HONG KONG · EAST ↔ WEST
info@lockhartyip.comResponse within 4 hours (UTC+8)
Discuss your matter
Home/Insights/Disputes & Arbitration
Tech & Web3

Update: a cross-border SaaS or data agreement touching the CIS

A cross-border SaaS or data agreement touching the CIS. What changed and the action it calls for. The Hong Kong angle in focus. Write to info@lockhartyip.com.

SaaS and data agreements that cross the boundary between Hong Kong and the Commonwealth of Independent States – the post-Soviet regional grouping whose member states include Russia, Kazakhstan, Uzbekistan and several others – are under increasing compliance pressure in mid-2028. The convergence of new data-localisation requirements in several CIS jurisdictions, tightened virtual-asset and platform-licensing rules in Hong Kong, and shifting sanctions posture (the alignment of a given jurisdiction's sanctions obligations with international or unilateral measures) means that agreements structured even twelve months ago may now carry regulatory exposure that was not visible at signing.

A cross-border SaaS or data agreement touching the CIS now requires a two-layer compliance review: first, the licensing and data-handling position under the Hong Kong regime, including obligations under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance where the platform processes payments or virtual-asset transfers; second, the in-country requirements in the CIS jurisdiction of delivery, which vary significantly across the corridor. The governing instruments are jurisdiction-specific, but the Hong Kong side is anchored in the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and, where virtual assets are involved, the Securities and Futures Ordinance.

One sentence on what follows: this briefing sets out what has changed, who it affects, and the immediate steps a counterparty or service provider should take.

What has changed across the Hong Kong – CIS corridor

Several developments converge in mid-2028. In Hong Kong, the mandatory licensing regime for centralised virtual-asset trading platforms – which commenced 1 June 2023 under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, with the Securities and Futures Commission as licensing authority – has matured into an enforcement phase. Platforms that were operating under a transitional posture now face active scrutiny. A SaaS agreement that routes payment flows or data through a platform with any virtual-asset component cannot treat the licensing question as theoretical.

At the same time, the FATF travel rule applies to virtual-asset transfers processed by licensed platforms. Where a CIS-domiciled counterparty is on the receiving end of such transfers, the originating entity's customer due-diligence file must meet the standard required under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance – regardless of where the counterparty sits. That creates a documentation obligation that runs upstream into the commercial agreement itself.

On the CIS side, data-localisation rules in several member states have been tightened. The practical effect for a SaaS provider is that a standard cross-border data-processing schedule drafted for a European or US counterparty is unlikely to satisfy local requirements without amendment. The specific instrument varies by state; counsel on our desk regularly identifies mismatches between the Hong Kong governing-law clause and the in-country mandatory provisions that override it.

Hong Kong implements United Nations sanctions and does not give domestic effect to unilateral measures of other states. That position is factual and well-established. It does, however, mean that a counterparty operating in a CIS jurisdiction subject to unilateral measures imposed by a third state must be analysed carefully: the Hong Kong compliance position differs from the position of a US or EU co-investor or licensor. Getting that distinction right in the agreement is not optional.

Who is affected and what to do now

The immediate audience for this briefing is any principal or in-house team that falls into one of three positions. First, a Hong Kong-based SaaS or data-services provider with existing commercial agreements in Kazakhstan, Uzbekistan, Georgia, Armenia or other CIS jurisdictions. Second, a CIS-based technology group using a Hong Kong entity as its contracting or licensing hub. Third, a fund or treasury operation with portfolio companies on both sides of the corridor whose intercompany data and service agreements have not been reviewed against the current licensing and AML position.

The window here is not academic. A licensed platform operating under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance that discovers a non-compliant cross-border agreement after the fact has fewer options than one that corrects the position before regulatory contact. The same logic applies to the in-country CIS position: several jurisdictions have introduced or are introducing administrative penalties for data-handling breaches that now exceed the commercial value of a mid-market SaaS contract.

The immediate steps are straightforward to describe, though less straightforward to execute without cross-border counsel. Review every active SaaS or data agreement with a CIS counterparty against the current licensing posture of the Hong Kong entity. Identify whether any payment or data flow has a virtual-asset component that engages the Anti-Money Laundering and Counter-Terrorist Financing Ordinance or the Securities and Futures Ordinance. Verify whether the CIS jurisdiction of delivery has imposed data-localisation requirements that override the governing-law clause. Document the sanctions-posture analysis in the compliance file, distinguishing the Hong Kong position from that of any co-licensor or investor subject to a different sanctions regime. Parties should verify the current position before acting, as both the Hong Kong regulatory position and CIS domestic rules continue to develop.

Our desk has reviewed a number of cross-border SaaS and data arrangements across the Hong Kong – CIS corridor over the past eighteen months. The most common gap we identify is not in the commercial terms but in the compliance schedule: the agreement describes the service correctly, but the AML, data-handling and sanctions-posture provisions have not been updated to reflect the current regulatory position on either side.

For a structured assessment of your SaaS or data agreement across the Hong Kong and CIS jurisdictions, write to us at info@lockhartyip.com.

For further analysis on related matters, see our practice page on Tech & Web3, our analysis of a digital asset fund structured through Hong Kong for CIS exposure, and our guide on a digital asset fund structured through Hong Kong and the Cayman Islands.

Frequently asked questions

How long does a cross-border SaaS or data agreement touching the CIS usually take?
The review and amendment cycle for an existing agreement typically runs over several weeks rather than days, depending on the number of CIS jurisdictions involved and the complexity of the data flows. A new agreement drafted with the current compliance position in mind can move faster. In either case, the licensing and AML analysis on the Hong Kong side and the in-country data-localisation check on the CIS side must run in parallel; attempting to sequence them sequentially extends the timeline materially. Parties should verify the current regulatory position before signing.
Do I need a Hong Kong adviser for a cross-border SaaS or data agreement touching the CIS?
Where the contracting entity is Hong Kong-based, or where the agreement routes data or payment flows through Hong Kong, the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and potentially the Securities and Futures Ordinance apply regardless of the governing law chosen. A CIS-jurisdiction adviser alone cannot assess that position. International counsel covering both sides of the corridor – coordinating with locally licensed Hong Kong firms where Hong Kong law questions arise – provides the analysis a CIS-only or Hong Kong-only approach cannot.
How does the cross-border element affect a cross-border SaaS or data agreement touching the CIS?
The cross-border element creates a layered compliance obligation. The Hong Kong contracting entity carries duties under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, including customer due diligence and, where virtual assets are processed, the FATF travel rule. The CIS counterparty may be subject to data-localisation rules that override the governing-law clause. Hong Kong's distinct sanctions posture – implementing United Nations sanctions only – must be documented separately from the position of any co-investor or licensor operating under a different sanctions regime. Each layer requires separate analysis and specific contractual drafting.

Speak with Lockhart & Yip

For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.

This site uses only strictly necessary cookies. Non-essential cookies are declined by default. Cookie policy