DPIA and FRIA: running the European pair
Lesson 2 of 5 in AI Risk and Impact Assessment Methodologies.
The DPIA is the oldest muscle most organisations have for AI assessment — privacy teams have run them since 2018 — and the FRIA was deliberately built to ride on it. Master the pair as one workflow with two report formats and you have covered the majority of European AI systems that will ever cross your desk.
When does a DPIA fire for an AI system? Article 35 says: when processing is likely to result in a high risk to rights and freedoms, especially using new technologies. The EDPB’s guidance (WP248) turned that into nine concrete criteria, and the working rule of thumb — two or more criteria present → do the DPIA — catches nearly every consequential AI system, because AI use cases stack criteria by nature: a CV-screening model is evaluation or scoring + automated decision-making with significant effect + often large scale + often vulnerable data subjects. In practice, arguing an AI system out of DPIA territory is usually harder than just doing the assessment.
The EDPB nine criteria — the AI reading
- Evaluation or scoring, including profiling and predicting — almost every ML decisioning system. 2. Automated decision-making with legal or similarly significant effect — the Art 22 overlap. 3. Systematic monitoring — biometric surveillance, workplace monitoring, telematics. 4. Sensitive or highly personal data — health AI, biometric systems. 5. Large scale — most production deployments. 6. Matching or combining datasets — feature-store pipelines that join data collected for different purposes. 7. Vulnerable data subjects — employees, children, patients, benefit claimants. 8. Innovative use or new technology — the criterion that names AI explicitly. 9. Processing that prevents exercise of a right or use of a service — credit denial, insurance pricing, access screening.
Count how many a typical high-risk AI system hits: usually four or more. The nine criteria are also an excellent intake questionnaire — many organisations reuse them as gating questions in the use-case intake form.
What the DPIA must contain (Art 35(7))
Four mandatory elements: (a) a systematic description of the processing and its purposes, including legitimate interests pursued; (b) an assessment of the necessity and proportionality of the processing; (c) an assessment of the risks to rights and freedoms of data subjects; (d) the measures envisaged to address those risks. For AI, element (a) must describe the model and data flows honestly — a DPIA that describes “an automated tool” without naming the training data, the features, or the decision logic is a compliance artifact, not an assessment.
Article 36: the escalation valve
If, after mitigations, residual risk remains high, the controller must consult the supervisory authority before processing begins — and the authority can effectively stall the launch for eight weeks or longer, or advise against it. This is the one point where a paper exercise becomes a regulator conversation, and it disciplines the whole workflow: teams that overstate mitigations to dodge Art 36 are creating the evidence trail that will sink them after an incident.
The FRIA is narrower in who it binds and wider in what it sees. Article 27 captures three deployer categories using Annex III high-risk systems: bodies governed by public law, private entities providing public services (schools, hospitals, utilities, transport), and deployers of two specific Annex III use cases — creditworthiness scoring and life/health insurance risk pricing. If you are a private manufacturer deploying a high-risk hiring tool, Article 27 does not apply to you; your obligations run through Article 26 and the DPIA instead.
What it demands is a structured, before-first-use analysis: the deployer’s processes in which the system will be used, the period and frequency of use, the categories of persons and groups affected, the specific risks of harm to them, the human oversight measures taken from the provider’s instructions for use, and the arrangements if risks materialise — internal governance and complaint mechanisms. Then notify the market surveillance authority. Where a DPIA already covers ground, Art 27(4) says the FRIA complements it — build one evidence base, generate both documents.
Which assessments does this use case owe?
Interactive decision tree — outcomes:
- DPIA + FRIA + internal risk & impact assessment
The full European stack: GDPR Art 35 DPIA, AI Act Art 27 FRIA (built on the DPIA per Art 27(4), notified to the market surveillance authority), plus your internal 42005-style impact assessment and risk assessment feeding both. One evidence base, four report formats.
- DPIA + high-risk deployer duties, no FRIA
Art 27 does not capture ordinary private deployers outside credit/insurance — but the DPIA is owed, Art 26 deployer duties apply from the high-risk applicability date, and your internal impact assessment should cover the fundamental-rights ground anyway: it is the same evidence you will need if the deployment ever faces a discrimination claim.
- DPIA + internal assessment, no AI Act high-risk duties
The DPIA carries the legal weight here. Keep the classification decision on file — Annex III mapping is a judgment you may need to defend, and re-triage if the use case, population, or purpose shifts.
- FRIA territory without a DPIA trigger — rare, check again
An Annex III high-risk system that genuinely processes no personal data is unusual (most Annex III categories are about people). Double-check the no-personal-data claim — inferred and derived data count — then run the FRIA on your internal impact-assessment evidence.
- Internal risk & impact assessment + provider/deployer duties
No DPIA, no FRIA — but high-risk classification still brings Art 26 deployer duties (or Art 16 provider duties), and your AIMS requires the internal assessments regardless.
- Internal assessment at proportionate depth
No statutory assessment fires. Proportionality cuts both ways: run a lightweight internal assessment, record the triage decision and its date, and set re-triage triggers — today’s minimal-risk chatbot is one repurposing away from Annex III.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.