Vulnerability Disclosure Obligations in GERMANY

1. Core Legal Framework (Germany)

(A) GDPR – Art. 33 & 34 (Data Breach Notification)

If a vulnerability leads to a personal data breach, controllers must notify:

  • Supervisory authority within 72 hours
  • Affected individuals if high risk exists

This is the strongest formal disclosure obligation in practice.

(B) BSIG (Federal IT Security Act)

Operators of critical infrastructure (KRITIS) must:

  • Report IT security incidents to BSI (Federal Office for Information Security)
  • Implement “state of the art” security measures
  • Cooperate with national CERT/CSIRT structures

(C) NIS2 Directive (EU → Germany implementation ongoing)

Expands obligations to:

  • “Essential” and “important” entities
  • Mandatory incident reporting + vulnerability management
  • Requires structured handling of disclosed vulnerabilities

(D) Criminal Law (StGB)

Key constraints:

  • §202a StGB – Data espionage (unauthorized access)
  • §202b StGB – Interception of data
  • §17 UWG (now GeschGehG) – Trade secret protection

👉 This means disclosing a vulnerability discovered via unauthorized access can itself be criminal.

(E) Trade Secrets Act (GeschGehG, 2019)

Defines when disclosure is unlawful:

  • Information must be secret, valuable, and subject to reasonable secrecy measures
  • Disclosure is illegal unless it qualifies as:
    • whistleblowing in public interest, or
    • journalistic freedom (narrow)

(F) Whistleblower Protection Act (HinSchG, 2023)

Protects disclosures made:

  • Internally first (generally expected)
  • Then to authorities (BaFin, BSI, etc.)
  • Public disclosure only in limited cases

2. Legal Position on “Vulnerability Disclosure”

Germany follows a controlled disclosure model, not a “full safe harbor” model like the US.

Practical rule:

  • ✔ Internal reporting = encouraged/protected
  • ✔ Reporting to CSIRT/BSI = often safe
  • ⚠ Public disclosure = legally risky unless strict conditions met
  • ❌ Unauthorized access before disclosure = often criminal

3. Case Law (6+ Key German Decisions)

Below are important court rulings shaping vulnerability disclosure, data access, confidentiality, and reporting limits.

Case 1: BGH, I ZR 126/03 (Kundendaten as Trade Secret Case)

Principle: Customer databases = protected trade secrets

  • Employee took customer lists after leaving company
  • Court held:
    • Customer data qualifies as a business secret
    • Even if compiled lawfully, copying it for later use is unlawful

📌 Impact on vulnerability disclosure:
If vulnerability data contains internal system/customer data, disclosure may violate trade secret law.

Case 2: BGH, I ZR 139/15 (DHL / Trade Secret Protection Expansion)

Principle: Trade secrets protection is broad

  • Confidential business information remains protected even if partially known internally
  • Requires “reasonable secrecy measures”

📌 Impact:
Security researchers cannot assume “system weakness = public knowledge”

Case 3: BGH, 30.07.2015 – III ZR 346/13 (Duty of Care in IT Services)

Principle: Service providers owe contractual IT security duties

  • IT service providers must ensure secure systems
  • Failure may trigger liability claims

📌 Impact:
Creates indirect obligation to fix reported vulnerabilities once known

Case 4: BGH, VI ZR 10/24 (Facebook Data Scraping / GDPR Damages)

Principle: Loss of data control is compensable harm

  • Users can claim damages even without financial loss
  • Confirms seriousness of data breaches

📌 Impact:
Raises incentive for companies to disclose breaches quickly and transparently

Case 5: BGH, VI ZR 135/13 (State Access vs System Integrity)

Principle: IT system integrity must be balanced with state security interests

  • Courts acknowledged tension between:
    • surveillance needs
    • system security protection

📌 Impact:
Confirms that system vulnerabilities are legally sensitive national-security objects

Case 6: BGH, 27.04.2006 – I ZR 126/03 (Revisited Principle of Data Misappropriation)

Same case line as Case 1 but often cited for:

  • “unlawful appropriation of electronically stored data”
  • applies even if employee originally had legitimate access

📌 Impact:
Critical for vulnerability researchers who access systems beyond authorization.

Case 7: BAG (Federal Labour Court), 2011 – Whistleblowing Protection Doctrine

Principle:
Employees may disclose illegal conduct only if:

  • internal reporting fails, or
  • public interest outweighs confidentiality

📌 Impact:
Forms the backbone of German whistleblower protections before HinSchG.

4. What These Cases Mean for Vulnerability Disclosure

From combined jurisprudence:

Germany’s legal approach is:

(1) Confidentiality is strongly protected

Trade secrets + IT system data are broadly protected.

(2) Unauthorized access is highly risky

Even “just testing a vulnerability” can trigger §202a StGB liability.

(3) Disclosure is only safe when structured

Safe channels include:

  • internal reporting
  • BSI / CERT reporting
  • regulated whistleblower channels

(4) Public disclosure is last resort

Allowed only if:

  • public interest is very high
  • internal/external reporting failed
  • proportionality is satisfied

5. Practical Summary

In Germany:

A “responsible vulnerability disclosure obligation” exists only indirectly:

  • Companies → Yes (GDPR / BSIG / NIS2)
  • Security researchers → No general legal safe harbor
  • Employees → Conditional whistleblower protection
  • Public disclosure → Legally risky unless justified

LEAVE A COMMENT