Hlinix.com

Chapter 8: FRIA and DPIA — The Two Assessments You May Need

EU AI Act Implementation Guide · Full Chapter

What you will know after reading this chapter: By the end of this chapter, you will understand what a Fundamental Rights Impact Assessment (FRIA) and a Data Protection Impact Assessment (DPIA) are, whether you are required to conduct one or both, how they differ, how they overlap, and how to approach each one in practice.

Why Two Separate Assessments Exist

The EU AI Act and the GDPR are two different laws with two different purposes. The GDPR protects personal data. The AI Act protects health, safety, and fundamental rights in the context of AI systems. Each law has its own impact assessment requirement, and they are not interchangeable.

The DPIA (Data Protection Impact Assessment) comes from GDPR Article 35. It has existed since 2018. If your AI system processes personal data in a way that is likely to result in a high risk to the rights and freedoms of natural persons, you must conduct a DPIA. Many organisations already have DPIA processes in place.

The FRIA (Fundamental Rights Impact Assessment) is new. It comes from AI Act Article 27. It focuses specifically on the impact of your AI system on fundamental rights — not just data protection rights, but the full spectrum of rights including non-discrimination, freedom of expression, human dignity, access to effective remedy, and the rights of the child.

These two assessments serve different purposes, ask different questions, and are required under different conditions. But they can be conducted together, and in many cases it makes sense to do so.

The FRIA: Fundamental Rights Impact Assessment (Article 27)

Who must conduct a FRIA?

The FRIA is mandatory for the following deployers of high-risk AI systems listed in Annex III. Article 27(1) applies to Annex III high-risk systems with the exception of those intended to be used in the area listed in point 2 of Annex III (critical infrastructure):

Category 1: Public bodies. Any body governed by public law that deploys a high-risk AI system in Annex III — other than a point 2 critical-infrastructure system — must conduct a FRIA.

Category 2: Private entities providing public services. Private organisations that provide services of a public nature — healthcare providers, housing authorities, utilities — are treated the same as public bodies for this obligation.

Category 3: Deployers of credit scoring systems (Annex III point 5(b)). Any deployer, public or private, that uses an AI system to evaluate the creditworthiness of individuals or establish their credit score must conduct a FRIA.

Category 4: Deployers of life and health insurance systems (Annex III point 5(c)). Any deployer, public or private, that uses an AI system for risk assessment and pricing in relation to individuals in life and health insurance must conduct a FRIA.

Important clarification: For categories 3 and 4 (credit scoring and insurance), the FRIA obligation applies to all deployers — not just public bodies. This is widely misunderstood. If you are a private fintech company using AI for credit scoring, you must conduct a FRIA. There is no exception based on the private nature of your organisation.

When must the FRIA be conducted?

The FRIA must be completed before putting the high-risk AI system into use. It cannot be conducted retrospectively after deployment and then backdated. If your system is already in use and you have not conducted a FRIA, you are in breach of Article 27 and should conduct one immediately.

The FRIA must be updated whenever relevant factors change or when the system is substantially modified — for example, if the system’s use is expanded to new populations, new decision types, or new contexts.

What must the FRIA contain?

Article 27(1), points (a) to (f), specifies the required contents of a FRIA. Your assessment must include: a description of the deployer’s processes in which the high-risk AI system will be used pursuant to its intended purpose, including the decisions made or assisted by the system; a description of the period and frequency in which the system is intended to be used; a description of the categories of natural persons and groups likely to be affected by the system; the specific risks of harm to those categories and groups, taking into account information given by the provider; and a description of the implementation of human oversight measures and the technical and organisational measures to mitigate identified risks.

The fundamental rights that must be assessed include: human dignity, right to respect for private life, protection of personal data, freedom of expression and information, right to non-discrimination, equality between women and men, rights of the child, rights of persons with disabilities, right to effective remedy and fair trial, right to good administration, workers’ rights and the right to fair working conditions, consumer protection, environmental protection, and the right to education.

