Sheila Thomas Law Office
Language
EN ID ZH
Search
← Back to Insights
TMT & Privacy • August 11, 2026 • 9 min read

Technology, Media & Telecommunications (TMT): A Roadmap for SaaS, Cloud Providers, Digital Platforms, and AI Developers Scaling Across Borders

ST
Sheila Thomas Law Office TMT, Privacy & Commercial Practice Group
Need Advisory?

Discussing a similar matter?

Consult with our specialists on structuring technology, privacy, or cross-border operations.

Technology, Media & Telecommunications (TMT): A Roadmap for SaaS, Cloud Providers, Digital Platforms, and AI Developers Scaling Across Borders

The Technology, Media & Telecommunications (TMT) sector has been one of the most dynamic engines of global economic growth over the past two decades. Unlike traditional manufacturing or retail industries, whose expansion is constrained by physical supply chains, TMT companies—particularly SaaS (Software-as-a-Service) providers, cloud providers, digital platforms, and AI developers—can reach users across multiple countries with a single "deploy." Yet this technical ease often masks a far more complex web of legal, regulatory, tax, and operational challenges than conventional businesses typically face.

This article provides a comprehensive look at the TMT landscape for companies that are scaling—or planning to scale—across borders. It covers the core structural challenges, the key regulatory frameworks at play, practical risk-mitigation strategies, and emerging trends that industry players need to anticipate.


1. Why TMT Is Different When It Comes to Global Expansion

Several unique characteristics make cross-border scaling in TMT require a distinct approach:

a. Products are intangible and infinitely replicable Software code, AI models, and digital content require no warehouses or physical distribution. This accelerates time-to-market, but it also accelerates exposure to foreign regulation—sometimes before a company even realizes it has become legally "present" in a given jurisdiction.

b. Data is both the core asset and the core risk For SaaS companies and digital platforms, user data is the fuel behind the business model—analytics, personalization, ad monetization, and training data for AI models. But that same data is also among the most heavily regulated assets in the world, from the EU's GDPR to California's CCPA/CPRA, to Indonesia's Personal Data Protection Law (UU PDP).

c. Cloud infrastructure spans multiple jurisdictions Major cloud providers (hyperscalers) operate data centers across many countries, but decisions about where data is stored, processed, and replicated carry significant legal consequences—including data localization obligations that a growing number of developing countries now impose.

d. Innovation outpaces regulation Generative AI is the clearest example: regulators in many countries are still drafting legal frameworks while AI products are already being used by millions of people. This creates legal uncertainty that companies must manage proactively rather than reactively.


2. Key Challenges in Cross-Border Expansion

2.1 Data Protection and Privacy Compliance

Every jurisdiction takes a different approach to data protection:

  • European Union (GDPR): requires a lawful basis for data processing, grants broad data subject rights, and mandates mechanisms for international data transfers such as Standard Contractual Clauses (SCCs).
  • United States: a sectoral and state-by-state approach (CCPA/CPRA in California and various other state privacy laws), with no single unified federal law.
  • Indonesia (Personal Data Protection Law No. 27/2022): requires explicit consent, mandates appointment of a data protection officer for certain categories of processing, and imposes cross-border transfer requirements that generally require the destination country to offer an equivalent level of protection or the existence of an applicable international agreement.
  • China (PIPL): one of the strictest regimes globally, requiring a security assessment for cross-border data transfers above certain volume or category thresholds.

For multi-tenant SaaS platforms and AI systems trained on user data, this challenge compounds further: data from a single enterprise customer in one country may end up being processed by infrastructure located in an entirely different country.

2.2 Licensing, Permits, and Sector-Specific Regulation

Several categories of digital services are subject to specialized licensing regimes:

  • Fintech and digital payments: typically require licenses from local financial authorities (in Indonesia, for example, from the OJK or Bank Indonesia, depending on the type of service).
  • Telecommunications and communication platforms: may be classified as electronic system operators subject to mandatory registration, such as the PSE registration requirement with Indonesia's Ministry of Communications and Digital Affairs for platforms serving Indonesian users.
  • Media and content platforms: subject to content moderation rules, broadcasting rights, and in some cases local content quotas.

2.3 Cross-Border Tax Structuring

Tax issues have grown increasingly complex with the emergence of concepts like Significant Economic Presence and Digital Services Taxes (DSTs), through which various countries seek to tax digital revenue even where a company has no physical permanent establishment there. The OECD's Pillar One and Pillar Two frameworks are also beginning to shape how multinational tech companies are subject to a global minimum tax. SaaS and cloud companies selling directly to consumers across borders need to understand cross-border VAT/GST obligations, such as the EU's One Stop Shop (OSS) regime or Indonesia's PMSE VAT collection obligation for foreign digital service providers.

2.4 Intellectual Property and AI Model Protection

AI developers face a distinct layer of IP risk:

  • Ownership and originality of training data: potential copyright disputes over data used to train models, currently the subject of major litigation across multiple jurisdictions.
  • Protection of models and algorithms: patent protection for AI methods is not uniformly recognized across countries; some jurisdictions apply stricter standards for the "inventive step" required for software and algorithms.
  • AI-generated output: the question of who holds copyright over AI-generated content is still answered differently from country to country.

