The expanding integration of digital technologies into the physical and administrative layers of modern cities has brought the smart city model to the forefront of urban development strategies. These environments rely on sensor-based infrastructures, interconnected operational systems, and continuous data circulation, forming complex digital ecosystems that reshape how public services function and how urban resources are managed. Yet the same technological density that enables efficiency also amplifies exposure to security breaches, intrusive data practices, and governance uncertainties. This study explores the legal dimensions of safeguarding these digitally dependent urban systems, with particular attention to how cybersecurity requirements intersect with data protection, infrastructural reliability, and the rights of city residents. Drawing on international regulatory experience, especially European approaches that integrate cybersecurity obligations with structured data protection rules, the article evaluates the capacity of Azerbaijan’s existing legal instruments to respond to the risks associated with smart city development. A comparative legal assessment reveals several gaps in national legislation, including fragmented responsibilities, limited procedural safeguards, and the absence of tailored norms for high-interconnectivity urban systems. Although Azerbaijan has established a baseline framework for information security and personal data handling, the operational complexity of smart infrastructures requires more adaptive, technically grounded, and enforceable regulatory measures. The article concludes by outlining direction-specific recommendations intended to strengthen legal resilience, refine cybersecurity governance, and support the secure and accountable development of smart city initiatives.
Qiymətləndir