An organization deploying high-risk AI in Europe may owe two impact assessments for the same system: a data protection impact assessment under GDPR Article 35 and a fundamental rights impact assessment under AI Act Article 27. Running them separately duplicates half the work and risks contradictory conclusions. The regulation anticipates this: Article 27(4) tells deployers to build the FRIA on the DPIA they already have. This guide sets out a combined methodology.
| Requirements | GDPR Art. 35 (DPIA) + AI Act Art. 27 (FRIA) |
|---|---|
| Max penalty | EUR 20M or 4% (GDPR); EUR 15M or 3% (AI Act) |
| FRIA applies from | 2 August 2026 with the high-risk regime |
| Official texts | GDPR, AI Act |
Who owes what
The DPIA duty is broad: any controller whose processing is likely to result in high risk, with Article 35(3) singling out systematic automated evaluation with significant effects, large-scale special category data, and public-space monitoring. An AI system that scores, ranks, filters, or profiles people meets this comfortably, and the EDPB’s DPIA criteria (new technology, automated decisions, vulnerable subjects, data matching) stack quickly for machine learning.
The FRIA duty is narrower but deeper: it binds deployers of specific Annex III systems, namely public bodies, private providers of public services, and users of credit-scoring and life/health insurance pricing AI. If you are a provider rather than a deployer, your parallel work is the Article 9 risk management system and Article 10 data governance.
The combined structure
Run one assessment with five blocks, each tagged to the law it satisfies:
- System and processing description (both): purpose, intended use and deployment period, data categories and sources, model behavior, recipients, retention. Fold in the provider’s instructions for use, which the FRIA expects you to rely on.
- Necessity and proportionality (DPIA): lawful basis, minimization, whether a less intrusive approach achieves the purpose.
- Affected persons and risk analysis (both): the DPIA’s risks to rights and freedoms, extended to the FRIA’s categories of natural persons and groups affected and specific risks of harm, including discrimination, exclusion from services, and chilling effects.
- Mitigations and human oversight (both): technical and organizational measures for the data risks, plus the FRIA’s human oversight arrangements, deployer staff competence, and the escalation path when the system errs.
- Governance, consultation, and sign-off (both): DPO advice (Article 35(2)), residual risk decision, Article 36 prior consultation with the DPA if residual risk stays high, and the FRIA’s authority notification.
Practical counsel
Do the assessment before procurement locks you in, since the strongest mitigations (different training data, narrower deployment, human review points) are design decisions. Version it: both laws require updates when the system or context changes, and model updates count. And keep the conclusions honest; an assessment that finds no risks in a credit-scoring model reads as evidence of a defective process, not a safe system. For the underlying legal architecture, see the AI Act and GDPR overview and the DPIA methodology guide.