logo

Germany drafts law to protect researchers who find security flaws

ID: a9fc217e-6824-5484-83b0-f363f4a21389

STIX ID: report--a9fc217e-6824-5484-83b0-f363f4a21389

Feed Name: Bleeping Computer

Date Published: 2024-11-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Germany’s Federal Ministry of Justice has proposed amendments to the Criminal Code (StGB) to legally protect authorized, good-faith security research that aims to identify and report vulnerabilities, while increasing penalties for severe data spying and interception—especially against critical infrastructure. The draft defines criteria for exemption from liability, extends protections to related offenses (e.g., data interception and modification), and introduces prison terms of three months to five years for serious cases. The proposal is under review by federal states and associations until December 13, 2024, and mirrors U.S. DOJ updates to the CFAA that exclude good-faith research from prosecution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.