Germany drafts law to protect researchers who find security flaws

Teilen:

The Federal Ministry of Justice in Germany has drafted a law to provide legal protection to security researchers who discover and responsibly report security vulnerabilities to vendors.

When security research is conducted within the specified boundaries, those responsible will be excluded from criminal liability and the risk of prosecution.

“Those who want to close IT security gaps deserve recognition—not a letter from the prosecutor,” stated Federal Minister of Justice Dr. Marco Buschmann.

“With this draft law, we will eliminate the risk of criminal liability for people who take on this important task,” mentions the Minister in the same statement.

Additionally, the proposed amendment to the criminal law introduces stricter penalties for serious cases of data spying and interception, particularly when critical infrastructure is targeted.

Protecting security researchers

The new draft law amends Section 202a of the Criminal Code (StGB) to protect IT security researchers, companies, and so-called “hackers” from punishment under computer criminal law.

This applies when their actions are carried out to detect and close a security vulnerability, as long as they are not considered “unauthorized.”

The criteria to meet for security research are the following:

  1. The action must be carried out with the aim of identifying a vulnerability or another security risk in an IT system.
  2. The researcher must intend to report the identified security vulnerability to a responsible entity capable of addressing the issue, such as the system operator, the software manufacturer, or the Federal Office for Information Security (BSI).
  3. The act of accessing the system must be necessary to identify the vulnerability. This ensures that the exemption only applies to the extent required for security testing, without unnecessary or excessive access.

The same exclusion from criminal liability is also applied to offenses pertaining to data interception (§ 202b StGB) and data modification (§ 303a StGB) as long as the related actions are deemed authorized.

At the same time, the draft fill introduces a penalty ranging from three months to five years of imprisonment for severe cases of malicious data spying and data interception (§ 202a StGB).

In terms of what constitutes a severe case, the draft bill mentions the following cases:

  • The offense results in substantial financial damage.
  • The act was driven by a profit motive, conducted on a commercial scale, or carried out as part of a criminal organization.
  • Cases that compromise critical infrastructure—like hospitals, energy suppliers, or transportation networks—or affect the security of Germany or one of its states, including attacks originating from abroad.

More details about the draft law and proposed amendments are available here.

Federal states and concerned associations have received it for review and are given until December 13, 2024, to submit their feedback before it is presented to the Bundestag for parliamentary deliberation.

The U.S. Department of Justice announced a similar revision to the Computer Fraud and Abuse Act (CFAA) in May 2022, introducing prosecution exclusions for “good-faith” security researchers.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:05 am, Juni 29, 2025
Wetter-Symbol 22°C
L: 20° | H: 23°
klarer Himmel
Luftfeuchtigkeit: 78 %
Druck: 1025 mb
Wind: 8 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:46 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
20° | 23°°C 0 mm 0% 7 mph 80 % 1026 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
20° | 34°°C 1 mm 100% 6 mph 66 % 1022 mb 0 mm/h
Di. Juli 01 10:00 pm
Wetter-Symbol
20° | 32°°C 0.77 mm 77% 11 mph 68 % 1019 mb 0 mm/h
Mi. Juli 02 10:00 pm
Wetter-Symbol
16° | 24°°C 1 mm 100% 12 mph 89 % 1019 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
15° | 22°°C 0 mm 0% 15 mph 81 % 1022 mb 0 mm/h
Today 1:00 am
Wetter-Symbol
20° | 22°°C 0 mm 0% 7 mph 78 % 1025 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
18° | 21°°C 0 mm 0% 5 mph 80 % 1025 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
19° | 20°°C 0 mm 0% 5 mph 80 % 1026 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
23° | 23°°C 0 mm 0% 4 mph 58 % 1026 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
28° | 28°°C 0 mm 0% 5 mph 43 % 1025 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 3 mph 35 % 1023 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 1 mph 34 % 1021 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 6 mph 56 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,625.15
0.22%
Ethereum(ETH)
€2,083.09
0.73%
Fesseln(USDT)
€0.85
-0.01%
XRP(XRP)
€1.87
2.02%
Solana(SOL)
€128.85
5.77%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.140286
1.86%
Shiba Inu(SHIB)
€0.000010
2.51%
Pepe(PEPE)
€0.000009
4.42%
Nach oben scrollen