Matter note: a cross-border SaaS or data agreement touching the BVI
A cross-border SaaS or data agreement touching the BVI. An anonymised matter and the route taken. The Hong Kong angle in focus. Write to info@lockhartyip.com.
A SaaS or data agreement that straddles Hong Kong, the British Virgin Islands, and a counterparty jurisdiction outside both creates a structural question that no single legal system answers alone: which law governs, which regulator has authority, and how the agreement holds up if the relationship breaks down. The governing instruments are not the same in each place, and the answer to each question changes depending on where the contracting entity sits, where the data flows, and whether the technology qualifies as a regulated service under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance or the Securities and Futures Ordinance.
This matter note describes an anonymised engagement in which those three questions arose together. The names of the parties, the specific technology, and the commercial terms are withheld. What follows is the sequence, the turning point, and the lesson that travels.
The situation and the initial constraint
A technology business incorporated in the BVI had built a data-processing and analytics platform. Its principal customer was based in a jurisdiction outside Hong Kong. The BVI entity had a Hong Kong affiliate – an operating company through which the platform was serviced and commercially deployed in Asia.
The group had entered a suite of SaaS and data-licensing agreements through the BVI entity. Those agreements were governed by the law of a common-law jurisdiction but were silent on which courts or arbitral body would have authority in the event of a dispute. The platform processed data that, depending on interpretation, touched transaction records of a type the Hong Kong affiliate's business generated.
That last point was the constraint. The Hong Kong affiliate was not licensed under any financial-services regime. The question no one had formally asked was whether the platform's data output, when fed back into the counterparty's decision-making process, brought the arrangement within the perimeter of a regulated activity in Hong Kong. If it did, the BVI contracting entity's immunity from that regulatory perimeter was not assured.
The group came to our desk because a new counterparty – a larger, more regulated institution – required a legal opinion on the contracting structure before signing. That requirement surfaced the question. It had not been visible before because both parties had treated the agreement as a purely commercial technology arrangement.
What was the real cross-border problem?
The technical problem was structural: a BVI entity contracted for technology services, but the delivery, the data, and the regulatory exposure all sat in Hong Kong. That is a common pattern in Greater China-adjacent tech businesses. It is also the pattern most likely to generate regulatory risk that falls between the advisory chairs of a pure BVI lawyer and a pure Hong Kong technology specialist.
Three questions needed to be resolved in sequence. First, did the platform's data output, as delivered to the counterparty, constitute the provision of a service that engaged Hong Kong regulatory authority? Second, if the BVI entity was the contracting party, did that displace Hong Kong jurisdiction over the activity? Third, what was the enforcement position if the agreement broke down – and did the governing-law and dispute-resolution clauses in the existing agreements actually work?
The third question was not hypothetical. The new counterparty's legal team had already identified that the dispute-resolution clause was ambiguous: it named a jurisdiction for litigation but did not specify the court, and it was inconsistent with the data-processing terms, which contained a different exclusive-jurisdiction clause for claims arising under those terms specifically. Two inconsistent clauses in one agreement is manageable; two inconsistent clauses across a suite of related agreements, where the suite is governed by the laws of different common-law systems, creates an enforcement exposure that is real and specific.
In our cross-border practice, we see this pattern regularly. A BVI holding or contracting structure is set up for tax or privacy reasons that made sense at the time. The operating business grows. Agreements are added to the suite without full cross-document consistency review. By the time a regulated counterparty applies scrutiny, the suite carries accumulated inconsistency that a counterparty's counsel – or a regulator – can exploit.
The route chosen and why the BVI entity was not sufficient on its own
The first decision was to define the regulatory perimeter before advising on the contracting structure. That meant working through the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and the Securities and Futures Ordinance as the two instruments most likely to apply to the platform's activities in Hong Kong. It also meant examining the VATP licensing regime (the mandatory licensing regime for centralised virtual-asset trading platforms, which commenced on 1 June 2023 under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance), because the platform processed data that could, on one reading, relate to virtual-asset transaction analytics.
The conclusion was not that the VATP regime applied. It did not, on the facts. But the exercise of reaching that conclusion was itself the deliverable. The new counterparty's legal team needed a structured analysis that placed each element of the platform's service against the relevant regulatory perimeter and explained why the activity fell outside it. That analysis needed to be grounded in the instruments as they stood, with a clear statement of the assumptions on which the conclusion rested.
The BVI entity's structure was not, on its own, sufficient to answer that question. A BVI company can contract freely. It can hold intellectual property and license it. But the regulatory perimeter in Hong Kong attaches to the activity and where it is performed, not to the nationality or domicile of the contracting entity. A BVI company performing a regulated activity through a Hong Kong affiliate, or directing a regulated service at Hong Kong users, is within scope. The form of the contracting entity does not change that.
This is the point that foreign technology counsel – and some BVI advisers – frequently miss. The question is not "where is the company?" The question is "where is the activity, and what does the Hong Kong regulatory regime say about that activity?"
The route chosen was to restructure the contracting framework so that the BVI entity's role was clearly defined as a licensor of technology, not a provider of a regulated service. The service delivery layer – the relationship with the Hong Kong affiliate – was documented separately, with its own agreement that made the affiliate's role explicit and that contained the correct governing-law and dispute-resolution clauses for that relationship.
