EU Privacy Law EU/EEA

AI Impact Assessments: Combining a GDPR DPIA with the AI Act's FRIA

How to run one assessment that satisfies both GDPR Article 35 DPIAs and the EU AI Act's Article 27 fundamental rights impact assessment for high-risk AI.

Regulation

GDPR Article 35; AI Act (2024/1689) Article 27

Max Penalty

EUR 20 million or 4% of turnover (GDPR); EUR 15 million or 3% (AI Act)

Enforcing Authority

Data protection authorities; EU AI Office and national authorities

Official Source

eur-lex.europa.eu

Executive Summary

  • Two assessments can attach to one AI system: a GDPR Article 35 DPIA when processing is high-risk to individuals, and an AI Act Article 27 fundamental rights impact assessment (FRIA) for certain high-risk deployers.
  • The FRIA duty falls on deployers that are public bodies, private entities providing public services, and deployers of credit-scoring and life/health insurance pricing systems.
  • Article 27(4) explicitly allows the FRIA to build on an existing DPIA, so one combined assessment is the intended design, not a workaround.
  • The DPIA is broader on data processing detail; the FRIA is broader on affected groups, societal context, human oversight, and complaint mechanisms.
  • AI processing personal data almost always meets the DPIA triggers: new technology, systematic evaluation, and large-scale processing.

An organization deploying high-risk AI in Europe may owe two impact assessments for the same system: a data protection impact assessment under GDPR Article 35 and a fundamental rights impact assessment under AI Act Article 27. Running them separately duplicates half the work and risks contradictory conclusions. The regulation anticipates this: Article 27(4) tells deployers to build the FRIA on the DPIA they already have. This guide sets out a combined methodology.

RequirementsGDPR Art. 35 (DPIA) + AI Act Art. 27 (FRIA)
Max penaltyEUR 20M or 4% (GDPR); EUR 15M or 3% (AI Act)
FRIA applies from2 August 2026 with the high-risk regime
Official textsGDPR, AI Act

Who owes what

The DPIA duty is broad: any controller whose processing is likely to result in high risk, with Article 35(3) singling out systematic automated evaluation with significant effects, large-scale special category data, and public-space monitoring. An AI system that scores, ranks, filters, or profiles people meets this comfortably, and the EDPB’s DPIA criteria (new technology, automated decisions, vulnerable subjects, data matching) stack quickly for machine learning.

The FRIA duty is narrower but deeper: it binds deployers of specific Annex III systems, namely public bodies, private providers of public services, and users of credit-scoring and life/health insurance pricing AI. If you are a provider rather than a deployer, your parallel work is the Article 9 risk management system and Article 10 data governance.

The combined structure

Run one assessment with five blocks, each tagged to the law it satisfies:

  1. System and processing description (both): purpose, intended use and deployment period, data categories and sources, model behavior, recipients, retention. Fold in the provider’s instructions for use, which the FRIA expects you to rely on.
  2. Necessity and proportionality (DPIA): lawful basis, minimization, whether a less intrusive approach achieves the purpose.
  3. Affected persons and risk analysis (both): the DPIA’s risks to rights and freedoms, extended to the FRIA’s categories of natural persons and groups affected and specific risks of harm, including discrimination, exclusion from services, and chilling effects.
  4. Mitigations and human oversight (both): technical and organizational measures for the data risks, plus the FRIA’s human oversight arrangements, deployer staff competence, and the escalation path when the system errs.
  5. Governance, consultation, and sign-off (both): DPO advice (Article 35(2)), residual risk decision, Article 36 prior consultation with the DPA if residual risk stays high, and the FRIA’s authority notification.

Practical counsel

Do the assessment before procurement locks you in, since the strongest mitigations (different training data, narrower deployment, human review points) are design decisions. Version it: both laws require updates when the system or context changes, and model updates count. And keep the conclusions honest; an assessment that finds no risks in a credit-scoring model reads as evidence of a defective process, not a safe system. For the underlying legal architecture, see the AI Act and GDPR overview and the DPIA methodology guide.

Frequently Asked Questions

Do I need a DPIA for an AI system?

Almost always, if it processes personal data. Article 35 triggers include systematic and extensive automated evaluation with significant effects, large-scale special category processing, and use of new technologies. AI systems making or supporting decisions about people typically hit at least one.

Who must do a fundamental rights impact assessment under the AI Act?

Deployers of certain Annex III high-risk systems: bodies governed by public law, private operators providing public services, and operators deploying systems for credit scoring or life and health insurance risk assessment and pricing (Article 27(1)).

Can one document satisfy both requirements?

Yes. Article 27(4) says the FRIA shall complement a DPIA where one is already required, and the EU AI Office is to provide a template. Run one assessment with sections mapped to both laws' required content.

What does the FRIA add beyond a DPIA?

Deployment context: the processes the system will support, the period and frequency of use, the categories of persons and groups affected, specific risks of harm to them, human oversight arrangements, and the governance and complaint measures if risks materialize.

When must the assessments be done?

Both before starting: the DPIA prior to the processing, the FRIA prior to first use of the system, updated when elements change. For the FRIA, the deployer must notify the market surveillance authority of the outcome unless exempt.

Regulatory Crosswalk

GDPR Art. 35ISO/IEC 42001NIST AI RMF

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.