HONG KONG · EAST ↔ WEST
info@lockhartyip.comResponse within 4 hours (UTC+8)
Discuss your matter
Home/Insights/Disputes & Arbitration
Tech & Web3

Where a cross-border SaaS or data agreement touching the BVI stands now

A cross-border SaaS or data agreement touching the BVI. The current cross-border position and what it means in practice. Write to info@lockhartyip.com.

A technology group structured through the British Virgin Islands and delivering software services to clients in Hong Kong, the Mainland or further across Asia faces a question that its offshore incorporators did not answer: which regulatory regime governs the agreement, and which regulator will act if something goes wrong. The BVI is a holding centre, not a regulatory home. The commercial relationship – the SaaS licence, the data-processing agreement, the API access arrangement – lives somewhere else entirely.

A cross-border SaaS or data agreement touching the BVI sits at the junction of the BVI's common-law contract posture, Hong Kong's technology-licensing and Anti-Money Laundering and Counter-Terrorist Financing Ordinance obligations, and the data-governance expectations of the jurisdiction where the counterparty or the data subject actually sits. The governing instrument is determined by the agreement's choice-of-law clause, the location of the regulated activity, and the characterisation of any digital asset component under the Securities and Futures Ordinance or the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (the AML Ordinance). The analysis below maps where the risk concentrates and what the current cross-border position requires in practice.

This analysis addresses the commercial stakes, the governing instruments, the comparative read across Hong Kong and the BVI, the licensing posture, the AML obligations, and our view on where the exposure sits now, as the regulatory environment continues to tighten around cross-border digital services and data flows.

What is actually at stake commercially?

The commercial risk in a cross-border SaaS or data agreement touching the BVI is not theoretical. An agreement that is unenforceable in the jurisdiction where the counterparty's assets sit is commercially worthless, regardless of how well it is drafted in the governing-law clause.

Technology groups use BVI holding entities for legitimate and well-understood reasons: clean capitalisation, no withholding tax on dividends, straightforward share transfer for investor rounds, and access to the common-law system. These advantages are real. But when the BVI entity becomes the contracting party for a SaaS agreement – supplying software, processing data, receiving subscription fees – a set of regulatory questions attach that the BVI entity itself cannot resolve.

The first question is where the regulated activity occurs. If the SaaS platform processes payments, holds client data, or interfaces with virtual assets, the activity may trigger licensing or AML obligations in the jurisdiction of the counterparty, the user, or the data subject – not in the BVI. A BVI entity contracting with a Hong Kong enterprise client is doing business in Hong Kong for most practical purposes. The second question is whether the contractual relationship is enforceable across the relevant borders. A judgment or award obtained against a counterparty in Hong Kong needs to reach the assets. If the assets are in the BVI or the Mainland, the route is not automatic.

In our cross-border technology practice, we regularly see groups where the BVI holding entity has accumulated contractual exposure – as licensor, as data processor, or as platform operator – without a clear map of which regulator has authority over the activity or which court has jurisdiction over a dispute. The commercial consequence of that gap materialises quickly when a client defaults, a data incident occurs, or a regulator issues an enquiry.

How does the governing framework engage across Hong Kong and the BVI?

The governing framework for a cross-border SaaS or data agreement touching the BVI is not a single instrument – it is a layered set of rules drawn from the lex contractus (the law governing the contract), the law of the place of regulated activity, and the data-governance regime applicable to the data subjects or the data custodian.

The BVI operates a common-law system. Its BVI Business Companies Act (the BVI companies statute) provides the corporate substratum, but the BVI has no technology-specific regulatory regime of its own that applies to a SaaS agreement at the user level. The BVI entity's contractual capacity and enforceability are strong within the common-law orbit. The BVI Financial Services Commission regulates certain financial services and funds, but a standard SaaS licence does not typically engage BVI financial services regulation unless the platform handles client money or virtual assets that meet the relevant threshold.

