Many companies hesitate to commission a penetration test due to legal uncertainty. Here's an honest explanation of how a test is conducted in a legally sound way — and what German criminal law says about it.
Data espionage — deliberately bypassing an access control to gain access to someone else's data — is a criminal offense under § 202a of the German Criminal Code (StGB), regardless of intent. Technically, that's exactly what happens during a penetration test.
The decisive difference from a real attack is solely the explicit, written permission of the system owner. That's why every engagement I take on starts with a signed scope document — before a single test runs.
Depending on the depth of testing, penetration tests can also touch on:
The same principle applies here: with a clearly defined, written agreement, a test stays within the legal framework. That's why the scope isn't a side detail — it's the legal foundation of the entire project.
During a test, I may gain access to personal or sensitive data. This is subject to the same duty of care as it would be for you — confidentiality isn't optional, it's the basis of every engagement. On request, this is additionally formalized in writing via an NDA.
A penetration test is also a recognized means of demonstrating the "regular testing, assessment and evaluation of the effectiveness" of technical security measures required under Art. 32 GDPR.
Questions about the legal framework for your project?
Get in touch →