The three-option structure

For each fundamental right assessed, your FRIA should document one of three conclusions:

Option A: No significant impact. The system does not significantly affect this right. Document why, with reference to the system’s design, use, and the population affected.

Option B: Potential impact, mitigated. The system has a potential impact on this right, but that impact is adequately mitigated by technical or organisational measures. Document the impact, the measures taken, and why those measures are sufficient.

Option C: Significant residual impact. The system has a significant impact on this right that cannot be fully mitigated. Document the impact, the measures taken, and why residual risk remains. This conclusion does not automatically prevent deployment, but it must be disclosed to the market surveillance authority and may attract scrutiny.

FRIA notification

Under Article 27(3), the deployer must notify the market surveillance authority of the results of the FRIA, submitting the filled-out template referred to in Article 27(5) as part of the notification (deployers may be exempt from that notification duty in the case referred to in Article 46(1)). In practice, this means filing the completed assessment with the national authority designated to oversee AI Act compliance in your Member State. Retain a copy of the submitted assessment and record the date of submission.

The DPIA: Data Protection Impact Assessment (Article 26(9) and GDPR Article 35)

Who must conduct a DPIA?

A DPIA is required under GDPR Article 35 when a type of processing — particularly using new technologies — is likely to result in a high risk to the rights and freedoms of natural persons. In practice, a DPIA is required when your AI system involves any of the following:

Large-scale processing of personal data. AI systems that process personal data at scale — across large numbers of individuals, large volumes of data, or over extended geographic areas.

Automated decision-making with legal or similarly significant effects. AI systems that make decisions about individuals that significantly affect their legal rights, financial situation, employment, or access to services — without meaningful human review.

Special-category data. AI systems that process health data, biometric data, genetic data, racial or ethnic origin data, political opinions, religious beliefs, trade union membership, sex life, or sexual orientation.

Systematic monitoring. AI systems that systematically monitor individuals — employee performance monitoring, movement tracking, online behaviour profiling.

In practice, most high-risk AI systems under the AI Act will also trigger a DPIA. If your system is high-risk under Annex III, assume a DPIA is required unless you can clearly demonstrate otherwise.

The AI Act’s specific requirement (Article 26(9))

Article 26(9) of the AI Act creates a direct link between the two assessments. It states that deployers shall use the information provided by the provider under Article 13 (the Instructions for Use) to comply with their DPIA obligations under GDPR Article 35 or the Law Enforcement Directive Article 27.

This means the provider’s IFU is not just an operational document — it is a required input to your DPIA. Your DPIA should explicitly reference and draw on the IFU when describing the system, its purpose, its data inputs, its known risks, and the oversight measures in place.

What must the DPIA contain?

Article 35(7) of the GDPR specifies the required contents. Your DPIA must include: a systematic description of the processing operations and the purposes of processing, including where applicable the legitimate interests pursued; an assessment of the necessity and proportionality of the processing in relation to those purposes; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address those risks, including safeguards, security measures, and mechanisms to ensure protection of personal data.

When to consult the supervisory authority

Under GDPR Article 36, if your DPIA indicates that the processing would result in a high risk that you cannot adequately mitigate with available measures, you must consult your Data Protection Authority (DPA) before proceeding with the processing. This is a mandatory prior consultation — not an optional escalation. The DPA has up to eight weeks (extendable by six weeks in complex cases) to provide written advice. If the DPA considers the processing would infringe GDPR, it must provide advice and may use its powers to prohibit or restrict the processing.

