HONG KONG · EAST ↔ WEST
info@lockhartyip.comResponse within 4 hours (UTC+8)
Discuss your matter
Home/Insights/Disputes & Arbitration
Tech & Web3

Matter note: a cross-border SaaS or data agreement touching Singapore

A cross-border SaaS or data agreement touching Singapore. An anonymised matter and the route foreign counsel took. Write to info@lockhartyip.com.

A cross-border SaaS agreement between a Hong Kong-based technology provider and a Singapore-incorporated commercial counterparty carries a legal interface that neither party's domestic counsel will see in full from one side: the governing law, the data-transfer regime, and the licensing question each pull in a different direction, and the document that resolves one can create exposure under another.

This matter note sets out an anonymised cross-border engagement handled by our desk. The facts have been altered in every identifying respect. The route, the sequence, and the transferable lesson are real.

What was the commercial situation?

A technology group incorporated in Hong Kong – with a development team on the Mainland and a sales operation directed at Southeast Asian enterprise clients – had entered into a multi-year SaaS arrangement with a Singapore-based financial services entity. The agreement had been prepared under time pressure, largely by the Hong Kong group's local commercial counsel, using a modified template originally drafted for an intra-group transaction.

The arrangement covered data hosting, API access, and a proprietary analytics layer. The Singapore counterparty was regulated. The Hong Kong provider was not licensed in Singapore under any applicable regime. No data-processing addendum had been prepared. The governing law clause pointed to Hong Kong; the dispute resolution clause provided for litigation in Singapore courts.

That combination – a Hong Kong-law contract, Singapore-court jurisdiction, no data annex, and a regulated Singapore client – created a structural tension the template had not been written to address.

Our desk came into the matter approximately nine months into the operational relationship, when the Singapore counterparty raised a formal query about the provider's regulatory status and asked for confirmation of the data-handling position before renewing.

What was the cross-border legal problem?

The core issue was not the governing law clause. Governing law in commercial SaaS agreements is, in itself, a manageable choice. The problem was that the contract had been assembled without a cross-border read: each clause had been drafted as though the relationship sat within a single jurisdiction, and none of the clauses had been tested against the legal position that actually applied on the Singapore side.

Three distinct issues presented themselves when we reviewed the full document set.

First, the data-transfer and data-handling position. Singapore's data-protection regime – the Personal Data Protection Act (the legislation governing the collection, use, and disclosure of personal data in Singapore, administered by the Personal Data Protection Commission) – imposes obligations on organisations that collect or process personal data in or from Singapore. The counterparty, as a regulated financial institution, had its own compliance obligations with respect to outsourcing and data residency. The existing SaaS agreement contained no data-processing annex, no specification of hosting location, and no provisions addressing what happened to Singapore-held data upon termination. That gap put the Singapore counterparty in a difficult position with its own regulator and made the agreement unworkable for renewal purposes.

Second, the licensing question. The Hong Kong provider's analytics layer, as described in the product schedule, came close to constituting a service that a Singapore regulator would characterise as a technology service provided to a regulated entity. Singapore's financial-services outsourcing expectations – issued by the Monetary Authority of Singapore (the financial regulator and central bank of Singapore, referred to here as the MAS) – impose requirements on regulated institutions that outsource material functions. That meant the counterparty's internal approval process would require the provider to meet standards the existing agreement did not address. The provider's own licensing posture in Hong Kong was not the relevant question: the question was what the MAS's outsourcing framework required of the regulated entity's supplier.

Third, the dispute resolution clause. A governing-law clause pointing to Hong Kong combined with a jurisdiction clause pointing to Singapore courts is not, in itself, fatal to a commercial agreement. But it creates procedural complexity in enforcement. A Hong Kong court applying Singapore law to a disputed term, or a Singapore court giving effect to Hong Kong law in a technical SaaS dispute, requires expert evidence on foreign law. In a relationship where the commercial risks were already crystallising, that procedural complexity would have added significant cost and delay. Hong Kong currently implements a well-tested framework for the recognition of foreign judgments under the common-law rules and, for Mainland counterparties, under the Mainland Judgments in Civil and Commercial Matters (Reciprocal Enforcement) Ordinance (Cap. 645), in force since 29 January 2024. Singapore judgments do not fall within that regime. Enforcement of a Singapore-court judgment in Hong Kong would proceed under the common-law route, which carries its own requirements. That route was workable but not the most efficient outcome for a relationship the parties still intended to preserve.

