Skip to content
Sophie Laurent, YuSMP Group

Sophie Laurent

Legal & Compliance Lead, YuSMP Group

Sophie Laurent covers software compliance for the YuSMP Group blog — GDPR, HIPAA, the EU AI Act, CCPA, DPAs and standard contractual clauses. She translates regulation into engineering checklists US and EU teams can actually ship against.

  • Born1988
  • LocationParis
  • Experience12 years
  • SpecializationGDPR, HIPAA, EU AI Act, data protection
  • EducationMaster of Laws (LLM), Université Paris 1 Panthéon-Sorbonne

Legal & Compliance Lead · 12 articles

NIST Secure Software Development Framework — an engineer reviewing secure code with padlock and shield overlays Enterprise 12 min read
SecurityCompliance

NIST Secure Software Development Framework (SSDF): A 2026 Guide

The NIST SSDF (SP 800-218) explained for 2026 — the four practice groups, the 2025-2026 attestation changes, SBOM, who must comply and how to implement it.

2026-07-30 Read article →
A client and a software vendor reviewing and signing a software development contract at a desk Custom 12 min read
ContractsIP Ownership

Software Development Contract: Key Clauses, IP Ownership & Template (2026)

What every software development contract needs in 2026 — scope, IP ownership, acceptance, milestones, change control and red flags — with a clause checklist.

2026-07-21 Read article →
Two biomedical software engineers reviewing medical device software and a patient vital-signs monitor in a clean development lab Compliance 12 min read
HealthTechMedTech

Medical Device Software Development: A 2026 Guide

Medical device software development in 2026 — SaMD classes, the IEC 62304 lifecycle, FDA and EU MDR rules, the EU AI Act, cybersecurity, and realistic cost and timelines.

2026-07-18 Read article →
FERPA and COPPA compliance for edtech — a young child using a tablet at home Compliance 12 min read
EdTechStudent Data

FERPA and COPPA Compliance for EdTech in 2026

FERPA and COPPA for edtech in 2026 — what student data the rules cover, the April 2026 COPPA deadline, the school-official exception, and a privacy-by-design checklist.

2026-06-29 Read article →
Ecommerce sales tax automation — a shopper paying online at checkout Compliance 12 min
E-commerceSales Tax

Ecommerce sales tax automation in 2026: nexus and tools

US ecommerce sales tax in 2026 — economic nexus thresholds by state, marketplace facilitator rules, and Avalara vs TaxJar vs Stripe Tax compared.

2026-06-23 Read article →
Web App Accessibility & WCAG 2.2 in 2026 Web 14 min
AccessibilityWCAG

Web App Accessibility & WCAG 2.2 in 2026

WCAG 2.2 and the EU Accessibility Act for web apps — ARIA, keyboard nav, contrast, testing and legal risk.

2026-05-14 Read article →
Mobile app security and GDPR compliance 2026 Mobile 13 min read
Security GDPR

Mobile app security & GDPR (2026)

Privacy by design, consent, the third-party SDK problem, encryption, App Tracking Transparency, CCPA and the GDPR 72-hour breach rule — a practical guide for US & EU mobile teams.

2026-04-06 Read article →
Web App Security Best Practices 2026 Web 14 min
SecurityOWASP

Web App Security Best Practices 2026

An OWASP-aligned checklist for SaaS and B2B web apps — auth, access control, injection, secrets, CSP and logging.

2026-03-02 Read article →
EU AI Act for SaaS compliance checklist 2026 Compliance 18 min read
EU AI Act Regulation

EU AI Act for SaaS — compliance checklist

Article-by-article checklist: Annex III/I classification, GPAI Article 53, Annex IV docs, Article 9 RMS, Article 72 PMM — what SaaS founders and counsel actually need to ship.

2026-02-13 Read article →
How to Choose a Software Development Company Custom 13 min
Vendor SelectionCompliance

How to Choose a Software Development Company

How to choose a software development company — certifications (ISO 27001, SOC 2, GDPR), IP protection, engagement models, red flags and 15 questions to ask.

2025-12-27 Read article →
HIPAA software development checklist 2026 Compliance 17 min read
HIPAA HealthTech

HIPAA software development checklist

Practical checklist for software vendors: §164.502–514 Privacy Rule, §164.308–316 Security Rule safeguards, §164.504 BAA, §164.400–414 breach notification, HITECH, OCR enforcement.

2025-12-10 Read article →
GDPR for US founders 2026 practical guide Compliance 19 min read
GDPR Privacy

GDPR for US founders selling to the EU

What US-incorporated SaaS founders actually need to ship into the EU: Article 3 scope, Article 27 EU representative, ROPA, SCCs 2021/914, DPF, Schrems II.

2025-09-23 Read article →

All articles →

Building something in gdpr? Let's talk.

Response within 1 business day. NDA on request.

Get a proposal

Get a proposal

Share a few details and a senior consultant will reply within one business day.