HONG KONG · EAST ↔ WEST
info@lockhartyip.comResponse within 4 hours (UTC+8)
Discuss your matter
Home/Insights/Disputes & Arbitration
Tech & Web3

A practical guide to a cross-border SaaS or data agreement touching the BVI

A cross-border SaaS or data agreement touching the BVI. A practical guide for in-house counsel. A note for cross-border groups. Write to info@lockhartyip.com.

A SaaS or data agreement that routes through a British Virgin Islands entity sits at an intersection that surprises many in-house teams: a common-law offshore centre with no domestic data-protection statute of its own, a Hong Kong counterparty or hub layer above it, and a service or data flow that typically involves at least one further jurisdiction's regulatory perimeter. The result is a layered compliance question, not a single-jurisdiction contract review.

A cross-border SaaS or data agreement touching the BVI requires careful sequencing across at least three layers: the governing law and dispute-resolution clause; the licensing and AML posture of any Hong Kong or regulated-jurisdiction entity in the chain; and the economic-substance position of the BVI contracting entity itself. The Anti-Money Laundering and Counter-Terrorist Financing Ordinance and, where virtual-asset components are present, the Securities and Futures Commission licensing regime under the relevant Hong Kong rules, set the compliance perimeter that governs the whole structure.

This guide walks through the decision the in-house team faces, the sequence of steps in order, the gates at each step, the most common structuring mistake, and a short decision checklist for cross-border groups.

What decision does the in-house team actually face?

The starting point is not the contract. It is the entity map. Which legal entity is the contracting party on the provider side? Which entity receives data or services? Where does the revenue book? Where does the intellectual property sit?

A BVI company is frequently used as the top-level holding entity or the IP-holding entity in a technology group. In that configuration, the BVI entity may be the licensor of the underlying software or data product, with a Hong Kong operating subsidiary acting as the service entity that actually delivers and supports the product. That split creates two distinct contractual relationships: an intercompany licence from the BVI holdco to the Hong Kong opco, and an external SaaS or data agreement from the Hong Kong opco to the end customer.

In-house teams often treat these as one exercise. They are not. The intercompany layer carries its own transfer-pricing and substance considerations. The external-facing agreement carries the AML, licensing and data-handling obligations. Conflating the two is the structural error that most frequently creates exposure.

The core decision is therefore: which entity contracts with the customer, under which law, with which dispute-resolution mechanism, and does that entity have the substance and regulatory posture to hold that position?

How does BVI company law shape the contracting structure?

The BVI Business Companies Act provides a flexible corporate vehicle with no local tax on offshore income, strong director authority, and a thin domestic regulatory perimeter for non-regulated activities. For a pure IP-holding or parent-company role, that is often the right tool.

What the BVI does not provide is a data-protection statute with extraterritorial reach, a licensed-services regime for SaaS activity directed at end users, or a domestic AML regime that covers the SaaS or data-services layer (as distinct from financial services). A BVI entity providing SaaS directly to end users in Hong Kong, the Mainland, or any regulated market does not acquire a domestic regulatory licence simply by being incorporated in the BVI.

The BVI economic-substance regime, which applies to BVI entities conducting relevant activities, requires that entities with intellectual-property businesses or holding businesses demonstrate adequate economic substance in the BVI. For an IP-holding entity that licences software, the substance test is relevant. In our cross-border practice, we regularly see groups that have incorporated a BVI entity as a technology IP-holder without assessing whether the BVI substance test is satisfied. The consequence is a reportable deficiency to the BVI International Tax Authority.

The practical implication for the contracting structure: the BVI entity should generally not be the outward-facing contractual counterparty for SaaS or data services delivered to end users in regulated markets. A Hong Kong operating entity – properly licensed where required and subject to the AML regime – is the more defensible front-of-house position.

What is the licensing and AML posture in Hong Kong, and when does it apply?

The Anti-Money Laundering and Counter-Terrorist Financing Ordinance sets the baseline AML and know-your-customer framework for financial institutions and, since 1 June 2023, for licensed virtual-asset trading platforms. Where a SaaS or data product has no financial-services or virtual-asset component, the Ordinance's financial-institution and VATP provisions do not directly apply to the SaaS layer – but the broader AML principles governing corporate conduct remain relevant, and the Hong Kong entity must still manage source-of-funds and counterparty-risk exposure at the commercial level.

