versioned.
No ballot is issued without a valid, unused eligibility token.
11.3.2 Ballot Encryption and Casting
Votes are encrypted on the voter device using the election public keys.
Zero-knowledge proofs are generated to confirm ballot validity without revealing vote choice.
Encrypted ballots are submitted to the ballot casting service and stripped of session metadata.
A controlled re-voting mechanism ensures that only the voter’s final submission is retained as valid.
Fig 2. Ghana National e-voting system: Secure and Verifiable Architecture
11.4. Vote Ledger and Public Bulletin Board
The vote ledger forms the single source of truth for all cast ballots and associated integrity proofs.
11.4.1 Ledger Characteristics
Append-only, immutable structure.
Stores encrypted ballots, hashes, timestamps, and proofs.
Does not store voter identity or authentication data.
The ledger is implemented as a permissioned distributed ledger, with validator nodes operated by institutionally independent stakeholders, including electoral authorities, political parties, and accredited civil society observers.
11.4.2 Public Bulletin Board
A subset of ledger data is exposed via a public bulletin board, enabling:
verification that ballots were included.
confirmation that tallies were correctly computed; and
post-election transparency without disclosure.
11.5. Tallying and Key Management (Architectural Boundary)
Vote tallying and key management operate in a logically and physically isolated zone:
encryption keys are split using threshold schemes.
tallying occurs without decrypting individual ballots; and
Final decryption is possible only after lawful poll closure and quorum approval.
11.6. Security Monitoring and Incident Response
Across all components, continuous monitoring is enforced through:
a central Security Operations Centre (SOC).
real-time integrity checks.
red-teaming and penetration testing; and
incident reporting obligations aligned with national cybersecurity law.
11.7 Effect of the Architecture
This architecture ensures that:
Voter identity, vote casting, and vote tallying remain permanently separated.
No single system component can undermine ballot secrecy or election integrity; and
Transparency is achieved through verifiability, not trust.
11.8 Resilient Active-Active Hosting (CII Designation and Disaster Recovery)
The national e-voting system shall be designated and operated as Critical Information Infrastructure (CII) in accordance with the Cybersecurity Act, 2020 (Act 1038). This designation recognizes that any disruption, compromise, or loss of availability of the system would pose a direct risk to national security, public order, and constitutional governance.
To meet CII resilience obligations, the system shall employ an active-active hosting model, with at least two geographically separated, sovereign-controlled data centres operating concurrently. All critical services, including authentication, ballot issuance, vote recording, and ledger replication, shall run in parallel across sites, ensuring that failure or isolation of any single facility does not interrupt voting or compromise data integrity.
Data replication between active sites shall be continuous, encrypted, and integrity-checked, with strict controls to prevent split-brain conditions or inconsistent tallies. Voting terminals and polling-station devices shall be capable of operating in offline or degraded network modes, securely buffering encrypted ballots until connectivity is restored.
A comprehensive disaster recovery and business continuity plan shall be maintained, tested, and audited before each electoral cycle. This plan shall cover power outages, network failures, cyber incidents, and physical security threats and shall ensure that elections can proceed safely without loss, duplication, or alteration of votes.
11.9 End-to-End (E2E) Voting Workflow (Cast-as-Intended to Tallied-as-Recorded)
The electronic voting system shall implement a verifiable end-to-end (E2E) voting workflow that allows voters, observers, and auditors to independently confirm the correctness of election outcomes without compromising ballot secrecy. The E2E model guarantees three core properties: cast-as-intended, recorded-as-cast, and tallied-as-recorded.
Cast-as-Intended is achieved by allowing the voter to review and confirm their ballot selections on the voting interface before final submission. Assistive technologies for voters with disabilities operate within this stage without exposing or altering vote choices. Once confirmed, the ballot is cryptographically sealed on the device, ensuring that no subsequent system action can modify the voter’s intent.
Recorded-as-Cast is ensured by encrypting the ballot immediately upon casting and committing it to an immutable vote ledger. The system generates a non-revealing cryptographic receipt or tracker that enables the voter or observer to later verify that the encrypted ballot was successfully recorded, without revealing the content of the vote or enabling proof to third parties.
