- Distinguish authorised from unauthorised security testing, legally and ethically
- Report a discovered vulnerability following responsible-disclosure practice
- Apply the core principles of personal data protection
- Calculate the GDPR maximum fine cap and the notification deadline
Aysel changes a number in the address bar of her school's website and suddenly sees another student's grades. She has found a vulnerability. What now: keep testing, show classmates, post it on social media, or quietly tell the school? In this lesson we study a field as important as technical skill — the ethics and law of cybersecurity. Note: this lesson is not legal advice; laws change, so check official sources (for Azerbaijan, for example, e-qanun.az).
Authorisation: what draws the line?
The same technical action is a professional service in one case and a crime in another. Authorisation makes the difference: written consent from the system owner, a precise scope (which addresses, which methods), a time window, contact people and rules for handling data. The Council of Europe's 2001 Convention on Cybercrime (the Budapest Convention) requires its parties to criminalise illegal access to computer systems, illegal interception, and data and system interference. Azerbaijan is a party to this convention, and its Criminal Code treats unauthorised access to computer systems as a crime.
Responsible disclosure
- 1Stop and record the minimum
Look at nothing beyond what proves the weakness, download no data, show it to no one. Write down what you saw and when.
- 2Find the official channel
Look for the site's security contact: many organisations publish it in a
/.well-known/security.txtfile (RFC 9116). Large companies sometimes run a bug bounty programme with safe-harbour rules. - 3Report privately
Describe clearly and briefly what you found, where and how, and suggest a fix. Do not threaten and do not demand money — that can count as extortion.
- 4Allow time and coordinate
Publication happens only after a fix and in agreement with the parties. A reasonable period widely used in the industry is 90 days (Google Project Zero's policy, for example).
Personal data protection
In Azerbaijan this area is governed by the Law on Personal Data, adopted in 2010: it sets requirements for collecting, processing and protecting personal data and, unless the law provides otherwise, requires the data subject's consent for processing. In the European Union the GDPR (General Data Protection Regulation, 2016/679) has applied since 25 May 2018. The GDPR also covers companies outside the EU when they offer goods or services to people in the EU or monitor their behaviour.
| GDPR principle | What it means in practice |
|---|---|
| Lawfulness, fairness, transparency | a legal basis (for example consent or a contract) and a clear privacy notice |
| Purpose limitation | an email collected for a newsletter is not sold for advertising |
| Data minimisation | only the fields you need are collected |
| Accuracy and storage limitation | outdated data is corrected or deleted |
| Integrity and confidentiality | encryption, access control, backups |
| Accountability | being able to prove compliance with documents |
- Fmaxthe GDPR fine cap for the most serious infringements
- Tthe company's worldwide annual turnover for the previous financial year, in euros
Whichever is higher applies. For other infringements: max(€10,000,000; 0.02 · T). This is a cap; the actual fine is set case by case.
a) Find the fine cap for a serious infringement for two companies with turnovers of €50 million and €2 billion. b) From what turnover does the 4 % rule exceed €20 million?
Show solutionHide solution
0.04 · 2,000,000,000 = 80,000,000 > 20,000,000 → cap €80 million.
b) 0.04 · T = 20,000,000 → T = 20,000,000 / 0.04 = €500 million. Above that turnover, the percentage rule decides. (The lower tier gives the same: 10,000,000 / 0.02 = 500 million.)
Under the GDPR, if a data breach creates a risk, the supervisory authority must be notified where feasible within 72 hours of becoming aware of it; when the risk is high, the affected people must also be told without undue delay. The clock keeps running over weekends.
from datetime import datetime, timedelta
def max_fine_eur(turnover, severe=True):
cap, share = (20_000_000, 0.04) if severe else (10_000_000, 0.02)
return max(cap, share * turnover)
for turnover in [50_000_000, 2_000_000_000]:
print(f'turnover {turnover:>13,} EUR -> up to {max_fine_eur(turnover):>11,.0f} EUR')
aware = datetime(2026, 3, 13, 16, 30) # a Friday afternoon
print('Breach noticed:', aware)
print('Notify the authority by:', aware + timedelta(hours=72))▸ Expected output
turnover 50,000,000 EUR -> up to 20,000,000 EUR turnover 2,000,000,000 EUR -> up to 80,000,000 EUR Breach noticed: 2026-03-13 16:30:00 Notify the authority by: 2026-03-16 16:30:00
Professional ethics: the codes of ethics of professional bodies such as ISC2 require protecting society and infrastructure, acting honestly and legally, giving competent service to those you work for and protecting the profession's reputation. Connections: this topic is used directly in application design (privacy by design — Article 25 of the GDPR), in incident response plans and in threat modelling.
Data minimisation: a newsletter needs only email and lang. Write minimise(record) that returns a new dictionary keeping only the keys in the ALLOWED set. Print the result for both records.
ALLOWED = {'email', 'lang'}
def minimise(record):
# keep only the allowed keys
return record
signups = [
{'email': 'leyla@example.com', 'lang': 'az', 'birthday': '2009-05-01', 'phone': '+994501234567'},
{'email': 'elvin@example.com', 'lang': 'ru', 'city': 'Gəncə'},
]
for record in signups:
print(minimise(record))▸ Expected output
{'email': 'leyla@example.com', 'lang': 'az'}
{'email': 'elvin@example.com', 'lang': 'ru'}Key points
- Written permission and an agreed scope are what turn the same action from a crime into a service.
- Responsible disclosure: stop, record the minimum, report privately through the official channel, allow time for a fix.
- Azerbaijan has the Law on Personal Data (2010), and the EU has the GDPR (since 2018); the GDPR can also apply to companies outside the EU.
- GDPR fine cap: max(€20 m; 4 % · T), breaking even at €500 m turnover; notification — 72 hours, weekends included.
- Data you never collect cannot leak: minimisation is the cheapest defence.
Check yourself
10 questions. Every correct answer earns XP.