FRIA and DPIA — The Two Assessments You May Need
The EU AI Act and GDPR each require their own impact assessment — and they are not interchangeable. The DPIA protects personal data. The FRIA protects fundamental rights broadly — including non-discrimination, human dignity, access to justice, and the rights of children and persons with disabilities. A DPIA that does not assess algorithmic bias is incomplete. A FRIA that does not address data-processing risks misses the GDPR dimension. You may need one, both, or neither — but assuming one covers the other is one of the most common compliance mistakes.
Who Must Conduct a FRIA
The FRIA under Article 27 is mandatory for four categories of deployers: public bodies, private entities providing public services, all deployers of credit-scoring systems (Annex III 5(b)), and all deployers of life and health insurance systems (Annex III 5(c)). Article 27(1) covers Annex III high-risk systems other than those in point 2 (critical infrastructure). For credit scoring and insurance, this applies to every deployer — public or private — a point that is widely misunderstood. The FRIA must be completed before deployment, not after. Results must be submitted to the market surveillance authority.
Who Must Conduct a DPIA
The DPIA under GDPR Article 35 is required when AI processing is likely to result in high risk to individuals — large-scale personal data, automated decisions with legal effects, special-category data, or systematic monitoring. In practice, most high-risk AI systems under the AI Act will also trigger a DPIA.
Conduct Them Together
The two assessments can and should be conducted together. Start with the DPIA, extend to the FRIA, assess the impact on vulnerable groups, document mitigations, determine residual risk, and file a single integrated report with clearly separated sections — one for each authority. Total effort for an integrated assessment is approximately 12 to 24 hours.
What’s in the Full Chapter
The full chapter covers who must conduct each assessment, what each must contain, a step-by-step integrated workflow, a practical timeline with effort estimates per step, the five most common mistakes, and a 10-item self-check to verify your assessment obligations.
Read the Full Chapter
Get the complete Chapter 8 with integrated FRIA and DPIA workflow, effort estimates, common mistakes, and a 10-item self-check.
Read the Full Chapter Check Your AI Risk Level — Free