For the dispute-resolution architecture, we recommended a single arbitral institution and seat for the core SaaS agreement, with Hong Kong as the seat. That gave the group access to the Mainland interim-measures mechanism under the Arrangement that has been in effect since 1 October 2019, which allows a party to a Hong Kong-seated arbitration to apply to Mainland courts for interim measures before or during the arbitration. For a group with assets and counterparties in the Mainland, that access is a structural advantage that a litigation clause in a common-law court cannot replicate.
The sequence and the turning point
The sequence ran in three phases. The first phase was a regulatory-perimeter review: mapping the platform's data outputs against the relevant Hong Kong regulatory instruments, documenting the basis for the conclusion that no licence was required, and flagging the conditions under which that conclusion could change.
The second phase was a contract-suite audit. Each agreement in the suite was reviewed for governing-law consistency, dispute-resolution consistency, and the allocation of liability for regulatory change. The audit identified two specific inconsistencies: the conflicting exclusive-jurisdiction clauses already mentioned, and a data-processing clause in one agreement that could be read to impose obligations on the BVI entity that it could not, as a matter of its own corporate constitution, discharge without creating a liability gap.
The turning point came in the second phase. The data-processing clause had been drafted by the counterparty's counsel and accepted without mark-up. It required the contracting party – the BVI entity – to comply with the data-protection laws of the counterparty's home jurisdiction. The BVI has no general data-protection statute of the kind that clause contemplated. The BVI entity could not, as a structural matter, comply. If a data incident had occurred, the counterparty would have had a breach claim that the BVI entity could not defend on the merits, because the obligation it had accepted was one it was structurally incapable of meeting.
That clause was renegotiated. The revised version placed the data-protection obligation on the Hong Kong affiliate, which was the entity actually processing the data, and which could take appropriate steps. The BVI entity's obligation was reframed as a pass-through: it would procure the affiliate's compliance. That is a standard drafting technique in multi-entity technology groups. The fact that it had not been used here reflected the original drafting assumption that the BVI entity was the whole of the contracting group, rather than one layer in a two-entity structure.
The third phase was preparation of the regulatory analysis opinion and the restated suite of agreements for signature by the new counterparty. The process ran across two rounds of counterparty comments. The new counterparty's legal team was principally concerned with the regulatory-perimeter analysis and with the dispute-resolution architecture. Both were resolved without further structural change; the renegotiation in phase two had addressed the substantive concerns.
Qualitative outcome and the lesson that travels
The agreements were signed. The regulatory-perimeter analysis was accepted by the counterparty's legal team. The matter closed with the contracting suite restated on a consistent governing-law and dispute-resolution basis, with Hong Kong arbitration as the single mechanism for the core agreement and a documented rationale for the allocation of data-protection obligations between the BVI entity and the Hong Kong affiliate.
The lesson is not unique to this matter. It repeats across the cross-border technology engagements our desk handles. A BVI contracting structure is a useful tool. It offers flexibility, relative administrative simplicity, and a well-tested legal environment for holding and licensing intellectual property. But it does not operate in isolation. Where the performance of the contract touches a regulated jurisdiction – and Hong Kong is a regulated jurisdiction with a growing perimeter around technology services that touch financial data or virtual assets – the structure must be designed with that regulatory environment built in, not treated as a separate question to be answered if the issue ever arises.
The second lesson is about dispute-resolution architecture. A suite of agreements that lacks a consistent dispute-resolution mechanism is not simply untidy. It is a risk. If a dispute arises across multiple agreements in the suite, the counterparty with a stronger position will select the forum that favours it. A well-drafted suite names one institution, one seat, and one governing law for each agreement, with a clear hierarchy for claims that arise under more than one agreement simultaneously. For a group operating across Hong Kong and the BVI with counterparties in the Mainland or Southeast Asia, the Hong Kong arbitration seat – and the interim-measures access it provides – is typically the right answer. But it has to be chosen deliberately, not inherited by default.
The third lesson is about the timing of legal review. This group's constraint was that the regulatory question surfaced only when a new counterparty applied scrutiny. Had the structure been reviewed when the BVI entity first contracted with the Hong Kong affiliate – or when the first regulated counterparty came into the picture – the remediation work would have been smaller and the risk window shorter. The cost of late review is not only the advisory fee; it is the exposure during the period in which the inconsistency sits undiscovered.
If an earlier filing, structure or enforcement attempt produced an adverse or stalled result in a cross-border technology matter, a second read can identify the strategic error and the routes still open. To discuss a cross-border SaaS or data arrangement involving Hong Kong and the BVI, write to us at info@lockhartyip.com.
For a fuller account of the licensing regime for virtual-asset trading platforms and the regulatory perimeter that matters in Hong Kong, see our VATP licence briefing. Groups structuring a digital-asset fund through Hong Kong and the BVI will also find relevant analysis in our matter note on digital-asset fund structuring. Our Tech & Web3 practice page sets out the full scope of cross-border advisory work in this area.
Related practices
- Sanctions & AML – AML obligations, counterparty diligence and compliance documentation for cross-border arrangements
- Holding Structures – BVI, Cayman and Hong Kong holding-entity design and restructuring across multiple jurisdictions
Frequently asked questions
Which jurisdiction's law applies to a cross-border SaaS or data agreement touching the BVI?
What documents are needed for a cross-border SaaS or data agreement touching the BVI?
Do I need a Hong Kong adviser for a cross-border SaaS or data agreement touching the BVI?
Speak with Lockhart & Yip
For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →
Related
- Tech Web3
- Virtual Asset Trading Platform Licence Hong Kong Briefing 2
- Digital Asset Fund Structured Through Hong Kong Bvi
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.