• Mehr als 3 Millionen Wörter Inhalt
  • |
  • info@itmedialaw.com
  • |
  • Tel: 03322 5078053
Kurzberatung

No products in the cart.

  • en English
  • de Deutsch
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact

Pentesting as a service: legal framework and contract design

28. February 2025
in Other
Reading Time: 6 mins read
0 0
A A
0
fc928a67 a526 4972 ac72 a769e4d69bb5 15307134

The demand for professional penetration tests (pentests for short) is growing steadily as companies place increasing importance on IT security. More and more companies are realizing that protecting sensitive data and systems is no longer just an option, but an indispensable part of a holistic corporate strategy. Pentesting service providers therefore play a crucial role in identifying potential vulnerabilities and proposing concrete measures to eliminate them. However, white-hat hackers or IT security consultants should not only view their activities from a technical perspective, but also create a solid legal basis to protect all parties involved from potential risks.

Content Hide
1. Legal basis of pentests
2. Drafting contracts for pentests
3. Regulations on documentation and rectification
4. Insurance cover and liability issues
5. Further aspects: Social engineering and compliance
6. Conclusion
6.1. Author: Marian Härtel
Key Facts
  • The demand for pentests is increasing, as IT security is crucial for corporate strategies.
  • Pentesting service providers identify vulnerabilities and suggest measures to rectify them.
  • A watertight contract is essential to minimize legal risks and clarify liability issues.
  • The GDPR requires the conclusion of a data processing agreement when processing personal data.
  • Pentests should be planned carefully, especially for hybrid infrastructures or cloud services.
  • Clear documentation and a rework phase are important to ensure the quality of the pentest.
  • Insurance cover and clear liability regulations are necessary to avoid economic risks.

In Germany, there is a whole range of legal standards that must be observed when carrying out pentests. Even minor violations can lead to serious consequences – for both the tester and the client. For this reason, a watertight contract is essential in order to regulate liability issues and create transparency regarding the exact scope of services. In addition to aspects such as limitations of liability and confidentiality obligations, topics such as data protection and compliance also play a central role. This ensures that the collaboration between service provider and client is built on a stable foundation from the outset.

In addition, the increasing complexity of modern IT systems requires careful planning of pentests. Tests often involve not only internal networks or web applications, but also hybrid infrastructures, cloud services or specialized industry-specific platforms. International standards such as ISO 27001 or the BSI IT baseline protection compendium provide points of reference here, and compliance with them is often even assumed by the client. Careful coordination with the client is therefore essential to ensure that all processes comply with legal requirements and company guidelines.

Legal basis of pentests

Penetration tests can essentially be understood as targeted checks of IT systems with the primary aim of uncovering security vulnerabilities. Pentesters slip into the role of potential attackers in order to identify both technical and organizational vulnerabilities. Companies that commission such tests want to minimize the risk of cyberattacks and increase the maturity of their security measures.

Despite being explicitly commissioned, the pentester’s actions can quickly fall into a legal gray area. Unauthorized intrusion into third-party systems is regulated in Germany in §§ 202a ff. of the German Criminal Code (StGB) and § 303b StGB. Even if the client has given their consent, this must be included in writing in the contract in order to avoid any subsequent ambiguities. A breach of these criminal provisions can have considerable consequences and may also trigger civil law claims for damages.

Another important point is data protection requirements. As soon as personal data is processed during testing activities, the GDPR applies. Article 28 GDPR stipulates that a data processing agreement (DPA) may need to be concluded in order to create the legal basis for data processing. This applies in particular if pentesters access data that allows conclusions to be drawn about natural persons, such as employee or customer data. Appropriate technical and organizational measures must be taken here to ensure that only the minimum necessary data is processed and that no sensitive information is collected without authorization.

Another legal hurdle is the potential disruption to ongoing business processes. If the attack simulations lead to system failures or data loss, this can quickly result in downtime that causes considerable economic damage. Such scenarios often lead to civil law disputes or insurance claims if the scope of liability and the question of possible negligence have not been contractually clarified. This makes it all the more important to precisely define the scope of the pentest and to clearly regulate in advance which measures are permitted and at what times they may be carried out.