Tallied-as-Recorded is enforced through cryptographic tallying mechanisms that aggregate encrypted ballots exactly as recorded in the ledger. No ballot is decrypted individually. Final tallies are produced only after lawful poll closure and are accompanied by mathematical proofs demonstrating that the tally corresponds precisely to the set of recorded encrypted ballots.
Throughout the E2E workflow, identity verification, ballot casting, vote recording, and tallying remain strictly segregated. At no point does the system permit linkage between voter identity and ballot content, and no system component is capable of altering a ballot without detection.
By implementing a full E2E verifiable workflow, the system replaces trust in administrators with verifiable correctness, allowing election results to be confirmed by technical proof rather than institutional assurance alone.
11.10 Software Integrity
The integrity of the electronic voting system shall be protected through mandatory software authenticity controls, strong cryptographic safeguards, and tamper-evident evidence preservation mechanisms. Software integrity is treated as a prerequisite for electoral legitimacy and judicial admissibility.
All executable code deployed across voter devices, backend services, and tallying systems shall be digitally signed using trusted cryptographic certificates. Voting devices and servers shall verify code signatures at installation and at runtime, preventing execution of unauthorized, modified, or malicious software. Any failure of signature verification shall result in automatic system lockdown and audit logging.
All sensitive data, including encrypted ballots, system logs, configuration states, and transmission payloads, shall be protected using AES-128 encryption or higher, applied consistently for data at rest and in transit. Cryptographic keys shall be generated, stored, and used within secure hardware environments, ensuring that encryption protections cannot be bypassed through software compromise alone.
Audit logs, vote records, and dispute-relevant artifacts shall be stored in Write-Once-Read-Many (WORM) or functionally equivalent immutable storage. Once written, such records shall not be alterable or deletable, ensuring preservation of evidentiary integrity throughout the electoral lifecycle. All stored records shall be cryptographically hashed and time-stamped to enable independent verification of completeness and authenticity.
Together, code signing, encryption, and immutable storage ensure that any unauthorized modification of the voting system or its records is either technically impossible or immediately detectable, thereby safeguarding the credibility of election outcomes and the reliability of electronic evidence.
11.11 Air-Gapped "Opinion Poll" Separated Function
Any electronic opinion polling, simulation, testing, or public sentiment collection functions shall be strictly separated from the live electronic voting system through air-gapped infrastructure. Under no circumstances shall opinion polls, mock elections, voter education simulations, or analytics platforms share networks, databases, cryptographic keys, personnel access credentials, or operational tooling with the national e-voting system.
This separation is necessary to prevent:
indirect influence on voter behaviour through perceived trends or early indicators.
leakage of live electoral data into analytical or predictive systems; and
contamination of legally protected voting infrastructure with non-electoral data flows.
The opinion polling environment shall operate on independently managed infrastructure, using distinct software stacks, identity systems, and data governance rules. Data transfer between the opinion poll environment and the e-voting system shall be prohibited in both directions, whether direct or indirect, automated or manual. Where opinion polling results are publicly released, such releases shall be governed by electoral regulations and timing restrictions and shall not rely on any artefacts, telemetry, or metadata derived from the live voting system.
By enforcing an air-gapped separation, the architecture ensures that public opinion measurement does not distort electoral choice, preserves voter autonomy, and protects the integrity, neutrality, and credibility of the electronic voting process.
12. Anti-Vote Buying and Coercion Controls
12.1 Biometric-Bound OTP Confirmation
To deter impersonation, proxy voting, and coerced submissions, the electronic voting system shall require biometric-bound one-time confirmation at the point of final vote submission. This confirmation links the act of voting to the verified presence of the eligible voter at that moment, without linking identity to ballot content.
The confirmation token shall be valid only for a single voting session and shall expire immediately after use. This ensures that votes cannot be cast in advance, delegated, or completed under delayed third-party instruction. No confirmation artefact shall be retained in a form capable of identifying the voter or revealing vote choice.
