Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

Intellectual Property and Data4 min read

Protecting a startup's source code: copyright and good practice

Your code is a strategic asset. Understand copyright protection, secure the chain of title, manage open source and anticipate GDPR requirements.

Source code embodies your competitive advantage, your ability to execute and, often, a major share of your valuation. Securing it legally and operationally is not optional: it is foundational work to undertake from the first lines of code.

Under French and European law, software — including its source code, object code, interfaces and preparatory documents — is protected by copyright from creation, subject to originality. This protection derives from the French Intellectual Property Code (particularly art. L112-2 et seq.), available on Legifrance, and the European directive on the legal protection of computer programs (EUR-Lex, 2009/24/EC).

Exclusive economic rights and exceptions

The author holds exclusive economic rights (reproduction, translation/adaptation/modification, placing on the market). Exceptions for the lawful acquirer (backup copy, observation, interoperability subject to conditions) are provided by art. L122-6-1 of the CPI (Legifrance, L122-6-1).

Moral rights: a specific regime for software

The author's moral rights exist but are subject to specific adjustments for software (particularly in view of development and maintenance needs). References on Legifrance.

2) Who owns the rights to the code?

Employees

For software created by an employee in the course of their duties or following the employer's instructions, economic rights automatically vest in the employer (CPI, art. L113-9, available through Legifrance). Nevertheless, include internal clauses clarifying the position (confidentiality, code delivery, documentation, tools).

Service providers, freelancers and agencies

By default, an independent developer retains the rights. An express written assignment is essential, specifying scope, territory, duration and remuneration. Without it, you risk an ownership claim over the code or even being prevented from bringing it to market. See the warning on risks arising from a lack of protection and technical governance published by the DGSI.

3.1 Secure the chain of title (contracts and processes)

  • Include compliant rights assignments in all provider contracts (scope, modules, deliverables, APIs, tests, documentation, duration, territories, future versions, maintenance, remuneration).
  • For employees: clauses on confidentiality, delivery and traceability of contributions (Git repositories, tickets), and no integration of unauthorised third-party code.
  • Introduce a Contributor License Agreement (CLA) for external contributions.
  • Control access to code (least-privilege principles, systematic revocation during offboarding).
  • Provide for commitments to not use generative AI without licence and training opt-out validation, with mandatory human review.

Need a ready-to-use framework? Explore AI and law resources for tech startups.

3.2 Evidence and evidentiary deposits

  • A digital Soleau envelope filed with INPI — special case: software: an established date and description of the protected elements.
  • Deposit with a trusted third party (e.g. a specialist organisation) and a judicial commissioner's report to capture the state of the code and build environment; useful information on Justice.fr.
  • Retain Git history, code reviews, tickets, roadmaps and technical correspondence: these help prove originality and prior creation (Service Public Pro).

3.3 Open-source governance (compliance by design)

  • Compile an SBOM (Software Bill of Materials) and licence register (MIT, Apache-2.0, GPL, AGPL, LGPL, etc.).
  • Implement dependency approval policies and continuous auditing tools (SCA).
  • Document redistribution obligations (copyleft, notices, provision of source code, attribution statements).
  • Choose your distribution licensing model deliberately (proprietary, dual licensing, OSS modules), with export controls where necessary.

For more on IP and data, you can also read our articles on GDPR and intellectual property.

4) Security and GDPR: what your code must incorporate

Code supports compliance: privacy by design, minimisation, proportionate logging, encryption; refer to European Data Protection Board (EDPB) guidelines and CNIL recommendations (data security, testing, anonymisation/pseudonymisation). Inadequate technical governance (hard-coded secrets, vulnerable dependencies, excessive personal-data logs) may expose you to liability, undermine evidence of prior creation and accelerate leakage of strategic assets.

5) Operational 30-60-90-day checklist

Day +30: essential foundations

  • Map code, repositories, access permissions and contributors.
  • Check all provider contracts; initiate missing assignment amendments.
  • Activate an open-source approval policy and generate an initial SBOM.
  • Initiate an evidentiary deposit (INPI Soleau) and freeze a signed Git tag.

Day +60: building maturity

  • Deploy an onboarding/offboarding process including revocation of code access.
  • Sign NDAs with everyone who has access (internal/external).
  • Deploy SCA/SAST tools and a mandatory code-review policy.
  • Formalise generative AI rules and output traceability.

Day +90: scaling up

  • Introduce a CLA for external contributions and licence templates for SDKs/APIs.
  • Conduct a licence compliance audit and address gaps (attribution, copyleft obligations).
  • Schedule recurring evidentiary deposits for every major release.
  • Run a crisis exercise (rights claim or code leak) and prepare a response plan.

6) Anticipate disputes and enforce your rights

  • Formal notice demonstrating prior creation and ownership; attach code extracts, hashes and deposit evidence.
  • Judicial commissioner's report (technical evidence, fingerprints) and preservation of digital evidence (Justice.fr).
  • Infringement proceedings and applications for interim measures where urgent (summary proceedings); rely on CPI provisions available through Legifrance.

Unsure about the strength of your chain of title, or facing an urgent dispute? Read our Explore blog resources and Explore AI and law resources to secure your software assets.

Brief FAQ

Is code protected without a deposit?

Yes. Copyright protection arises automatically if the code is original (CPI through Legifrance). An evidentiary deposit (INPI, official report) strengthens your evidence.

Who owns code developed by an employee?

For software created in the course of employment duties, economic rights belong to the employer (art. L113-9, CPI; see Legifrance).

What are the risks without a written assignment from a freelancer?

The provider may claim ownership and block exploitation. See the DGSI warning.

Can we use GPL dependencies?

Yes, but depending on the GPL chosen (GPL/AGPL/LGPL), obligations to make source code available may apply. Audit and document your choices (see INPI).

Further reading

Read our related guides: Protecting your trademark: INPI filing and strategy, Intellectual property and AI-generated content and GDPR and AI: legal obligations.

Further reading

Related resources

Frequently asked questions

FAQ

Is source code protected automatically in France?

Yes. Software is protected by copyright from creation, subject to originality (CPI). No registration is required, but an evidentiary deposit strengthens the evidence.

Who owns the rights to software developed by an employee?

For software created in the course of duties or following instructions, economic rights belong to the employer (art. L113-9 CPI).

Is a written assignment required with freelancers?

Yes. Without a written assignment, the provider retains copyright and may block exploitation. The assignment must specify scope, duration, territory and remuneration.

Which deposits can prove prior creation?

A digital Soleau envelope (INPI), deposits with a trusted third party and judicial commissioners' reports. Also retain Git history and documentation.

How can open-source risks be avoided?

Compile an SBOM, validate licences before integration, comply with obligations (attribution, copyleft) and implement continuous dependency auditing.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles