HONG KONG · EAST ↔ WEST
info@lockhartyip.comResponse within 4 hours (UTC+8)
Discuss your matter
Home/Insights/Disputes & Arbitration
Tech & Web3

Matter note: a cross-border SaaS or data agreement touching the CIS

A cross-border SaaS or data agreement touching the CIS. An anonymised matter and the route taken. The Hong Kong angle in focus. Write to info@lockhartyip.com.

A SaaS agreement that runs across the boundary between Hong Kong and the CIS (the Commonwealth of Independent States – the grouping of post-Soviet states that includes Russia, Kazakhstan, Ukraine, Uzbekistan, and a cluster of neighbouring jurisdictions) is rarely as simple as it appears at execution. The commercial terms are often settled. What remains unsettled is the regulatory position: which licensing requirements apply to the platform, which data-transfer rules govern the pipeline, and which AML obligations attach to the counterparty relationship. When the answers sit across two or more legal systems with markedly different postures, those questions cannot be deferred to implementation.

A cross-border SaaS or data agreement touching the CIS raises regulatory exposure at three distinct points: the licensing posture of the platform provider, the data-residency and cross-border transfer obligations of the CIS-side counterparty, and the AML and counterparty-screening obligations that Hong Kong law attaches to the relationship. The governing instrument on the Hong Kong side – the Anti-Money Laundering and Counter-Terrorist Financing Ordinance – imposes customer due diligence obligations on designated non-financial businesses and professions and on virtual-asset service providers, and those obligations run regardless of where the CIS counterparty is incorporated or where its end users sit. Parties should verify the current position before acting, because the perimeter of regulated activity in Hong Kong's technology and virtual-asset sector has widened materially since mid-2023.

This matter note sets out an anonymised account of a cross-border SaaS and data-sharing arrangement involving a Hong Kong-registered platform provider and a CIS-based operator. It covers the situation, the regulatory constraint that emerged, the route chosen, and the lesson that transfers to similar arrangements.

What was the situation, and where did the constraint sit?

A technology group incorporated in Hong Kong had built a platform-as-a-service product delivering financial analytics and reporting tools to institutional clients. Its primary CIS counterparty – a licensed financial operator in Kazakhstan – sought to white-label the platform for distribution across several CIS jurisdictions. The commercial structure was standard: a master SaaS agreement, a data-processing schedule, and a sub-licensing arrangement for the CIS operator's local clients.

The constraint emerged not from the commercial terms but from the product's functionality. Certain modules of the platform processed transaction data, generated risk-scoring outputs, and connected to payment-infrastructure APIs. In Hong Kong, that combination sits at the intersection of two regulatory questions. First: does the platform, taken as a whole, amount to operating a virtual-asset service or a regulated financial-technology function under the Securities and Futures Ordinance or the Anti-Money Laundering and Counter-Terrorist Financing Ordinance? Second: does the data pipeline – particularly the transfer of transaction records and risk-scoring outputs from the CIS operator's client base into the Hong Kong platform's processing infrastructure – engage the data-transfer and privacy obligations that CIS jurisdictions have been tightening since the early 2020s?

Neither question had been addressed in the draft agreement. The parties had negotiated the SaaS terms as if the product were a neutral software tool. It was not neutral. The moment it began processing financial transaction data for CIS-side institutional clients, the licensing and AML picture on the Hong Kong side changed materially.

What was the legal issue and why did it matter for both sides?

The core legal issue was a mismatch between the agreement's characterisation of the service and its actual regulatory profile. The platform provider had structured the arrangement as a pure technology licence – software delivered as a service, with data processing as an ancillary function. The CIS operator had accepted that characterisation without independent analysis.

On the Hong Kong side, the Anti-Money Laundering and Counter-Terrorist Financing Ordinance imposes customer due diligence obligations on a defined category of covered persons. The platform provider, depending on the scope of its transaction-data processing and any involvement in value transfer or risk-scoring for AML purposes, risked falling within the definition of a designated non-financial business and profession (a category of business subject to AML rules that falls outside the traditional financial-sector licensing regime) or, if its product touched virtual-asset activity, within the mandatory licensing regime for virtual-asset trading platforms that commenced on 1 June 2023 under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, with the Securities and Futures Commission as licensing authority.

The significance for the platform provider was direct: operating a product that engaged those obligations without an adequate compliance programme, and without proper customer due diligence on the CIS counterparty, created regulatory exposure in Hong Kong. That exposure was independent of whether any CIS-side regulator took an interest.

On the CIS side, the legal issue was different but equally material. Several CIS jurisdictions – Kazakhstan in particular – had enacted data-localisation requirements mandating that personal data of their residents be processed or stored on servers located within their territory before any cross-border transfer. The draft agreement assumed unconstrained data flow from the CIS operator's client base to the Hong Kong infrastructure. That assumption was incorrect.

For a reader assessing a similar arrangement: the combination of a Hong Kong platform provider, a CIS-licensed operator, and a product that processes financial transaction data is precisely the combination that generates concurrent obligations in both systems. Ignoring either side does not make the other side's obligations disappear.

How was the route chosen, and what was the turning point?

When our desk was engaged, the agreement was at an advanced draft stage. The commercial terms were agreed; only final legal review remained. The platform provider's in-house team had focused almost entirely on the commercial and IP provisions. The AML and regulatory sections were boilerplate.

Our initial review identified three structural problems. The first was the absence of a licensing analysis for the Hong Kong platform. The second was the absence of a data-transfer and residency analysis for the CIS counterparty's jurisdictions. The third was a counterparty-screening gap: the draft agreement contained no mechanism for the platform provider to conduct ongoing customer due diligence on the CIS operator or to monitor the operator's downstream distribution of the white-label product to sub-licensees.

What followed was not a negotiation with the counterparty – it was a restructuring of the platform provider's own compliance architecture before the agreement was signed. That sequencing was the turning point. A party that restructures its compliance position before execution retains control of the process. A party that signs first and restructures later is working against the agreement's existing terms.

The route chosen involved three concurrent workstreams. The first was a product-function analysis: mapping the platform's modules against the regulatory definitions in the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and the Securities and Futures Ordinance to determine which, if any, engaged licensing or AML obligations. The second was a data-flow mapping exercise: tracing the categories of personal and transaction data that would move from the CIS operator's environment into the Hong Kong infrastructure, and against which CIS-side data-localisation rules those flows needed to be assessed. The third was a contractual redesign: rebuilding the data-processing schedule and the AML compliance schedule so that the agreement itself documented the counterparty due diligence position and gave the platform provider ongoing monitoring rights and suspension triggers.

The product-function analysis produced a material result. One module – a real-time transaction-screening and flagging tool that fed outputs to the CIS operator's compliance team – was found to sit close to the perimeter of virtual-asset-adjacent activity as defined in the Anti-Money Laundering and Counter-Terrorist Financing Ordinance. It did not, on the facts, cross that perimeter. But the analysis produced a documented position that the platform provider could rely on if the point were ever tested by the Securities and Futures Commission or a counterparty audit.

The data-flow mapping produced an equally practical result. Kazakhstan's data-localisation requirements meant that a subset of the personal data the platform had planned to process in Hong Kong needed either to remain in Kazakhstan or to be processed under a contractual mechanism that the Kazakhstani regulator's published guidance accepted. The parties restructured the data-processing schedule to ring-fence that data subset and process it on the CIS operator's own infrastructure, with only anonymised outputs transferred to Hong Kong. That change removed the localisation risk entirely and required no concession from either commercial party.

The counterparty-screening gap was addressed by inserting a customer due diligence schedule modelled on the obligations in the Anti-Money Laundering and Counter-Terrorist Financing Ordinance. The schedule required the CIS operator to provide entity-level documentation, beneficial-ownership confirmation, and – critically – a list of the sub-licensees to whom the white-label product would be distributed. The platform provider retained a right to conduct screening on sub-licensees above a defined size threshold and to suspend access if a sub-licensee appeared on a United Nations sanctions list.

The agreement executed two months after our engagement. The three workstreams ran concurrently and added no delay to the commercial timeline that the parties could not absorb.

The sequence above describes the standard position. Your matter turns on the documents, the jurisdictions actually engaged, and the order of steps – which is where the route is won or lost.

To discuss how the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and cross-border data obligations apply to your SaaS or platform arrangement, contact info@lockhartyip.com.

What was the outcome, and what does it transfer to similar matters?

The qualitative outcome was straightforward: the agreement executed on commercially agreed terms, with a compliance architecture that the platform provider could defend to the Securities and Futures Commission and that the CIS operator could defend to its own domestic regulator. Neither party had made a material commercial concession. The restructuring had been absorbed entirely within the legal and technical workstreams.

The more transferable lesson concerns sequencing. The legal and regulatory analysis of a cross-border SaaS or data arrangement should not wait for the commercial terms to be finalised. It should run in parallel with the commercial negotiation, or ahead of it. The reason is structural. Once the commercial terms are agreed, renegotiating the data-processing architecture or the AML schedule becomes a second negotiation – one that the counterparty is not obliged to accept and may use as leverage. Running the analysis first eliminates that dynamic.

The second transferable lesson concerns the characterisation trap. Platform providers with financial-analytics or transaction-processing products frequently characterise their offering as neutral software. That characterisation may be accurate from a product-development perspective. It is rarely accurate from a regulatory perspective. The moment a SaaS product processes financial transaction data, generates risk-scoring outputs, or interfaces with payment or virtual-asset infrastructure, it enters a regulated perimeter that varies by jurisdiction. In Hong Kong, that perimeter has been actively enlarged by the mandatory virtual-asset trading platform licensing regime in force since 1 June 2023. Platform providers should assess their product's regulatory profile in Hong Kong before entering any cross-border arrangement that involves a counterparty in a jurisdiction with its own concurrent regulatory requirements.