Hong Kong presents a more textured picture. The AML Ordinance applies to designated non-financial businesses and professions and to virtual-asset trading platforms (VATPs). Where a SaaS agreement incorporates or enables virtual-asset services – for example, a wallet interface, a token-issuance module, or an exchange API – the Hong Kong regulatory perimeter expands materially. The VATP licensing regime under the AML Ordinance commenced on 1 June 2023, with the Securities and Futures Commission (the SFC) as licensing authority. Where a virtual-asset component constitutes a "security" or "futures contract" within the meaning of the Securities and Futures Ordinance, SFC licensing requirements apply additionally.

The choice-of-law clause in the agreement determines which courts interpret the contract. But it does not displace the mandatory rules of the jurisdiction where the regulated activity takes place. A BVI-law agreement that delivers regulated activity in Hong Kong will still attract Hong Kong regulatory supervision of that activity. Foreign principals frequently misread this point.

The sequence of analysis that counsel on our desk follows is: (1) characterise the activity – pure software licence, data processing, payment facilitation, virtual-asset service, or a combination; (2) identify the jurisdiction of each regulated layer; (3) map the mandatory rules that apply regardless of the governing-law clause; (4) assess the enforcement route for disputes; and (5) document the AML position for the regulated layers.

What does the comparative read across Hong Kong and the BVI show?

Comparing the Hong Kong and BVI positions reveals a structural asymmetry that most technology groups do not fully account for at the point of contracting.

The BVI is excellent at one thing in this context: it provides a clean, flexible corporate vehicle with a common-law contract foundation, a well-developed body of commercial law, and an internationally recognised equity jurisdiction for internal corporate disputes. The BVI courts regularly handle shareholder disputes, director-duty claims, and trust-related matters for groups with Asian operating businesses. For a SaaS agreement, BVI law as the governing law of the contract is defensible and workable. BVI contractual remedies – damages, injunctive relief, specific performance – are conventional and enforceable within the common-law orbit.

Hong Kong, by contrast, offers something the BVI cannot: a directly enforceable cross-border enforcement architecture. The Mainland Judgments in Civil and Commercial Matters (Reciprocal Enforcement) Ordinance (Cap. 645), in force since 29 January 2024, allows a Hong Kong court judgment to be registered and enforced in the Mainland, and vice versa, through a registration mechanism with the Court of First Instance. For a SaaS group with Mainland enterprise clients, this is a decisive structural advantage that a BVI-only contracting structure does not replicate.

The practical implication is that a technology group with meaningful Mainland counterparty exposure should consider whether the Hong Kong entity – rather than the BVI holding entity – should be the contracting party for its Mainland-facing agreements. The BVI entity remains useful as the holding layer and for investor-facing instruments. The operating agreement sits better in Hong Kong if enforcement against Mainland assets is a genuine prospect.

Does the group's data-governance position change across the two systems? In the BVI, there is a data-protection statute, but it is not the primary compliance driver for most cross-border SaaS arrangements. In Hong Kong, the Personal Data (Privacy) Ordinance applies to the collection, use, and transfer of personal data by data users operating in or from Hong Kong. Where a BVI entity processes personal data on behalf of a Hong Kong enterprise client, the Hong Kong data user (the client) bears primary compliance obligations, but the SaaS agreement should address the data-processor relationship clearly to avoid the BVI entity being characterised as a co-data-user with its own direct obligations.

Where does the licensing posture sit, and which regulator actually applies?

Licensing posture is the single most consequential variable for a cross-border SaaS or data agreement touching the BVI. The answer to "which regulator applies" depends on what the platform does, not where the entity is incorporated.

A SaaS platform incorporated in the BVI but operating a centralised virtual-asset exchange accessible to Hong Kong users is, in the SFC's regulatory view, operating in Hong Kong. The SFC's VATP licensing regime, commenced 1 June 2023 under the AML Ordinance, requires that any centralised virtual-asset trading platform that is licensed in Hong Kong or actively markets to Hong Kong investors holds an SFC licence. The BVI incorporation of the operator does not exempt the platform from this requirement. Failing to obtain the required licence is a regulatory breach; operating without one after the transition period carries enforcement risk.

