Understanding the Privacy Practices of Political Campaigns: A Perspective from the 2020 US Election Websites

Kaushal Kafle, Prianka Mandal, Kapil Singh, Benjamin Andow, Adwait Nadkarni

IEEE Symposium on Security and Privacy 2024 · Day 3 · Continental Ballroom 6

Overview

This article delves into the critical findings presented by Kaushal Kafle, a PhD student at William & Mary and lead graduate student at the Secure Platforms Lab, alongside his colleagues from William & Mary, IBM, and Google. Their research, titled "Understanding the Privacy Practices of Political Campaigns: A Perspective from the 2020 US Election Websites," exposes a significant and concerning gap in data privacy within the American political landscape. The talk highlights how US political campaigns, despite acting as extensive data harvesting operations, operate largely outside the scope of privacy regulations, leading to a severe lack of transparency regarding the collection, use, sharing, and retention of highly sensitive voter data.

Watch on YouTube

Visual summary for Understanding the Privacy Practices of Political Campaigns: A Perspective from the 2020 US Election Websites by Kaushal Kafle, Prianka Mandal, Kapil Singh, Benjamin Andow, Adwait Nadkarni
Visual summary for Understanding the Privacy Practices of Political Campaigns: A Perspective from the 2020 US Election Websites by Kaushal Kafle, Prianka Mandal, Kapil Singh, Benjamin Andow, Adwait Nadkarni

Key moments

  1. 0:00 Introduction: Political campaigns as data harvesters, privacy concerns
  2. 2:00 US political campaigns exempt from privacy regulations (unlike EU)
  3. 2:20 Rationale for studying campaign websites for data practices
  4. 3:40 Three main research questions guiding the study
  5. 4:50 Overview of Potier framework for data collection and analysis
  6. 7:20 Description of the study's large dataset (2000+ campaign websites)
  7. 8:00 Initial finding: Campaigns overwhelmingly collect data via websites

Understanding the Privacy Practices of Political Campaigns: A Perspective from the 2020 US Election Websites

Speakers: Kaushal Kafle, PhD Student; Prianka Mandal; Kapil Singh; Benjamin Andow; Adwait Nadkarni

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=J3lJ6Esza3Q

Overview

This article delves into the critical findings presented by Kaushal Kafle, a PhD student at William & Mary and lead graduate student at the Secure Platforms Lab, alongside his colleagues from William & Mary, IBM, and Google. Their research, titled "Understanding the Privacy Practices of Political Campaigns: A Perspective from the 2020 US Election Websites," exposes a significant and concerning gap in data privacy within the American political landscape. The talk highlights how US political campaigns, despite acting as extensive data harvesting operations, operate largely outside the scope of privacy regulations, leading to a severe lack of transparency regarding the collection, use, sharing, and retention of highly sensitive voter data.

The study, the largest-scale analysis of its kind for US election campaign websites, reveals that a vast majority of campaigns collect personally identifiable information (PII) and even deeply sensitive socioeconomic opinions, often without proper disclosure to voters. This absence of regulation and transparency stands in stark contrast to the European Union's General Data Protection Regulation (GDPR), which explicitly covers political data. The researchers underscore the importance of this work by drawing parallels to past scandals like Cambridge Analytica and demonstrating how current practices expose voters to non-consensual data collection and an unbounded risk to their privacy, both during and after election cycles.

The findings presented are crucial for voters, policymakers, and privacy advocates alike, as they shed light on a largely unaddressed vulnerability in the democratic process. By meticulously analyzing hundreds of campaign websites from the 2020 US election, the team provides concrete evidence of widespread privacy shortcomings. The research not only quantifies the extent of the problem but also offers a framework for understanding the mechanisms of data collection and the profound implications for individual privacy in a hyper-partisan political environment.

Background

▶ Watch: Introduction: Political campaigns as data harvesters, privacy concerns (0:00)

The landscape of modern political campaigning has fundamentally transformed, evolving into sophisticated data harvesting operations. As highlighted by Kafle, historical incidents such as the Cambridge Analytica scandal and reports of a 2016 presidential campaign selling voter data to opposing parties underscore the inherent risks and potential misuse of politically sensitive information. These events have rightly fueled public concern, with surveys post-Cambridge Analytica indicating that approximately 74% of users expressed apprehension about their data being used for political purposes. Prior research consistently demonstrates that users desire strong privacy guarantees, but only once they are informed about how their data is being utilized within a system.