Where the product does involve virtual assets – token-related services, data analytics feeding trading infrastructure, custody tooling, or any function characterised as operating a centralised virtual-asset trading platform – the mandatory VATP licensing regime under the Ordinance applies. The Securities and Futures Commission is the licensing authority. An unlicensed entity providing a service that falls within the VATP perimeter is in breach, regardless of where it is incorporated. A BVI-incorporated entity that actively markets and delivers such services in or from Hong Kong does not escape licensing by reason of its offshore incorporation.

Where the virtual asset in question constitutes a security or futures contract under the Securities and Futures Ordinance, a second licensing layer applies. In our cross-border practice, we regularly encounter SaaS products – particularly in the data and analytics segment – whose output is used by clients to generate investment decisions in tokenised securities. Whether that characterisation triggers the SFO layer turns on the specific function of the product and the nature of the data output. The assessment must be made before the agreement is signed, not after.

The sequence matters here: the licensing assessment must precede the contractual drafting, not follow it. A contract that describes a function falling within a licensed perimeter but omits the licensing disclosure is not a way around the regime – it is evidence of the breach.

Customer due diligence (the AML process of identifying and verifying a counterparty's identity and source of funds) is a separate but parallel obligation. For any Hong Kong entity contracting with a BVI-incorporated counterparty, the ultimate beneficial owner of the BVI entity must be established before the agreement is executed. The BVI does not publish a public beneficial-ownership register accessible to contracting parties; the disclosure obligation falls on the BVI entity to produce its register of members and a director-certified ownership structure chart.

The sequence above describes the standard position. Your matter turns on the specific products, the entities actually involved, and the regulatory characterisation of the data output – which is where the licensing question is decided, not in the generic description of the service.

For a preliminary read on your SaaS or data product and the applicable regulatory perimeter, email info@lockhartyip.com.

What is the step-by-step sequence for executing the agreement?

The sequence below applies to a cross-border SaaS or data agreement where the provider side involves a BVI holding entity and a Hong Kong operating entity, and the customer is in a third jurisdiction or is itself an offshore entity.

Step 1: Map the entity chain and identify the contractual counterparty. Confirm which entity is the licensor, which is the service entity, and which is the contracting counterparty vis-à-vis the customer. Document the intercompany licence separately. Do not allow the BVI holdco to contract directly with external customers unless the substance and licensing analysis supports that position.

Step 2: Run the licensing assessment. The gate at this step is regulatory characterisation. Does the product fall within the VATP perimeter, the SFO perimeter, or neither? This assessment is conducted by reference to the function of the product, the nature of the data or service delivered, and the customer profile. If the answer is unclear, the assessment should be resolved before proceeding. An "unclear" answer that is left unresolved is a compliance gap.

Step 3: Conduct counterparty due diligence. Obtain and verify the beneficial-ownership structure of the customer entity. For a BVI customer, this means the register of members, the ultimate-beneficial-owner declaration, and, where the ownership chain involves further offshore layers, the supporting documentation for each layer. The FATF travel rule (the Financial Action Task Force rule requiring originator and beneficiary information to accompany virtual-asset transfers) applies to VATP-to-VATP transactions; if the agreement involves a VATP on either side, the travel-rule obligations attach at this step.

Step 4: Draft the governing-law and dispute-resolution clause. For a BVI–Hong Kong structure, Hong Kong governing law is defensible, enforceable, and familiar to both common-law systems. Hong Kong arbitration under the HKIAC Administered Arbitration Rules (in their 2024 version, effective 1 June 2024) gives both parties access to a well-tested institutional process. The default seat absent party agreement is Hong Kong, which is generally the preferred position for a group with a Hong Kong operating entity. BVI governing law is available but adds a layer of unfamiliarity for non-BVI counsel and does not improve enforceability.

Step 5: Address data-handling and privacy obligations by reference to the relevant regimes. The BVI has no comprehensive data-protection statute equivalent to the EU General Data Protection Regulation or the Mainland's Personal Information Protection Law. If the data processed under the agreement includes personal data of individuals in the EU, the UK, the Mainland, or any other jurisdiction with an extraterritorial data-protection regime, the obligations of that regime attach regardless of where the contracting entity is incorporated. The agreement must identify which regimes apply, which entity acts as controller and which as processor, and what the transfer mechanism is for cross-border data flows.