2.5 Rapidly Evolving AI Regulation

AI regulatory frameworks are evolving quickly and inconsistently:

  • The EU AI Act applies a risk-based approach, imposing strict obligations on high-risk AI systems.
  • Many Asian countries, including Indonesia, are currently developing AI ethics guidelines that are likely to evolve into more binding regulation over time.
  • The United States has taken a more fragmented approach, with policy that can vary by state and remains subject to change depending on the direction of federal policy.

This lack of uniformity forces AI companies to design flexible, jurisdiction-adaptable compliance frameworks rather than relying on a single generic approach across all markets.

2.6 Employment and Entity Structuring

Expanding teams across borders—whether through local entity formation, an Employer of Record (EOR) arrangement, or independent contractors—carries implications for income tax withholding, social security obligations, and the risk of an unintended "permanent establishment" (accidental PE), where the presence of employees in a country can be deemed to create corporate tax liability there even without a formal intent to establish a local entity.


3. Considerations Specific to Each Business Model

3.1 SaaS Companies

  • Contract structures (Master Service Agreements, Data Processing Agreements) must be adapted to the laws governing enterprise customers, particularly around liability caps, SLAs, and data breach notification clauses.
  • Subscription-based pricing needs to account for currency fluctuations and cross-border VAT/GST obligations.
  • Multi-tenant architecture requires contractual clarity on data residency for customers subject to data localization requirements.

3.2 Cloud Providers

  • Data center placement decisions affect legal compliance as well as latency and user experience.
  • Cloud providers often act as "data processors" for their customers, meaning their contractual and regulatory responsibilities differ from those of a "data controller."
  • Cybersecurity obligations are tightening through frameworks such as the EU's NIS2 Directive and various sector-specific cybersecurity regulations across Asia.

3.3 Digital Platforms (Marketplaces, Social Media, Content Platforms)

  • Content moderation responsibilities are becoming increasingly regulated, including obligations to remove illegal content within specific time frames (following the trend set by frameworks such as the EU's Digital Services Act).
  • Transparency requirements around recommendation algorithms are beginning to appear in various jurisdictions.
  • Consumer protection in cross-platform transactions requires adaptation to local consumer protection laws.

3.4 AI Developers

  • Thorough due diligence on training data sources is essential to minimize the risk of copyright disputes.
  • Model documentation (model cards, risk cards) is increasingly becoming best practice and, in some jurisdictions, a regulatory expectation.
  • Companies need mechanisms for human oversight of high-risk AI applications, particularly in healthcare, finance, and employment contexts.

4. Risk Mitigation Strategies for TMT Companies Expanding Globally

  1. Map regulations early. Conduct regulatory mapping for target markets before product launch—not after receiving a warning letter from a regulator.
  2. Privacy by design. Build product architecture that is flexible enough to accommodate different data protection regimes, including the ability to segment data by region.
  3. Adaptive corporate structuring. Consider holding companies, local subsidiaries, or strategic partnerships based on market needs, while carefully weighing the tax and legal liability implications of each.
  4. Strong, scalable contracts. Standardize core contract templates, but build in adaptable addendum modules that can be tailored to local law without restructuring the entire agreement.
  5. Cross-functional collaboration. Involve legal, tax, cybersecurity, and product teams from the earliest stages of expansion planning—not only once problems arise.
  6. Continuous regulatory monitoring. Given the pace of change in TMT regulation—especially around AI—companies need an ongoing regulatory monitoring mechanism, whether through an internal team or external advisors.
  7. Vendor and partner due diligence. Ensure data sub-processors, infrastructure providers, and local distribution partners meet the same compliance standards the company applies internally.

5. Trends to Watch

  • Convergence of AI and data regulation, as AI governance rules become increasingly integrated with existing data protection frameworks.
  • Rising data localization requirements in developing markets, including Indonesia, as part of broader data sovereignty policies.
  • Increasingly coordinated global digital taxation through the OECD framework, even as implementation continues to vary from country to country.
  • Growing emphasis on interoperability and data portability standards, pushing platforms toward more open system design.
  • Intensifying scrutiny of generative AI models, particularly around training data transparency and output bias.

6. Conclusion

Cross-border expansion offers enormous growth potential for SaaS providers, cloud providers, digital platforms, and AI developers—but it also comes with a regulatory landscape that is constantly shifting and far from uniform across markets. Success at global scale depends not only on the strength of the product and technology, but on a company's ability to build a solid foundation of legal compliance, data governance, tax structuring, and AI governance from the earliest stages of growth.

Companies that treat cross-border compliance as an integral part of their product strategy—rather than a mere administrative obligation—will hold a lasting competitive advantage: they can move faster into new markets, build trust with enterprise customers, and reduce the risk of operational disruption from regulatory disputes down the line.


Note: This article is intended for general informational purposes, offering a broad overview of the TMT landscape in the context of cross-border expansion. For guidance specific to a particular business situation, consult legal and tax advisors familiar with the relevant jurisdictions.

Disclaimer

The content of this publication is provided for general informational purposes only and does not constitute formal legal advice. Readers should seek specific legal counsel regarding their particular situation before taking action.