A critical regulatory void exists in the United States concerning political campaigns. Despite collecting vast volumes of sensitive data—including not only political leanings but also deeply personal socioeconomic beliefs on topics like immigration or gun control—US campaigns are largely exempt from privacy regulations. This exemption stems from their classification as non-profit entities, which places them outside the purview of laws like the California Consumer Privacy Act (CCPA) or other state-level privacy statutes that bind for-profit organizations. This stands in stark contrast to the European Union, where the GDPR specifically regulates the processing of political data, offering a precedent for robust oversight.

The research specifically chose to focus on campaign websites for several reasons. Websites serve as the central hub for modern campaign operations, enabling data collection at scale. Even social media posts or other outreach efforts are often designed to funnel voters back to a campaign's website to sign up, donate, or volunteer. Furthermore, websites allow campaigns to directly solicit and collect information that may not be available from public voter rolls, filling in "missing information" through surveys or sign-up processes. This direct interaction makes websites a primary vector for sensitive data acquisition.

The study aimed to answer three core questions:

  1. What data do campaigns collect from their websites?
  2. Do campaigns disclose their data processing practices (collection, use, sharing, retention) to voters?
  3. Is there any conflict between their disclosed practices and their actual data handling?

To provide a comparative context, the researchers occasionally referenced findings from their prior work on Smart Home vendors. These vendors, being for-profit entities, are subject to existing privacy regulations, offering a baseline to contrast the privacy posture of a regulated domain against the unregulated space of political campaigns. This comparison helps to underscore the unique challenges and deficiencies inherent in the current regulatory environment for political data in the US.

Key Findings

▶ Watch: Rationale for studying campaign websites for data practices (2:20)

The study's findings reveal a pervasive lack of transparency and alarming privacy practices among US political campaigns, significantly worse than those observed in regulated sectors.

Widespread Data Collection:

The research confirmed that political campaigns overwhelmingly use their websites for private data collection. A staggering 71% of the analyzed campaign websites were found to be collecting personally identifiable information (PII) from visitors. The study identified 28 unique types of data being collected, with the most common being names, email addresses, phone numbers, and location data—information typically expected in a sign-up process.

Non-Consensual Third-Party Data Collection:

A particularly concerning finding was the collection of data pertaining to individuals other than the direct user. 12 campaigns were observed collecting PII not just from users, but also from their parents or friends (e.g., names, emails of parents/friends). In two specific cases, campaigns extended this to collecting the same information from users' partners. This practice is inherently problematic as it involves the collection of data from third parties who cannot provide direct consent, making it non-consensual by definition and impacting the privacy of individuals who have no direct interaction with the campaign website.

Collection of Sensitive Opinions:

Beyond basic PII, 3% of campaigns were found to be collecting socioeconomic opinions alongside private voter data. This allows campaigns to directly build granular voter profiles based on sensitive beliefs (e.g., on immigration or gun control) from their own websites. Such direct collection of highly sensitive opinion data, combined with PII, facilitates sophisticated micro-targeting and raises significant concerns about potential manipulation and discrimination, especially when transparency is lacking.

Severe Deficiencies in Privacy Policy Disclosure:

The cornerstone of privacy protection, the privacy policy, was found to be largely inadequate or entirely absent.

  • 71% of campaigns did not properly disclose their data collection, sharing, or retention practices. This represents a vast majority operating without informing voters of fundamental privacy postures.
  • For comparison, in the Smart Home vendor context, only 10.5% of vendors lacked any privacy policy, and 43% lacked a smart-home specific policy. This indicates that political campaigns have a significantly worse baseline for privacy disclosure than regulated for-profit entities.

Incomplete Disclosure Even When Policies Exist:

Even among the campaigns that did provide a privacy policy, significant gaps remained:

  • 41% of campaigns with a privacy policy failed to disclose all the types of private data they were collecting. This means even when users tried to inform themselves, the disclosed information was incomplete. In contrast, this number was only 25% for Smart Home vendors, reinforcing the pattern of poorer disclosure in the political domain.

