Each country has specific laws. So it can be difficult to be aware of all of these, but you still need to. You need to read all of these, congrats.

CategoriesUSAEUUKIndiaChina
General InformationCISAGDPRData Protection Act 2018Information Technology Act 2000Cyber Security Law
Classifying CriminalsCFAANISD2Computer Misuse Act 1990Information Technology Act 2000National Security Law
Protecting copyrightDMCACybercrime Convention of the Council of EuropeAnti-Terrorism Law
Communication InterceptionECPAE-Privacy Directive 2002/58/ECHRAIndian Evidence Act of 1872
Health InformationHIPAAPolice and Justice Act 2006Indian Penal Code of 1860
Youth InformationCOPPAIPA
International Cybercrime prosecutionRIPA
Individual InformationDigital Personal Data Protection ActMeasures for the Security Assessment of Cross-border Transfer of Personal Information and Important Data

TL;DR

When you are doing a penetration test, here are some common guidelines to avoid violating most laws.

  • Obtain written consent from the authorized representative of the system
  • Follow the scope of consent
  • Avoid damaging the systems
  • Don’t access/use/disclose info found
  • Don’t intercept communication
  • Don’t test health systems without authorization