Cyber Security Notes— Modules 8
CYBER SECURITY NOTES
Study Notes — Modules 8
Intermediate Phase
Module 8 — Cyber Laws, Ethics & Privacy
Page 1
Cyber Security Notes— Modules 8
MODULE 8 — Cyber Laws, Ethics & Privacy
Sessions 79–86 | Duration: 12 hours | Phase: Intermediate
8.1 Overview of Cyber Laws
Cyber law is the body of legislation that governs digital behaviour — covering data protection, computer misuse,
electronic transactions, and online offences. Specific laws vary by country, so this section should be adapted to
your local legislation.
Representative Examples (Adapt to Your Country)
Region / Law Focus Area
IT Act, 2000 (India) Legal recognition of electronic records/signatures; cybercrime
offences (hacking, identity theft, data breaches)
GDPR (European Union) Data protection and privacy rights for individuals; strict rules on
consent and data handling
Computer Fraud and Abuse Act (United Criminalises unauthorised access to computer systems
States)
Computer Misuse Act (United Kingdom) Criminalises unauthorised access, modification, and impairment of
computer systems
Classroom note:
The instructor should substitute the most relevant national/regional cyber law for the learners' jurisdiction,
since enforcement, penalties, and definitions differ significantly between countries.
8.2 Data Privacy Basics: Personal Data & Consent
What Counts as Personal Data?
• Directly identifying information: full name, address, phone number, government ID numbers.
• Indirectly identifying information: IP address, device ID, location history, browsing behaviour.
• Sensitive categories requiring extra protection: health data, biometric data, financial records.
Consent — The Core Principle
Consent means a person freely, specifically, and knowingly agrees to how their personal data will be collected
and used — and can withdraw that agreement at any time.
15. Freely given — not coerced or hidden behind a requirement to use the service.
16. Specific — for a clearly stated purpose, not a vague 'we may use your data for anything'.
17. Informed — the person understands what data is collected and why before agreeing.
18. Revocable — the person can withdraw consent as easily as they gave it.
Example scenario:
Page 12
Cyber Security Notes— Modules 8
A school app asks students to 'accept all permissions' just to log in, without explaining why it needs camera or
contact access. This fails the 'specific' and 'informed' consent tests, even if a checkbox was technically clicked.
8.3 Intellectual Property & Software Piracy
Intellectual Property (IP) law protects creative and technical works — including software, media, and written
content — from unauthorised use or reproduction.
IP Type Protects Example
Copyright Original creative works (software code, Unauthorised copying/distribution of a
music, writing, art) licensed application
Trademark Brand names, logos, and identifying Using a company's logo to create a fake
marks phishing website
Patent Novel inventions and technical processes A unique encryption algorithm or
hardware design
Trade Secret Confidential business information A company's proprietary source code or
internal formulas
Software Piracy — Risks Beyond the Legal Issue
• Pirated/cracked software is a common vector for trojans and malware (see Module 6).
• No official updates or patches — leaving known vulnerabilities unfixed indefinitely.
• No legitimate technical support if the software fails or is compromised.
8.4 Ethics in AI and Emerging Technologies
As AI systems make more decisions that affect people's lives, ethical considerations become as important as
technical performance.
Key Ethical Themes
Theme Concern
Bias & Fairness AI trained on biased data can produce discriminatory outcomes (e.g., in hiring or
lending decisions)
Privacy AI systems (facial recognition, tracking algorithms) can enable mass surveillance
without consent
Transparency 'Black box' AI decisions can be difficult to explain or challenge
Accountability Unclear who is responsible when an AI system causes harm — the developer,
deployer, or user
Misuse AI-generated deepfakes and synthetic content can be used for fraud or
disinformation
Discussion prompt:
Page 13
Cyber Security Notes— Modules 8
Theme Concern
Where should the line be drawn between using AI/surveillance technology for legitimate safety purposes
(e.g., public security cameras) and infringing on individual privacy? There is no single correct answer — this is
the basis for the Session 85 debate.
8.5 Hands-On Labs & Activities — Module 8
🧪 Hands-On Lab Activities
• Case-study analysis of a real, age-appropriate cyber-law case relevant to your region.
• Draft a response to a 'personal data consent' scenario, identifying what makes the consent request
valid or invalid.
• Debate: Ethics in AI and surveillance technology — argue both sides of a real-world scenario.
• Module 8 recap activity and quiz.
Module 8 — Key Takeaways
• Cyber laws vary by country but generally cover unauthorised access, data protection, and electronic
transactions.
• Valid consent must be freely given, specific, informed, and revocable — not just a checkbox.
• Intellectual property law (copyright, trademark, patent, trade secret) protects software and creative work;
piracy carries both legal and security risks.
• AI ethics centres on bias, privacy, transparency, and accountability — issues that will only grow more
relevant as AI adoption increases.
Page 14