MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Before having a penetration test performed, first establish the legal basis: a written assignment with consent and a clear scope, agreements regarding liability and confidentiality, and, in the case of personal data, a data processing agreement. Without these agreements, both you and the tester run unnecessary risk.
Why a penetration test must be legally regulated
During a penetration test, an ethical hacker attempts to infiltrate your systems with your permission to find vulnerabilities. Doing so without explicit permission is a criminal offense. Therefore, a written consent and assignment agreement forms the basis of every pentest.
Consent and scope
Precisely define which systems, applications, and IP addresses may be tested, when, and by which methods. A clear scope prevents the tester from accidentally exceeding the limits or affecting third-party systems. If you are testing systems running on a hosting provider, you also require their permission.
Liability and confidentiality
A penetration test can unintentionally cause a malfunction. Make agreements regarding liability and what happens in the event of damage. Additionally, establish confidentiality: the tester gains access to sensitive information and discovered vulnerabilities that must not be disclosed.
GDPR and personal data
If the tester accesses personal data, they act as a processor, and you require a data processing agreement (Article 28 GDPR). Agree on how any data found will be handled and that it will be destroyed after the test. Furthermore, the GDPR requires you to actually close any vulnerabilities found.
Frequently Asked Questions
What document do I need at a minimum for a penetration test?
A written assignment specifying consent and scope, plus agreements regarding liability and confidentiality. In the case of personal data, a data processing agreement is added.
Do I need to ask my hosting provider for permission?
Yes, if the systems to be tested are running at a third party, you generally also need their permission to stay within the rules.
What if the penetration test finds a vulnerability?
You are required to remedy any vulnerabilities found. A penetration test without follow-up offers a false sense of security and does not resolve the risk.
Handling the legal side of your pentest?
Our legal experts draft the engagement, the pentest waiver , and the data processing agreement . View our privacyteam or schedule a free consultation.