A Briefing for Privacy, AI & Cyber Counsel · EDPB Guidelines 03/2026
The EDPB's web-scraping guidelines turn AI training data into an audit target. Legal advice tells clients what to demonstrate; SBOMator DataBOM produces the technical artifacts they demonstrate it with.
Who We Are
Track Record
Israel Aerospace Industriesdefence & aerospace
Elbit Systemsdefence electronics
Rafaeladvanced defence systems
Medtronicmedical devices · FDA
Philips Medicalmedical imaging · FDA
NeuroDerm (Mitsubishi Tanabe)drug-device combination
MobileyeADAS / autonomous driving
Innovizautomotive LiDAR
Elmo Motion Control (Bosch)motion control · servo drives
PathKeeper Surgicalsurgical navigation · FDA
SCD SemiConductor Devicesinfrared detectors & lasers
KLA-Tencorsemiconductor process control…and many more across defence, medical, automotive and industrial. These organisations run our tooling inside networks that never touch the internet.
The ESL Tool Family
Software bill of materials for firmware and applications: components, licenses, CVE matching against NVD/OSV. Fully offline.
Hardware bill of materials for FPGA/MPSoC platforms (Xilinx Zynq UltraScale+) — the hardware side of supply-chain transparency.
AI/ML bill of materials aligned with CISA's SBOM for AI minimum elements and G7 supply-chain expectations.
Audits AI-agent skills and plugins before they run in your environment — supply-chain scrutiny for the agent era.
Detects hallucinated / squatted package names that AI coding assistants invent — before they become a supply-chain attack.
Dataset provenance scanning for AI training data — the subject of this briefing.
Methodology · Who Verifies the Verifier?
Counsel should ask any AI-tooling vendor this question. Our answer is public: the SPDF Control Mapping — 13 audit-ready controls, 9 threat models, 5 verification layers, built for FDA premarket cybersecurity submissions.
The Regulatory Shift
The Advisory Pattern
Inventory scraped and third-party datasets; assess by sensitivity, anti-scraping signals, and controller/processor roles.
Establish where each record came from, when it was collected, and whether the source is legitimate.
Necessity, reasonable expectations, minors' data, website restrictions — for existing and planned collection.
AI training purposes, data categories, precise source indication, legal basis, objection channels (Art. 14).
Steps 1 and 2 are technical work at terabyte scale. Steps 3 and 4 are legal work — that consumes the output of steps 1 and 2. That dependency is the gap.
The Gap
The Solution
The scanner architecture our defence and medical clients already trust, pointed at AI training data. Runs 100% on the client's machine — the dataset never leaves their network.
In the Product
Product mockup — DataBOM tab in the ESL-SBOMator desktop application (v1.3.x UI)
Traceability for Your Compliance File
| DataBOM report section | Guideline expectation it evidences |
|---|---|
| Source inventory — domains, counts, dates, searchable | Art. 14(5)(b) published source list (paras 30–31) |
| Regex PII scan — emails, phones, IPs, cards | "Syntax-based filtering mechanisms (e.g. regular expressions)" (para 38) |
| Art. 9 keyword indicators with sanitized excerpts | Post-collection detection of special-category data (para 68) |
| Timestamp coverage metric | Accuracy — "timestamp the data" (para 42) |
| Full report + CycloneDX ML-BOM | Art. 5(2) accountability record for the dataset (para 16) |
DataBOM output is evidence for the compliance file your firm builds — it is not legal advice and not a compliance certification. The legal judgment stays with counsel.
Honest Scope — Ask Any Vendor for This Slide
Our positioning is deliberate: DataBOM makes the dataset provable; counsel makes it lawful. We are the technical half of your advisory, not a competitor to it.
Why Local Matters
SBOMator was engineered for classified, disconnected networks — IAI, Elbit, Rafael-grade environments where no data may ever leave the premises. That same architecture eliminates GDPR exposure by construction:
ESL never touches the client's data. Nothing to negotiate, no sub-processors to audit, no vendor risk assessment for the dataset.
Nothing crosses a border because nothing crosses the firewall. No SCCs, no adequacy analysis, no TIA.
Security of processing inherits the controls the client already certified: disk encryption, access control, physical security.
Vulnerability and metadata databases install from offline bundles. Disconnected networks are a supported configuration, not an afterthought.
Site license + support agreement. No per-scan metering, no usage telemetry — there is no "home" for the software to phone.
Working With Counsel
Consultation Closes 30 October 2026
Talk to us about dataset provenance evidence for your clients — or a joint briefing for your privacy & AI practice.
Contact ESLeswlab.com/contact-us · SBOMator product page · SPDF Control Mapping