Lack of Data Sharing Transparency:

Data sharing, a common practice among campaigns and their affiliated entities, was rarely disclosed:

  • 23% of campaigns did not discuss data sharing at all in their privacy policies. This is a dramatic difference compared to Smart Home vendors, where only 2.1% failed to mention sharing. This highlights a critical black box in how voter data moves between campaigns, parties, and third-party vendors.

Zero Disclosure on Data Retention:

Perhaps the most critical finding related to data retention:

  • ZERO campaigns (0%) disclosed what happens to the private data they collect after the campaign ends. This absence of a data retention policy grants campaigns unbounded access and control over sensitive voter data indefinitely, even after the election is over and the original purpose for collection has passed. This poses a significant long-term privacy risk, as the data could be repurposed, sold, or fall into malicious hands without any accountability or user recourse.

These findings collectively paint a grim picture of privacy protections in US political campaigning, underscoring an urgent need for regulatory intervention and enhanced transparency.

Technical Deep Dive

▶ Watch: Three main research questions guiding the study (3:40)

To conduct this large-scale analysis, the research team developed a custom framework named Potier. This framework was designed to automate and streamline the complex task of identifying campaign websites, collecting their content, and systematically analyzing their privacy practices. Potier consists of three primary components: the Campaign Collector, the Campaign Processor, and the Analyzer.

The first component, the Campaign Collector, was responsible for gathering the raw data – the campaign websites themselves. This task presented significant challenges due to the fragmented and often informal nature of political campaign data. The Federal Election Commission (FEC), while registering candidates and campaigns, does not maintain a centralized repository of campaign website URLs. To overcome this, the researchers leveraged Ballotpedia, a non-profit political encyclopedia for the US, as a primary source. Ballotpedia provided a more comprehensive listing of candidates and their associated online presences.

However, simply using Ballotpedia wasn't straightforward. The FEC often uses formal names for candidates, whereas Ballotpedia might use informal or common names (e.g., "Joseph" versus "Joe"). To bridge this discrepancy, the Campaign Collector incorporated a specialized search mechanism. This mechanism paired candidate names with other available metadata, such as state, party affiliation, or district, to perform targeted searches within Ballotpedia. Once a candidate's Ballotpedia profile was located, the system then parsed these profiles to extract the official campaign website URLs. Finally, a web crawler was deployed to systematically visit these identified URLs and save the HTML pages locally, creating a comprehensive archive for subsequent analysis.

The second component, the Campaign Processor, took the collected website data and prepared it for privacy analysis. Its primary function was to intelligently extract the specific parts of the website relevant to the study. For privacy policy analysis, the Campaign Processor first performed a keyword search across every webpage and every URL within a given campaign website. It looked for a predefined bag of privacy-related keywords, including "privacy," "policy," and "statements." If a privacy policy page was identified, the privacy policy extractor sub-component within the Campaign Processor then went to work. This extractor was designed to parse the text of the privacy policy and specifically identify sentences pertaining to data collection, sharing, and retention practices. These extracted sentences were then outputted in a structured format, ready for detailed labeling and analysis.

The final component, the Analyzer, was responsible for performing the actual qualitative and quantitative analysis of the extracted data. This included tasks such as categorizing collected data types, determining the presence and completeness of privacy disclosures, and identifying conflicts between stated policies and observed practices. The Analyzer aggregated these results, enabling the researchers to draw the key findings discussed previously.

The dataset assembled using Potier was substantial, encompassing more than 2,000 campaign websites. This included candidates for the House, Senate, and Presidential elections. The dataset was further categorized into "active" campaigns (those that participated in the general election) and "inactive" campaigns (those that either lost in primaries or dropped out). Additionally, for Senate races, "incumbents" were included – these were Senators who, due to their six-year terms, were not up for re-election but still maintained functional campaign websites, contributing to the broader understanding of campaign data practices. This robust methodology and comprehensive dataset underpinned the validity and scale of the study's conclusions.