Consider the position of a mid-market technology group that came to our desk in late 2026. The group operated a SaaS data-analytics platform through a BVI entity. The platform had a module that allowed users to track token portfolios. The group's founders believed – on the basis of advice received at incorporation – that the BVI vehicle insulated them from Hong Kong securities regulation. It did not. The portfolio-tracking module, when combined with an API that permitted trade execution on a third-party exchange, arguably brought the platform within the VATP perimeter. The group needed to restructure the module, document the non-securities analysis, and consider whether a Hong Kong operating entity was required. The cost of the restructuring was substantially higher than the cost of front-end licensing advice would have been.

Where the SaaS agreement does not touch virtual assets, the licensing position is less acute. A clean B2B software licence, an API data feed, or a cloud-infrastructure agreement between a BVI licensor and a Hong Kong enterprise client does not typically trigger SFC or HKMA licensing. The AML Ordinance obligations still attach to the Hong Kong client as a regulated entity, and the agreement should be clear about which party holds the relevant customer-due-diligence file. But the BVI licensor is not itself a regulated entity in Hong Kong for that activity.

The AML dimension for the BVI entity is governed by BVI AML requirements, which apply to certain categories of regulated activity within the BVI's own perimeter. For most SaaS arrangements, the relevant AML obligations will sit with the Hong Kong counterparty, not the BVI entity. However, where the BVI entity receives subscription payments from counterparties in higher-risk jurisdictions, or where the payment chain is complex, basic source-of-funds documentation is prudent regardless of the formal AML obligation.

The sequence of analysis that our desk applies to a new mandate of this type is: (1) map the activity layer by layer; (2) test each layer against the VATP perimeter and the securities-characterisation question; (3) identify the regulator for each layer; (4) assess the AML obligations and identify which entity holds the compliance file; and (5) document the non-regulated analysis for layers that fall outside the perimeter, as a defence record.

The contextual bridge for any group at this assessment stage: the mapping above describes the standard analytical sequence. The specific result turns on the product architecture, the user base, the payment structure, and the jurisdiction of the data subjects – which is where the real risk is won or lost.

For a structured assessment of the licensing and AML position across the Hong Kong and BVI layers, write to us at info@lockhartyip.com.

How does the enforcement architecture operate across this structure?

Enforcement is the practical test of any cross-border technology agreement. A dispute between a BVI SaaS licensor and a Hong Kong enterprise client raises three questions in sequence: which forum has jurisdiction; which law governs the dispute; and where can a judgment or award be enforced against the defendant's assets.

Arbitration is the standard answer for technology agreements with international counterparties, and it is a good one for this structure. A Hong Kong-seated arbitration under the HKIAC Administered Arbitration Rules (the 2024 Rules, effective 1 June 2024) provides a neutral forum acceptable to BVI and Hong Kong parties alike. The governing statute is the Arbitration Ordinance (Cap. 609), modelled on the UNCITRAL Model Law. An award from a Hong Kong-seated arbitration can be enforced in the BVI and across the New York Convention network – the BVI acceded to the Convention – and against Mainland assets through the 1999 Arrangement and 2020 Supplemental Arrangement on mutual enforcement of arbitral awards between the Mainland and the HKSAR.

Importantly, simultaneous enforcement applications have been permitted since the 2021 amendment to the Supplemental Arrangement. This allows an award creditor with assets on both sides of the Mainland–Hong Kong boundary to pursue enforcement concurrently rather than sequentially – a meaningful practical advantage for a technology licensor owed subscription arrears or damages by a Mainland enterprise client.

