HONG KONG · EAST ↔ WEST
info@lockhartyip.comResponse within 4 hours (UTC+8)
Discuss your matter
Home/Insights/Disputes & Arbitration
Tech & Web3

A cross-border SaaS or data agreement touching the BVI

A cross-border SaaS or data agreement touching the BVI. How Lockhart & Yip advises foreign principals on the route. Write to info@lockhartyip.com.

A technology company incorporating a British Virgin Islands holding entity above a Hong Kong or Asian operating subsidiary faces a question that few standard SaaS templates answer: which law governs, which regulator applies, and what happens to the agreement when enforcement becomes necessary? The BVI holding layer changes the analysis at every point – from the governing-law clause to the AML compliance file to the question of where a dispute actually lands.

A cross-border SaaS or data agreement touching the BVI requires a precise mapping of three distinct legal environments – Hong Kong, the British Virgin Islands, and the jurisdiction where the counterparty or end-user sits – before a single contract term is agreed. The governing instrument in Hong Kong for platforms with a virtual-asset or regulated-data dimension is the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, alongside the Securities and Futures Ordinance where any token or data product is characterised as a security. The BVI Business Companies Act and the territory's economic-substance rules then sit above the commercial relationship, shaping how the contracting entity presents itself to its counterparty and to regulators.

This note explains how we structure and advise on that route, where the risks concentrate, and what the client must own before execution.

When does a foreign principal actually need this?

The trigger is almost always enforcement risk. A SaaS provider with a BVI parent and a Hong Kong-registered subsidiary has signed – or is about to sign – a data-processing or platform-access agreement with a Mainland, Asian or European counterparty. The first moment of genuine legal exposure arrives when the counterparty raises a compliance question, when a regulator asks to see the contracting chain, or when performance fails and the question of which entity is liable becomes urgent.

In our cross-border practice, we see three recurring triggers. First, the Hong Kong operating entity is approaching or has crossed a threshold that engages the licensing obligations of the Securities and Futures Commission or the Hong Kong Monetary Authority. Second, the BVI holding entity is named in the agreement as the licensor or data controller, creating a mismatch between the regulated entity in Hong Kong and the contracting party offshore. Third, a Mainland or European counterparty's legal team flags that the contracting chain is incomplete or that the source-of-service analysis is unclear.

Each trigger demands a different first response. But all three share a common root: the agreement was drafted without mapping which regulatory regime governs the activity at the level of the entity that is actually contracting.

What makes the BVI dimension distinctive? The BVI does not apply the licensing requirements that the Securities and Futures Commission or the Hong Kong Monetary Authority apply to the platform's activity. A BVI company can be the holding entity, the IP licensor, or the data controller under the commercial documents – but that choice is not neutral. It determines where the regulatory obligation sits, whether the economic-substance regime of the BVI is engaged, and whether the agreement's governing-law clause is coherent with the structure.

How the governing instruments apply across Hong Kong and the BVI

The Anti-Money Laundering and Counter-Terrorist Financing Ordinance is the primary Hong Kong instrument for technology platforms engaging in virtual-asset activity. Since 1 June 2023, centralised virtual-asset trading platforms operating in or towards Hong Kong are required to hold a licence from the Securities and Futures Commission under the mandatory licensing regime. The critical question for any SaaS or data agreement in this space is whether the platform's activity – the service being licensed under the agreement – falls within that perimeter.

Where the virtual-asset element is absent, the Securities and Futures Ordinance still applies if the data product or platform access constitutes a dealing in securities or futures. A subscription to a data feed that drives automated trading decisions, or a software licence that enables a client to execute transactions in instruments that are securities under Hong Kong law, can engage the Ordinance without any token being involved. The characterisation analysis comes first. The contract drafting follows.

