South African Electoral Commission’s mobile app for voters: Data privacy and security dimensions

In 2014, the Electoral Commission of South Africa (also known the “IEC”) launched a mobile app to support voter participation in electoral processes. The app, called IEC South Africa, can be used to verify, update, and confirm a voter’s registration details and voting station. It also provides an i...

Full description

Saved in:
Bibliographic Details
Main Authors: Nawal Omar, Scott Timcke
Format: Article
Language:English
Published: LINK Centre, School of Literature Language and Media (SLLM) 2024-12-01
Series:The African Journal of Information and Communication
Subjects:
Online Access:https://ajic.wits.ac.za/article/view/18132
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1841559951880749056
author Nawal Omar
Scott Timcke
author_facet Nawal Omar
Scott Timcke
author_sort Nawal Omar
collection DOAJ
description In 2014, the Electoral Commission of South Africa (also known the “IEC”) launched a mobile app to support voter participation in electoral processes. The app, called IEC South Africa, can be used to verify, update, and confirm a voter’s registration details and voting station. It also provides an interface for special-vote applications and real-time election results. This study conducted a privacy and security analysis of the app, through a compliance review of the IEC’s privacy policy in terms of the South African data protection legislation, followed by an analysis of the app’s APK files, permissions, third-party trackers, and vulnerabilities, including API (application programming interface) calls. The analysis revealed several security and privacy concerns, including inadequately secured API keys, the potential for unauthorised access, and the potential for data breaches. In addition, the presence of advertising and analytics trackers suggested third-party data-sharing, raising concerns about transparency and user consent. The study draws attention to the need for the IEC to take action to address the app’s security and privacy weaknesses. The study also demonstrates the importance of data minimisation, transparent practices, and adherence to privacy policies in order to maintain user trust and security in electoral technology.
format Article
id doaj-art-9547fedb4e6942d3b0b0c4da339eb980
institution Kabale University
issn 2077-7205
2077-7213
language English
publishDate 2024-12-01
publisher LINK Centre, School of Literature Language and Media (SLLM)
record_format Article
series The African Journal of Information and Communication
spelling doaj-art-9547fedb4e6942d3b0b0c4da339eb9802025-01-05T08:27:41ZengLINK Centre, School of Literature Language and Media (SLLM)The African Journal of Information and Communication2077-72052077-72132024-12-013410.23962/ajic.i34.18132South African Electoral Commission’s mobile app for voters: Data privacy and security dimensionsNawal Omar0https://orcid.org/0009-0008-4665-1227Scott Timcke1https://orcid.org/0000-0001-7125-8306Research ICT Africa (RIA), Cape TownResearch ICT Africa (RIA), Cape Town In 2014, the Electoral Commission of South Africa (also known the “IEC”) launched a mobile app to support voter participation in electoral processes. The app, called IEC South Africa, can be used to verify, update, and confirm a voter’s registration details and voting station. It also provides an interface for special-vote applications and real-time election results. This study conducted a privacy and security analysis of the app, through a compliance review of the IEC’s privacy policy in terms of the South African data protection legislation, followed by an analysis of the app’s APK files, permissions, third-party trackers, and vulnerabilities, including API (application programming interface) calls. The analysis revealed several security and privacy concerns, including inadequately secured API keys, the potential for unauthorised access, and the potential for data breaches. In addition, the presence of advertising and analytics trackers suggested third-party data-sharing, raising concerns about transparency and user consent. The study draws attention to the need for the IEC to take action to address the app’s security and privacy weaknesses. The study also demonstrates the importance of data minimisation, transparent practices, and adherence to privacy policies in order to maintain user trust and security in electoral technology. https://ajic.wits.ac.za/article/view/18132elections, voters, technology, mobile apps, data privacy, data security, South Africa, Electoral Commission, IEC
spellingShingle Nawal Omar
Scott Timcke
South African Electoral Commission’s mobile app for voters: Data privacy and security dimensions
The African Journal of Information and Communication
elections, voters, technology, mobile apps, data privacy, data security, South Africa, Electoral Commission, IEC
title South African Electoral Commission’s mobile app for voters: Data privacy and security dimensions
title_full South African Electoral Commission’s mobile app for voters: Data privacy and security dimensions
title_fullStr South African Electoral Commission’s mobile app for voters: Data privacy and security dimensions
title_full_unstemmed South African Electoral Commission’s mobile app for voters: Data privacy and security dimensions
title_short South African Electoral Commission’s mobile app for voters: Data privacy and security dimensions
title_sort south african electoral commission s mobile app for voters data privacy and security dimensions
topic elections, voters, technology, mobile apps, data privacy, data security, South Africa, Electoral Commission, IEC
url https://ajic.wits.ac.za/article/view/18132
work_keys_str_mv AT nawalomar southafricanelectoralcommissionsmobileappforvotersdataprivacyandsecuritydimensions
AT scotttimcke southafricanelectoralcommissionsmobileappforvotersdataprivacyandsecuritydimensions