A court litigation route is less flexible for this structure. A BVI court judgment has no reciprocal-enforcement arrangement with Hong Kong. Enforcement in Hong Kong of a BVI judgment would require a common-law action on the judgment – workable, but slower and more costly than registration under a statutory regime. A Hong Kong court judgment, by contrast, can now be registered in the Mainland under Cap. 645, provided the judgment meets the scope requirements and was made on or after 29 January 2024.

The practical conclusion is that an arbitration clause with Hong Kong as seat, HKIAC as the administering institution, and a governing law suited to the contract (often English law or Hong Kong law) gives the BVI–Hong Kong SaaS structure the strongest enforcement architecture currently available across the Greater China corridor.

If an earlier filing or enforcement attempt in this structure produced an adverse or stalled result, a second read of the arbitration agreement and the enforcement route can identify whether the sequencing or the registration step was the point of failure and what routes remain open. To discuss a stalled enforcement position, contact info@lockhartyip.com.

What do foreign principals commonly get wrong in this structure?

The errors we see most frequently are structural rather than drafting errors, and they are almost always made at the outset rather than mid-contract.

The first and most common error is treating the BVI incorporation as a regulatory shield. It is not. The BVI entity's corporate form does not determine the regulatory perimeter applicable to the activity. A BVI entity running a SaaS platform that executes or facilitates virtual-asset transactions accessible to Hong Kong users is within the SFC's supervisory reach. The BVI incorporation determines the entity's corporate governance, its share structure, and the applicable company law – no more.

The second error is a poorly drafted or absent choice-of-law and dispute-resolution clause. Technology agreements between offshore entities and Asian counterparties often use US-law or English-law governing-law clauses without considering whether those choices are practical for enforcement in the actual jurisdictions of the counterparty's assets. An English-law governing clause in a BVI–Mainland enterprise agreement produces an enforcement problem: the English courts have no reciprocal-enforcement arrangement with the Mainland courts, and a Hong Kong arbitral award would be more efficiently deployed. The governing law and the dispute-resolution mechanism should be selected in light of the enforcement destination, not the lawyers' comfort zone.

The third error is underestimating the data-governance exposure. A BVI entity that processes personal data of Hong Kong residents as part of a SaaS arrangement may be characterised as a data user under the Personal Data (Privacy) Ordinance even without a physical presence in Hong Kong, depending on the facts of the processing relationship. The agreement's data-processing terms should clearly allocate responsibility between the licensor and the client, specify the processing purposes, and address cross-border data transfer. Where the data subject base includes Mainland residents, the relevant Mainland data-governance requirements attach to the processing, regardless of where the BVI entity is incorporated.

A European technology group expanding into Asia through a BVI vehicle came to us in early 2027. The group had a standard US-law SaaS agreement used across its global client base. That agreement had no provision for the FATF travel rule (the obligation to transmit originator and beneficiary information on virtual-asset transfers above a threshold), no AML-Ordinance-compliant due-diligence schedule, and an arbitration clause specifying ICC arbitration with New York as seat. For Mainland and Hong Kong enterprise clients, the New York seat and ICC clause would have required an enforcement route that was significantly longer than a Hong Kong-seated HKIAC award. The group's onboarding for its first Asian clients was delayed while the agreement was restructured.

Where does the risk sit now, and where is this heading?

The direction of travel across the Hong Kong–BVI–digital-services corridor is unmistakable, and the window for passive compliance is narrowing.

In Hong Kong, the regulatory infrastructure for virtual-asset services is now substantially in place. The VATP licensing regime under the AML Ordinance is operational. The SFC's approach to unlicensed platforms operating in or from Hong Kong has been explicitly supervisory and, where the facts support it, enforcement-oriented. The HKMA's fiat-referenced stablecoin issuer licensing regime, commenced in 2025 – groups should verify the current commencement date and perimeter before relying on the position – extends the regulatory perimeter to stablecoin issuance, which a number of SaaS platforms are beginning to integrate as a payment mechanism. A SaaS agreement that incorporates stablecoin settlement may engage both the VATP regime and the stablecoin-issuer regime, depending on the platform architecture.