Drafting contracts for pentests

A solid contract is the cornerstone of a legally compliant pentest implementation. Ideally, the collaboration should begin with a detailed agreement in which all parties involved clarify the objective of the pentest and which resources may be used. This prevents the tester from going beyond the agreed scope and inadvertently causing damage or accessing data that was not intended for the test.

Contracts should therefore precisely define which systems, networks or applications are to be tested. The type of test – such as a black box, white box or grey box approach – should also be specified. This not only has an impact on the tester’s approach, but also allows a more precise assessment of the time required and the potential risks. At the same time, details of the methodology or specific attack techniques (e.g. SQL injection, social engineering tests or automated tools) should be clarified so that the customer knows exactly which procedures will be used.

In addition, it is advisable to specify in the contract whether external service providers or subcontractors are involved. In larger projects in particular, the pentester may commission specialists for certain sub-areas. Here too, responsibilities should be clearly defined so that there are no legal loopholes. Ultimately, stringent planning and contractual stipulations facilitate the pentest and create trust among all parties involved.

Regulations on documentation and rectification

Most clients want to receive detailed documentation after completing a pentest in order to understand the weaknesses and potential risks found. A clearly structured report that not only lists the weaknesses but also sets priorities and makes specific recommendations for action is therefore essential. Ideally, this report should also be supplemented with management summaries so that decision-makers without in-depth IT knowledge can understand the results.

A rectification phase or a so-called “re-test” can also be part of the contract. Here, the pentesters check in a separate run whether the previously identified gaps have been closed or whether new weaknesses have arisen. It is important to set clear deadlines so that it is clear in which time window the improvements are to be carried out. This kind of structured documentation and rectification not only increases the quality of the pentest, but also achieves a sustainable security gain for the company.

Insurance cover and liability issues

Pentesting can have far-reaching consequences for the system integrity of a company. Particularly when sensitive systems are being tested, a failure can result in expensive production stoppages, contractual penalties or disgruntled customers. In such cases, it is advisable to take out professional indemnity insurance that covers such scenarios. A carefully drafted scope of insurance creates additional security for both parties and shows that the pentester is acting professionally and responsibly.

The contract should also clearly define the cases in which liability for damages is excluded or limited. A typical formulation is the limitation of liability to intentional or grossly negligent acts. The question of whether consequential damages or loss of profit are recoverable should also be clarified in advance. Such regulations avoid disputes and enable a fair distribution of risk. Ideally, internal escalation levels should also be defined so that disagreements can be resolved before a legal dispute arises.

Further aspects: Social engineering and compliance

One area that often gains importance in pentest contracts is social engineering. This is where testers attempt to obtain information from employees through phishing emails, fake calls or fake websites in order to penetrate company networks. While such tests are often very effective in checking the human element in security concepts, they can also be legally tricky if the consent of the employees or works councils concerned is not obtained. Clearly defined procedures and limits should therefore also be set out in the contract for social engineering tests.

The topic of compliance also plays a major role in many industries. Certain sectors, such as banking, insurance or healthcare, are subject to strict regulations regarding the handling of data or the type of security checks carried out. Here, it is important to determine in advance which standards and guidelines apply and how the pentest can be tailored to them. Close coordination with the client and its specialist departments ensures that the pentest does not violate internal or external rules and that the results can be used for future audits or certifications.

Conclusion

The legally compliant implementation of pentests requires a well thought-out concept, careful coordination with the client and a seamless contract design. Starting with the selection of suitable test methods and the definition of liability limits through to data protection issues, all points should be set out in clear agreements. Precise preparation prevents misunderstandings and creates the basis for successful collaboration.

It is particularly important that both parties define in advance exactly what goals are to be achieved with the test and what risks they wish to take. Good communication and transparency are essential to ensure that neither the company nor the pentester experience any unpleasant surprises. Especially in a highly dynamic environment such as IT security, it is advantageous to rely on the expertise of a lawyer who is familiar with the technical and legal particularities.

As a specialist in IT law and a passionate technology enthusiast, I can help draft contracts in such a way that they both meet the client’s requirements and are legally watertight. In this way, cyber risks are minimized and trust between all parties involved is strengthened. With my in-depth understanding of security processes and my legal advice, pentests can be carried out not only effectively but also in a legally compliant manner. The result is optimized IT structures, an improved security culture and the certainty of being protected from unforeseeable consequences in the event of an emergency.

 

Marian Härtel
Author: Marian Härtel

Marian Härtel ist Rechtsanwalt und Fachanwalt für IT-Recht mit einer über 25-jährigen Erfahrung als Unternehmer und Berater in den Bereichen Games, E-Sport, Blockchain, SaaS und Künstliche Intelligenz. Seine Beratungsschwerpunkte umfassen neben dem IT-Recht insbesondere das Urheberrecht, Medienrecht sowie Wettbewerbsrecht. Er betreut schwerpunktmäßig Start-ups, Agenturen und Influencer, die er in strategischen Fragen, komplexen Vertragsangelegenheiten sowie bei Investitionsprojekten begleitet. Dabei zeichnet sich seine Beratung durch einen interdisziplinären Ansatz aus, der juristische Expertise und langjährige unternehmerische Erfahrung miteinander verbindet. Ziel seiner Tätigkeit ist stets, Mandanten praxisorientierte Lösungen anzubieten und rechtlich fundierte Unterstützung bei der Umsetzung innovativer Geschäftsmodelle zu gewährleisten.

Weitere spannende Blogposts

Chamber Court on Influencers and Advertising

medienrecht
23. January 2019

In the meantime, there is a few more information about the decision of the Court of Appeal (the Higher Regional...

Read moreDetails

Federal Court of Justice on Influencer Advertising

Brief reminder: Influencer as target of warning letters
7. November 2022

The I. Civil Senate of the Federal Court of Justice today ruled in three proceedings on the question of whether...

Read moreDetails

What makes a games law attorney? Or interview at ZAP

What makes a games law attorney? Or interview at ZAP
7. November 2022

Today an exciting interview with me went online, which the "ZAP - Zeitschrift für die Anwaltspraxis" published. The journal is...

Read moreDetails

Esport Association for the Promotion of Youth?

Esport Association for the Promotion of Youth?
6. December 2018

As already explained in this article, the linchpin in assessing whether an association can be recognized as a non-profit organization...

Read moreDetails

Data protection consent with cookie alternatives?

Data protection consent with cookie alternatives?
7. November 2022

Last year, the ECJ ruled that numerous types of cookies must be expressly authorized by the user before they can...

Read moreDetails

Direct debit in online retail at the end? The EU’s SEPA Regulation!

Direct debit in online retail at the end? The EU’s SEPA Regulation!
5. September 2019

Legal experts have been pointing out the risk of offering the direct debit procedure due to the Geoblocking Regulation (see...

Read moreDetails

Employee participation in early-stage start-ups: work for equity from a legal perspective

Employee participation in early-stage start-ups: work for equity from a legal perspective
8. April 2025

In the early phase of a start-up, there is often a lack of liquidity to pay salaries in line with...

Read moreDetails

NFT and esports: an additional income opportunity or high legal hurdles?

What is “digital property” and how can I benefit from it?
16. May 2023

Introduction to NFTs and Digital Assets Non-fungible tokens (NFTs) are an emerging area of digital assets based on blockchain technology....

Read moreDetails

Digital Services Act (DSA): What creators, influencers and agencies need to know now

Digital Services Act (DSA): What creators, influencers and agencies need to know now
16. May 2025

Key Facts: Stricter transparency obligations for platforms: The Digital Services Act (DSA) forces Very Large Online Platforms (VLOPs) such as...

Read moreDetails
ChatGPT and lawyers: recordings of the Weblaw launch event
Law on the Internet

Private AI use in the company

24. October 2025

Private accounts on ChatGPT & Co. for corporate purposes are a gateway to data protection breaches, leaks of secrets and...

