Launching SaaS into China requires more than translating the product and selecting a cloud region. The legal analysis must connect the supplied functions, China contracting entity, hosting and network model, customer data, app or website distribution and sector-specific features.
This guide is for inbound or China-hosted SaaS. Chinese vendors expanding overseas should use the separate outbound SaaS guide.
Choose the deployment model
| Model | Questions to resolve |
|---|---|
| Cross-border service with no mainland hosting | Accessibility, contracting, customer support, data collection/transfer, sector restrictions and whether China-side activity still triggers local requirements |
| Mainland cloud hosting through a provider | China operator, domain/app filing, provider permits, customer-facing service classification and allocation of compliance duties |
| China subsidiary operates the service | Business scope, VATS classification, ownership restrictions, licences, filing, invoicing, staffing and intercompany arrangements |
| Licensed local partner | Which party genuinely supplies the regulated service, branding and customer contract, operational control, data roles and anti-fronting risk |
| Dedicated or private deployment | Whether the provider supplies software only, managed infrastructure, network resources, support or data-processing services |
Telecom and filing screen
Map the product against the telecommunications catalogue, especially information services, online data and transaction processing, and infrastructure/resource functions such as IDC or internet resource collaboration. Then determine whether the website or app needs filing and whether an operating licence is required. Keep a written classification memo tied to architecture and contracts.
Foreign ownership and operating structure
If a China entity will operate a catalogued telecom service, screen the precise category against the 2024 negative list, the 2022 foreign-invested telecom provisions and current opening measures. Do not assume that a variable-interest, reseller or partner label transfers regulatory responsibility when the facts show another party controls and supplies the service.
Data and cybersecurity workstream
- Inventory customer, account, device, support, telemetry and employee data.
- Assign personal-information handler and processor roles by actual control.
- Set lawful processing, notices, sensitive-information and retention controls.
- Map mainland storage, remote access and cross-border transfers.
- Screen cybersecurity, MLPS and incident-response requirements with the data owner guide.
- Control administrator access, subprocessors, logs, encryption and deletion evidence.
Customer contract checklist
- Correct licensed/filing entity and service description.
- Permitted use, user administration and prohibited content.
- Availability, support, maintenance and change control.
- Data roles, security measures, subprocessors and cross-border access.
- Incident notification and investigation cooperation.
- IP ownership, feedback and customer content.
- Fees, tax, invoicing, suspension and exit assistance.
- Governing law, dispute route and enforceability strategy.
Launch gate
- Freeze the business-model and architecture diagram.
- Complete telecom classification and foreign-investment screen.
- Complete website/app filing and sector-approval map.
- Complete privacy, data-transfer and cybersecurity assessment.
- Align contracts, product claims, billing and actual operator.
- Test complaints, security incidents, regulator contact and service exit.
- Re-screen every material feature, ownership or infrastructure change.
Related guides
- China ICP, VATS & Telecom Licensing Guide
- China ICP Filing Guide
- China Data Privacy & Cybersecurity Guide
- SaaS and software outbound compliance for Chinese vendors
Official sources and version control
- Telecommunications Regulations
- MIIT Telecommunications Business Classification Catalogue (2015 edition)
- MIIT Order No. 42 licensing measures
- 2024-amended non-commercial internet information service filing measures
- MIIT APP filing notice
- 2022 foreign-invested telecommunications enterprise provisions
- 2024 national foreign-investment negative list
Version note: Sources checked 30 August 2026. Confirm later amendments, local communications-administration practice and any pilot opening before relying on a classification or ownership conclusion.
General information only, not legal advice. Classification and administrative practice can change; obtain advice for the actual service, entity, ownership and deployment.