Step 6: Document the intercompany IP licence. If the BVI entity is the IP holder and the Hong Kong entity is the service provider, the intercompany licence must exist in executed, written form before the external agreement is signed. Transfer-pricing principles require that the licence terms reflect arm's-length conditions. In our cross-border practice, we regularly see external SaaS agreements executed before the intercompany licence is in place – which means the service entity is delivering a product it does not have the rights to deliver.

Step 7: Verify BVI substance requirements. Before the structure is finalised, confirm that the BVI entity's intellectual-property or holding activity meets the BVI economic-substance test. This is not a one-time check; it is an ongoing annual obligation. The substance position should be confirmed by BVI-specialist counsel.

Step 8: Execute and maintain the compliance file. The executed agreement, the counterparty due-diligence file, the licensing-assessment memorandum, the intercompany licence, and the substance-verification record should be held as a consolidated compliance file. This file is the first thing a regulator or counterparty in a dispute will request.

If an earlier agreement or structure produced a compliance gap – an unlicensed function, an undocumented intercompany licence, or a counterparty whose beneficial ownership was never verified – a remediation exercise can identify the exposure and the steps still available.

To discuss how the licensing and AML regime applies to your cross-border structure, contact info@lockhartyip.com.

What is the most common mistake in cross-border SaaS structures touching the BVI?

The single most common mistake is treating the BVI entity as the active service-delivery entity rather than the passive holding entity it is designed to be.

The BVI is an effective IP-holding and structural vehicle for a technology group. It is not an effective front-of-house entity for customer-facing SaaS delivery into regulated markets. When a group allows the BVI holdco to contract directly with customers in Hong Kong or other regulated markets, several problems compound simultaneously: the BVI entity may not satisfy the economic-substance test for the activity level implied by active customer contracting; the BVI entity has no regulatory licence in the customer's market; the customer's own AML requirements may not be met by a BVI counterparty that cannot produce audited financials or a licensed entity certificate; and in a dispute, the BVI entity's judgment-enforcement footprint is thinner than a Hong Kong entity's, particularly for counterparties with Mainland assets.

A manufacturing group from an Asian jurisdiction – with a BVI holdco and a Hong Kong technology subsidiary that had built a data-analytics product used by financial institutions – came to our desk in late 2026. The BVI holdco had been named as the contracting party in the external agreements because the IP was held there. When two institutional customers simultaneously raised AML-compliance objections to the BVI counterparty, the group had no licensed Hong Kong entity in the contractual chain. The remediation required novating the customer agreements to the Hong Kong opco, executing the intercompany licence retrospectively (with transfer-pricing documentation), and conducting a licensing assessment for the data-analytics product. The process took one quarter. Had the structure been set correctly at the outset, it would have taken one week.

The correct structure is straightforward: the BVI entity holds the IP and licences it to the Hong Kong opco on arm's-length terms; the Hong Kong opco contracts with customers, holds the compliance file, and carries the regulatory posture. The BVI entity's role is upstream and passive. That separation is the design principle.

How does the Hong Kong–BVI interface affect enforcement?

A SaaS or data agreement is a commercial contract. If a counterparty defaults – fails to pay, misuses data, or breaches a confidentiality undertaking – the enforcement route depends on where the assets are and how the dispute-resolution clause is drafted.

For a Hong Kong governing-law agreement with an HKIAC arbitration clause, an award can be enforced in Hong Kong against assets held by the BVI entity through the normal registration and execution mechanisms of the Court of First Instance. If the BVI counterparty has assets in the BVI, enforcement there requires recognition proceedings in the Eastern Caribbean Supreme Court. If assets are in the Mainland, the arbitral-award mutual-enforcement arrangements between the Mainland and Hong Kong, in effect since 1999 and supplemented in 2020, provide a route to recognition in the people's courts.

