Using AI with personal data or high-risk decisions? Learn the difference between a GDPR DPIA and an EU AI Act FRIA, and when your business may need both.
What is a DPIA?
Your business introduces an AI system that processes information about people. Do you need a DPIA, a Fundamental Rights Impact Assessment, or both? The answer depends on what the AI does, the data involved and who is deploying it.
The two assessments are related, but they come from different laws and should not be treated as interchangeable.
A Data Protection Impact Assessment, or DPIA, comes from the GDPR. It is required where personal-data processing is likely to result in a high risk to people's rights and freedoms.
AI can increase that risk, particularly where systems process sensitive information, operate at scale, monitor people or contribute to automated decisions with significant effects.
A business can therefore need a DPIA even where its AI system is not classified as high-risk under the EU AI Act. The key question is the risk created by the personal-data processing.
What is a FRIA?
A Fundamental Rights Impact Assessment, or FRIA, comes from Article 27 of the EU AI Act. It looks beyond data protection alone.
A FRIA considers how certain high-risk AI systems could affect fundamental rights in the context in which they will actually be used. This can include privacy, discrimination, human dignity and access to services.
For high-risk systems listed in Annex III, the Article 27 requirement follows the revised high-risk timetable and applies from 2 December 2027. Not every business using a high-risk AI system will automatically be required to perform a FRIA.
Who actually needs a FRIA?
Article 27 applies to specific deployers of relevant high-risk AI systems. These include bodies governed by public law, private organisations providing public services, and organisations using high-risk AI for particular creditworthiness or life and health insurance decisions.
The creditworthiness category is subject to the Act's exception for AI used to detect financial fraud. For life and health insurance, Article 27 covers high-risk AI used for risk assessment and pricing.
This distinction matters. An ordinary private recruitment company using a high-risk candidate-screening system may have significant AI Act obligations, but that fact alone does not automatically put it within the Article 27 FRIA requirement. Other obligations can still apply.
The Commission is preparing practical guidance and a FRIA template. These resources can support implementation, but they do not expand the organisations covered by the binding Article 27 text.
Could you need both?
Yes. An AI deployment can involve both the GDPR and the AI Act.
Where parts of the FRIA requirement have already been addressed through a GDPR DPIA, the amended AI Act allows the deployer to cross-reference relevant sections of the DPIA or include relevant parts within the FRIA. That can reduce unnecessary duplication.
The assessments are still not identical. A DPIA focuses on risks arising from personal-data processing. A FRIA considers a broader range of potential impacts on fundamental rights from the use of certain high-risk AI systems.
Four questions to ask before deploying AI
- Does the system process personal data? If yes, assess whether the processing could trigger a GDPR DPIA.
- Is the AI system classified as high-risk? Check its intended purpose rather than relying on the vendor's marketing description.
- Who is deploying it? FRIA requirements depend partly on the type of organisation and the particular high-risk use case.
- Can existing assessment work be reused? Where both assessments are required, identify information that can legitimately be cross-referenced or incorporated rather than creating two completely separate exercises.
Blanche perspective
AI compliance increasingly sits at the intersection of several rules. The mistake is starting with: ‘Which template do we need?’
Start instead with: ‘What does the AI do, what data does it use, who can it affect and what role does our organisation have?’
Once those questions are clear, the required assessment becomes much easier to identify. Good AI governance should reduce duplication, not create paperwork for the sake of paperwork.
Sources
Primary and authoritative sources used for this Insight.
- EU AI Act, Article 27: Fundamental rights impact assessment (binding law)
- European Commission: Navigating the AI Act (explanatory guidance)
- European Data Protection Board: AI and data protection training material (training guidance)
- Regulation (EU) 2026/1744, including the Article 27 amendments (binding law)
- European Commission: Implementation guidance programme and forthcoming FRIA template (implementation update)