12.2 Re-Voting "Last Vote Counts" Rule
The system shall permit voters to re-cast their vote multiple times within the legally defined polling period, with only the final valid submission being counted in the official tally. Earlier submissions shall be cryptographically invalidated and excluded from the count.
This rule directly undermines vote-buying and coercion schemes by eliminating the buyer’s ability to rely on an initial vote as final. A voter subjected to pressure may subsequently change their vote privately, rendering coercion and vote purchasing economically and practically ineffective.
12.3 "No Proof" Cryptographic Tracker Receipts
Voters may receive a cryptographic tracker or receipt that allows them to verify that their encrypted ballot was included in the public vote ledger. However, such receipts shall be non-transferable, non-interpretable, and incapable of revealing ballot content. The receipt shall not constitute proof of how the voter voted and shall not be usable to convince a third party of compliance with vote-buying or coercion demands. Any design that enables a voter to demonstrate their vote choice to another person is expressly prohibited.
12.4 Effect of Anti-Coercion Controls
By combining biometric confirmation, re-voting capability, and no-proof receipts, the system ensures that:
Coercion cannot be reliably enforced.
Vote buying cannot be verified, and
Voter autonomy is preserved even in high-risk environments.
These controls shift the electoral environment decisively in favour of free choice, ensuring that technological convenience does not erode the fundamental democratic principle of voluntary voting.
13. Audit Evidence Outputs
13.1 Public Vote Record Dump
To support transparency, independent verification, and public confidence, the electronic voting system shall generate a public vote record dump at legally prescribed stages of the electoral process. This dump shall contain non-identifying cryptographic artifacts sufficient to verify the integrity and correctness of the election outcome without exposing voter identities or ballot choices.
The public vote record dump shall include:
cryptographic hashes of all encrypted ballots.
proofs of ballot inclusion in the immutable vote ledger.
verifiable tally proofs demonstrating that results were computed exclusively from recorded ballots; and
system integrity attestations confirming that approved software versions were used.
These artifacts shall be published through the public bulletin board and made accessible to political parties, accredited observers, civil society organizations, the media, and the general public. Independent technical experts shall be able to reproduce verification checks using publicly available data and methods, without requiring privileged access to election infrastructure.
Under no circumstances shall the public vote record dump contain personal data, biometric identifiers, polling-station identifiers capable of voter inference, or metadata that could indirectly reveal voting behavior.
13.2 Restricted Forensic Voter Fraud Dump
In addition to public transparency outputs, the system shall generate a restricted forensic audit dump intended solely for lawful investigation of electoral irregularities. This dump shall not be publicly accessible and shall be released only upon authorization by the Electoral Commission, a competent court, or another body empowered by law.
The restricted forensic dump may include:
anonymized authentication and voting event logs.
statistical indicators of anomalous voting patterns.
records of failed or repeated authentication attempts; and
integrity alerts generated by security monitoring systems.
These records shall be designed to support pattern-based forensic analysis, enabling investigators to detect coordinated fraud, system misuse, or operational failures without reconstructing individual voter choices or identities. Access to forensic audit data shall be strictly controlled, logged, and auditable. Any disclosure beyond authorized purposes shall constitute a serious breach of electoral and data protection obligations.
13.3 Evidentiary Value and Legal Admissibility
Both public and restricted audit outputs shall be generated automatically, time-stamped, cryptographically signed, and preserved in immutable storage. This ensures that audit evidence meets the standards of authenticity, completeness, and non-repudiation required for judicial proceedings, election petitions, and post-election reviews. By separating public verifiability from restricted forensic investigation, the system balances transparency with privacy, enabling effective oversight without undermining ballot secrecy or voter trust.
Phased Five-Year Implementation Roadmap
The introduction of electronic voting in Ghana shall follow a phased, incremental approach designed to minimize risk, build public trust, and ensure legal, technical, and institutional readiness before nationwide deployment. Each phase shall be subject to independent review and approval before progression to the next stage.
14.1 Phase 1: Legal Alignment and Strategy Formulation
This phase focuses on aligning existing electoral, cybersecurity, and data protection laws with electronic voting requirements. Activities include legal gap analysis, stakeholder consultations, drafting of legislative amendments and subsidiary instruments, and development of national e-voting standards and governance frameworks. No live voting systems are deployed during this phase.