The BVI layer introduces two further instruments: the BVI Business Companies Act, which governs the corporate capacity and existence of the holding entity, and the BVI's economic-substance legislation, which requires certain BVI companies to demonstrate genuine activity and management in the territory depending on their income type. A BVI entity acting as a licensor of software or intellectual property under a SaaS agreement may be within the scope of the substance requirements. Parties should verify the current position with locally licensed BVI counsel before acting.

The interaction between these regimes is where the agreement either holds together or fractures. A governing-law clause that specifies BVI law for an agreement whose entire commercial activity is conducted through a Hong Kong-licensed platform is coherent in one direction – it determines how corporate questions about the licensor are resolved – but it does not displace the regulatory obligations of the Hong Kong entity. Both sets of rules apply, simultaneously, to different aspects of the same transaction.

The sequence above describes the standard position. Your matter turns on the documents, the jurisdictions actually engaged, and the order of steps – which is where the route is won or lost. To discuss how the governing instruments apply to your cross-border SaaS or data structure, contact info@lockhartyip.com.

The cross-border interface: Hong Kong and the BVI in the same contracting chain

The intersection of Hong Kong and BVI law in a single SaaS or data agreement creates four decision points that the client must resolve before execution.

The first is entity selection. Which entity is the licensor: the BVI parent or the Hong Kong subsidiary? The answer determines where the regulatory obligation sits, which entity's compliance file governs the relationship, and which courts or arbitral fora the counterparty is contracting with. A BVI licensor contracting with a Hong Kong-regulated operator creates a vertical split that requires careful drafting to close.

The second is governing law and dispute resolution. BVI law, Hong Kong law, or a neutral third choice? Each has consequences. A Hong Kong-law clause and a Hong Kong International Arbitration Centre arbitration agreement gives both parties access to Hong Kong's common-law system, its strong enforcement record, and – if the Mainland is in the picture – the arbitral-award mutual enforcement arrangements that have been in place since 1999 and supplemented in 2020. A BVI-law clause keeps the corporate questions clean but may leave the regulatory obligations of the Hong Kong entity without explicit recognition in the agreement.

The third is the AML and know-your-customer posture. Under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, a licensed or registrable entity in Hong Kong must conduct customer due diligence and maintain records regardless of where the contracting entity sits in the structure. A BVI holding entity above the Hong Kong operator does not absorb or displace those obligations. The compliance file must reflect the actual contracting chain.

The fourth is the economic-substance question for the BVI entity. If the BVI company derives income from intellectual property or other relevant categories under the substance rules, it must be able to demonstrate that genuine activity occurs in the BVI. A company that licenses software to a Hong Kong subsidiary, receives royalty payments, but conducts all real activity in Hong Kong may not satisfy the substance test. The practical answer is usually a structural adjustment – not a drafting fix.

We work alongside locally licensed Hong Kong firms and, where required, allied counsel admitted in the BVI to coordinate all four points. The international advisory layer – structuring the agreement, mapping the regulatory perimeter, framing the dispute-resolution clause – sits with our desk.

The route we run, step by step

The engagement begins with a regulatory characterisation review. Before any contract term is discussed, our desk assesses whether the platform activity or data service engages the Securities and Futures Commission's licensing perimeter, the Hong Kong Monetary Authority's stablecoin regime (where a fiat-referenced element is present), or the standard AML obligations under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance. The outcome of that review determines the contracting structure.

Step two is entity and structure mapping. We review the existing corporate chain – typically a BVI parent over a Hong Kong subsidiary or a Cayman Islands fund entity with a BVI subsidiary – and identify the optimal contracting entity for the SaaS or data agreement. Where the structure needs adjustment before the agreement is signed, we flag that and model the options.

Step three is the agreement itself. We draft or review the licence agreement, data-processing addendum, or platform-access agreement. The key provisions are the governing-law and dispute-resolution clause, the scope of the licensed activity (mapped to the regulatory characterisation), the data-processing obligations if personal data is in scope, the AML representations from both parties, and the termination and liability structure. For a BVI licensor contracting with a regulated Hong Kong entity, the interplay between corporate capacity, regulatory status, and enforcement rights requires deliberate drafting.

