Legal Basis

Why a penetration test isn't a legal grey area.

Many companies hesitate to commission a penetration test due to legal uncertainty. Here's an honest explanation of how a test is conducted in a legally sound way — and what German criminal law says about it.

Without authorization, it's a criminal offense § 202a StGB

Data espionage — deliberately bypassing an access control to gain access to someone else's data — is a criminal offense under § 202a of the German Criminal Code (StGB), regardless of intent. Technically, that's exactly what happens during a penetration test.

The decisive difference from a real attack is solely the explicit, written permission of the system owner. That's why every engagement I take on starts with a signed scope document — before a single test runs.

Other relevant statutes

Depending on the depth of testing, penetration tests can also touch on:

  • § 202c StGB — preparing to intercept or spy on data (including possession and use of relevant tools)
  • § 303a StGB — data tampering
  • § 303b StGB — computer sabotage, e.g. system outages caused by testing

The same principle applies here: with a clearly defined, written agreement, a test stays within the legal framework. That's why the scope isn't a side detail — it's the legal foundation of the entire project.

What the scope document covers

  • Which systems, domains, and IP ranges may be tested
  • Which methods are explicitly excluded
  • The approved time window for active testing
  • Who is notified in an emergency (e.g. unexpected outages)
  • Confirmation that you, as the client, have obtained any necessary third-party consent (e.g. from a hosting provider), where required

Confidentiality & GDPR

During a test, I may gain access to personal or sensitive data. This is subject to the same duty of care as it would be for you — confidentiality isn't optional, it's the basis of every engagement. On request, this is additionally formalized in writing via an NDA.

A penetration test is also a recognized means of demonstrating the "regular testing, assessment and evaluation of the effectiveness" of technical security measures required under Art. 32 GDPR.

Important note: This page does not constitute legal advice. It explains the general legal framework within which penetration testing takes place in Germany. Details specific to your project — particularly contract terms and liability questions — are discussed with you during our initial conversation, together with your legal department if needed.

Questions about the legal framework for your project?

Get in touch →