FRIA vs DPIA: The Differences

FRIADPIA
Legal basisAI Act Article 27GDPR Article 35
FocusFundamental rights broadly (dignity, non-discrimination, access to justice, workers’ rights, and more)Personal data rights (privacy, data protection)
TriggerMandatory for specific deployer categories (public bodies, public service providers, credit scoring, insurance)Processing likely to result in high risk to rights and freedoms of individuals
ScopeAll rights in the EU Charter of Fundamental Rights relevant to the systemRights related to personal data processing under GDPR
TimingBefore deployment; updated on significant changeBefore processing begins; updated on significant change
NotificationResults submitted to market surveillance authorityConsult DPA only if residual high risk cannot be mitigated
Update requiredYes, when relevant factors change or system is modifiedYes, when processing activities change significantly

How to Conduct Them Together

Because the FRIA and DPIA overlap significantly in the information they require, conducting them as a single integrated exercise is more efficient than running two separate processes. Here is the recommended approach:

Step 1: Start with the DPIA

Begin with the DPIA framework because it is more familiar to most organisations and provides the structured data processing description that both assessments need. Draft the systematic description of processing, the data flows, the legal basis, the retention periods, and the safeguards already in place. Draw on the provider’s IFU throughout this step.

Step 2: Extend to the FRIA

Once the DPIA’s data processing description is complete, extend the scope of analysis to cover all fundamental rights — not just data protection rights. Work through each right listed in the EU Charter and determine whether the system could affect it. Use the three-option structure (no impact, potential impact mitigated, significant residual impact) for each right.

Step 3: Assess impact on specific groups

Article 27 specifically requires assessment of impact on marginalised and vulnerable groups. This step goes beyond typical DPIA analysis. Consider the impact of the system on elderly people, children, persons with disabilities, people in financial hardship, people with limited digital literacy, minority ethnic groups, and others who may be disproportionately affected by errors or biases in the system.

Step 4: Document mitigation measures

For every identified risk — whether to data protection rights or fundamental rights more broadly — document the mitigation measures you have implemented or will implement. Be specific: a vague statement that “appropriate safeguards are in place” is not sufficient. Describe the actual technical or organisational measures, who is responsible, and how their effectiveness will be verified.

Step 5: Determine residual risk

After accounting for all mitigation measures, assess the residual risk. For the DPIA: if residual risk is high and cannot be mitigated, you must consult the DPA before processing. For the FRIA: if significant residual impact on fundamental rights remains, document it clearly and be prepared to justify your deployment decision to the market surveillance authority.

Step 6: Document and file

Produce a single integrated document that contains clearly labelled sections for the DPIA and the FRIA. This makes it clear which content satisfies which obligation. File the FRIA section with the market surveillance authority. If DPIA prior consultation is required, submit the DPIA to the DPA. Retain both the original assessment and evidence of filing.

Practical Timeline

StepActionEffortTiming
1Determine whether FRIA is required for your deployment category1 hourWeek 1
2Determine whether GDPR Article 35 requires a DPIA1 hourWeek 1
3Collect system documentation: IFU, intended purpose, data flows, existing safeguards2 hoursWeek 1
4Draft systematic description of processing and data flows (DPIA step 1)2–3 hoursWeek 2
5Assess necessity, proportionality, and legal basis (DPIA step 2)2–3 hoursWeek 2
6Assess data protection risks and mitigation measures (DPIA step 3)2–3 hoursWeek 2
7Extend to fundamental rights analysis across all applicable rights (FRIA)3–5 hoursWeek 2–3
8Assess impact on vulnerable and marginalised groups (FRIA specific requirement)1–2 hoursWeek 3
9Document mitigations, determine residual risk, prepare final integrated report and file with authorities2–3 hoursWeek 3
Total estimated effort12–24 hours3 weeks

File the FRIA with the market surveillance authority on completion. If the DPIA indicates residual high risk that cannot be mitigated, initiate DPA prior consultation before processing begins.

Common Mistakes

Mistake 1: Treating FRIA as optional for credit scoring and insurance deployers. Private companies in the financial sector routinely treat the FRIA as a public-sector obligation. Article 27(1) is explicit: FRIA is mandatory for all deployers of Annex III 5(b) and 5(c) systems regardless of whether they are public or private. If you use AI for credit scoring or insurance pricing, you must conduct a FRIA — full stop.

