Skip to content
Educora
University24 min12 / 12

Ethics and law in cybersecurity

Learn what authorisation means legally, responsible (coordinated) disclosure, the Budapest Convention, Azerbaijan's Law on Personal Data and the core principles of the GDPR, its fine cap and the 72-hour notification rule.

Check yourself
In this lesson you will learn
  • Distinguish authorised from unauthorised security testing, legally and ethically
  • Report a discovered vulnerability following responsible-disclosure practice
  • Apply the core principles of personal data protection
  • Calculate the GDPR maximum fine cap and the notification deadline

Aysel changes a number in the address bar of her school's website and suddenly sees another student's grades. She has found a vulnerability. What now: keep testing, show classmates, post it on social media, or quietly tell the school? In this lesson we study a field as important as technical skill — the ethics and law of cybersecurity. Note: this lesson is not legal advice; laws change, so check official sources (for Azerbaijan, for example, e-qanun.az).

Authorisation: what draws the line?

The same technical action is a professional service in one case and a crime in another. Authorisation makes the difference: written consent from the system owner, a precise scope (which addresses, which methods), a time window, contact people and rules for handling data. The Council of Europe's 2001 Convention on Cybercrime (the Budapest Convention) requires its parties to criminalise illegal access to computer systems, illegal interception, and data and system interference. Azerbaijan is a party to this convention, and its Criminal Code treats unauthorised access to computer systems as a crime.

Responsible disclosure

  1. 1
    Stop and record the minimum

    Look at nothing beyond what proves the weakness, download no data, show it to no one. Write down what you saw and when.

  2. 2
    Find the official channel

    Look for the site's security contact: many organisations publish it in a /.well-known/security.txt file (RFC 9116). Large companies sometimes run a bug bounty programme with safe-harbour rules.

  3. 3
    Report privately

    Describe clearly and briefly what you found, where and how, and suggest a fix. Do not threaten and do not demand money — that can count as extortion.

  4. 4
    Allow time and coordinate

    Publication happens only after a fix and in agreement with the parties. A reasonable period widely used in the industry is 90 days (Google Project Zero's policy, for example).

Personal data protection

In Azerbaijan this area is governed by the Law on Personal Data, adopted in 2010: it sets requirements for collecting, processing and protecting personal data and, unless the law provides otherwise, requires the data subject's consent for processing. In the European Union the GDPR (General Data Protection Regulation, 2016/679) has applied since 25 May 2018. The GDPR also covers companies outside the EU when they offer goods or services to people in the EU or monitor their behaviour.

GDPR principleWhat it means in practice
Lawfulness, fairness, transparencya legal basis (for example consent or a contract) and a clear privacy notice
Purpose limitationan email collected for a newsletter is not sold for advertising
Data minimisationonly the fields you need are collected
Accuracy and storage limitationoutdated data is corrected or deleted
Integrity and confidentialityencryption, access control, backups
Accountabilitybeing able to prove compliance with documents
Fmax = max(20 000 000 €; 0,04 · T)
where:
  • Fmaxthe GDPR fine cap for the most serious infringements
  • Tthe company's worldwide annual turnover for the previous financial year, in euros

Whichever is higher applies. For other infringements: max(€10,000,000; 0.02 · T). This is a cap; the actual fine is set case by case.

Example 1: the fine cap and the break-even point

a) Find the fine cap for a serious infringement for two companies with turnovers of €50 million and €2 billion. b) From what turnover does the 4 % rule exceed €20 million?

Show solution
a) 0.04 · 50,000,000 = 2,000,000 < 20,000,000 → cap €20 million.
0.04 · 2,000,000,000 = 80,000,000 > 20,000,000 → cap €80 million.
b) 0.04 · T = 20,000,000 → T = 20,000,000 / 0.04 = €500 million. Above that turnover, the percentage rule decides. (The lower tier gives the same: 10,000,000 / 0.02 = 500 million.)

Under the GDPR, if a data breach creates a risk, the supervisory authority must be notified where feasible within 72 hours of becoming aware of it; when the risk is high, the affected people must also be told without undue delay. The clock keeps running over weekends.

Python
from datetime import datetime, timedelta

def max_fine_eur(turnover, severe=True):
    cap, share = (20_000_000, 0.04) if severe else (10_000_000, 0.02)
    return max(cap, share * turnover)

for turnover in [50_000_000, 2_000_000_000]:
    print(f'turnover {turnover:>13,} EUR -> up to {max_fine_eur(turnover):>11,.0f} EUR')

aware = datetime(2026, 3, 13, 16, 30)   # a Friday afternoon
print('Breach noticed:', aware)
print('Notify the authority by:', aware + timedelta(hours=72))
▸ Expected output
turnover    50,000,000 EUR -> up to  20,000,000 EUR
turnover 2,000,000,000 EUR -> up to  80,000,000 EUR
Breach noticed: 2026-03-13 16:30:00
Notify the authority by: 2026-03-16 16:30:00
Example 2: if a breach is noticed on a Friday afternoon, the deadline is Monday at 16:30 — the weekend is not excluded.

Professional ethics: the codes of ethics of professional bodies such as ISC2 require protecting society and infrastructure, acting honestly and legally, giving competent service to those you work for and protecting the profession's reputation. Connections: this topic is used directly in application design (privacy by design — Article 25 of the GDPR), in incident response plans and in threat modelling.

Exercise

Data minimisation: a newsletter needs only email and lang. Write minimise(record) that returns a new dictionary keeping only the keys in the ALLOWED set. Print the result for both records.

Exercise · Python
ALLOWED = {'email', 'lang'}

def minimise(record):
    # keep only the allowed keys
    return record

signups = [
    {'email': 'leyla@example.com', 'lang': 'az', 'birthday': '2009-05-01', 'phone': '+994501234567'},
    {'email': 'elvin@example.com', 'lang': 'ru', 'city': 'Gəncə'},
]
for record in signups:
    print(minimise(record))
▸ Expected output
{'email': 'leyla@example.com', 'lang': 'az'}
{'email': 'elvin@example.com', 'lang': 'ru'}

Key points

  • Written permission and an agreed scope are what turn the same action from a crime into a service.
  • Responsible disclosure: stop, record the minimum, report privately through the official channel, allow time for a fix.
  • Azerbaijan has the Law on Personal Data (2010), and the EU has the GDPR (since 2018); the GDPR can also apply to companies outside the EU.
  • GDPR fine cap: max(€20 m; 4 % · T), breaking even at €500 m turnover; notification — 72 hours, weekends included.
  • Data you never collect cannot leak: minimisation is the cheapest defence.

Check yourself

10 questions. Every correct answer earns XP.

1 / 10
A student finds a vulnerability on the university website. Which action fits responsible disclosure?