Any executive who has signed a cross-border contract remembers the supplier assessment questionnaire: where is our data stored? Which decisions does software make? What is your deletion policy? A few years ago legal drafted those answers. Today they are written into product architecture.
In November 2025 the European Commission unveiled its proposed Digital Omnibus package: an attempt to simplify and align a scattered body of data and AI rules — from data protection to the Data Act and the AI Act — while resetting some implementation timelines. Details will shift before adoption, but the direction is clear: rules read in isolation until recently are converging into one framework.
What this convergence changes
- A shared vocabulary for data: Fragmented duties on retention, transfer and transparency align, so serving several markets stops meaning several separate compliance projects.
- More predictability: With clearer rules and firmer deadlines, compliance can be budgeted into the roadmap rather than improvised in a crisis.
- Cost moves, it does not vanish: Pay early and it is part of the build; pay late and it is the cost of rebuilding.
Why the timing matters
In a regulatory transition the winner is rarely the company with the deepest reading of the text. It is the one that translates it into technical requirements first. A firm that knows where each data item lives, who can reach it and which decisions are automated will complete a buyer questionnaire in hours. A competitor without that map spends weeks, and in many tenders the delay alone is disqualifying. Compliance, understood this way, is not a legal expense; it is part of time-to-market.
Where the impact lands: product and contract
These rules touch two places in a business. First the product: data minimisation, letting users export and delete records, event logging for automated decisions, and marking AI-generated output — features that cost a multiple to retrofit. Second the contract: each party's role in processing, liability for model output, data residency and audit rights — clauses enterprise buyers now read before they reach the price.
Why it matters for Iranian SMEs
An Iranian company working with clients or partners abroad already plays on this field, because its counterparty must push those obligations down the supply chain. Basic readiness needs no large budget. Firms that do this well keep a two-page brief ready before every export conversation: what they collect, how long they keep it, where it is stored, and where a model intervenes. That document compresses a discussion of several weeks into one meeting.
A 90-day starting map
- Days 1–30: Write down what data you collect, why, where it lives and who can access it.
- Days 30–60: Translate your target market's rules into technical and contractual requirements, and rank the gaps by risk.
- Days 60–90: Close the costliest gap, assemble your customer-facing documentation, and make the review a quarterly exercise.
Recurring mistakes
- Handing the whole subject to legal when most of the work sits with data architecture and the product team.
- Waiting for the final text; duties such as transparency and data minimisation survive every draft.
- Hoarding data just in case. Data you retain and never use is a liability.
- Leaving the file without a named owner; responsibility spread across departments is no responsibility.
Three moves for this quarter
- Read your main target market's data rules and rewrite them as technical requirements.
- Put your retention and deletion policy in writing, then enforce it in the product.
- Measure readiness with one metric: how many days to answer a customer assessment questionnaire in full?
Frequently asked questions
- We have no European customers. Does this still concern us?
If your partner, platform or your customer's customer falls in scope, the obligations reach you through the contract. - Where do we begin?
With the data asset inventory. Until you know what you hold and where it sits, nothing else is dependable. - Do these rules ban the use of AI?
No. Their focus is transparency, explainability and keeping a human as final arbiter in high-stakes decisions.
Takeaway
Converging regulation can be read two ways: as a fresh list of obligations, or as a reason to put the house in order. Companies choosing the second reading gain more than compliance — cleaner data, clearer processes, shorter sales cycles.
Glossary
- Regulatory convergence: Rules across different domains moving toward one shared standard.
- Data minimisation: Keeping only the data a defined purpose requires.
- Automated decision: A decision software makes without human involvement, requiring transparency and a route to challenge it.
- Human in the loop: System output approved by an accountable person before it takes effect.
- Data asset inventory: A written list of an organisation's data, with each item's location, purpose and access level.