Step four is the compliance file. Where the Hong Kong entity is licensed or registrable, the agreement must be supported by a compliant customer due diligence file. We review and prepare the AML and know-your-customer documentation and advise on the travel-rule obligations that apply to any virtual-asset transfer component under FATF standards as implemented in Hong Kong.

Step five is execution coordination. For instruments that require execution by the BVI entity, we coordinate with allied counsel admitted in that territory. For instruments that require notarisation or registration in Hong Kong, we work alongside locally licensed Hong Kong firms. The client receives a single, coordinated instruction set.

A European software group with a BVI holding entity and a Hong Kong-incorporated operating company came to us in late 2027 with a data-licensing agreement ready for signature. The counterparty was a Hong Kong-licensed financial institution. Our review identified that the BVI licensor had not completed its substance analysis, the data product triggered the securities characterisation question, and the dispute-resolution clause named a forum that would not recognise BVI corporate documents without a further step. We restructured the contracting chain, recharacterised the data product, and drafted a new arbitration clause. The agreement executed within one cycle.

Documents and decisions the client must own

The client is not a passive recipient of drafted documents. Three categories of decision belong to the principal and cannot be delegated to counsel.

The first is the regulatory posture decision. Is the platform activity in Hong Kong at the threshold that requires a licence from the Securities and Futures Commission? That question turns on a characterisation analysis that we advise on, but the decision to operate as a licensed entity, to restructure below the threshold, or to seek an exemption is a business and governance decision. No counsel can make it on the client's behalf.

The second is the substance decision for the BVI entity. If the economic-substance rules apply to the BVI company, the client must decide whether to invest in genuine BVI activity, move the IP or licensor function to a different jurisdiction, or accept the risk. We model the options. The client decides.

The third is the dispute-resolution choice. Arbitration under the HKIAC Administered Arbitration Rules – which came into force in their current form on 1 June 2024 – gives both parties a well-tested procedural regime with emergency-arbitrator provisions, a default Hong Kong seat, and access to the mutual enforcement arrangements with the Mainland. Litigation in the Hong Kong courts gives access to the Mainland Judgments in Civil and Commercial Matters (Reciprocal Enforcement) Ordinance (Cap. 645), which came into force on 29 January 2024 and enables registration of effective Mainland judgments with the Court of First Instance. The choice between arbitration and litigation, and the choice of governing law, have downstream enforcement consequences that the principal must understand before signing.

If an earlier filing, structure or enforcement attempt produced an adverse or stalled result, a second read can identify the strategic error and the routes still open. Email info@lockhartyip.com to discuss a review.

What foreign principals get wrong

The most common error is treating the BVI holding entity as invisible for regulatory purposes. Foreign counsel – particularly those advising from a US or European perspective – sometimes characterise the BVI company as a clean corporate layer that sits outside the regulatory perimeter of any operating jurisdiction. That characterisation is incorrect in the context of a Hong Kong-licensed or registrable platform.

The Anti-Money Laundering and Counter-Terrorist Financing Ordinance and the Securities and Futures Ordinance look at the activity and the entity conducting it in or from Hong Kong. They do not stop at the boundary of the Hong Kong subsidiary. A BVI entity that directly licenses a regulated service into Hong Kong, receives payment from a Hong Kong counterparty, or controls the key decisions of a Hong Kong-licensed entity can be within the regulatory perimeter for specific purposes.

The second error is the governing-law mismatch. An agreement that places the BVI entity as licensor, specifies BVI law as the governing law, and names the BVI courts as the dispute-resolution forum – while the entire commercial performance occurs in Hong Kong – will produce a result that neither party intended when enforcement is needed. The counterparty's Hong Kong lawyers will raise the question; the agreement will not have a clean answer.

