Launching a startup in 2026 without a sound legal plan means accepting avoidable risks: loss of intangible assets, governance deadlocks, commercial litigation, tax reassessments and GDPR penalties (up to 4% of worldwide turnover according to the CNIL). Here are the 12 most common mistakes we encounter, with practical ways to avoid them.
1) Choosing an unsuitable company form (SAS/SARL)
The SAS offers considerable governance flexibility (BSPCE, approval/lock-up clauses), while the SARL is more regulated but provides protection for small family businesses. A poor choice creates obstacles to fundraising, recruitment and directors' tax arrangements.
- Typical mistakes: choosing a SARL when a SAS is intended for growth and investor participation; ignoring the social-security/tax impact of directors' remuneration.
- Action: define your objectives (fundraising, international expansion, employee equity) and decide with a lawyer. Compare the key points in a dedicated guide to choosing between SAS and SARL.
Official resources: guidance from Service Public Pro — business information and the Commercial Code on Legifrance.
2) Copy-and-paste articles of association and no shareholders' agreement
Unsuitable generic articles of association can result in registry refusals, invalidity and shareholder disputes. Without a shareholders' agreement, there is no safety net for departures, disagreements or buyouts.
- Frequently overlooked clauses: tag-along/drag-along, pre-emption and approval, lock-up, founder vesting, governance (committees), reserved decisions and post-sale non-competes.
- Action: draft tailored articles of association and a consistent shareholders' agreement. Use a startup legal audit checklist to map your risks before signing.
3) Neglecting intellectual property (trademarks, patents, copyright)
Without protection, a competitor can register your brand first, dispute your rights in the code or copy your design.
- Trademarks: conduct a clearance search and file early with INPI (appropriate classes, monitoring, extension strategy). See our guide to developing a trademark filing strategy.
- Software/code: code is protected by copyright, but secure the chain of title (employees, freelancers, founders). Formalise the assignment of founders' rights to the company.
- Patents/designs: assess patentability (technical character, novelty), and consider a European patent after filing with the INPI.
4) Generic, incomplete or non-compliant contracts and terms of sale
Templates “found online” omit essential clauses and may be incompatible with your business model or sector regulations.
- Key clauses: precise deliverable definitions, SLAs, penalties, liability limits, force majeure, ownership of deliverables, exit and data return, GDPR compliance, governing law and jurisdiction.
- Action: build a contract library by use case and automate internal generation (see how to automate contract management).
In B2B dealings, anticipate termination and non-payment (reasonable notice, L442‑1 C. com., available on Legifrance).
5) Ignoring GDPR and data transfers
The GDPR requires a lawful basis, information, minimisation, DPAs with processors, records of processing, data protection impact assessments (DPIAs) where necessary, security and safeguards for transfers outside the EU.
- Risk: administrative fines of up to 4% of worldwide turnover (CNIL), processing bans and reputational damage.
- Action: map your processing, establish a record, sign SCCs, update your privacy policy and appoint a DPO if necessary.
Legislation and guidance: GDPR (Regulation 2016/679) on EUR‑Lex and practical guides from the CNIL.
6) Underestimating cybersecurity and NIS2
Beyond the GDPR, the NIS2 Directive imposes enhanced security and incident-management requirements on many sectors and critical subcontractors.
- Risk: downtime, theft of secrets, mandatory notifications and penalties.
- Action: adopt ANSSI good practices (IT hygiene, disaster recovery/business continuity plans, strong authentication) and check whether NIS2 applies to you (EUR‑Lex – NIS2, ANSSI).
7) Overlooking AI compliance (AI Act) and model governance
If you develop or integrate AI, prepare the technical documentation, risk management, data quality and transparency expected under the forthcoming European framework (AI Act). For an operational overview, consult our AI Act guide for startups and EU legislation on EUR‑Lex.
8) Poor management of tax and support schemes (CIR, JEI, grants)
The research tax credit (Crédit d’Impôt Recherche, CIR) and innovative young company (JEI) status are powerful tools but demand strong evidence. An undocumented CIR application or incorrectly classified R&D scope leads to reassessment.
- Action: define an R&D methodology, track time and deliverables, retain the bibliography/state of the art and audit your costs. Seek information from Bpifrance and Service Public Pro — business guidance.