How did the sequence run?

The engagement ran in three stages.

Stage one: diagnosis. Our desk reviewed the full agreement, the product schedule, and the correspondence exchanged with the Singapore counterparty. We identified the three issues above and produced a cross-border memorandum setting out the position under each applicable regime: the data-protection position under Singapore's Personal Data Protection Act, the MAS outsourcing framework, and the enforcement implications of the dispute resolution clause as drafted. We did not advise on Singapore law directly; that analysis was carried out in coordination with allied counsel admitted in Singapore. Our role was to frame the cross-border structure, identify the points of interaction, and manage the overall remediation sequence.

Stage two: remediation drafting. With the diagnosis agreed, we prepared a restructured contractual package. The core agreement was amended to clarify the governing law (Hong Kong) and to replace the Singapore-court jurisdiction clause with an HKIAC arbitration clause. The HKIAC Administered Arbitration Rules (the rules of the Hong Kong International Arbitration Centre, in force in their 2024 version effective 1 June 2024) provided an agreed procedural framework enforceable in both Hong Kong and Singapore, both of which are parties to the New York Convention on the Recognition and Enforcement of Foreign Arbitral Awards. That alignment removed the asymmetric enforcement risk created by the mixed governing-law/jurisdiction combination.

A data-processing addendum was prepared addressing the Singapore data-protection position: specifications of hosting location, data-transfer mechanisms, breach notification timelines, and data-return and deletion provisions at termination. That addendum was structured to allow the Singapore counterparty to present it to its own compliance function as meeting the outsourcing documentation standard.

The product schedule was re-scoped to clarify the boundary of the analytics layer: the drafting was adjusted to ensure that the service description did not, on its face, constitute a regulated activity under the Singapore regime, and to include the contractual representations that a MAS-regulated entity's supplier would typically be asked to make in a material-outsourcing context.

Stage three: negotiation and execution. The restructured package was presented to the Singapore counterparty's in-house and external counsel. The negotiation centred on two points: the hosting-location specification (the counterparty's data-residency preference required a more granular technical annex than our initial draft) and the liability cap in the data-processing addendum (the counterparty's regulatory exposure meant its counsel sought a higher cap than standard). Both points were resolved within the negotiation cycle. The agreement was executed on the amended terms.

The sequence from engagement to execution ran over one complete commercial review cycle. The turning point was the decision to switch the dispute resolution mechanism to arbitration under the HKIAC Rules: it resolved the enforcement asymmetry in a way both counsel teams recognised as sound, and it unblocked a negotiation that had stalled on the jurisdiction point.

For a structured read on your own cross-border technology position, write to us at info@lockhartyip.com.

What was the qualitative outcome?

The commercial relationship continued. The agreement was renewed on the amended terms. The Singapore counterparty's compliance function accepted the data-processing addendum as meeting its outsourcing documentation threshold. The provider's licensing posture in Hong Kong was not altered by the process: no Singapore licensing obligation attached to the re-scoped service description.

The enforcement position improved materially. An HKIAC award would be enforceable in Singapore under the New York Convention, and in Hong Kong under the Arbitration Ordinance (Cap. 609). That two-way enforceability – absent from the original litigation clause – meant both parties held a credible enforcement right without the need to commence proceedings in a foreign court and establish foreign law.

There was a secondary outcome worth noting. The cross-border memorandum produced at stage one was used by the Hong Kong provider's general counsel to update the group's standard SaaS template for Southeast Asian counterparties. That meant the issues identified in this relationship were addressed at template level before they arose in the next round of commercial negotiations. In our cross-border technology practice, that outcome – a template upgrade that prevents the same issue recurring – is often as commercially significant as the immediate remediation.

If an earlier agreement structure produced a stalled renewal or a regulatory query you have not yet resolved, a second read of the document set can identify the route still open. Write to us at info@lockhartyip.com.

What is the transferable lesson?

The issues in this matter were not exotic. A mismatched governing-law and jurisdiction clause, a missing data annex, and an unconsidered licensing posture are recurring features of cross-border SaaS agreements drafted under time pressure by counsel working from one side of the relationship. They appear in agreements between Hong Kong and Singapore counterparties more often than either party expects, because the two legal environments are sufficiently similar in commercial culture that the gap between them is easy to underestimate.

