Karnataka Electoral Rolls: Has the ECI Created a Massive Privacy and Doxxing Risk by Publishing Voter Data Online?
TL;DR: The Karnataka CEO has published the 2026 draft electoral rolls online, containing voters' names, age, gender, residential address, and father/spouse details at the polling-station level, with PDFs downloadable across the state. The ASDDO (Absentee, Shifted, Dead, Duplicate, or Official-list electors) data was also made publicly accessible through Google Drive. While electoral rolls need to be transparent and publicly accessible, I question whether unrestricted online access and bulk downloading of this amount of personally identifying information is necessary or proportionate, and whether stronger privacy/security controls should be in place. ECI already provides individual voter lookup functionality, so I believe there are ways to preserve electoral transparency while significantly reducing the risk of mass harvesting, profiling, stalking and doxxing.
On August 24, 2026, the Office of the Chief Electoral Officer of Karnataka published the Draft Electoral Rolls, following the earlier publication of the ASDDO list at the polling-booth level for the entire state. Both datasets have been made accessible online for anyone to view and download. This creates a significant privacy and security issue for the citizens of Karnataka.
Data currently published by the CEO of Karnataka on their website [1] contains the following electors' information at the polling booth level:
- Full Name
- Approximate or Exact Age
- Gender
- Residential Address including Home Number
- Father's or Spouse's Name
- Polling Station and Constituency Name
This is a very powerful dataset that can be used for identity correlation and doxxing. Any bad actor can potentially combine the electoral roll information with social media, data-broker information (available for purchase), leaked databases, property records, and other publicly available information to identify, profile, stalk, or worse harm someone.
The bigger concern is the scale and permanence of this disclosure. Once these PDFs are downloaded for the entire state, they can be copied, indexed, mirrored, sold, combined with other datasets, and redistributed indefinitely. Removing the original files later would not undo that exposure.
Exposing the Address in combination with Name, Father/Spouse's Name, and Gender creates significant risks for:
- Victims of stalking or domestic violence
- Women/Individuals who may be trying to keep their residential location private
- People facing several forms of harassment (communal/political)
- Celebrities, politicians, public figures, and ordinary people who may receive targeted threats to their physical safety or life
As of this moment, the PDF files of all electors across the state can be downloaded by selecting the Constituency, selecting the Polling Booth(s), entering a CAPTCHA and hitting the download button. Furthermore, the website allows for download of every polling booth across the entire state one constituency at a time. Also, ASDDO data was made publicly accessible through Google Drive. Anyone with access to the internet, including criminals, stalkers, commercial data brokers, political organizations, and other third parties, can potentially obtain this data.
The Legal and Regulatory Frame
Article 21 of the constitution provides for a right to privacy. Additionally, the Digital Personal Data Protection Act, 2023 (DPDP) regulates the processing of digital personal data while also providing exemptions for publicly mandatory data under Section 17 of the Act. DPDP Act framework is being brought into force in phases. However, controls for privacy protection put in place by the Election Commission of India appear to be insufficient. Now the public has to deal with the implications of publishing this online for all to see.
Today, ECI already provides a tool for individual voters to search their information with "Search Your Name in Voter List". The Election Commission could use the same platform and expand it to transparently make available voters lists to authorised recipients by setting up controls not limited to the following:
- Individuals should be able to look up their own information after providing their personal particulars (name, and address or voter ID number followed by a CAPTCHA)
- Limiting Bulk Downloads (rate limits, redacting or not publishing public datasets)
- Using controls for where citizens' personal information is hosted
- Providing full copies to political parties and authorised election participants with seeded lists (canary records) to identify leaks
Now that we are here, it is up to each and every one of us in civil society to engage with your MP, ECI, and MLA to get them to fix their error and not repeat it in other states. Reach out to your MP, MLA, and news media.
Disclaimer: I would like to clarify that this is not a political post and as a security researcher, I am trying to bring the actual issue to notice and want it addressed.
[1] https://ceo.karnataka.gov.in/en
[2] https://egazette.gov.in/WriteReadData/2023/248045.pdf
Example ASDDO Google Drive: [REDACTED] (Available directly from CEO website)