Europe's regulators just made dataset provenance a compliance requirement.
SBOMator already speaks that language — 100% local, air-gap ready, zero data leaves your PC.
ESL · SBOMator
ESL · SBOMatorA searchable list of scraped domains and URLs, with collection dates and periods — published, not just filed away.
Syntax-based filters for identifiers — emails, ID numbers, financial data — applied and documented before training.
Health, political, ethnic, religious content: incidental collection tolerated only with demonstrable lifecycle safeguards.
robots.txt, ai.txt, CAPTCHAs and login walls now carry weight in the GDPR balancing test. Ignoring them has legal consequences.
Bought a scraped dataset? You must document its sources, exclusion criteria, warranties and the originating controller.
Legitimate-interest assessments and DPIAs, case by case. The first thing an authority will ask for is your documentation.
ESL · SBOMatorSoftware provenance failures can be fixed after the fact — re-scan, patch, redeploy.
Data provenance failures are permanent: the EDPB itself notes that removing personal data from a trained model is close to impossible.
ESL · SBOMator| Software supply chain (SBOM) | AI training data (EDPB 03/2026) |
|---|---|
| Component inventory — what's in the build | Source list — domains, URLs, searchable |
| Version & timestamp per component | Collection date per source |
| Supplier identity | Originating controller & contact point |
| License compliance per component | Legal basis per source |
| Vulnerability scan against inventory | PII & special-category screening |
| Attestations when buying binaries | Warranties when buying datasets |
EO 14028, FDA and the EU CRA made SBOMs mandatory after software learned this lesson the hard way.
The EDPB is applying the same principle to data — before the incident that forces it.
ESL · SBOMatorThe same scanner your security team already trusts for firmware SBOMs
now generates the provenance evidence regulators expect for AI training data.
Runs entirely on your machine. Your dataset never leaves your PC.
ESL · SBOMator
ESL · SBOMator| DataBOM report section | EDPB requirement it evidences |
|---|---|
| Source inventory — domains, counts, dates | Art. 14(5)(b) transparency source list |
| PII scan — emails, IDs, IPs, GPS | Data-minimization filters |
| Special-category flags — with review samples | Art. 9 lifecycle safeguards |
| Secrets scan | Security & minimization |
| Opt-out signal status — robots.txt / ai.txt | Reasonable-expectations balancing |
| Risky-source flags — minor-directed, sensitive sites | Source-exclusion expectation |
| Provenance completeness score | Accountability · DPIA input |
An evidence generator for your DPO and legal team — the documented inputs a
legitimate-interest assessment and DPIA are built on.
ESL · SBOMatorProduct mockup — DataBOM tab in the ESL-SBOMator desktop application (v1.3.x UI)
ESL · SBOMatorCloud scanning tools create the very GDPR problems they claim to solve.
SBOMator's architecture removes them before they exist.
ESL never touches your data — so there is no data-processing agreement to negotiate, no sub-processor list to audit, no vendor risk assessment for your dataset.
Nothing crosses a border because nothing crosses your firewall. No SCCs, no adequacy analysis, no transfer impact assessment.
The scanner reads your dataset in place and stores nothing but the report you asked for. Storage limitation is enforced by design, not by policy.
Security of processing inherits the controls you already certified — disk encryption, access control, physical security. No new attack surface.
Vulnerability and metadata databases install from an offline bundle. Fully disconnected networks are a supported configuration, not an afterthought.
One site license, real engineering support, no per-scan metering — and no usage telemetry phoning home, because there is no home to phone.
The consultation window closes 30 October 2026. The final guidelines land by year end.
Teams that can already produce provenance evidence won't be the ones scrambling.