The practical lesson is structural: a cross-border SaaS or data agreement touching Singapore requires a read from both sides at the outset, not a remediation exercise when the counterparty raises a compliance query nine months into the operational relationship. The data-protection analysis is not a boilerplate exercise – Singapore's Personal Data Protection Act imposes substantive requirements that interact with the MAS outsourcing framework in ways that affect how the product schedule and the data annex are drafted. The dispute resolution clause is not a formality – the enforcement route it creates is part of the commercial deal.

The HKIAC arbitration framework resolved the enforcement question in this matter because both Hong Kong and Singapore are New York Convention states and both have well-tested regimes for recognising and enforcing arbitral awards. That is not an accident of geography. It is a reason to consider the HKIAC seat and rules as the default dispute resolution mechanism for cross-border technology agreements between these two jurisdictions, rather than a fallback to be adopted after negotiation has stalled.

A broader point applies. The licensing question in this matter – whether the Hong Kong provider's analytics layer constituted a service subject to MAS regulatory oversight through the outsourcing framework – was not answered by looking at the provider's Hong Kong licensing position. It was answered by looking at what the Singapore regulatory regime required of the counterparty. That shift in analytical perspective – from "what is my regulatory status?" to "what does my client's regulator require of me as a supplier?" – is a central feature of cross-border technology compliance work, and one that domestic counsel on either side of the interface will not always surface without a cross-border instruction.

Our desk operates at precisely that interface. We regularly act on technology and data agreements between Hong Kong and Singapore counterparties, coordinating the cross-border read with allied counsel in the relevant jurisdiction and managing the remediation or negotiation from a position that sees both sides of the legal environment. The Lockhart & Yip Tech & Web3 practice covers the full range of cross-border technology structuring, licensing, and data-compliance work in Greater China and Southeast Asia. For a broader view of how we structure technology businesses through Hong Kong, see our analysis at Structuring a Web3 business through Hong Kong. For digital-asset fund structures, see our briefing at Digital asset fund structured through Hong Kong and the Mainland.

Related practices

  • Tech & Web3 – cross-border technology structuring, licensing, AML, and data compliance
  • Sanctions & AML – counterparty review, source-of-funds analysis, and compliance documentation

Frequently asked questions

Which jurisdiction's law applies to a cross-border SaaS or data agreement touching Singapore?
The governing law is a matter of contractual choice, but the choice does not determine the regulatory obligations that apply to the parties. A Hong Kong-law agreement can still engage Singapore's data-protection obligations under the Personal Data Protection Act and the MAS outsourcing framework if the Singapore counterparty is regulated and the service is material. In our cross-border practice, we regularly see agreements where the governing law is cleanly chosen but the regulatory compliance layer has not been addressed in the document set. The two questions are related but distinct, and both require analysis before the agreement is executed.
How does the cross-border element affect a cross-border SaaS or data agreement touching Singapore?
The cross-border element affects the agreement in at least three ways: the data-protection obligations that attach to the data flows, the dispute resolution and enforcement route, and the licensing or outsourcing compliance position of the regulated counterparty. A purely domestic SaaS agreement can address all three within a single legal regime. A cross-border agreement touching Singapore and Hong Kong requires each of those questions to be answered by reference to the applicable regime in each jurisdiction, and the document set to be structured so that both sides of the interface are addressed. The enforcement point is particularly material: an HKIAC arbitration clause, enforceable under the New York Convention in both Hong Kong and Singapore, typically produces a more workable outcome than a mixed governing-law and court-jurisdiction combination.
What are the main risks in a cross-border SaaS or data agreement touching Singapore?
The principal risks are: a data-handling gap that puts the Singapore regulated counterparty in breach of its own compliance obligations; a dispute resolution clause that creates an asymmetric enforcement position; and an unaddressed licensing or outsourcing compliance question that surfaces when the counterparty seeks internal approval to renew. In the matter described above, all three risks were present. The remediation was achievable, but the cost – in time, in negotiation friction, and in the commercial uncertainty generated by the counterparty's compliance query – was materially higher than a properly structured agreement at the outset would have required. Parties should verify the current position under the applicable Singapore and Hong Kong regimes before executing agreements of this kind.

Speak with Lockhart & Yip

For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.

This site uses only strictly necessary cookies. Non-essential cookies are declined by default. Cookie policy