ESL

EDPB Guidelines 03/2026 · Web Scraping & Generative AI

New GDPR Guidance Just Made Your
AI Training Data an Audit Target

What the guidelines demand, the risks they create for CTOs, CISOs and legal teams — and an honest look at which parts SBOMator DataBOM solves.

← Swipe to navigate →

What Happened

Guidelines 03/2026 on Web Scraping in the Context of Generative AI

  • Adopted 7 July 2026 by the European Data Protection Board; public consultation runs until 30 October 2026.
  • Not a new law — interpretive guidance on how the GDPR already applies to scraping training data for generative AI. Supervisory authorities will enforce along these lines.
  • Covers organisations that scrape data themselves, contract scrapers, or acquire already-scraped datasets from brokers.
  • Core message: scraping "publicly available" data is fully in scope of the GDPR — with concrete, checkable expectations.
"It might be challenging … to determine exactly what personal data … are included in the data set. It is thus not obvious how to meet the principle of accountability."— Guidelines 03/2026, on Art. 5(2) GDPR accountability

The Demands

Five Concrete Expectations Hidden in the Guidelines

Art. 14(5)(b)

Published source list

Even under the "disproportionate effort" exemption: publish a precise indication of sources — good practice is domain names, URLs, searchable format, collection dates.

Art. 5(1)(c)

Syntax-based filtering

Apply "syntax-based filtering mechanisms (e.g. regular expressions)" during and after collection to strip unnecessary personal data.

Art. 9

Special-category safeguards

Health, political, religious, ethnic data: incidental collection tolerated only with demonstrable detection and lifecycle safeguards.

Art. 5(1)(d)

Timestamps & reliable sources

Timestamp the data, validate it, and prefer maintained, trustworthy sources.

Art. 5(2)

Accountability records

You must be able to demonstrate all of the above — for every dataset, including ones you bought.

Risk · CTO

Your Datasets Are Opaque — and Now That's a Liability

  • Training corpora are terabytes of crawled text with no manifest. Nobody on the team can say which domains are in there, from when, or what personal data they carry.
  • Datasets acquired from brokers or open repositories inherit the compliance burden — the guidelines put acquirers in scope, not just scrapers.
  • Building internal provenance tooling means diverting engineers from the product, for a moving regulatory target.
  • Retrofitting provenance after a model ships is far more expensive than evidencing it at ingestion.

Risk · CISO

Auditing the Data Without Creating a New Exposure

  • Every cloud "data compliance" service means uploading your training corpus to a third party — a new processor, a new transfer, a new breach surface.
  • Datasets often contain exactly what you don't want leaving the building: residual PII, customer content, proprietary crawls.
  • Regulators and enterprise customers increasingly ask for evidence artifacts — you need reports you can hand over without handing over the data itself.
  • Air-gapped and classified environments can't use SaaS scanners at all.

Risk · Legal / DPO

Legitimate Interest Now Needs Evidence, Not Assertions

  • Art. 6(1)(f) balancing requires knowing what data, from which sources, under what expectations — you can't balance what you can't see.
  • The Art. 14(5)(b) exemption is conditional: no source list, no exemption.
  • Art. 9 incidental-collection tolerance (GC & Others, C-136/17) depends on demonstrable detection and remediation of special-category data.
  • In an investigation, "we believe the dataset is clean" is not a defence. A dated, itemised provenance report is.

The Solution

SBOMator DataBOM — Dataset Provenance, Scanned Like Firmware

The scanner architecture your security team already uses for firmware SBOMs, pointed at AI training data. Runs 100% locally — your dataset never leaves your PC.

Datasetdirectory · JSONL / CSV · crawl exports
DataBOM scanlocal · offline · no upload
EvidenceHTML provenance report + CycloneDX ML-BOM
  • Source inventory: every domain, record counts, first/last collection dates
  • Regex PII screening: emails, phones, IPs, card numbers (Luhn-validated)
  • Art. 9 keyword indicators: health, political, religious content flags
  • Provenance completeness score with per-component breakdown

Traceability

Each Report Section Maps to a Guideline Demand

DataBOM report sectionGuideline expectation it evidences
Source inventory — domains, counts, dates, searchableArt. 14(5)(b) published source list (paras 30–31)
Regex PII scan — emails, phones, IPs, cards"Syntax-based filtering mechanisms (e.g. regular expressions)" (para 38)
Art. 9 keyword indicatorsPost-collection detection of special-category data (para 68)
Timestamp coverage metricAccuracy — "timestamp the data" (para 42)
Full report + CycloneDX ML-BOMArt. 5(2) accountability record for the dataset (para 16)

DataBOM output is evidence for your compliance file — it is not legal advice and not a compliance certification.

Honest Scope

What We Solve — and What We Don't

Solved

Evidence layer

  • Source list generation (Art. 14(5)(b))
  • Regex PII screening (para 38)
  • Dataset accountability record (Art. 5(2))
Partial

Detection, not remediation

  • Art. 9 indicators are keyword screens, not legal classification
  • Timestamp coverage measured; source reliability is your judgment
  • Removal / anonymisation stays your workflow
Not solved

Lawyer-shaped problems

  • Legitimate-interest balancing (Art. 6(1)(f))
  • robots.txt / ai.txt opt-out checks (needs network — on the roadmap as an optional online step)
  • Collection-time exclusions, privacy notices, DPIAs, data-subject rights

Our positioning is deliberate: DataBOM makes your dataset provable, your lawyers make it lawful. Tools that promise both are overselling.

Why Local Matters

Air-Gapped by Design = GDPR by Design

No new processor

No cloud vendor touches your data — no Art. 28 processor agreement, no sub-processor chains to audit.

No transfer risk

Nothing crosses a border. Chapter V transfer assessments simply don't arise for the scan itself.

Art. 32 inherited

Security of processing inherits the controls you already certified — disk encryption, access control, physical security.

Works fully offline

Same site-license model as SBOMator firmware scanning. Suitable for air-gapped and classified environments.

Know Your Data
Like You Know Your Code

Talk to us about dataset provenance scanning on your own hardware — and tell us which capability your compliance file needs next.

Contact ESL

eswlab.com/contact-us · SBOMator product page

1 / 11