14.2 Phase 2: Systems Development and Infrastructure Hardening
Core e-voting systems are designed, developed, and tested in controlled environments. This phase includes infrastructure hardening in line with Critical Information Infrastructure obligations, security audits, accessibility testing, and simulated elections. All testing remains non-binding and does not affect real electoral outcomes.
14.3 Phase 3: Hybrid Pilots in Target Districts
Limited pilot deployments are conducted in carefully selected districts, including conflict-sensitive or logistically challenging areas such as Bawku, to validate system resilience, usability, accessibility, and public confidence. Pilots operate alongside traditional electoral safeguards and are closely monitored by independent observers and auditors.
14.4 Phase 4: National Staff Training and Public Education
This phase emphasizes human readiness. Electoral officers, security agencies, political parties, and judicial stakeholders receive comprehensive training. Public education campaigns are conducted nationwide to familiarize voters with electronic voting procedures, accessibility features, and verification mechanisms.
14.5 Phase 5: National General Election and Final Audit
Following successful pilots and nationwide preparedness, the system is deployed for a general election under full legal authority. A comprehensive post-election audit is conducted, covering technical performance, legal compliance, accessibility outcomes, and public trust indicators. Findings inform future refinements or legislative adjustments.
14.6 Normative Effect of the Roadmap
This phased approach ensures that electronic voting in Ghana evolves through evidence-based progression rather than abrupt transformation, reducing systemic risk while reinforcing democratic legitimacy and institutional confidence.
15. Required Legal Instruments
The lawful deployment of electronic voting in Ghana requires a clear and coherent legal framework that expressly authorizes electronic electoral processes, defines institutional responsibilities, and safeguards constitutional rights. The following legal instruments are required to give binding effect to the proposed system.
15.1 Principal Electoral (Electronic Voting) Act Amendments
Primary electoral legislation shall be amended to explicitly recognize electronic voting as a lawful method of voting under specified conditions. Such amendments shall define:
the legal status of electronic ballots and electronic tallies.
the conditions under which electronic voting may be conducted.
the authority of the Electoral Commission to deploy and regulate e-voting systems; and
the evidentiary status of electronic election records in electoral disputes.
These amendments shall preserve constitutional principles of universal suffrage, secrecy of the ballot, and electoral transparency.
15.2 Subsidiary Constitutional Instruments (C.I.s) for Registration and Conduct
Detailed operational rules governing electronic registration, authentication, voting, tallying, and audits shall be set out in Constitutional Instruments (C.I.s) issued pursuant to the Constitution and enabling legislation. These instruments shall address:
voter eligibility verification procedures.
acceptable voting channels and conditions for remote voting.
accessibility accommodations for persons with disabilities.
polling station procedures for electronic voting; and
post-election audit and verification processes.
C.I.s shall provide flexibility for technical evolution while remaining subject to parliamentary oversight.
15.3 Regulatory Directives for CII and Voter Privacy
Regulatory directives issued under existing cybersecurity and data protection laws shall formally designate the e-voting system as Critical Information Infrastructure and impose mandatory security, resilience, and incident-reporting obligations. Additional directives shall clarify:
lawful data-sharing boundaries between identity systems and electoral systems.
limits on data retention and processing.
audit powers of cybersecurity and data protection authorities; and
sanctions for unauthorized access, misuse, or disclosure of electoral data.
15.4 Effect of the Legal Instruments
Together, these instruments ensure that electronic voting in Ghana is not introduced through administrative discretion alone but is anchored firmly in primary legislation, constitutional instruments, and regulatory oversight, providing legal certainty, democratic legitimacy, and judicial enforceability.
16. Multi-Stakeholder Governance and Oversight
Effective governance of electronic voting requires shared oversight across independent institutions, ensuring that no single actor controls the electoral process end-to-end. The governance model for e-voting in Ghana shall therefore be multi-stakeholder, transparent, and legally accountable.