9) Poorly configured employee equity (BSPCE, BSA, AGA)
A poorly structured incentive plan dilutes excessively, demotivates or triggers social-security/tax reassessment.
- Action: size the pool, define conditions (vesting, cliff, good/bad leaver), and secure documentation and grant governance.
10) Employment and freelancer reclassification
Extensive use of independent contractors without precautions can be reclassified as employment (subordination, exclusivity, imposed working hours).
- Action: autonomy clauses, deliverables, multiple clients, no imposed tools/hours, and no integration into the organisation chart. Guidance on Service Public Pro — business guidance and legislation on Legifrance.
11) Unclear governance and no delegations
Without a clear allocation of powers, delegated signing authority and regular minutes, you risk invalid transactions and directors' personal liability.
- Action: organise the legal function, formalise delegations and schedule meetings. See how to establish legal operations from the outset.
12) Inadequate funding preparation (term sheet, crowdfunding, AMF)
Poorly negotiated clauses (liquidation preference, anti-dilution, information rights) or non-compliant crowdfunding.
- Action: prepare a data room, define the term sheet, check crowdfunding rules with the AMF, and align the articles of association and shareholders' agreement.
90-day action plan to avoid these mistakes
Days 1–30: map and secure the essentials
- Choose or confirm the company form with a lawyer; if necessary, prepare a conversion (SARL→SAS) and assess its tax implications.
- Review the articles of association and shareholders' agreement (exit clauses, reserved decisions, vesting, approval).
- Start clearance searches and trademark filing; arrange the assignment of founders' IP rights.
- Inventory critical contracts and close gaps (SLAs, liability, exit and data return, DPAs).
Days 31–60: data/tech compliance and security
- Build processing records, internal policies and GDPR information templates; provide safeguards for transfers outside the EU (SCCs).
- Assess NIS2 applicability and deploy the first technical/organisational controls (ANSSI guides).
- For AI products, start documentation (risk management, datasets, assessment) in preparation for the AI Act.
Days 61–90: funding, people and scaling processes
- Pre-audit CIR/JEI (R&D methodology, traceability) with help from Bpifrance.
- Configure employee equity (pool, BSPCE/BSA/AGA) and delegations of authority.
- Put your legal processes into operation with workflows and templates; see our legal audit checklist to validate coverage.
Warning signs to address immediately
- Your trademark is unregistered although you are already selling.
- Freelancers work full-time on site with imposed tools/hours.
- No processing records or DPAs with your cloud/SaaS processors.
- No limitation-of-liability clause in your terms of sale/contracts.
- You are preparing a funding round without a data room or a clearly defined term sheet.
For structured and sustainable oversight, establish a legal ops framework and prioritised budget. Our experience is detailed in this article on organising the legal function.
Useful official references and resources
Legislation and guides: Service Public Pro — business guidance, Legifrance, CNIL, EUR‑Lex (NIS2), EUR‑Lex (GDPR/AI), ANSSI, INPI, Bpifrance, AMF. On common mistakes, also see practitioner overviews such as StartLaw and Frédéric Simon, lawyer.
Further reading
Related resources
- SAS or SARL: which company form should a startup choose in 2026?
- Startup legal audit: complete checklist
- Legal ops for startups: organising the legal function from day one
- Protecting your trademark: INPI filing, classes and protection strategy
- Assignment of founders' intellectual property to the company
Frequently asked questions
FAQ
When should a startup register its trademark?
Before going to market. Conduct a clearance search and file with the INPI to secure the name and relevant classes.
Does the GDPR apply to B2B-only data?
Yes, if it identifies individuals (contacts, users). You must document the lawful basis, provide information, ensure security and keep processing records.
Is an NDA enough to protect a technology?
No. An NDA protects confidentiality, not ownership. Register the trademark, secure copyright in the code and assess patent protection.
Can we start with generic terms of sale?
Strongly discouraged. Adapt your terms/contracts to your model (SaaS, services), including clauses on liability, data, SLAs and governing law.
How can we prioritise legal work on a small budget?
Priorities: articles/shareholders' agreement, trademark, key contracts, core GDPR compliance and security. Then scale with legal operations processes and tools.
References
Sources used
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.