Society, Law and Ethics in ICT: Privacy, Cybercrime and Worked Examples

Learn to separate social, legal, ethical and security questions through worked ICT cases on access, privacy, phishing, intellectual property and e-waste.

KnowledgeGate Team

Exam prep & CS education

Updated 11 Aug 20266 min read

An ICT scenario can involve a social effect, a legal rule, an ethical choice and a security failure, yet learners often label the whole problem “cyber law.” That shortcut hides what each question is asking. Four lenses pull the parts back apart, and one fictional platform, StudyCircle, carries all of them: a 240-learner access funnel, an 8,000 to 5,000 data-minimisation calculation, a 200-account phishing drill, a 12-asset licence audit, an 80-device refresh and a weighted ethics decision that lands on 4.15. Every figure is reproducible on paper. Statutes, penalties and copyright durations change and differ by country, so take those from the current official text.

Society, law, ethics and security ask different questions

Lens

Core question

Who or what answers it

StudyCircle example

Society

Who gains, loses, what changes?

People and evidence

Could names enable access or harassment?

Law

What enforceable duties apply?

Current official text

May profiles be public?

Ethics

What ought to happen?

Values and stakeholders

Is consent meaningful?

Security

What needs protection?

Threats and controls

Can controls limit scraping?

StudyCircle proposes searchable names. Society checks exclusion, law checks current rules, ethics tests consent and harm, security checks access and scraping. Policy may exceed the legal minimum. Lawful is not ethical; secure is not fair. The same split is what general-paper exams test when they move from ICT facts to judgement: the UGC NET Paper 1 versus Paper 2 comparison sets out what each paper tests, and the GATE preparation category collects the CS subject route for readers who meet these topics inside information security.

Digital society, the digital divide and a traceable footprint

Stage

Learners

Overall rate

Suitable device

192

192 / 240 = 80%

Stable connection

168

168 / 240 = 70%

Accessible language and format

144

144 / 240 = 60%

Task completed

120

120 / 240 = 50%

This fictional funnel has a 192 - 144 = 48 access gap and a 192 - 120 = 72 completion gap. Ownership does not prove inclusion.

L-042's 10:02 comment, 10:05 answer.pdf upload and 10:06 optional choice are active. The 10:00 login, 180-second duration and 10:07 error are system-generated. “Passive” is not harmless or anonymous. Ask who drops out, whether assisted or offline access exists, and whether completion measures learning or submission.

Access funnel narrowing from 240 learners to 120 completions, with a learner log separating active actions from system events.

Worked privacy case: collect less, separate permissions and expire data

StudyCircle stores name, email, mobile, birth date, address, institution, course choice and accessibility preference for 1,000 profiles: 1,000 x 8 = 8,000 values. Review removes mobile, birth date and address, retaining five: 1,000 x 5 = 5,000. That is 3,000 fewer, or 3,000 / 8,000 x 100 = 37.5%.

Identity

Permitted view

Learner L-042

View and correct own five fields

Mentor M-07

Name, institution, course progress

Support S-03

Name and email only while ticket T-118 is open

Analyst A-02

course=C1, active_learners=600, with no direct learner fields

Authentication verifies identity, authorisation limits views, purpose limitation explains access, and minimisation removes fields.

An internal rule finds 600 active, 250 inactive under 90 days and 150 inactive at least 90 days. Deleting 150 after review takes the live store from 1,000 to 850. A 14-day fictional backup rotation delays backup deletion. Require logs, exceptions and communication.

StudyCircle data minimisation from 8,000 to 5,000 stored values, with per-role access permissions and a retention schedule.

Cybercrime, cyber safety and malware: classify before responding

A fake login message is an event. Submitted credentials and unauthorised access can make it an incident. A named offence depends on current law and evidence. Do not label anyone a criminal without an official source and due process.

In a safe 200-account drill, 50 open, 20 click and five enter test credentials. Open rate is 50 / 200 = 25%. Click rate is 20 / 200 = 10% overall and 20 / 50 = 40% among openers. Submission is 5 / 200 = 2.5% overall and 5 / 20 = 25% among clickers. Name the denominator.

