Skip to main content
Praxikon

Knowledge base

Search the GDPR and the AI Act in context

One search across both laws: articles and recitals, rulings, guidelines and fines, obligations and evidence, and the themes where the GDPR and the AI Act meet.

Direct answer

Do we need to perform a FRIA and how do we approach it?

This falls under Article 27: FRIA. That obligation applies from 2 December 2027. There is one exception you have to assess yourself.

This could go the other way

  • In the situation covered by Article 46(1), an exemption from notification may apply. This does not generally remove the assessment itself.

First step: Map the affected groups and their specific risks of harm.

You describe: A fundamental rights impact assessment (Article 27) for deploying a high-risk AI system. Likely role: public body, public service provider or credit/insurance deployer.

The conclusion and your first steps

This applies now

Coming up

Depends on your situation

These provisions only apply once the stated fact is established. The locator says which provision settles it.

The FRIA duty applies only to specific deployers and follows the high-risk timeline to 2 December 2027. A FRIA is not a DPIA: they overlap, but the FRIA assesses more than data protection.

Your first actions

  1. Map the affected groups and their specific risks of harm. Name the categories of natural persons and groups likely to be affected by the use in this specific context, and work out the specific risks of harm per category, using the information the provider supplied under Article 13.
  2. Assign human oversight and give those people a mandate. Name, per high-risk system, who exercises oversight, and ensure that person has the competence, training, authority and support to actually set the output aside.
  3. Complete the conformity route before market placement. Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database.
Read the official sourceChecked on

General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.

Full map for your situation

Shareable version of this answer

Does this answer your question?

Results for “dpia”

51 results

GDPR enforcement and fines

2

GDPR and AI Act side by side

3

GDPR guidelines

9

GDPR legislation in motion

3

GDPR case law

2

Practice examples

2

GDPR articles

6

AI Act obligations and evidence

5

Official AI Act sources

6

AI Act articles

3

GDPR recitals

7

AI Act annexes

1

AI Act recitals

2