Read moreDetails
Lego brick still protected as a design patent

App purchases, in-app purchases and sales tax

21. October 2025
dsgvo 1

What belongs in a DPA? Data processing agreement in accordance with Art. 28 GDPR

17. October 2025
Smart contracts in the insurance industry: contract design and regulatory compliance for InsurTech start-ups

Contract for work vs. service contract in software, AI and games projects

15. October 2025

Influencer contract: performance profile, rights/buyouts, labeling and AI content

13. October 2025

Podcastfolge

3c671c5134443338a4e0c30412ac3270

“Digital law decoded” with lawyer Marian Härtel

26. September 2024

In this exciting 30-minute podcast, lawyer Marian Härtel decodes the complex world of digital law for the self-employed, start-ups and...

Read moreDetails
d5ab3414c7c4a7a5040c3c3c60451c44

The metaverse – legal challenges in virtual worlds

26. September 2024
4f3597d5481e0f38e37bf80eaad208c7

The IT Media Law Podcast. Episode No. 1: What is this actually about?

26. August 2024
247f58c28882e230e982fa3a32d34dea

Digital sovereignty: Europe’s path to a self-determined digital future

8. December 2024
Looking to the future: How technology is changing the law

Looking to the future: How technology is changing the law

18. February 2025

Video

My transparent billing

My transparent billing

10. February 2025

In this video, I talk a bit about transparent billing and how I communicate what it costs to work with...

Read moreDetails
Fascination between law and technology

Fascination between law and technology

10. February 2025
My two biggest challenges are?

My two biggest challenges are?

10. February 2025
What really makes me happy

What really makes me happy

10. February 2025
What I love about my job!

What I love about my job!

10. February 2025
  • Privacy policy
  • Imprint
  • Contact
  • About lawyer Marian Härtel
Marian Härtel, Rathenaustr. 58a, 14612 Falkensee, info@itmedialaw.com

Marian Härtel - Rechtsanwalt für IT-Recht, Medienrecht und Startups, mit einem Fokus auf innovative Geschäftsmodelle, Games, KI und Finanzierungsberatung.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Informationen
    • Ideal partner
    • About lawyer Marian Härtel
    • Quick and flexible access
    • Principles as a lawyer
    • Why a lawyer and business consultant?
    • Focus areas of attorney Marian Härtel
      • Focus on start-ups
      • Investment advice
      • Corporate law
      • Cryptocurrencies, Blockchain and Games
      • AI and SaaS
      • Streamers and influencers
      • Games and esports law
      • IT/IP Law
      • Law firm for GMBH,UG, GbR
      • Law firm for IT/IP and media law
    • The everyday life of an IT lawyer
    • How can I help clients?
    • Testimonials
    • Team: Saskia Härtel – WHO AM I?
    • Agile and lean law firm
    • Price overview
    • Various information
      • Terms
      • Privacy policy
      • Imprint
  • Services
    • Support and advice of agencies
    • Contract review and preparation
    • Games law consulting
    • Consulting for influencers and streamers
    • Advice in e-commerce
    • DLT and Blockchain consulting
    • Legal advice in corporate law: from incorporation to structuring
    • Legal compliance and expert opinions
    • Outsourcing – for companies or law firms
    • Booking as speaker
  • News
    • Gloss / Opinion
    • Law on the Internet
    • Online retail
    • Law and computer games
    • Law and Esport
    • Blockchain and web law
    • Data protection Law
    • Copyright
    • Labour law
    • Competition law
    • Corporate
    • EU law
    • Law on the protection of minors
    • Tax
    • Other
    • Internally
  • Podcast
    • ITMediaLaw Podcast
  • Knowledge base
    • Laws
    • Legal terms
    • Contract types
    • Clause types
    • Forms of financing
    • Legal means
    • Authorities
    • Company forms
    • Tax
    • Concepts
  • Videos
    • Information videos – about Marian Härtel
    • Videos – about me (Couch)
    • Blogpost – individual videos
    • Videos on services
    • Shorts
    • Podcast format
    • Third-party videos
    • Other videos
  • Contact
  • en English
  • de Deutsch
Kostenlose Kurzberatung