Sophie Laurent
Legal & Compliance Lead, YuSMP Group
Sophie Laurent covers software compliance for the YuSMP Group blog — GDPR, HIPAA, the EU AI Act, CCPA, DPAs and standard contractual clauses. She translates regulation into engineering checklists US and EU teams can actually ship against.
- Born1988
- LocationParis
- Experience12 years
- SpecializationGDPR, HIPAA, EU AI Act, data protection
- EducationMaster of Laws (LLM), Université Paris 1 Panthéon-Sorbonne
Legal & Compliance Lead · 12 articles
Enterprise
12 min read
NIST Secure Software Development Framework (SSDF): A 2026 Guide
The NIST SSDF (SP 800-218) explained for 2026 — the four practice groups, the 2025-2026 attestation changes, SBOM, who must comply and how to implement it.
Custom
12 min read
Software Development Contract: Key Clauses, IP Ownership & Template (2026)
What every software development contract needs in 2026 — scope, IP ownership, acceptance, milestones, change control and red flags — with a clause checklist.
Compliance
12 min read
Medical Device Software Development: A 2026 Guide
Medical device software development in 2026 — SaMD classes, the IEC 62304 lifecycle, FDA and EU MDR rules, the EU AI Act, cybersecurity, and realistic cost and timelines.
Compliance
12 min read
FERPA and COPPA Compliance for EdTech in 2026
FERPA and COPPA for edtech in 2026 — what student data the rules cover, the April 2026 COPPA deadline, the school-official exception, and a privacy-by-design checklist.
Compliance
12 min
Ecommerce sales tax automation in 2026: nexus and tools
US ecommerce sales tax in 2026 — economic nexus thresholds by state, marketplace facilitator rules, and Avalara vs TaxJar vs Stripe Tax compared.
Web
14 min
Web App Accessibility & WCAG 2.2 in 2026
WCAG 2.2 and the EU Accessibility Act for web apps — ARIA, keyboard nav, contrast, testing and legal risk.
Mobile
13 min read
Mobile app security & GDPR (2026)
Privacy by design, consent, the third-party SDK problem, encryption, App Tracking Transparency, CCPA and the GDPR 72-hour breach rule — a practical guide for US & EU mobile teams.
Web
14 min
Web App Security Best Practices 2026
An OWASP-aligned checklist for SaaS and B2B web apps — auth, access control, injection, secrets, CSP and logging.
Compliance
18 min read
EU AI Act for SaaS — compliance checklist
Article-by-article checklist: Annex III/I classification, GPAI Article 53, Annex IV docs, Article 9 RMS, Article 72 PMM — what SaaS founders and counsel actually need to ship.
Custom
13 min
How to Choose a Software Development Company
How to choose a software development company — certifications (ISO 27001, SOC 2, GDPR), IP protection, engagement models, red flags and 15 questions to ask.
Compliance
17 min read
HIPAA software development checklist
Practical checklist for software vendors: §164.502–514 Privacy Rule, §164.308–316 Security Rule safeguards, §164.504 BAA, §164.400–414 breach notification, HITECH, OCR enforcement.
Compliance
19 min read
GDPR for US founders selling to the EU
What US-incorporated SaaS founders actually need to ship into the EU: Article 3 scope, Article 27 EU representative, ROPA, SCCs 2021/914, DPF, Schrems II.
Building something in gdpr? Let's talk.
Response within 1 business day. NDA on request.
Get a proposal
Share a few details and a senior consultant will reply within one business day.