Joint DPIA + AI Act FRIA assessment
Your assessment preview appears here once you fill in the fields.
A decision wizard and joint assessment workbook for the GDPR Data Protection Impact Assessment and the AI Act Fundamental Rights Impact Assessment. Drives you through the nine WP248 criteria and the AI Act Article 27(1) deployer test, then lets you capture the combined record.
Runs entirely in your browser — nothing is stored, nothing is sent anywhere. See the deep-dive reference for the legal reasoning and primary sources.
What is the system actually doing, for whom, and who decided to put it in place?
Tick whichever applies. If more than one, tick all that apply.
Tick the categories of personal data the system processes. Special categories are GDPR Article 9 data: health, biometric, ethnic origin, etc.
Triggers DPIA criterion 2 and most FRIA use cases. "Legal effects" means affecting someone's legal rights (e.g. denying a benefit, terminating a contract). "Similarly significant" covers decisions that meaningfully affect someone's circumstances (e.g. access to a service, financial opportunity).
For each criterion, mark whether it applies to this system. "Yes" means the criterion clearly applies. "Partial" means it applies in part (e.g. the system scores some but not all data subjects, or for some decisions but not others). The screen tallies automatically. Two or more "yes" is the typical DPIA trigger; one "yes" can also be enough in some cases.
criteria marked "yes" or "partial".
The FRIA is required when the AI system is high-risk under Article 6(2) (an Annex III system, unless the Article 6(3) "no significant risk" exception applies) AND the deployer is in one of the named categories.
"Yes" if it falls into one of the eight Annex III categories. The Article 6(3) exception (narrow procedural task, preparatory task, etc.) is the "but it might not be" option.
Public body, private entity providing a public service, or bank/insurer under Annex III 5(b)-5(c). The tool looks at the deployer-type checkboxes above.
Fill in the screens above to get a verdict.
The verdict is a starting point, not a legal determination. If you mark "not sure" anywhere, treat the higher-scrutiny outcome as the default.
The seven steps below mirror the process diagram in the deep-dive reference. Each step pulls in the cross-mapped element from both regimes, so one written section satisfies both. The tool saves to your browser as you type.
One paragraph covers the use case, the data subjects, the data flows, the legal basis, the provider's instructions for use, and the deployer's role. This is the cover of the combined assessment.
Copy the verdict from the wizard and attach the screen results. If you change your mind, the wizard updates in real time on tab 1.
Nothing saved yet. The tool saves to localStorage every time you change a field. Nothing leaves this page.
The same table that lives in the deep-dive reference, with the verbatim source quotes one click away. Use this to build a single document that satisfies both regimes.
| DPIA element (GDPR Art. 35(7)) | FRIA counterpart (AI Act Art. 27(1)) | Verbatim cite | Notes |
|---|---|---|---|
| (a) systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller | (a) description of the deployer's processes in which the high-risk AI system will be used in line with its intended purpose | GDPR 35(7)(a)AI Act 27(1)(a) |
One paragraph covers both. The FRIA adds the "in line with intended purpose" constraint, which mirrors AI Act provider obligations in Article 16. |
| (b) assessment of the necessity and proportionality of the processing operations in relation to the purposes | No direct element, but covered by (e) and (d) | GDPR 35(7)(b)AI Act 27(1)(d), (e) |
The necessity and proportionality test sits underneath the whole FRIA. Document it once, in the introduction. |
| (c) assessment of the risks to the rights and freedoms of data subjects | (d) specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified in (c), taking into account the information given by the provider pursuant to Article 13 | GDPR 35(7)(c)AI Act 27(1)(d) |
The FRIA is explicit that the provider's Article 13 instructions-for-use are an input. Use the provider's risk section verbatim where you can. |
| (d) measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance | (e) description of the implementation of human oversight measures, according to the instructions for use, and (f) measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms | GDPR 35(7)(d)AI Act 27(1)(e), (f) |
Split into two FRIA elements on purpose. The DPIA "measures" element covers technical and organisational controls, human oversight, and the complaint route. |
| No direct element | (b) description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used | AI Act 27(1)(b) |
Unique to the FRIA. The DPIA does not ask for it. Pull it from the AI Act notification. |
| No direct element | (c) categories of natural persons and groups likely to be affected by its use in the specific context | AI Act 27(1)(c) |
The DPIA asks for "categories of data subjects". The FRIA widens this to "groups" of natural persons, which lets you call out collective-impact risks the DPIA alone would miss. |
| Views of data subjects (Art. 35(9), where appropriate) | Not explicit, but Recital 96 says deployers "could involve relevant stakeholders, including the representatives of groups of persons likely to be affected by the AI system, independent experts, and civil society organisations" | GDPR 35(9)AI Act Recital 96 |
Use one stakeholder-consultation record. State who you consulted, what you asked, and how the assessment changed as a result. |
| DPO advice (Art. 35(2)) | No FRIA equivalent | GDPR 35(2) |
The DPO must be involved in a DPIA. Not by name required for a FRIA, but most organisations will want them in the room. Document the role split. |
| Outcome communicated to the supervisory authority (Art. 36 prior consultation) | Outcome notified to the market surveillance authority (Art. 27(3)) | GDPR 36AI Act 27(3) |
Two different authority channels. A combined assessment may trigger both, in parallel, depending on residual risks. |
Click to expand. These are the words the assessment has to live up to.
"The assessment shall contain at least:
(a) a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller;
(b) an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
(c) an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and
(d) the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned."
"Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5(b) and 5(c) of Annex III, shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of:
(a) a description of the deployer's processes in which the high-risk AI system will be used in line with its intended purpose;
(b) a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used;
(c) the categories of natural persons and groups likely to be affected by its use in the specific context;
(d) the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13;
(e) a description of the implementation of human oversight measures, according to the instructions for use;
(f) the measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms."
"If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the fundamental rights impact assessment referred to in paragraph 1 of this Article shall complement that data protection impact assessment."
This is the legal hook for doing both as one exercise. The FRIA "shall complement" the DPIA. The word is complement, not replace, and not duplicate.
"1. Evaluation or scoring, including profiling and predicting, especially from 'aspects concerning the data subject's performance at work, economic situation, health, personal preferences or interests, reliability or behaviour, location or movements' (recitals 71 and 91).
2. Automated-decision making with legal or similar significant effect.
3. Systematic monitoring.
4. Sensitive data or data of a highly personal nature.
5. Data processed on a large scale.
6. Matching or combining datasets.
7. Data concerning vulnerable data subjects.
8. Innovative use or applying new technological or organisational solutions.
9. When the processing in itself 'prevents data subjects from exercising a right or using a service or a contract'."
"In most cases, a data controller can consider that a processing meeting two criteria would require a DPIA to be carried out." (WP248, Section III.B.a)
"DPIAs are an important element of accountability, where the processing in the context of AI models is likely to result in a high risk to the rights and freedoms of natural persons."
The opinion also notes that the AI Act's EU declaration of conformity under Article 16(g), Article 47, and Annex V point 5 must include a statement that the AI system complies with EU data protection laws. The DPIA is the upstream evidence for that statement.
A live preview of the joint assessment, rendered from the fields above. Use the buttons to print (which hides the tabs and tool chrome) or to copy or download the markdown.
Your assessment preview appears here once you fill in the fields.