Chinese SaaS vendors selling abroad must reconcile China cybersecurity and data-export rules, possible ICP duties for China-facing services, and host-market privacy, sector regulation and security reviews.

Architecture models
- Global multi-tenant outside China — still watch China staff admin access to overseas PI
- China instance + overseas instance — residency split with routing playbooks
- Sold via overseas subsidiary — ODI, IP licence and transfer pricing
China-side anchors
The Cybersecurity Law, Data Security Law and Personal Information Protection Law (PIPL) frame assessments and PI outbound pathways. China-user apps may need ICP practice—confirm for your topology. Support tickets can be transfers: roadmap.
Host privacy and sector overlays
- GDPR / UK GDPR roles, SCCs, DPIAs
- US state privacy if in scope
- Finance, health, education and government cloud certifications
- AI features and EU AI Act risk tiers
Export controls and encryption
Use the export control tracker; classify before global download mirrors.
Contracts and board checklist
MSA/DPA packages: breach notice, audits, subprocessors, governing law. Forums: arbitration. Entity docs: Apostille.
- [ ] Customer geography vs data residency matrix
- [ ] PI outbound pathway for each China-to-global flow
- [ ] Subprocessor register and DPA templates
- [ ] Export-control classification memo
- [ ] ODI / IP licence chain
- [ ] Incident response across time zones
Next steps
Industry rules change quickly. Confirm licences, ratings, and host-country rules for your product before launch.

