Vulnerability Disclosure Obligations in GERMANY
1. Core Legal Framework (Germany)
(A) GDPR – Art. 33 & 34 (Data Breach Notification)
If a vulnerability leads to a personal data breach, controllers must notify:
- Supervisory authority within 72 hours
- Affected individuals if high risk exists
This is the strongest formal disclosure obligation in practice.
(B) BSIG (Federal IT Security Act)
Operators of critical infrastructure (KRITIS) must:
- Report IT security incidents to BSI (Federal Office for Information Security)
- Implement “state of the art” security measures
- Cooperate with national CERT/CSIRT structures
(C) NIS2 Directive (EU → Germany implementation ongoing)
Expands obligations to:
- “Essential” and “important” entities
- Mandatory incident reporting + vulnerability management
- Requires structured handling of disclosed vulnerabilities
(D) Criminal Law (StGB)
Key constraints:
- §202a StGB – Data espionage (unauthorized access)
- §202b StGB – Interception of data
- §17 UWG (now GeschGehG) – Trade secret protection
👉 This means disclosing a vulnerability discovered via unauthorized access can itself be criminal.
(E) Trade Secrets Act (GeschGehG, 2019)
Defines when disclosure is unlawful:
- Information must be secret, valuable, and subject to reasonable secrecy measures
- Disclosure is illegal unless it qualifies as:
- whistleblowing in public interest, or
- journalistic freedom (narrow)
(F) Whistleblower Protection Act (HinSchG, 2023)
Protects disclosures made:
- Internally first (generally expected)
- Then to authorities (BaFin, BSI, etc.)
- Public disclosure only in limited cases
2. Legal Position on “Vulnerability Disclosure”
Germany follows a controlled disclosure model, not a “full safe harbor” model like the US.
Practical rule:
- ✔ Internal reporting = encouraged/protected
- ✔ Reporting to CSIRT/BSI = often safe
- ⚠ Public disclosure = legally risky unless strict conditions met
- ❌ Unauthorized access before disclosure = often criminal
3. Case Law (6+ Key German Decisions)
Below are important court rulings shaping vulnerability disclosure, data access, confidentiality, and reporting limits.
Case 1: BGH, I ZR 126/03 (Kundendaten as Trade Secret Case)
Principle: Customer databases = protected trade secrets
- Employee took customer lists after leaving company
- Court held:
- Customer data qualifies as a business secret
- Even if compiled lawfully, copying it for later use is unlawful
📌 Impact on vulnerability disclosure:
If vulnerability data contains internal system/customer data, disclosure may violate trade secret law.
Case 2: BGH, I ZR 139/15 (DHL / Trade Secret Protection Expansion)
Principle: Trade secrets protection is broad
- Confidential business information remains protected even if partially known internally
- Requires “reasonable secrecy measures”
📌 Impact:
Security researchers cannot assume “system weakness = public knowledge”
Case 3: BGH, 30.07.2015 – III ZR 346/13 (Duty of Care in IT Services)
Principle: Service providers owe contractual IT security duties
- IT service providers must ensure secure systems
- Failure may trigger liability claims
📌 Impact:
Creates indirect obligation to fix reported vulnerabilities once known
Case 4: BGH, VI ZR 10/24 (Facebook Data Scraping / GDPR Damages)
Principle: Loss of data control is compensable harm
- Users can claim damages even without financial loss
- Confirms seriousness of data breaches
📌 Impact:
Raises incentive for companies to disclose breaches quickly and transparently
Case 5: BGH, VI ZR 135/13 (State Access vs System Integrity)
Principle: IT system integrity must be balanced with state security interests
- Courts acknowledged tension between:
- surveillance needs
- system security protection
📌 Impact:
Confirms that system vulnerabilities are legally sensitive national-security objects
Case 6: BGH, 27.04.2006 – I ZR 126/03 (Revisited Principle of Data Misappropriation)
Same case line as Case 1 but often cited for:
- “unlawful appropriation of electronically stored data”
- applies even if employee originally had legitimate access
📌 Impact:
Critical for vulnerability researchers who access systems beyond authorization.
Case 7: BAG (Federal Labour Court), 2011 – Whistleblowing Protection Doctrine
Principle:
Employees may disclose illegal conduct only if:
- internal reporting fails, or
- public interest outweighs confidentiality
📌 Impact:
Forms the backbone of German whistleblower protections before HinSchG.
4. What These Cases Mean for Vulnerability Disclosure
From combined jurisprudence:
Germany’s legal approach is:
(1) Confidentiality is strongly protected
Trade secrets + IT system data are broadly protected.
(2) Unauthorized access is highly risky
Even “just testing a vulnerability” can trigger §202a StGB liability.
(3) Disclosure is only safe when structured
Safe channels include:
- internal reporting
- BSI / CERT reporting
- regulated whistleblower channels
(4) Public disclosure is last resort
Allowed only if:
- public interest is very high
- internal/external reporting failed
- proportionality is satisfied
5. Practical Summary
In Germany:
A “responsible vulnerability disclosure obligation” exists only indirectly:
- Companies → Yes (GDPR / BSIG / NIS2)
- Security researchers → No general legal safe harbor
- Employees → Conditional whistleblower protection
- Public disclosure → Legally risky unless justified

comments