Demo / Proof of Concept

▶ Watch: Description of the study's large dataset (2000+ campaign websites) (7:20)

While the talk did not feature a live "demo" of the Potier framework itself, the researchers provided compelling proof-of-concept evidence for data sharing practices through their own direct engagement with campaigns. To practically verify whether campaigns were indeed sharing user data, the research team personally signed up for 26 different campaigns. For each sign-up, they created unique, dedicated email addresses, allowing them to meticulously track the flow of these specific email addresses to other entities.

This direct investigative approach yielded concrete results: eight of the 26 campaigns (approximately 31%) were observed sharing the researchers' email addresses with third parties. Even more critically, three of these eight campaigns were doing so without any prior disclosure in a privacy policy, or in some cases, without even having an accessible privacy policy at all. This direct observation provided empirical validation that data sharing was not only occurring but was often happening without the informed consent or even knowledge of the user, directly contradicting the lack of disclosure found in the privacy policy analysis.

Furthermore, the study uncovered a subtle yet significant mechanism of indirect data sharing through third-party services. The researchers identified instances where campaigns using a particular fundraising website (the name of which was redacted in the paper and talk) might have been inadvertently facilitating data sharing, even if their own privacy policies claimed they did not share data. The conflict arose because while these campaigns stated they did not share data, the privacy policy of the fundraising website itself explicitly stated that it was allowed to share data with "other likeminded campaigns" when candidates submitted their data to the platform. This scenario highlights a critical vulnerability where campaigns' individual disclosures can be overridden or circumvented by the privacy policies of the third-party platforms they integrate, creating a hidden channel for data dissemination that voters are unlikely to be aware of. This practical finding underscores the complexity of tracking data flows and the need for comprehensive oversight that extends beyond a campaign's direct statements to encompass its entire vendor ecosystem.

Defensive Implications

▶ Watch: Initial finding: Campaigns overwhelmingly collect data via websites (8:00)

The findings of this study carry profound defensive implications for various stakeholders, from individual voters to policymakers and the campaigns themselves. The current state of privacy practices in US political campaigning necessitates immediate attention and action.

For Voters:

  • Exercise Extreme Caution: Voters must understand that providing PII to political campaign websites is a significantly riskier endeavor than interacting with regulated commercial entities. The data collected is highly sensitive, revealing political leanings and potentially deeply personal socioeconomic opinions.
  • Assume Lack of Transparency: Given that 71% of campaigns fail to disclose their practices and zero disclose data retention, voters should assume that their data may be collected, shared, and retained indefinitely without their knowledge or consent.
  • Be Wary of Third-Party Data Requests: The collection of data on friends, family, or partners is non-consensual. Voters should refuse to provide such information, as it compromises the privacy of others who cannot provide their own consent.
  • Scrutinize All Policies (if available): While many policies are incomplete, voters should still review them. However, they should also be aware that stated policies may not align with actual practices, especially concerning third-party services like fundraising platforms.
  • Advocate for Change: Ultimately, the most effective defense for voters is to demand stronger privacy regulations for political campaigns. Engaging with advocacy groups and contacting elected officials can help push for legislative reform.

For Political Campaigns (and their Central Parties):

  • Prioritize Privacy by Design: Campaigns need to fundamentally shift their approach, integrating privacy considerations from the outset of website development and data collection strategies.
  • Develop Comprehensive Privacy Policies: Campaigns must create clear, accessible, and truthful privacy policies that explicitly detail all types of data collected, the purposes for collection, all entities with whom data is shared (including third-party vendors and other campaigns), and, critically, explicit data retention policies outlining what happens to data after the campaign concludes.
  • Obtain Informed Consent: For sensitive data collection (e.g., socioeconomic opinions) and sharing, campaigns should implement robust consent mechanisms that are granular and easily understood by users.
  • Vet Third-Party Vendors: Campaigns must thoroughly audit the privacy policies and practices of all third-party services they utilize (e.g., fundraising platforms, analytics providers) to ensure alignment with their own stated policies and to prevent inadvertent data sharing.
  • Seek Legal and Technical Expertise: The talk highlighted a "clear misunderstanding of what privacy policies are" and "lack of technical expertise." Campaigns need to invest in legal counsel specializing in privacy and technical staff capable of implementing secure and compliant data handling practices.
  • Acknowledge Regulatory Need: As some campaigns admitted, the lack of federal law is a reason for poor practices. Campaigns and central parties should actively engage in discussions about establishing a regulatory framework rather than using its absence as an excuse.

