ESL logo
ESL · SBOMator

Your AI Training Data
Now Needs an SBOM

Europe's regulators just made dataset provenance a compliance requirement.
SBOMator already speaks that language — 100% local, air-gap ready, zero data leaves your PC.

← Swipe to navigate →
ESL logoESL · SBOMator
The Problem · July 7, 2026

The EDPB Adopted Guidelines 03/2026 on
Web Scraping for Generative AI

"Publicly available" is not an exemption. Web scraping for AI training is fully regulated under the GDPR — collection, storage, structuring, and reuse. EDPB Guidelines 03/2026, adopted 7 July 2026 · public consultation until 30 October 2026 · final version expected end of 2026
Art. 6
Documented legal basis
required per source
Art. 9
Sensitive-data safeguards
across the full lifecycle
Art. 14
Searchable source list
with collection dates
ESL logoESL · SBOMator
The Problem · The New Checklist

What You Must Now Evidence — For Every Dataset

DEMAND Source inventory

A searchable list of scraped domains and URLs, with collection dates and periods — published, not just filed away.

DEMAND PII minimization

Syntax-based filters for identifiers — emails, ID numbers, financial data — applied and documented before training.

DEMAND Special-category control

Health, political, ethnic, religious content: incidental collection tolerated only with demonstrable lifecycle safeguards.

DEMAND Opt-out respect

robots.txt, ai.txt, CAPTCHAs and login walls now carry weight in the GDPR balancing test. Ignoring them has legal consequences.

DEMAND Supply-chain evidence

Bought a scraped dataset? You must document its sources, exclusion criteria, warranties and the originating controller.

DEMAND Accountability on paper

Legitimate-interest assessments and DPIAs, case by case. The first thing an authority will ask for is your documentation.

ESL logoESL · SBOMator
The Problem · Why It Hurts

A Trained Model Cannot Be Patched

Software provenance failures can be fixed after the fact — re-scan, patch, redeploy.
Data provenance failures are permanent: the EDPB itself notes that removing personal data from a trained model is close to impossible.

4%
of global annual turnover —
maximum GDPR fine exposure
0
ways to "untrain" personal data
out of a shipped model
100%
of the evidence must exist
before training starts
It is no longer enough to know you have a dataset.
You must know its provenance.
ESL logoESL · SBOMator
The Insight

This Is Exactly What SBOMs Did to Software

Software supply chain (SBOM)AI training data (EDPB 03/2026)
Component inventory — what's in the buildSource list — domains, URLs, searchable
Version & timestamp per componentCollection date per source
Supplier identityOriginating controller & contact point
License compliance per componentLegal basis per source
Vulnerability scan against inventoryPII & special-category screening
Attestations when buying binariesWarranties when buying datasets

EO 14028, FDA and the EU CRA made SBOMs mandatory after software learned this lesson the hard way.
The EDPB is applying the same principle to data — before the incident that forces it.

ESL logoESL · SBOMator
The Solution

SBOMator DataBOM — Dataset Provenance,
Scanned Like Firmware

The same scanner your security team already trusts for firmware SBOMs
now generates the provenance evidence regulators expect for AI training data.

Dataset
directory · archive · JSONL / CSV / Parquet · crawl logs
SBOMator
DataBOM scan
HTML provenance report
+ CycloneDX ML-BOM

Runs entirely on your machine. Your dataset never leaves your PC.