One practical note: the reciprocal-enforcement regime for Mainland judgments under the Mainland Judgments in Civil and Commercial Matters (Reciprocal Enforcement) Ordinance (Cap. 645), which came into force on 29 January 2024, applies to judgments of the Mainland courts, not to BVI entities per se. A BVI entity with Mainland assets that has submitted to Hong Kong jurisdiction will be subject to the normal Hong Kong enforcement route, not the Cap. 645 regime (which is for Mainland court judgments). The distinction matters: if the preferred outcome is enforcement against assets in the Mainland, the dispute-resolution clause must be designed with that enforcement route in mind from the start.

For a data-specific breach – unauthorised data access, failure to delete on termination, or a transfer in breach of the data-handling provisions – the enforcement route is the same, but the damages calculation and the interim-measures application are more urgent. The HKIAC emergency-arbitrator procedure, ordinarily completed within 14 days of file transmission, provides a route to interim relief before a full tribunal is constituted.

Decision checklist for the in-house team

Before a cross-border SaaS or data agreement touching the BVI is executed, the in-house team should be able to answer each of the following questions affirmatively or have a documented explanation for any negative answer.

  • Has the contracting entity been identified, and is it the Hong Kong operating entity (not the BVI holdco) for customer-facing agreements?
  • Has a licensing assessment been completed for the product, and is the conclusion that no VATP, SFO, or other licensed-activity perimeter is engaged – or, if it is engaged, is the entity appropriately licensed?
  • Has counterparty due diligence been completed, including beneficial-ownership verification for any BVI counterparty?
  • Does the governing-law clause specify Hong Kong law, and does the dispute-resolution clause specify HKIAC arbitration with Hong Kong as the seat?
  • Does the agreement identify the applicable data-protection regimes by jurisdiction and allocate controller and processor roles?
  • Is the intercompany IP licence between the BVI holdco and the Hong Kong opco in executed, written form with arm's-length pricing?
  • Has the BVI entity's economic-substance position been confirmed by BVI-specialist counsel for the current year?
  • Is a consolidated compliance file in place, covering the executed agreement, the due-diligence record, the licensing assessment, and the substance confirmation?

This checklist is not exhaustive. It covers the standard gates. Complex structures – multiple BVI entities, tiered intercompany arrangements, virtual-asset components, or customers in data-heavy regulated sectors – require a more detailed assessment.

For a structured assessment of your SaaS or data agreement and the BVI–Hong Kong interface, write to us at info@lockhartyip.com.

Related practices

Frequently asked questions

What documents are needed for a cross-border SaaS or data agreement touching the BVI?
The core document set covers the external SaaS or data agreement (governed by Hong Kong law, with HKIAC arbitration), the intercompany IP licence between the BVI holdco and the Hong Kong operating entity, a counterparty due-diligence file including beneficial-ownership verification for any BVI party, a licensing-assessment memorandum, and the BVI entity's economic-substance confirmation for the current year. Where personal data is involved, a data-processing addendum identifying the applicable data-protection regimes and allocating controller and processor roles is also required. Each document is a gate, not an optional add-on.
What are the main risks in a cross-border SaaS or data agreement touching the BVI?
The principal risks fall into four categories. First, regulatory risk: a product that touches the VATP or SFO licensing perimeter without a licensed Hong Kong entity in the contractual chain creates direct regulatory exposure. Second, structural risk: a BVI entity used as the customer-facing contracting party rather than the IP holder may fail the economic-substance test and face a reportable deficiency. Third, enforcement risk: an agreement without a well-drafted dispute-resolution clause may leave an award creditor with no effective route to assets. Fourth, data-compliance risk: the BVI's absence of a domestic data-protection statute does not insulate the structure from the data-protection obligations of the jurisdictions where data subjects are located.
What does the route look like for a cross-border SaaS or data agreement touching the BVI?
The route runs in eight steps: map the entity chain and identify the correct contracting entity; run the licensing assessment before drafting; conduct counterparty due diligence including beneficial-ownership verification; draft the governing-law and dispute-resolution clause (Hong Kong law; HKIAC arbitration); address data-handling obligations by reference to the applicable data-protection regimes; document the intercompany IP licence; verify the BVI entity's substance position; and assemble the consolidated compliance file. Each step has a gate. The sequence is fixed – steps cannot be reordered without creating a gap that the next step cannot close.

Speak with Lockhart & Yip

For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.

This site uses only strictly necessary cookies. Non-essential cookies are declined by default. Cookie policy