For Regulators and Policymakers:

  • Close the Regulatory Gap: The most critical implication is the urgent need for targeted privacy regulations for political campaigns in the US. The current "non-profit" exemption leaves a massive loophole for sensitive data.
  • Mandate Transparency and Disclosure: New regulations should mandate clear, comprehensive, and accessible disclosure requirements for data collection, processing, sharing, and retention for all political entities.
  • Address Cross-Campaign and Third-Party Sharing: Regulations must specifically address the sharing of data between campaigns, central parties, and third-party vendors, requiring explicit consent and robust oversight.
  • Enforce Data Retention Policies: A clear mandate for defining and adhering to data retention schedules, particularly post-election, is essential to prevent indefinite data hoarding and potential misuse.
  • Consider GDPR-like Protections: The EU's GDPR provides a strong model for regulating political data. US policymakers should study and adapt similar principles to protect American voters.
  • Empower Enforcement: Any new regulations must be accompanied by strong enforcement mechanisms and penalties for non-compliance to ensure their effectiveness.

The current environment represents a significant threat to voter privacy and informed democratic participation. Addressing these defensive implications is crucial for restoring trust and protecting fundamental rights in the digital political sphere.

Key Takeaways

  • Widespread Unregulated Data Collection: US political campaigns operate as extensive "data harvesting operations," with 71% of websites collecting PII, often including highly sensitive socioeconomic opinions and non-consensual data from third parties (friends, family, partners).
  • Severe Lack of Transparency: A vast majority (71%) of campaigns fail to adequately disclose their data collection, sharing, and retention practices, a significantly worse posture compared to regulated for-profit entities like Smart Home vendors.
  • Incomplete and Misleading Disclosures: Even when privacy policies exist, 41% of campaigns with a policy do not disclose all collected data, and 23% completely omit discussions about data sharing, leaving voters uninformed about critical data flows.
  • Unbounded Data Retention Risks: Zero campaigns disclose what happens to collected data after the election ends, granting them indefinite control and posing a long-term risk of misuse, sale, or compromise of sensitive voter information.
  • Practical Proof of Undisclosed Sharing: Direct investigation confirmed that 31% of campaigns shared email addresses, with three doing so without any privacy policy or disclosure, further demonstrating the gap between stated policy (or lack thereof) and actual practice.
  • Urgent Need for Regulation: The study clearly demonstrates that the unregulated status of US political campaigns leads to significantly poorer privacy protections than in regulated domains, highlighting the critical need for targeted privacy legislation similar to the EU's GDPR to protect voter data and ensure transparency.

About the Speaker(s)

The research was led by Kaushal Kafle, a PhD student at William & Mary and the lead graduate student at the Secure Platforms Lab. His work focuses on understanding and improving privacy practices in various technological domains. He presented the findings of this in-depth study at the IEEE S&P conference.

Kaushal Kafle collaborated with a team of researchers including Prianka Mandal, Kapil Singh, Benjamin Andow, and Adwait Nadkarni. These colleagues hail from a combination of academic institutions and industry leaders, specifically William & Mary, IBM, and Google, bringing diverse expertise to the study of privacy in political campaigns. Their collective effort underscores the interdisciplinary nature of addressing complex privacy challenges in the modern digital landscape.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This research meticulously exposes a critical regulatory void in US political campaign data practices. The team's large-scale analysis using their custom framework, Potier, provides compelling evidence of widespread, undisclosed PII collection and sharing, underscoring significant privacy risks for voters. The findings present actionable insights for policymakers and individuals facing an unregulated data harvesting landscape.

Heather Calloway (CISO) — STRONG ACCEPT

This research meticulously exposes the critical regulatory void surrounding data privacy in US political campaigns. The absence of disclosure, particularly concerning unbounded data retention, creates an unacceptable and systemic risk for citizen privacy. It demands immediate policy intervention.

→ Top-rated talks at IEEE Symposium on Security and Privacy 2024

All talks from IEEE Symposium on Security and Privacy 2024