The AML travel rule – the FATF requirement to transmit originator and beneficiary information on virtual-asset transfers – applies to VATPs operating in Hong Kong. Where a SaaS agreement routes subscription payments through a virtual-asset mechanism, the travel-rule compliance position must be documented. That documentation is not a formality; it is a regulatory deliverable.

In the BVI, the BVI Business Companies Act has seen incremental reforms to economic-substance requirements, and the BVI's engagement with international tax-transparency initiatives continues. A BVI entity that is the contracting party for a SaaS agreement generating material subscription revenue should satisfy itself that its economic-substance position is adequate for the relevant activity category. Counsel on our desk regularly advise on the interaction between the BVI's substance requirements and the group's Hong Kong operational footprint – the two are complementary when structured correctly.

The broader direction is towards greater regulatory convergence across the technology-services corridor. Data-governance regimes are becoming more prescriptive. Virtual-asset regulation is expanding in scope and in the jurisdictions that apply it. Enforcement capacity across the Mainland–Hong Kong border has materially improved since 29 January 2024. A cross-border SaaS or data agreement touching the BVI that was adequate when drafted two years ago may now carry regulatory exposure that was not visible at the time.

Our view is that the risk concentration in this structure is currently highest at three points: (1) the licensing characterisation of any virtual-asset or payment-facilitation component; (2) the data-governance documentation for cross-border data processing; and (3) the enforcement architecture of the dispute-resolution clause relative to the actual jurisdiction of the counterparty's assets. Groups that have not reviewed their cross-border SaaS or data agreements within the last 18 months should treat that review as a near-term priority rather than a deferred task.

Related practices

  • Tech & Web3 – licensing posture, VATP compliance and virtual-asset regulatory structuring across Asian jurisdictions
  • Sanctions & AML – AML Ordinance compliance, counterparty due diligence and source-of-funds documentation for cross-border technology groups
  • Disputes & Arbitration – cross-border enforcement architecture, arbitration-clause design and award registration under the Hong Kong–Mainland arrangements

Frequently asked questions

Do I need a Hong Kong adviser for a cross-border SaaS or data agreement touching the BVI?
Yes, where the agreement delivers regulated activity in Hong Kong or involves counterparties with Hong Kong-based assets. A BVI-incorporated entity contracting with Hong Kong clients may trigger obligations under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, the Securities and Futures Ordinance's VATP perimeter, or the Personal Data (Privacy) Ordinance, depending on the product architecture. Hong Kong-seated arbitration, enforcement through Cap. 645, and AML compliance all require coordination with the Hong Kong legal environment, even where the contracting entity is offshore.
What is the first step in a cross-border SaaS or data agreement touching the BVI?
The first step is a structured characterisation of the activity: what does the platform do, who are the users, where are the data subjects, and does any component touch virtual assets or payment facilitation? That characterisation determines which regulatory regime applies and which regulator has authority. From that point, the choice-of-law clause, the dispute-resolution mechanism, and the AML-compliance schedule can be designed for the specific jurisdictions engaged, rather than imported from a generic precedent that may not fit the cross-border structure.
How does the cross-border element affect a cross-border SaaS or data agreement touching the BVI?
The cross-border element affects enforceability, regulatory reach, and data-governance obligations simultaneously. A BVI-law agreement does not displace the mandatory rules of the jurisdiction where the regulated activity takes place. An agreement without a Hong Kong-seated arbitration clause loses access to the Mainland–Hong Kong enforcement architecture under the 1999 and 2020 Arrangements. A data-processing agreement that does not address cross-border data transfer may leave the BVI entity exposed as a de facto data user under Hong Kong or Mainland data-governance requirements. Each cross-border layer requires its own analysis.

Speak with Lockhart & Yip

For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.

This site uses only strictly necessary cookies. Non-essential cookies are declined by default. Cookie policy