The third error is the AML file that stops at the Hong Kong subsidiary. In our cross-border practice, we regularly see compliance files that cover the licensed Hong Kong entity but do not trace the ownership and control structure to the BVI parent. A regulator conducting a review, or a counterparty exercising its own AML obligations, will ask for the full picture. A file that stops at the subsidiary boundary is incomplete.

A common belief among technology founders is that a BVI structure simplifies the regulatory position by placing the main contractual weight offshore. In practice, the opposite is often true: the BVI layer adds a compliance surface, a substance question, and a corporate documentation requirement without reducing the regulatory obligations of the Hong Kong operating entity.

Decision guide: structure, instrument, and route

The right structure depends on the nature of the activity, the counterparty, and the enforcement priority.

Where the platform activity is within the Securities and Futures Commission's licensing perimeter and the counterparty is a Hong Kong financial institution: the Hong Kong entity should be the contracting party, the agreement should be governed by Hong Kong law, and the dispute-resolution clause should specify HKIAC arbitration with a Hong Kong seat. The BVI entity's role is limited to holding the shares of the Hong Kong subsidiary and, where relevant, licensing intellectual property under a separate intercompany agreement that is independently compliant with the BVI substance rules.

Where the platform activity does not engage the SFC licensing perimeter and the counterparty is a Mainland Chinese enterprise: the choice between a BVI licensor and a Hong Kong licensor turns on the enforcement priority. A Hong Kong-law agreement with an HKIAC arbitration clause gives access to the mutual enforcement arrangements with the Mainland. A BVI-law agreement does not, unless the arbitration clause provides for Hong Kong-seated arbitration – in which case the benefit of the arrangement is preserved regardless of the governing law.

Where the data product is personal data subject to the counterparty's domestic data-protection regime: the contracting entity, the governing law, and the data-processing addendum must all align with the applicable regime. A BVI entity acting as data controller for a service delivered into the European Union, for example, must either establish an EU representative or structure the data flow through a compliant intermediary. The BVI corporate layer does not resolve that question; it adds to it.

Where a virtual-asset transfer component is present and the travel rule applies: the compliance obligations run with the licensed Hong Kong entity regardless of where the contractual licensor sits. The agreement must reflect that the Hong Kong entity is the relevant obliged person for those purposes, and the counterparty must be informed accordingly.

Self-assessment: is your SaaS or data agreement structured for the BVI interface?

A principal with an existing or draft agreement should work through the following before execution or renewal.

Is the contracting entity – the licensor or data controller named in the agreement – the correct entity given the regulatory characterisation of the platform activity? A mismatch between the regulated entity and the contracting entity creates a structural gap that will be exposed at enforcement or regulatory review.

Does the governing-law clause reflect the jurisdiction whose regulatory regime applies to the activity? A BVI-law clause is not wrong for a BVI licensor, but it must be paired with a clear analysis of which obligations of the Hong Kong entity survive regardless of the governing law.

Has the BVI entity completed its economic-substance analysis for the income type generated by the agreement? Where the analysis has not been done, the risk is not merely regulatory; it affects the entity's standing to sue under the agreement.

Is the AML and know-your-customer file current, complete, and traceable to the ultimate beneficial owner through the BVI layer? A file that stops at the Hong Kong subsidiary is incomplete for the purposes of the Anti-Money Laundering and Counter-Terrorist Financing Ordinance.

Does the dispute-resolution clause give the preferred enforcement route? For a counterparty with Mainland assets, an HKIAC arbitration clause with a Hong Kong seat preserves the mutual enforcement route. Parties should verify the current position before acting, as the enforcement arrangements continue to develop.

Are the data-processing obligations reflected in a compliant addendum if personal data is processed? The addendum must be consistent with the applicable data-protection regime, not simply with the governing law of the main agreement.

If any of these questions produces an uncertain answer, the agreement needs a structural review before execution.

