Update: a cross-border SaaS or data agreement touching the CIS
A cross-border SaaS or data agreement touching the CIS. What changed and the action it calls for. The Hong Kong angle in focus. Write to info@lockhartyip.com.
SaaS and data agreements that cross the boundary between Hong Kong and the Commonwealth of Independent States – the post-Soviet regional grouping whose member states include Russia, Kazakhstan, Uzbekistan and several others – are under increasing compliance pressure in mid-2028. The convergence of new data-localisation requirements in several CIS jurisdictions, tightened virtual-asset and platform-licensing rules in Hong Kong, and shifting sanctions posture (the alignment of a given jurisdiction's sanctions obligations with international or unilateral measures) means that agreements structured even twelve months ago may now carry regulatory exposure that was not visible at signing.
A cross-border SaaS or data agreement touching the CIS now requires a two-layer compliance review: first, the licensing and data-handling position under the Hong Kong regime, including obligations under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance where the platform processes payments or virtual-asset transfers; second, the in-country requirements in the CIS jurisdiction of delivery, which vary significantly across the corridor. The governing instruments are jurisdiction-specific, but the Hong Kong side is anchored in the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and, where virtual assets are involved, the Securities and Futures Ordinance.
One sentence on what follows: this briefing sets out what has changed, who it affects, and the immediate steps a counterparty or service provider should take.
What has changed across the Hong Kong – CIS corridor
Several developments converge in mid-2028. In Hong Kong, the mandatory licensing regime for centralised virtual-asset trading platforms – which commenced 1 June 2023 under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, with the Securities and Futures Commission as licensing authority – has matured into an enforcement phase. Platforms that were operating under a transitional posture now face active scrutiny. A SaaS agreement that routes payment flows or data through a platform with any virtual-asset component cannot treat the licensing question as theoretical.
At the same time, the FATF travel rule applies to virtual-asset transfers processed by licensed platforms. Where a CIS-domiciled counterparty is on the receiving end of such transfers, the originating entity's customer due-diligence file must meet the standard required under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance – regardless of where the counterparty sits. That creates a documentation obligation that runs upstream into the commercial agreement itself.
On the CIS side, data-localisation rules in several member states have been tightened. The practical effect for a SaaS provider is that a standard cross-border data-processing schedule drafted for a European or US counterparty is unlikely to satisfy local requirements without amendment. The specific instrument varies by state; counsel on our desk regularly identifies mismatches between the Hong Kong governing-law clause and the in-country mandatory provisions that override it.
Hong Kong implements United Nations sanctions and does not give domestic effect to unilateral measures of other states. That position is factual and well-established. It does, however, mean that a counterparty operating in a CIS jurisdiction subject to unilateral measures imposed by a third state must be analysed carefully: the Hong Kong compliance position differs from the position of a US or EU co-investor or licensor. Getting that distinction right in the agreement is not optional.
Who is affected and what to do now
The immediate audience for this briefing is any principal or in-house team that falls into one of three positions. First, a Hong Kong-based SaaS or data-services provider with existing commercial agreements in Kazakhstan, Uzbekistan, Georgia, Armenia or other CIS jurisdictions. Second, a CIS-based technology group using a Hong Kong entity as its contracting or licensing hub. Third, a fund or treasury operation with portfolio companies on both sides of the corridor whose intercompany data and service agreements have not been reviewed against the current licensing and AML position.
The window here is not academic. A licensed platform operating under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance that discovers a non-compliant cross-border agreement after the fact has fewer options than one that corrects the position before regulatory contact. The same logic applies to the in-country CIS position: several jurisdictions have introduced or are introducing administrative penalties for data-handling breaches that now exceed the commercial value of a mid-market SaaS contract.
The immediate steps are straightforward to describe, though less straightforward to execute without cross-border counsel. Review every active SaaS or data agreement with a CIS counterparty against the current licensing posture of the Hong Kong entity. Identify whether any payment or data flow has a virtual-asset component that engages the Anti-Money Laundering and Counter-Terrorist Financing Ordinance or the Securities and Futures Ordinance. Verify whether the CIS jurisdiction of delivery has imposed data-localisation requirements that override the governing-law clause. Document the sanctions-posture analysis in the compliance file, distinguishing the Hong Kong position from that of any co-licensor or investor subject to a different sanctions regime. Parties should verify the current position before acting, as both the Hong Kong regulatory position and CIS domestic rules continue to develop.
Our desk has reviewed a number of cross-border SaaS and data arrangements across the Hong Kong – CIS corridor over the past eighteen months. The most common gap we identify is not in the commercial terms but in the compliance schedule: the agreement describes the service correctly, but the AML, data-handling and sanctions-posture provisions have not been updated to reflect the current regulatory position on either side.
For a structured assessment of your SaaS or data agreement across the Hong Kong and CIS jurisdictions, write to us at info@lockhartyip.com.
For further analysis on related matters, see our practice page on Tech & Web3, our analysis of a digital asset fund structured through Hong Kong for CIS exposure, and our guide on a digital asset fund structured through Hong Kong and the Cayman Islands.
Frequently asked questions
How long does a cross-border SaaS or data agreement touching the CIS usually take?
Do I need a Hong Kong adviser for a cross-border SaaS or data agreement touching the CIS?
How does the cross-border element affect a cross-border SaaS or data agreement touching the CIS?
Speak with Lockhart & Yip
For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →
Related
- Tech Web3
- Digital Asset Fund Structured Through Hong Kong Cis 6
- Digital Asset Fund Structured Through Hong Kong Cayman
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.