Legality and fundamental rights
Every activity respects applicable law, dignity, privacy, data protection, freedom of expression, equality and the rights of the child.
This code turns IBCSC values into decisions that can be checked. It governs cybersecurity research, publications, training, the use of artificial intelligence, partnerships and every activity carried out in the association’s name.
The code is used to prepare an activity, resolve doubt, document a refusal and examine a departure from the rules. Compliance with law is the minimum. When an action remains technically possible but creates human risk, the Institute chooses the option that best protects people and the public interest.
Each commitment must leave a concrete trace in the work. Good intent does not compensate for an intrusive method, a weak source or undefined accountability.
Every activity respects applicable law, dignity, privacy, data protection, freedom of expression, equality and the rights of the child.
Collection, testing and distribution are limited to what is genuinely needed. The least intrusive effective option is preferred.
IBCSC remains independent of commercial, partisan and personal interests. It does not present itself as a public authority or use its work to support a political party.
Facts, interpretations and hypotheses are separated. Important conclusions carry sources, dates, limits and an appropriate confidence level.
Personal data, secrets, reports and technical access are protected and only collected, shared or retained for a defined need.
No one accepts work beyond their ability without supervision. Criminal, medical, social and legal matters are referred to the competent services.
Activities oppose discrimination, adapt language and materials and work to include people with disabilities or limited digital access.
An important decision has an identifiable owner, can be explained and can be challenged. An acknowledged error leads to a visible and proportionate correction.
This check is used before a test, collection, publication, partnership or deployment of AI that may affect a person.
The legal basis, mandate and owner of the system or data are known.
The public-interest objective cannot reasonably be achieved with less data or access.
Scope, duration, rate and distribution are reduced to the actual need.
An affected person can understand the logic, limits and consequences of the decision.
An owner can stop the action, handle a challenge and organise a correction.
IBCSC observes, prevents, teaches and helps reduce risk. It does not conduct clandestine operations, punitive attribution or offensive access to third-party systems.
Read the CVD policyA local model can reduce some data transfers, but it does not guarantee confidentiality, accuracy or freedom from bias. Risk depends on the data, model, hosting, access controls and actual use.
A competent person remains responsible for decisions, publications and advice and can reject, correct or stop the system.
The tool, version, purpose and important checks are documented when AI influences a significant result.
Personal, confidential or protected data is not sent to an external service without necessity, a valid basis and appropriate safeguards.
Citations, technical facts, translations, images and recommendations produced with model assistance are checked before release.
Effects on different groups are considered. A discriminatory or inaccessible result is not accepted as a mere technical limitation.
Risks of leakage, prompt injection, malicious content, dependency, unavailability and misuse are assessed.
People using a system understand its purpose, limits, likely errors and required verification procedures.
IBCSC does not use a fully automated decision to publicly accuse a person, reject a candidate, determine access to training or settle a matter affecting rights without appropriate human review.
Courses for school pupils and students develop technical curiosity in a lawful, supervised and respectful setting. Being able to do something never amounts to permission to do it.
Exercises use laboratories, machines, accounts and datasets created or expressly authorised for training.
Content, communication, schedules and supervision take account of age, maturity and rules protecting minors.
Registration requests only necessary information. Personal accounts and learner work do not become promotional material by default.
Trainers maintain professional boundaries, reject harassment and humiliation and report concerning situations through the defined channel.
Lack of equipment, income, language proficiency or a disability is treated as a barrier to reduce, not a lack of merit.
Success includes documentation, teamwork, safety, respect for scope and the ability to ask for help.
Agreements define the objective, responsibilities, data, visibility, payments or contributions and stopping conditions. Public interest and beneficiary safety remain the priority.
A partner does not choose the outcome of an analysis, alert or recommendation.
Sponsorship, equipment contributions and supported content are presented without hidden advertising.
A relevant personal, financial or professional relationship is declared before the decision.
A partnership does not automatically grant access to data, systems, beneficiaries or restricted reports.
A personal benefit capable of influencing a decision is refused or declared and handled by someone who is not affected.
IBCSC may refuse or end cooperation that conflicts with law, safety, independence or this code.
Publications should help readers decide without amplifying fear, exposing a victim or turning a hypothesis into an established fact.
A conflict may be actual, potential or merely perceived. Declaring one is not misconduct. Concealing it can weaken the decision and public trust.
The person describes the relevant link, benefit or relationship as soon as they become aware of it.
An unaffected person considers influence, the appearance of bias and available safeguards.
Access to the file, discussion, voting or external representation may be restricted.
The decision, chosen safeguard and its duration are retained proportionately.
Anyone may report in good faith conduct, a decision, a conflict or a risk that may breach this code. The message should describe known facts, affected people or activities and any urgent protection need.
Ethics channel info@ibcsc.beDo not send a technical secret or vulnerability evidence through this channel. Use the CVD policy for a security flaw. Confidentiality is pursued, but cannot be promised absolutely when a legal duty or urgent protection requires referral.
Access to the message is limited to people needed for the review and immediate protection.
If the concern involves the usual recipient, it is transferred to an unaffected director or reviewer.
Facts, documents, rules and relevant responses are examined without presuming fault or exposing the reporter unnecessarily.
Measures, reasons, limits and follow-up routes are recorded and communicated to an appropriate extent.
A response considers severity, intent, impact, repetition, cooperation and the possibility of repair. It respects the statutes, agreements and rights that apply.
The code is reviewed at least annually and after a significant incident, a material legal change or the launch of an activity presenting a new risk.
These sources guide interpretation of the code. They do not replace an examination of applicable law, professional advice or the detailed policies of IBCSC.
The code cannot anticipate every situation. These answers explain how common cases are handled.
No. It complements applicable rules and does not reduce a legal right or duty. Where there is a conflict, applicable law and mandatory texts prevail.
Yes, when the report is made in good faith and separates what was observed from what remains suspected. Do not conduct your own intrusion, surveillance or excessive collection to obtain evidence.
Not every minor wording correction. Disclosure is expected when AI substantially influences content, a recommendation, image, assessment or decision and that information helps people evaluate the result.
It may check facts about itself or an agreed mention, but it cannot impose a conclusion, remove justified criticism or turn educational content into hidden advertising.
Use the coordinated vulnerability disclosure page. It sets out the authorised scope, channel, testing rules and publication conditions.
Use the ethics channel for conduct, a decision or a conflict. For a technical vulnerability, follow the CVD policy to protect users and evidence.