ESL logoESL · SBOMator
The Solution · How It Works

Everything Happens Inside Your Perimeter

PUBLIC INTERNET NVD / OSV public databases only Offline DB bundle USB / one-way transfer Contains no customer data. Never sees your dataset. AIR GAP inbound only CUSTOMER PC · YOUR SECURITY PERIMETER TRAINING DATASET JSONL · CSV · Parquet directories · archives crawl logs stays on disk, in place SBOMator DataBOM local scan engine Source inventory & timestamps PII & secrets detection Art. 9 content flags Opt-out signal audit Provenance scoring HTML Provenance Report evidence for DPO / DPIA CycloneDX ML-BOM machine-readable, standard Dataset, findings and reports never leave this box No uploads · no telemetry · no cloud processing · no vendor access Outbound customer data: blocked by design there is nothing to DPA, nothing to transfer, nothing to breach at the vendor
ESL logoESL · SBOMator
The Solution · One Report, Every Requirement

Each Report Section Maps to an EDPB Demand

DataBOM report sectionEDPB requirement it evidences
Source inventory — domains, counts, datesArt. 14(5)(b) transparency source list
PII scan — emails, IDs, IPs, GPSData-minimization filters
Special-category flags — with review samplesArt. 9 lifecycle safeguards
Secrets scanSecurity & minimization
Opt-out signal status — robots.txt / ai.txtReasonable-expectations balancing
Risky-source flags — minor-directed, sensitive sitesSource-exclusion expectation
Provenance completeness scoreAccountability · DPIA input

An evidence generator for your DPO and legal team — the documented inputs a
legitimate-interest assessment and DPIA are built on.

ESL logoESL · SBOMator
The Solution · In the Product

The DataBOM Tab — Right Next to Your Firmware Scans

ESL-SBOMator v1.3.4
DatabasesProject Scan🔒 NVD Database🔓 OSV Database📋 Report Information🤖 AI/ML SBOM Add-on📂 DataBOM Dataset Scan
Dataset Provenance Scan
C:\Datasets\crawl_2026_q2\ Browse… Start Dataset Scan 📊 Generate Provenance Report ● ESL Ready · Offline mode
Last scan — crawl_2026_q2 · 1,247,880 records
Source inventory: 4,318 domains · collection timestamps present for 96% of records
PII detected: 12,407 findings (emails 8,112 · phone numbers 3,051 · national IDs 1,244) — review list generated
Special-category (Art. 9) flags: 342 records (health 201 · political 141) — samples queued for review
Secrets: 3 findings (API keys) — exclusion recommended
Opt-out signals: 118 source domains publish robots.txt / ai.txt disallow — exclusion list exported
Provenance completeness score: 82 / 100
📄 crawl_2026_q2_provenance_Report.html    📦 crawl_2026_q2_databom.cdx.json   saved locally · nothing uploaded

Product mockup — DataBOM tab in the ESL-SBOMator desktop application (v1.3.x UI)

ESL logoESL · SBOMator
The Solution · Architecture as Compliance

Air-Gapped by Design = GDPR by Design

Cloud scanning tools create the very GDPR problems they claim to solve.
SBOMator's architecture removes them before they exist.

Art. 28 No processor, no DPA

ESL never touches your data — so there is no data-processing agreement to negotiate, no sub-processor list to audit, no vendor risk assessment for your dataset.

Ch. V No international transfer

Nothing crosses a border because nothing crosses your firewall. No SCCs, no adequacy analysis, no transfer impact assessment.

Art. 5 Minimization by architecture

The scanner reads your dataset in place and stores nothing but the report you asked for. Storage limitation is enforced by design, not by policy.

Art. 32 Your perimeter, your controls

Security of processing inherits the controls you already certified — disk encryption, access control, physical security. No new attack surface.

OFFLINE True air-gap operation

Vulnerability and metadata databases install from an offline bundle. Fully disconnected networks are a supported configuration, not an afterthought.

LICENSE Site license + support

One site license, real engineering support, no per-scan metering — and no usage telemetry phoning home, because there is no home to phone.

ESL logo
Get Ahead of October 30, 2026

Know Your Data Like You Know Your Code

The consultation window closes 30 October 2026. The final guidelines land by year end.
Teams that can already produce provenance evidence won't be the ones scrambling.

Contact Us →

eswlab.com/contact-us  ·  SBOMator product page

1 / 11