The interaction with AML obligations and the VASP licensing regime

For SaaS and data agreements that touch virtual-asset activity, the AML and licensing dimension is not a peripheral consideration. It is the centre of gravity of the regulatory analysis in Hong Kong.

Since 1 June 2023, the Securities and Futures Commission has been the licensing authority for centralised virtual-asset trading platforms under the mandatory licensing regime introduced through the Anti-Money Laundering and Counter-Terrorist Financing Ordinance. A SaaS agreement that licences software infrastructure to a virtual-asset trading platform – or that provides data feeds, analytics, or connectivity services to such a platform – sits within a regulatory perimeter that applies to the Hong Kong-connected activity regardless of where the licensor is incorporated.

The practical consequence is that a BVI company licensing software to a Hong Kong-licensed virtual-asset trading platform must ensure that its agreement does not transfer or share in a regulated activity in a way that would require the BVI entity itself to be licensed. The characterisation question – is the software provider a participant in the regulated activity or a pure-infrastructure vendor? – is not always clear. We advise on that line regularly.

The FATF travel rule, as implemented in Hong Kong, requires virtual-asset service providers to collect and transmit originator and beneficiary information for virtual-asset transfers above the applicable threshold. A SaaS agreement that facilitates such transfers must include provisions that enable the licensed Hong Kong entity to comply with those obligations. The BVI entity above the structure cannot contract away that requirement.

Where a fiat-referenced stablecoin is part of the data or platform service, the Hong Kong Monetary Authority's licensing regime for stablecoin issuers – which commenced in 2025 – may be engaged. Parties should verify the current perimeter and commencement details with locally licensed Hong Kong counsel before the agreement is executed.

We advise on the Tech & Web3 practice across all of these dimensions: licensing posture review, AML compliance file preparation, agreement drafting, and coordination with the relevant regulators. See also our related matter note and our guide to cross-border SaaS agreements touching the Mainland.

Related practices

  • Sanctions & AML – AML compliance files, counterparty review, and sanctions-neutral contracting for cross-border technology transactions
  • Holding Structures – BVI, Cayman and offshore holding entity structuring above Hong Kong operating companies

Frequently asked questions

What does the route look like for a cross-border SaaS or data agreement touching the BVI?
The route begins with a regulatory characterisation review to determine whether the platform activity engages the Securities and Futures Commission's licensing perimeter or the Anti-Money Laundering and Counter-Terrorist Financing Ordinance's AML obligations. The contracting entity is then confirmed, the agreement is drafted with a governing-law and dispute-resolution clause matched to the enforcement priority, the AML compliance file is prepared, and execution is coordinated across the Hong Kong and BVI layers with the assistance of locally licensed counsel in each territory. The sequence turns on the regulatory analysis; that analysis must be completed before the contracting structure is finalised.
What are the main risks in a cross-border SaaS or data agreement touching the BVI?
The principal risks are a mismatch between the regulated entity in Hong Kong and the contracting entity in the BVI, a governing-law clause that does not reflect the regulatory regime actually applicable to the activity, an incomplete AML and know-your-customer file that stops at the Hong Kong subsidiary rather than tracing through to the BVI parent, and an economic-substance exposure for the BVI entity if it derives income from intellectual property or platform licensing without demonstrating genuine activity in the territory. Each risk has a structural fix; none has a drafting fix alone.
What is the first step in a cross-border SaaS or data agreement touching the BVI?
The first step is a regulatory characterisation analysis of the platform activity or data service: does it fall within the Securities and Futures Commission's licensing perimeter, does it engage the Hong Kong Monetary Authority's stablecoin licensing regime, or does it sit within the standard AML obligations under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance? That analysis determines the correct contracting entity, the governing-law choice, and the compliance file required. Drafting the agreement without completing the characterisation analysis first produces a contract that is coherent on its face but exposed at enforcement.

Speak with Lockhart & Yip

For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.

This site uses only strictly necessary cookies. Non-essential cookies are declined by default. Cookie policy