HONG KONG · EAST ↔ WEST
info@lockhartyip.comResponse within 4 hours (UTC+8)
Discuss your matter
Home/Insights/Disputes & Arbitration
Tech & Web3

Update: a cross-border SaaS or data agreement touching Mainland China

A cross-border SaaS or data agreement touching Mainland China. The instrument, the sequence and the risk most miss. Write to info@lockhartyip.com.

For any business running a software-as-a-service product or a data-processing arrangement across the Hong Kong–Mainland China corridor, the compliance exposure is no longer theoretical. Two regulatory regimes now apply simultaneously – and the sequence of obligations under each determines whether the agreement is enforceable, whether data can lawfully cross the boundary, and whether the service provider is properly licensed. Missing either layer is the single most common error our desk sees in cross-border tech mandates.

A cross-border SaaS or data agreement touching Mainland China engages the Mainland's Personal Information Protection Law (PIPL, China's principal statute governing the collection, processing and cross-border transfer of personal information) and the Data Security Law, alongside Hong Kong's own data-protection regime, the Anti-Money Laundering and Counter-Terrorist Financing Ordinance for any platform with payment or financial-data flows, and – where the platform handles virtual assets – the licensing rules administered by the Securities and Futures Commission. No single instrument controls the entire agreement. The cross-border element creates a layered compliance stack that must be mapped before the contract is signed.

What the compliance trigger looks like in practice

The trigger is typically one of three facts in the deal: personal data originating in the Mainland is processed by a server or entity outside the Mainland; a SaaS product is provided to a Mainland-based subscriber by a Hong Kong-incorporated entity; or a data-processing agreement is concluded between a Mainland data controller and an offshore processor.

Each of those fact patterns activates a cross-border data-transfer mechanism under the PIPL. The Mainland regime requires either a standard contract (a prescribed form of data-transfer agreement filed with the competent Mainland regulator) or – depending on the volume and sensitivity of the data – a security assessment (a formal review by the Cyberspace Administration of China). The threshold at which a security assessment becomes mandatory, rather than the standard-contract route, is determined by data volume and category, and those thresholds have been refined by implementing rules. Any counsel preparing a cross-border SaaS agreement for a client with Mainland personal-data flows should verify the current thresholds before filing.

On the Hong Kong side, the Personal Data (Privacy) Ordinance applies to data-user entities incorporated or operating here. The two regimes are not identical in their definitions of personal data, their legitimate-processing grounds, or their cross-border transfer rules. A standard contract that satisfies Mainland requirements will not automatically satisfy Hong Kong's position, and vice versa.

Where the SaaS product handles financial data or payment flows – common in B2B enterprise deployments – the Anti-Money Laundering and Counter-Terrorist Financing Ordinance imposes customer due-diligence and record-keeping obligations on the Hong Kong entity. If the platform is a virtual-asset trading platform, the mandatory licensing regime under the same Ordinance applies: the Securities and Futures Commission is the licensing authority, and that regime commenced 1 June 2023. Operating without a licence, or without a pending application in the correct form, is not a compliant position.

Who is affected across the corridor

The affected population is broader than most in-house teams initially assume. It includes Hong Kong-incorporated SaaS vendors with Mainland enterprise clients. It includes offshore holding entities that act as the nominal contracting party for a group whose actual data processing occurs in the Mainland. It includes non-Chinese technology companies that route Asia-Pacific data through a Hong Kong entity and whose Mainland subscriber base generates personal data subject to the PIPL.

The common factor is the data flow, not the governing-law clause. A SaaS agreement governed by English law and seated in Hong Kong arbitration still engages Mainland data-compliance rules if the data originates with Mainland data subjects. Choosing a neutral forum is strategically sound. It does not disapply the regulatory layer.

In our cross-border practice, we regularly advise on the interface between the contractual structure – governing law, arbitration clause, liability cap, data-processor obligations – and the regulatory compliance stack. The two are designed independently by their respective authors and must be made to work together by counsel.

What to do now

Three actions are immediate.

First, map the data flows before the agreement is executed. Identify each category of personal data, its origin jurisdiction, its processing location, and the entity that is the data controller under each of the applicable regimes. A flow-mapping exercise takes days, not weeks, and it determines which transfer mechanism applies.

Second, confirm the licensing position of every entity in the contractual chain. A Hong Kong entity that operates a platform with financial-data or virtual-asset components needs to know whether it falls within the SFC's licensing perimeter before it contracts with a Mainland counterparty. Our desk can assess the licensing posture against the current regulatory perimeter.

Third, review the dispute-resolution clause with enforcement in mind. A cross-border data or SaaS dispute is most efficiently resolved through arbitration with a Hong Kong seat, using the HKIAC Administered Arbitration Rules. Under the Arbitration Ordinance (Cap. 609), which is modelled on the UNCITRAL Model Law, Hong Kong-seated awards are enforceable across the Mainland under the mutual-enforcement Arrangements between the Mainland and the HKSAR. That route is materially different from – and more direct than – enforcement via the New York Convention, which does not govern PRC–HK awards.

The sequence matters. A well-drafted arbitration clause is worth significantly less if the regulatory compliance file is incomplete at the time a dispute arises: a counterparty's first line of defence in Mainland proceedings is often a challenge to the underlying contract's lawfulness under Mainland mandatory rules.

For a structured read on your cross-border SaaS or data agreement and the compliance steps required on each side of the boundary, contact our Tech & Web3 desk at lockhartyip.com/practices/tech-web3/ or write to us at info@lockhartyip.com.

For related guidance, see our analysis of digital asset fund structures through Hong Kong and Cyprus and our guide to cross-border SaaS and data agreements touching Cyprus.

Frequently asked questions

How does the cross-border element affect a cross-border SaaS or data agreement touching Mainland China?
The cross-border element activates two parallel compliance regimes at once: the Mainland's Personal Information Protection Law governs any transfer of personal data originating with Mainland data subjects, while Hong Kong's own data-protection regime and, where relevant, its AML obligations apply to the Hong Kong-side entity. Neither regime defers to the other. The governing-law clause in the SaaS agreement does not disapply mandatory Mainland data rules. Counsel must map both layers before the contract is signed and ensure the chosen transfer mechanism – standard contract or security assessment – is filed correctly.
Do I need a Hong Kong adviser for a cross-border SaaS or data agreement touching Mainland China?
An adviser with cross-border experience across the Hong Kong–Mainland interface is important because the compliance stack combines Mainland mandatory rules, Hong Kong regulatory obligations, and the contractual dispute-resolution architecture. A Mainland lawyer alone will not advise on Hong Kong licensing or AML exposure. A purely Hong Kong lawyer may not have working knowledge of the PIPL transfer mechanisms. Our desk handles the international and foreign-law layer and coordinates with locally licensed Hong Kong firms on Hong Kong-law matters, providing a single point of contact for the cross-border position.
How long does a cross-border SaaS or data agreement touching Mainland China usually take?
Timeline depends on the complexity of the data flows, the licensing position of the parties, and whether a Mainland security assessment is required. Data-flow mapping and a first draft of the compliance structure can typically be completed within a few weeks for a straightforward B2B arrangement. Where a Mainland security-assessment filing or an SFC licensing application is required, the timeline extends considerably – those processes run on regulatory timetables outside the parties' control. Early engagement, before the agreement is near execution, produces the most efficient outcome.

Speak with Lockhart & Yip

For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.

This site uses only strictly necessary cookies. Non-essential cookies are declined by default. Cookie policy