Mistake 2: Assuming the DPIA covers the FRIA. The DPIA addresses data protection rights under GDPR. The FRIA addresses a broader set of fundamental rights — non-discrimination, dignity, access to justice, workers’ rights, rights of the child, and more. A DPIA that does not assess algorithmic bias against protected groups, or the impact on workers’ rights, does not satisfy the FRIA obligation. They are separate instruments that answer different questions.

Mistake 3: Conducting the assessments after deployment. Both the FRIA and the DPIA must be completed before the system is put into use. Conducting them retrospectively — after deployment — is a compliance failure, even if the assessments are technically complete and well-documented. If your system is already deployed and you have not conducted these assessments, treat this as an immediate priority and do not wait for enforcement to prompt action.

Mistake 4: Treating the assessments as one-time exercises. Both assessments must be kept current. If the system is substantially modified, if it is used in new contexts, if new risks emerge, or if relevant factors change, the assessments must be updated. An assessment conducted in 2025 for a system that has since been expanded to new use cases is no longer adequate. Build a review trigger into your change management process.

Mistake 5: Failing to act on the results. An assessment that identifies risks but leads to no change in how the system is deployed is worse than no assessment — it creates a documented record that you knew about the risks and chose to ignore them. If your FRIA or DPIA identifies significant risks, document the mitigation measures you take, or document why you have concluded the residual risk is acceptable. An assessment is not a formality: it is a decision-making tool.

Self-Check: Assessment Requirements

Verify your assessment obligations before deployment:

#QuestionStatus
1Have you identified all high-risk AI systems you deploy under Annex III?
2Have you confirmed whether you are a public body or a private entity providing public services?
3Do you deploy any credit scoring systems (Annex III 5(b))? If yes, FRIA is mandatory.
4Do you deploy any life or health insurance systems (Annex III 5(c))? If yes, FRIA is mandatory.
5If a FRIA is required, has it been completed and documented before deployment?
6Does the FRIA cover every element listed in Article 27(1), points (a) to (f), including the categories of persons and groups likely to be affected?
7Have the FRIA results been submitted to the relevant market surveillance authority?
8Have you assessed whether GDPR Article 35 requires a DPIA for your AI system?
9If a DPIA is required, does it draw on the provider’s Instructions for Use as required by Article 26(9)?
10If your DPIA indicates residual high risk that cannot be mitigated, have you consulted the DPA before processing began?

Any item marked incomplete is a gap that must be resolved before or immediately after deployment. Items 3–7 and 8–10 carry direct legal risk if left open at the enforcement date of 2 December 2027.

Summary

The EU AI Act and GDPR each impose a separate impact assessment requirement. The FRIA (Article 27) focuses on the full spectrum of fundamental rights and is mandatory for public bodies, private entities providing public services, and all deployers of credit scoring and life and health insurance AI systems — regardless of whether they are public or private. The DPIA (GDPR Article 35, referenced by AI Act Article 26(9)) focuses on data protection risks and is required when AI processing is likely to result in a high risk to the rights and freedoms of individuals. These assessments serve different purposes and must not be conflated: a DPIA alone does not satisfy a FRIA obligation, and a FRIA alone does not satisfy a DPIA obligation. Both must be completed before deployment. Both must be updated when the system or its context changes. Conducting them together as an integrated exercise reduces total effort to approximately 12 to 24 hours and produces a single document with clearly separated sections for each authority. The five most common mistakes are: treating FRIA as optional for private financial deployers, assuming the DPIA covers the FRIA, conducting assessments retrospectively, treating them as one-time exercises, and failing to act on the results. Chapter 9 covers transparency and disclosure obligations for limited-risk AI systems under Article 50.

← Back to Blog Summary