A Princeton University study has revealed that Georgia's ballot secrecy is at risk, with researchers demonstrating that publicly available election data can be used to reconstruct how most voters cast their ballots in recent primaries. The findings highlight a vulnerability in the state's voting system that could allow bad actors to identify individual votes, undermining Georgia's legal requirement for absolute ballot secrecy.

Explainer Election Integrity in America: Safeguarding Voter Trust and Ballot Security

The core issue is that Georgia's ballot scanning machines assign predictable, sequential numbers to each ballot, making it possible to reverse-engineer the order in which ballots were cast and link them to individual voters using other public records. This flaw, first documented by University of Michigan researchers in 2022, remains unaddressed in Georgia despite the availability of a software patch.

Election security and ballot privacy have been under increased scrutiny in Georgia following multiple data breaches and ongoing concerns about the integrity of electronic voting systems. The ability to match ballots to voters not only threatens privacy but could also enable political targeting and voter intimidation.

How the Vulnerability Works

Max Springer, a researcher at Princeton's Center for Information Technology Policy, used data from Georgia's May 2026 primary to reconstruct the scanning order of approximately 1.5 million ballots—covering 98.9% of in-person votes across 139 counties. In smaller jurisdictions, such as Heard County and Ball Ground in Cherokee County, Springer was able to match every early in-person voter to a specific ballot.

The vulnerability is compounded during early voting, where voters from multiple precincts use different ballot styles, creating more data points for linking ballots to individuals. According to Springer, even non-experts using AI tools can exploit this flaw to perform substantial voter profiling.

"Within a few hours, using AI tools and nothing but public records, I was able to reconstruct the order in which 1.5 million ballots were cast in Georgia’s May 2026 primary—98.9% of the in-person ballots."

— Max Springer, Princeton researcher

The risk is particularly acute in small communities, where social and professional relationships make it easier to identify voters. The exposure of individual votes could lead to discrimination, intimidation, or targeted political pressure.

Georgia law mandates "absolute secrecy" of the ballot, prohibiting anyone—including election officials and vendors—from determining how a specific voter cast their ballot. The ability to reconstruct voting choices raises legal concerns and could have significant commercial and political value, as campaigns and advocacy groups seek detailed voter profiles for micro-targeting.

The flaw was formally disclosed to Georgia officials in October 2022, and a peer-reviewed paper on the vulnerability, known as DVSorder, was published in 2024. Despite these warnings, Georgia has not installed the software patch released by Dominion Voting Systems to randomize ballot record IDs and prevent the exploit.

On July 28, 2026, State Elections Director Blake Evans issued an Official Election Bulletin requiring counties to stop releasing ballot images directly and to redact record IDs from public Cast Vote Records. This move aims to limit public access to traceable data but does not address the underlying vulnerability within official systems, where the data remains accessible to state and county officials and vendors.

Responses and Ongoing Debate

The Secretary of State's office has not publicly acknowledged the vulnerability by name, and the directive to restrict public data access was issued without action from the State Election Board, which is considering a similar rule advanced by Board Member Salleigh Grubbs. Critics argue that merely restricting public access fails to solve the problem, as the traceable data persists within government systems.

Mark Davis, president of Data Productions, Inc. and a member of the Georgia Republican Party’s Election Confidence Task Force, warned that the creation of traceable ballots must stop while preserving the ability to audit elections. He noted that the July 28 bulletin severs the public audit trail needed for independent verification, potentially undermining transparency.

"An election system that protects secrecy only by limiting the public’s ability to verify results, while leaving the traceable data in official hands, fails to meet both obligations at once."

— Mark Davis, Data Productions, Inc.

Supporters of the new restrictions argue that redacting record IDs from public releases is a necessary step to protect voter privacy. However, the Election Assistance Commission’s Voluntary Voting System Guidelines and the NIST Cast Vote Records model emphasize the importance of both ballot secrecy and the ability to audit election results. The debate continues over how to balance these competing priorities.

The state has not indicated whether it will implement the Dominion patch or pursue further technical fixes. Data from previous election cycles remains exposed, and the underlying issue of traceable ballots persists in Georgia’s voting infrastructure.

The Bottom Line

  • Princeton's Max Springer showed how Georgia's ballot scanning flaw exposes nearly all in-person votes from the May 2026 primary.
  • Georgia's July 28, 2026 directive restricts public access to ballot data but leaves the underlying vulnerability unaddressed in official systems.
  • The State Election Board is considering further rules, but Georgia has not implemented Dominion's patch to fix the traceable ballot flaw.