Skip to main content
Praxikon
All answers

Direct answer

How do the GDPR and the AI Act relate to each other? (We assess credit or insurance risk)

This falls under Article 27: FRIA. That obligation applies from 2 December 2027. There is one exception you have to assess yourself.

This could go the other way

  • In the situation covered by Article 46(1), an exemption from notification may apply. This does not generally remove the assessment itself.

First step: Map the affected groups and their specific risks of harm.

You describe: Your organisation is GDPR compliant and wants to know what the AI Act adds on top, and where DPIA and FRIA meet. Likely role: deployer in credit or insurance.

The conclusion and your first steps

This applies now

Coming up

Besides public organisations, Article 27 also names deployers of high-risk systems for creditworthiness and for risk assessment and pricing in life and health insurance. If you assess people with such a system, the fundamental-rights assessment applies to you as well, whether you are public or private.

Your first actions

  1. Map the affected groups and their specific risks of harm. Name the categories of natural persons and groups likely to be affected by the use in this specific context, and work out the specific risks of harm per category, using the information the provider supplied under Article 13.
  2. Assign human oversight and give those people a mandate. Name, per high-risk system, who exercises oversight, and ensure that person has the competence, training, authority and support to actually set the output aside.
  3. Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
Read the official sourceChecked on

General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.

Full map for your situation

Your route

From your situation, via your role, to what applies and when it starts.

1 now · 4 later

Your situation

Your organisation is GDPR compliant and wants to know what the AI Act adds on top, and where DPIA and FRIA meet.

Role

Deployer in credit or insurance

To record: Notification to the market surveillance authority with the completed template · Deployment dossier: logs, worker information and information to affected persons · AI literacy measures record

Source and locator

Every statement above rests on these texts. The locator points to the place in the text, the version and the date say which edition was checked.

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council, version original-oj-2024-07-12, checked on , ELI http://data.europa.eu/eli/reg/2024/1689/oj

    Locators in this source

    • Article 27(1)-(5)
    • Article 27(1)
    • Article 26(1)-(12)
    • Article 6 and Annex III
    • Article 6(2)-(4), Article 49 and Annex III
    • Article 10(1)-(6)
  • Digital Omnibus on AI 2026/1744

    European Parliament and Council, version official-journal-2026-07-24, checked on , ELI http://data.europa.eu/eli/reg/2026/1744/oj

    Locators in this source

    • Amended application schedule and Article 27 DPIA cross-reference
    • Article 27 amendment on DPIA inclusion or cross-reference
    • Amendment of Article 4; entry into force 27 July 2026
    • Amended Article 113, Article 6(2) and Annex III application date
    • Amended Article 113 application dates
  • AI literacy questions and answers

    European Commission, version updated-2026-07-27, checked on

    Locators in this source

    • Questions on measures, formats, certificates and records
    • Implementation examples and evidence guidance

Dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0, schema 1.5.0.

Execution

Where relevant, connect the FRIA to the DPIA, register and decision-making

Whether a FRIA is required depends on your role and the use case. Where it applies, you record the assessment and measures and, where relevant, connect them to the AI register, a DPIA and decision-making. Embed AI guides this connected assessment with your team. The source interpretation above is separate from this commercial referral by Praxikon to an affiliated brand.

See the FRIA and DPIA approach
Does this answer your question?
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist