HONG KONG · EAST ↔ WEST
info@lockhartyip.comResponse within 4 hours (UTC+8)
Discuss your matter
Home/Insights/Disputes & Arbitration
Tech & Web3

Matter note: a cross-border SaaS or data agreement touching Mainland China

A cross-border SaaS or data agreement touching Mainland China. An anonymised matter and the route foreign counsel took. Write to info@lockhartyip.com.

A SaaS or data agreement that spans the Mainland China–Hong Kong boundary is not a standard commercial contract with an exotic governing-law clause. It sits at the intersection of the Mainland's data-export control regime, Hong Kong's own data-privacy rules, and whatever licensing obligations attach to the underlying technology – obligations that are determined by what the platform does, not simply where it is incorporated. The governing instruments are plural, and the sequence of compliance steps is not interchangeable.

This matter note describes an anonymised engagement involving a cross-border SaaS arrangement with a Mainland-side data flow and a Hong Kong-incorporated operator entity. The note is written for general counsel and compliance officers who are working through a comparable position. It describes the constraint the client faced, the route chosen, the turning point in the process, and the transferable lesson.

What was the situation?

The operator was a technology business incorporated in Hong Kong, providing a subscription-based software service to enterprise customers in Mainland China. The platform processed data on behalf of those customers – user-behaviour data, transaction records, and a category of data that, on analysis, touched personal information of Mainland residents.

The arrangement had run for a period without formal legal structuring. The commercial terms were documented in a master services agreement governed by Hong Kong law, with a dispute-resolution clause pointing to Hong Kong arbitration. That choice is common and, in principle, defensible. The difficulty was that the agreement was silent on the Mainland data-protection instruments and said nothing about the data-export control mechanism that applied to the flow of personal information from a Mainland-based processor to a Hong Kong-based operator.

When the client's Mainland customers began raising due-diligence questions from their own compliance teams, the commercial arrangement stalled. Enterprise procurement decisions were being delayed. Two customers had placed the renewal on hold pending receipt of a compliant data-processing agreement. The window for renewal was closing.

The client came to us in autumn 2025. The immediate question was whether the existing agreement could be adapted, or whether the structure itself needed to change.

What was the cross-border legal constraint?

The Mainland's data-protection regime imposes substantive obligations on the handling of personal information of Mainland residents, regardless of where the processing entity is located. The governing instrument is the Personal Information Protection Law, which applies extraterritorially where personal information of Mainland residents is handled outside the Mainland for the purpose of providing products or services to individuals in the Mainland.

The data-export control mechanism adds a further layer. Where personal information is transferred out of the Mainland – including a transfer to a Hong Kong operator – the Mainland-side entity must comply with one of three routes before the transfer may lawfully proceed: a security assessment by the Cyberspace Administration of China (the PRC's primary data-regulation authority, commonly referred to as the CAC), a personal-information protection certification, or a standard contract filing. The applicable route depends on the volume and category of data transferred and the nature of the Mainland-side party.

On the Hong Kong side, the Personal Data (Privacy) Ordinance governs the operator's handling of personal data held in Hong Kong. The two regimes do not mirror each other. A compliant position under one does not automatically produce a compliant position under the other. The contractual architecture had to address both simultaneously.

There was a further complication. The platform's functionality included a payment-adjacent feature that, depending on how it was characterised, could attract licensing scrutiny. In Hong Kong, the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (the AML/CTF Ordinance) governs certain financial-service activities alongside sector-specific licensing instruments. The AML/CTF Ordinance also underpins the virtual-asset trading platform licensing regime administered by the Securities and Futures Commission – relevant context for our wider tech and Web3 practice, though in this matter the payment feature fell outside the virtual-asset perimeter. The relevant question was whether the payment feature triggered any licensing obligation under the regime administered by the Hong Kong Monetary Authority (HKMA). After analysis, it did not; but the determination required a structured assessment rather than an assumption.

The sequence was therefore: determine the applicable Mainland data-export route; map the Hong Kong data-handling obligations; confirm the licensing position; then rebuild the contractual framework to reflect the compliant structure.

For general counsel managing a comparable position, the interaction between data-export control and licensing is the point that foreign advisers most commonly underestimate. The two analyses do not run in parallel; the licensing position can affect which data-export route is available.

How was the route chosen?

The first step was a structured read of the data flows. We mapped, with the client's technical team, exactly what categories of personal information moved across the boundary, in what direction, at what volume, and under what processing instruction. That mapping exercise was the predicate for everything that followed. Without it, neither the applicable Mainland data-export route nor the appropriate Hong Kong-side contractual provision could be determined with any precision.

The data-flow mapping produced a cleaner picture than the client had expected. The payment-adjacent feature processed only anonymised aggregated data; personal information of identifiable Mainland residents flowed through a separate pipeline tied to the user-account function. The volume and category of that personal information, as mapped, pointed to the standard-contract-filing route under the Mainland regime rather than the full CAC security assessment – a materially lighter burden.

On that basis, the route chosen was a two-document restructure. The first document was a data-processing agreement between the Mainland-side customers and the Hong Kong operator, drafted to satisfy the substantive requirements of the Mainland standard-contract template and simultaneously address the Personal Data (Privacy) Ordinance requirements. The second document was a revised master services agreement that incorporated the data-processing agreement by reference and removed the ambiguities in the earlier version's data-handling provisions.

We advised that the Mainland-side entities were responsible for the filing step with the relevant Mainland authority. Our role was to ensure the contractual architecture was compliant on its face so that the filing could proceed. Co-ordination with the Mainland-side legal advisers of the client's customers was handled through the client, with our desk providing the technical input on the Hong Kong-law side and the cross-border structuring logic.

The licensing assessment ran concurrently. We prepared a written analysis of the payment feature against the applicable Hong Kong licensing instruments. The conclusion – that no additional licensing step was required – was documented in a form that the client could provide to its procurement counterparts as part of the due-diligence response.

What was the turning point?

The turning point in this matter was the data-flow mapping exercise itself. The client had assumed, on reasonable commercial grounds, that the volume of personal information crossing the boundary was large enough to require the full CAC security assessment. That assumption, had it been acted on without verification, would have extended the compliance timeline by several months and almost certainly caused the two stalled renewals to lapse.

The mapping showed that a significant portion of what the client had characterised as personal information was, on the applicable Mainland definition, below the threshold for the full-assessment route. The standard-contract-filing route was available. That change in the analysis compresses the compliance timeline substantially.

The second turning point was narrower but commercially decisive. One of the two customers whose renewal was on hold had a group-level data-governance requirement that the data-processing agreement had to be executed by a Mainland-registered entity, not a Hong Kong-incorporated operator, as the counterparty. The client's corporate structure included a Mainland-registered wholly-foreign-owned enterprise – a WFOE (a company incorporated in the Mainland under foreign investment by a wholly foreign parent) – that had not previously been part of the service-agreement structure. Routing the data-processing agreement through the WFOE resolved the customer's internal governance requirement and was consistent with the chosen standard-contract-filing route.

That structural adjustment – inserting the WFOE as the Mainland-side contracting party – had implications for the holding structure and for the intercompany service arrangement between the WFOE and the Hong Kong operator. Those implications were scoped but were addressed separately, with the holding-structure analysis handled by colleagues on our corporate desk. The cross-practice coordination is a recurring feature of matters of this kind; data agreements rarely sit in isolation from the corporate and tax position.

What was the outcome and the transferable lesson?

Both stalled renewals were executed within the quarter. The data-processing agreement and revised master services agreement were adopted as the client's standard contractual suite for all Mainland-facing customers. The licensing analysis was incorporated into the client's standard due-diligence pack.

The qualitative outcome was not simply the resolution of the immediate commercial stall. The client emerged from the engagement with a repeatable compliance architecture – a documented data-flow map, a standard-contract suite, a licensing position paper, and a clear allocation of responsibility between the Hong Kong operator and the Mainland-side WFOE for the filing and renewal obligations.

What is transferable from this matter to other cross-border SaaS and data arrangements?

First, the governing instruments on the Mainland side apply to the data flow, not the incorporating jurisdiction of the operator. A Hong Kong-incorporated entity that processes personal information of Mainland residents in the course of providing a service into the Mainland is within scope. This is the point most frequently misunderstood by foreign principals structuring their Asia presence from outside the region.

Second, the data-export route is determined by the volume and category of data, not by the size of the commercial arrangement. The mapping exercise is not bureaucratic; it is determinative. Getting it wrong in the direction of over-estimate wastes months. Getting it wrong in the direction of under-estimate creates regulatory exposure at the point of a customer audit or a regulator inquiry.

Third, the licensing position and the data-protection position interact. In our cross-border practice, we regularly see arrangements where the data-protection analysis has been done carefully and the licensing analysis has been left to an assumption. The assumption is frequently wrong, or at least untested. A documented licensing determination – even a short one – is worth considerably more to a client's enterprise customers than an assurance that "we checked and there is no issue".

Fourth, the corporate structure is relevant to the contractual architecture. A WFOE, a Hong Kong holding entity, and an offshore parent sit in a chain that determines who can be a contracting party to the data-processing agreement, who must file with the relevant Mainland authority, and who bears the regulatory exposure if the arrangement is not compliant. The data agreement and the corporate structure need to be read together.

For international groups building or renewing a Mainland-facing SaaS or data service from a Hong Kong base, the window between a customer raising a compliance question and a renewal lapsing is typically shorter than the compliance process takes if started from scratch. The structural questions are best addressed before the commercial pressure arrives.

The sequence above describes the standard position. Your matter turns on the data flows, the jurisdictions actually engaged, and the corporate structure – which is where the route is won or lost. To discuss how the data-export control and licensing analysis applies to your cross-border SaaS or data arrangement, contact info@lockhartyip.com.

If an earlier structuring attempt or a prior compliance determination produced an adverse result or a stalled renewal, a second read can identify the analytical gap and the routes still available. For a structured assessment of your cross-border data and licensing position, write to us at info@lockhartyip.com.

Related practices

Frequently asked questions

What is the first step in a cross-border SaaS or data agreement touching Mainland China?
The first step is a structured data-flow mapping exercise that identifies the categories and volumes of personal information moving across the Mainland–Hong Kong boundary. That mapping exercise determines which of the available Mainland data-export routes applies – the CAC security assessment, the personal-information protection certification, or the standard-contract-filing route – and is the predicate for any compliant contractual architecture. Without it, the governing instruments cannot be applied accurately.
What does the route look like for a cross-border SaaS or data agreement touching Mainland China?
The route involves four parallel workstreams: mapping the Mainland data-export obligations under the Personal Information Protection Law; addressing the Personal Data (Privacy) Ordinance requirements on the Hong Kong side; confirming the licensing position under the relevant Hong Kong instruments; and restructuring the contractual suite – typically a data-processing agreement and a master services agreement – to reflect the compliant position. The Mainland-side entity is generally responsible for the filing step. The Hong Kong operator is responsible for ensuring the contractual architecture is compliant on its face before the filing proceeds.
Do I need a Hong Kong adviser for a cross-border SaaS or data agreement touching Mainland China?
A Hong Kong international counsel is the appropriate starting point where the operator entity is Hong Kong-incorporated, the service is delivered from Hong Kong, or the governing-law clause points to Hong Kong. The Hong Kong-side licensing position and the Personal Data (Privacy) Ordinance analysis require a Hong Kong perspective, and the cross-border structuring logic – particularly where a WFOE sits in the chain – requires an adviser who works across both sides of the boundary. We regularly advise on arrangements of this kind from our Hong Kong desk, working alongside locally licensed advisers where Mainland-law steps are required.

Speak with Lockhart & Yip

For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.

This site uses only strictly necessary cookies. Non-essential cookies are declined by default. Cookie policy