Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Chapter III Section 3 · Article 27

FRIA vs DPIA

They overlap, they are not the same, and Article 27(4) does not let a DPIA discharge a FRIA. The most useful way to see the difference: a DPIA asks what your processing does to data subjects. A FRIA asks what deploying this system does to people, whether or not their data is involved.

Art. 27 FRIAGDPR Art. 35 DPIAapplies 2 Dec 2027

Side by side

 DPIA — GDPR Art. 35FRIA — AI Act Art. 27
TriggerProcessing likely to result in a high risk to rights and freedoms of natural personsDeployment of certain high-risk AI systems by certain deployers
Who owes itThe controllerThe deployer, not the provider
Which deployersAny controller meeting the triggerBodies governed by public law; private entities providing public services; deployers of Annex III point 5(b) creditworthiness and credit scoring, and point 5(c) life and health insurance risk assessment and pricing
Scope of assessmentBounded by personal data processingImpact on fundamental rights, whether or not personal data is involved
TimingPrior to processingPrior to first use of the system
Regulator involvementPrior consultation with the DPA where residual high risk remainsNotify the market surveillance authority of the results
Applies fromIn force since 20182 Dec 2027

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

What Article 27 requires in the assessment

  1. A description of the deployer’s processes in which the high-risk AI system will be used, in line with its intended purpose.
  2. The period of time and frequency for which each system is intended to be used.
  3. The categories of natural persons and groups likely to be affected by its use in the specific context.
  4. The specific risks of harm likely to have an impact on those categories, taking account of the information the provider gave under Article 13.
  5. A description of the implementation of human oversight measures, according to the instructions for use.
  6. The measures to be taken if those risks materialise, including internal governance arrangements and complaint mechanisms.

Point 3 is what makes it different

The DPIA asks about data subjects. The FRIA asks about categories of persons and groups in the specific deployment context, which invites a question about differential impact that a data-processing frame does not naturally raise. A credit scoring deployment may process the same personal data uniformly and still affect two groups very differently. That is the gap Article 27 exists to close.

What Article 27(4) actually says

Where any of the FRIA obligations are already met through a DPIA conducted under GDPR Article 35, the fundamental rights impact assessment complements that DPIA.

Read carefully, that is a duplication-avoidance provision, not a substitution provision. It means you do not redo work already done. It does not mean a DPIA discharges Article 27: the elements above that a DPIA does not cover still have to be produced, and the notification goes to a different authority.

Art. 27(4)GDPR Art. 35

How to run them together

Practical recommendation. One assessment, two outputs. Structure a single exercise that produces the GDPR Article 35 elements and the Article 27 elements from the same evidence base, then generate two documents for two audiences and two authorities.

  • Share: system description, data flows, affected populations, risk identification, mitigations.
  • DPIA-only: lawful basis, necessity and proportionality against the processing purpose, data subject rights, prior consultation trigger.
  • FRIA-only: the deployment process description, period and frequency of use, group-level differential impact, oversight implementation, materialisation response and complaint mechanisms, notification to the market surveillance authority.

The Commission and the AI Office are to develop a template questionnaire to support the FRIA. Check whether it has been published before drafting your own structure. Our FRIA template →

Status labels on this page

Verified fact: Who owes a FRIA, the Art. 27 prescribed contents, the notification duty, the Art. 27(4) complementarity provision, and the 2 December 2027 application date.

Expert analysis: The one-assessment-two-outputs recommendation and the reading of point 3 as the substantive difference.

Unsettled: The content and publication status of the Commission and AI Office template questionnaire.

Next step

The FRIA is a deployer artefact

If you buy high-risk AI rather than build it, this is one of the few obligations that lands squarely on you. It is worth knowing now whether you are inside Article 27, because the assessment has to precede first use.

Not sure where you sit?

The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.

Run the classifier →

Frequently asked

What is the difference between a FRIA and a DPIA?

A DPIA is a Data Protection Impact Assessment under Article 35 of the GDPR, required where processing is likely to result in a high risk to the rights and freedoms of natural persons. A FRIA is a Fundamental Rights Impact Assessment under Article 27 of the EU AI Act, required of certain deployers of high-risk AI systems.

The DPIA is bounded by personal data processing; the FRIA assesses the impact of deploying a specific high-risk AI system on fundamental rights, whether or not personal data is involved. Article 27(4) provides that where any of the FRIA obligations are already met through a DPIA, the FRIA complements that DPIA.

Who has to do a FRIA under the EU AI Act?

Article 27 applies to deployers that are bodies governed by public law or private entities providing public services, and to deployers of high-risk AI systems listed in Annex III point 5(b) on creditworthiness evaluation and credit scoring and point 5(c) on risk assessment and pricing in life and health insurance. It is a deployer obligation, not a provider obligation.

Does a DPIA replace a FRIA?

No. Article 27(4) says the FRIA complements a DPIA where obligations overlap, which means you do not duplicate work already done, but it does not mean a DPIA discharges the FRIA. The FRIA has its own prescribed contents, including the deployer's processes, the period and frequency of use, the categories of persons and groups likely to be affected, the specific risks of harm to those groups, the human oversight measures, and the measures to take if risks materialise.

When does the FRIA obligation apply?

Article 27 sits in Chapter III Section 3 and applies from 2 December 2027 for stand-alone Annex III high-risk systems, following the deferral in Regulation (EU) 2026/1744. Deployers who will owe a FRIA should note that the assessment must be performed before the first use of the system.