The Electoral Commission of Ghana shall retain primary constitutional responsibility for the conduct of elections, including policy direction, system deployment, and certification of results. However, the Commission shall not exercise unilateral control over cryptographic keys, system audits, or forensic investigations. Cybersecurity oversight shall be exercised by the Cyber Security Authority, which shall monitor compliance with Critical Information Infrastructure obligations, incident response readiness, and system resilience. Data governance and voter privacy compliance shall fall under the supervisory authority of the Data Protection Commission, with powers to audit data processing practices and enforce statutory safeguards.
Political parties, accredited domestic and international observers, and civil society organizations shall participate in oversight through:
access to public audit artifacts and verification data.
representation in independent audit or verification processes; and
observation of key procedural milestones, including system certification and tally verification.
Independent technical auditors and judicially recognized experts may be appointed to conduct system reviews, penetration testing, and post-election audits. Courts and election tribunals shall retain ultimate authority to adjudicate disputes using system-generated electronic evidence.
This multi-stakeholder governance structure ensures that electronic voting operates within a framework of institutional balance, mutual oversight, and public accountability, reinforcing trust in both the technology and the democratic process.
17. Risk Register and Contingency Planning
The electronic voting system shall be supported by a formal risk register and contingency framework identifying foreseeable technical, operational, and security risks and defining pre-approved mitigation and response measures. Risk management is treated as an ongoing obligation throughout the electoral lifecycle, not a one-time deployment activity.
17.1 Power and Infrastructure Risks
Given the possibility of power instability in certain districts, polling-station voting devices shall be equipped with battery backup and capable of sustained offline operation. Encrypted ballots shall be securely buffered on devices and synchronized automatically once power or connectivity is restored. Manual fallback procedures shall be legally defined and rehearsed in advance.
17.2 Connectivity and Network Risks
The system shall be resilient to partial or total network outages through offline-first design and decentralized polling-station operations. No real-time connectivity shall be required to cast a valid vote. Network disruptions shall not result in vote loss, duplication, or forced poll suspension.
17.3 Malware and Cyberattack Risks
To mitigate malware, insider threats, and external cyberattacks, the system shall employ code signing, runtime integrity checks, intrusion detection, and continuous monitoring. Any detected compromise shall trigger immediate isolation of affected components, preservation of forensic evidence, and activation of incident response protocols in coordination with national cybersecurity authorities.
17.4 Operational and Human Risks
Risks arising from human error, insufficient training, or procedural deviations shall be mitigated through standardized operating procedures, mandatory training, and role-based access controls. All critical actions shall be logged and auditable.
17.5 Escalation and Continuity Measures
Clear escalation paths shall be defined for technical, legal, and security incidents, including authority thresholds for system suspension, reruns in affected areas, or invocation of contingency voting methods. No contingency action shall compromise ballot secrecy or electoral fairness.
Conclusion
The adoption of electronic voting in Ghana is neither a purely technical exercise nor a political shortcut; it is a constitutional undertaking that must be approached with caution, discipline, and institutional maturity. This framework demonstrates that electronic voting can be introduced in Ghana without compromising ballot secrecy, electoral integrity, or public trust, provided that legal principles are allowed to dictate system design rather than the reverse. By grounding system architecture in existing cybersecurity and data protection laws, embedding accessibility as a constitutional obligation, and adopting a hybrid deployment model sensitive to infrastructure gaps and conflict-prone zones, this framework rejects technological absolutism in favour of context-aware democratic engineering. The emphasis on in-person electronic voting, restricted remote channels, end-to-end verifiability, and anti-coercion safeguards reflects Ghana’s socio-political realities and electoral history.
Equally important, the framework recognizes that legitimacy arises not only from correct outcomes but from verifiable processes. Through public audit artifacts, legally admissible electronic evidence, and multi-stakeholder oversight, the system enables elections to be trusted, challenged, and defended using proof rather than conjecture. This document proposes not the digitization of voting for its own sake, but the modernization of electoral governance, one that strengthens inclusion, resilience, and accountability while remaining firmly anchored in constitutional democracy. If implemented incrementally and lawfully, electronic voting can enhance Ghana’s electoral system without undermining the democratic values it exists to protect.