The third lesson concerns the data-flow assumption. CIS jurisdictions have enacted data-localisation requirements with real operational bite. The assumption that data will flow freely from a CIS operator's environment to a Hong Kong processing infrastructure is not safe to make without a jurisdiction-specific analysis. The fix, as in this matter, is often operational rather than commercial: ring-fencing the affected data categories and restructuring the processing architecture so that localisation requirements are met without affecting the commercial purpose of the arrangement.

If an earlier filing, structure or enforcement attempt produced an adverse or stalled result, a second read can identify the strategic error and the routes still open.

To map the compliance and contractual position for a cross-border SaaS or data agreement touching the CIS, email info@lockhartyip.com.

The cross-border interface in focus: Hong Kong and the CIS

Hong Kong and the CIS jurisdictions engage each other across a growing number of technology and data arrangements. The two systems do not share a mutual legal-assistance instrument in the commercial technology space, and there is no bilateral data-transfer adequacy determination comparable to those that exist between certain European and Asian jurisdictions. That absence is a structural feature, not an oversight. It means that cross-border data arrangements between Hong Kong and CIS counterparties must be managed contractually, not assumed away.

From the Hong Kong side, the relevant regulatory bodies are the Securities and Futures Commission – as licensing authority for virtual-asset trading platforms and for any financial-services activity engaging the Securities and Futures Ordinance – and the Hong Kong Monetary Authority, which has developed a separate licensing regime for fiat-referenced stablecoin issuers (entities that issue digital tokens designed to maintain a stable value by reference to a fiat currency), a regime that commenced in 2025 and whose perimeter parties should verify before relying on it.

From the CIS side, the regulatory picture is heterogeneous. Kazakhstan has moved more aggressively than most CIS states in both data-localisation enforcement and financial-technology licensing. Russia maintains extensive data-localisation requirements and a separate fintech licensing regime. Ukraine has its own developing digital-services regulatory framework, distinct from the Russian model. Uzbekistan and the smaller CIS states are at earlier stages of regulatory development but are moving. For a Hong Kong platform provider, the practical implication is that the CIS counterparty's licensing and data-compliance position cannot be assumed to mirror any single CIS regime – it must be assessed on a jurisdiction-by-jurisdiction basis, and the agreement must reflect that assessment.

Our cross-border practice sees this combination – a Hong Kong technology or platform provider, a CIS-based operator or distributor, and a product that touches financial data or virtual-asset-adjacent functionality – with increasing frequency. The regulatory exposure sits at the intersection of Hong Kong's expanding technology-licensing regime and the CIS jurisdictions' data-localisation and financial-services rules. Neither side can be managed without understanding the other.

For further background on Hong Kong's technology and virtual-asset regulatory environment, see our Tech & Web3 practice page. For the data-transfer and privacy implications for Asia-facing platforms, see our briefing on data transfer and privacy terms for Asia-facing platforms. On the stablecoin and digital-asset custody dimension, see our briefing on stablecoin and digital-asset custody arrangements.

Related practices

  • Tech & Web3 – licensing, AML compliance and cross-border structuring for technology platforms
  • Sanctions & AML – counterparty screening, compliance files and sanctions-neutral contracting

Frequently asked questions

How does the cross-border element affect a cross-border SaaS or data agreement touching the CIS?
The cross-border element creates concurrent regulatory obligations in both systems simultaneously. A Hong Kong platform provider must assess its product's licensing profile under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and, where virtual-asset activity is engaged, under the mandatory virtual-asset trading platform regime in force since 1 June 2023. The CIS counterparty brings its own data-localisation and financial-services licensing requirements, which vary by jurisdiction and which the Hong Kong-side agreement must accommodate. Neither side's obligations are waived by the other side's compliance position.
Do I need a Hong Kong adviser for a cross-border SaaS or data agreement touching the CIS?
A Hong Kong-registered platform provider operating a product that processes financial transaction data or touches virtual-asset-adjacent functionality needs a Hong Kong regulatory analysis as a precondition to executing any cross-border arrangement. The Securities and Futures Commission's licensing perimeter and the Anti-Money Laundering and Counter-Terrorist Financing Ordinance's AML obligations apply to activities conducted from Hong Kong regardless of where the counterparty sits. International counsel advising only on the CIS side cannot substitute for that analysis. The two workstreams should run in parallel.
What are the main risks in a cross-border SaaS or data agreement touching the CIS?
Three risks arise most frequently. The first is the characterisation risk: treating a financial-analytics or transaction-processing product as a neutral software tool when it in fact engages Hong Kong's regulatory perimeter for virtual-asset or financial services. The second is the data-localisation risk: assuming unconstrained cross-border data flow from a CIS operator's environment when CIS-side localisation requirements restrict or condition that flow. The third is the counterparty-screening gap: executing an agreement without a documented customer due diligence and sanctions-screening mechanism, leaving the Hong Kong platform provider exposed to AML and United Nations sanctions obligations. All three are addressable at the drafting stage.

Speak with Lockhart & Yip

For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.

This site uses only strictly necessary cookies. Non-essential cookies are declined by default. Cookie policy