Report, isolate the session or device, reset credentials, review authorised logs, preserve evidence, remove the artefact, and notify where policy and law require. A virus attaches to a host, a worm self-spreads, a trojan disguises itself, ransomware blocks access for payment, and spyware observes covertly. Each label names a behaviour rather than a payload, so one file can fit more than one of them.

Intellectual property and open source need an asset check

Copyright protects qualifying expression; a patent concerns an eligible invention; a trademark identifies source; a licence grants conditional permissions. Public-domain does not mean merely public-facing. Plagiarism concerns attribution and integrity but is not identical to infringement. Protection terms, fair-dealing exceptions and remedies are set by statute and differ by country.

A 12-asset register has seven original code or graphics files, three open-source libraries with licence files recorded, one purchased icon pack with proof of use, and one image from an unverified search result. Exactly 11 / 12 x 100 = 91.67% are documented; 1 / 12 x 100 = 8.33% is unresolved. Replace, license or resolve that image before release. Credit alone does not establish permission.

Open source does not mean no rules. Inspect each library's licence for notices, redistribution conditions and compatibility. Obligations vary, and no-cost access does not remove intellectual-property duties.

E-waste and green computing require separate measures

In an 80-device refresh, 50 are redeployed, 20 repaired and returned, and 10 irreparable. Reuse-or-repair is (50 + 20) / 80 x 100 = 87.5%; disposal is 10 / 80 x 100 = 12.5%. Verify an authorised route against current local official rules, not an advertisement.

Measure energy separately. Forty lab computers draw 60 W idle but 8 W asleep for 10 hours daily. Saving is (60 - 8) W x 40 x 10 h / 1,000 = 20.8 kWh daily; across 22 days, 20.8 x 22 = 457.6 kWh. Money or carbon needs a current tariff or sourced emissions factor.

Secure wiping, reuse, repair, material recovery and lower energy use solve different risks. Low power does not prove responsible disposal, and recycling cannot undo avoidable electricity use.

Worked ethics decision, common traps and assessment patterns

Change the weights and the ranking can change, so fix them before scoring anything. Privacy is 0.30, inclusion 0.20, accountability 0.20, utility 0.15 and autonomy 0.15, totalling 1.00.

Option

Scores in that order

Weighted calculation

Total

A: real-name public by default

1, 2, 5, 5, 1

0.30 + 0.40 + 1.00 + 0.75 + 0.15

2.60

B: real-name private to learner and mentor

4, 4, 4, 3, 4

1.20 + 0.80 + 0.80 + 0.45 + 0.60

3.85

C: pseudonymous public only after opt-in

4, 5, 3, 4, 5

1.20 + 1.00 + 0.60 + 0.60 + 0.75

4.15

C ranks highest. Pilot with 60 learners, not all 600 active ones. If 45 opt in, uptake is 45 / 60 = 75%; learn why 15 decline. Law, severe harm or inaccessibility can veto the ranking. Ethics needs stakeholder input, reasons, appeal and review.

Five traps: legal is not ethical; privacy is not secrecy; a box does not ensure consent; open source is not public domain; live-row deletion does not prove backup deletion. Assessments may ask for lens classification, correct denominators, proportionate response, licence checks or a defended trade-off. Reasoning from a source instead of memorising a list is the same habit behind the SSC CGL General Awareness approach, worth borrowing when this topic sits next to current-affairs revision.

Society, law and ethics in ICT: the short version and next step

Use five checks: name which lens the question is actually asking about; identify who is affected and which current rule applies; separate legal permission from ethical justification; reduce and protect the data before defending the design; and state the denominator behind every rate you quote. Answer checks are 50% completion, 37.5% fewer values, 5 / 200 = 2.5% submission, 87.5% reuse-or-repair, and Option C at 4.15.

KnowledgeGate has over 150 practice questions on these topics. Use GATE Guidance by Sanchit Sir for the broader subject sequence and the GATE Test Series for broader practice. Recalculate every case above, then explain which lens each result answers.