MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
What is a pentest waiver? It is a written consent and indemnity statement by which an organization grants an ethical hacker permission to break into its systems within an agreed scope, and by which the pentester is indemnified against liability for computer trespass as long as they remain within that scope. Without such a waiver, breaking into a computer system is a punishable offense under Article 138ab of the Dutch Criminal Code, even if well-intentioned. The pentest waiver removes the unlawfulness by establishing prior consent from the rights holder.
The short answer
- What: consent plus indemnity for a pentest, or a controlled intrusion test.
- Why: breaking and entering without permission is punishable, Article 138ab of the Dutch Criminal Code.
- Core: scope, authorization, liability, confidentiality, and a responsible disclosure agreement.
- Who: the rights holder of the system signs, together with the pentester.
- Goal: Legally and safely find weak spots before a real attacker finds them.
What is a pentest waiver and why do you need one?
A penetration test, or pentest for short, is a controlled attempt to break into an IT system to find vulnerabilities. That is exactly what a malicious hacker does as well, but only with permission and with the goal of helping the organization. Legally, the distinction is thin. Without the permission of the rights holder, intentionally entering a computer system falls under computer trespass, punishable under Article 138ab of the Dutch Criminal Code. Rendering data unusable (Article 350a of the Criminal Code) or disrupting a service (Article 138b of the Criminal Code) can also be punishable.
The pentest waiver resolves this. Because the rights holder grants written permission in advance, the element of unlawfulness is absent. The hacker then acts not against the will of the rights holder, but rather on instructions. Consequently, the test is legal, provided the pentester stays within the agreed limits.
Consent removes criminal liability
The core of the waiver is the consent of the person who has control over the system. Important in this regard:
- Only the rights holder can grant permission. If you test systems running on a hosting provider or cloud service, permission from your own organization is not sufficient. The owner of the underlying infrastructure must also agree; otherwise, you are testing on a third party's systems without their permission.
- Consent must be demonstrable. A verbal instruction is legally weak. A signed waiver with date, scope, and signature of an authorized signatory is proof that access was permitted.
- The permission is limited. It applies only to the systems, methods, and period stated in the waiver. If the pentester goes beyond this, that part does not fall under the permission and may still be punishable.
What a pentest waiver regulates
At its core, a good pentest waiver contains:
- Scope and authorization: which systems, IP ranges, applications, and methods may be tested, and what is explicitly outside the scope.
- Time window: when the test takes place, so that the organization can distinguish it from a real attack.
- Indemnification: the rights holder indemnifies the pentester against liability for access and actions within the scope.
- Liability and damage: what happens if unintended damage or failure occurs during the test.
- Confidentiality: the pentester keeps discovered vulnerabilities and data confidential.
- Responsible disclosure: how and to whom findings are reported, and that they are not made public.
- Personal data: if the test involves personal data, the requirements of the GDPR apply and a data processing agreement is usually required.
A brief illustration. An online store has its ordering system tested. The waiver states which domains and IP ranges are within scope, that the payment provider is explicitly outside the scope, that the test takes place at night, and that the penetration tester may not retain any customer data found. When the test accidentally caused a malfunction, it had already been determined in advance who bore which risk.
Limits of the waiver
A waiver does not cover everything. Consent from your own organization does not apply to third-party systems, so separate consent is required for shared infrastructure. An indemnity only works between the signing parties; it does not bind third parties who suffer damage. And the GDPR remains in effect: if you process personal data during the test, this must be done lawfully and securely, with a legal basis and appropriate measures pursuant to Article 32 of the GDPR. Intentional or grossly negligent damage also generally falls outside the scope of an indemnity. The waiver legalizes the test within the agreed framework but does not provide a free pass for everything.
Honest recommendation
For a simple, internal test on your own systems that you fully manage, and which does not affect personal data or third-party systems, a concise, signed consent form will suffice. Do ensure that the scope, timeframe, and signing authority are clearly defined. That way, you have the minimum legal requirements covered.
As soon as third-party systems, customer data, production environments, or an external penetration tester are involved, a good penetration test waiver is important. Scope definition, liability for damages, and GDPR compliance determine who bears the risk if something goes wrong. A missing indemnity or an overly broad scope can cause problems for both the penetration tester and the client. Have a lawyer draft or review the waiver before the test begins, especially regarding shared infrastructure and personal data.
More about drafting and costs: pentest waiver, drafting a pentest waiver and having a pentest waiver drafted.
Frequently Asked Questions
A written consent and indemnity statement by which an organization grants an ethical hacker permission to test its systems within an agreed scope, and by which the pentester is indemnified against liability for computer intrusion as long as he remains within that scope.
Yes. Intentionally entering a computer system without permission is computer trespass, punishable under Article 138ab of the Dutch Criminal Code. Disrupting a service or damaging data can also be punishable. The waiver removes that criminal liability by establishing prior consent.
The rights holder of the systems, represented by an authorized signatory, together with the penetration tester. If the systems run on a hosting provider or cloud service, permission from that party is also required, as only they are the rights holder of the underlying infrastructure.
The scope determines which systems, IP ranges, applications, and methods may be tested and what falls outside the test. The consent applies only within that scope. If the pentester goes beyond it, that part does not fall under the consent and may still be punishable.
You arrange this in advance in the waiver. Usually, the client bears the risk of unintended failure within the scope, while intentional or grossly negligent damage falls outside the indemnification. Clearly define who bears which risk.
Yes, as soon as the test involves personal data. The processing must be lawful and secure in accordance with the GDPR, with appropriate measures pursuant to Article 32 of the GDPR. A data processing agreement with the penetration tester is often required, and any data found must remain confidential.
An agreement on how discovered vulnerabilities are reported: only to the client, confidentially, and not publicly. This gives the organization the opportunity to patch the weaknesses before a real attacker can exploit them.