The DPIA and the FRIA are one assessment, not two¶
An AI system that processes personal data lands on your desk. Two obligations attach to it, from two regulations, answerable to two different authorities.
Almost everyone runs them as two projects. The legal text does not ask for that, and the second risk register is where the trouble starts.
What the texts actually say¶
AI Act Article 27(4) is explicit: where the obligations are already met by a data protection impact assessment, the FRIA shall complement that DPIA. Complement. Not replace, and not duplicate.
EDPB Opinion 28/2024 comes at it from the other side and treats the DPIA as the accountability backbone for AI processing of personal data.
Put those together and the shape is obvious. One scope, one risk register, one document, read through two legal lenses. The DPIA lens looks at impact on data protection and privacy. The FRIA lens looks at the wider set of fundamental rights: non-discrimination, dignity, effective remedy, and the rest of the Charter.
The overlap is large enough that separating them is mostly transcription.
Why two registers is the actual risk¶
The duplicated effort is annoying. The drift is dangerous.
Run them separately and you get two lists of risks about the same system, maintained by two people, updated at different times. Six months in, the DPIA says the model was retrained and the FRIA does not. A mitigation gets closed in one and stays open in the other. Then a supervisor asks about a specific risk and gets two different answers from the same organisation about the same system.
That is not a documentation problem. It is the thing the documentation was supposed to prevent.
The triggers do not line up, and that matters¶
Doing them as one exercise does not mean they are the same obligation, and the page is careful about this because it is where people get it wrong in the other direction.
The DPIA triggers come from Article 35 and the WP248 nine criteria: evaluation and scoring, automated decision-making with legal effect, systematic monitoring, sensitive data, large scale, matching datasets, vulnerable data subjects, innovative use, and preventing data subjects from exercising a right. Two or more usually means you do one.
The FRIA triggers come from AI Act Article 27(1), and they are about who is deploying and what for: certain public bodies, and private deployers in specific high-risk uses such as creditworthiness and life or health insurance pricing.
So you can land in either one without the other. An organisation can owe a DPIA and no FRIA, or a FRIA where the DPIA was already done years ago and needs revisiting rather than rewriting. The page has a section on exactly that case, because "I have one but not the other" is the common starting position rather than the exception.
The tool¶
The worked example runs one system end to end through seven steps, and there is a self-contained decision wizard that drives the joint assessment. It runs entirely in your browser: nothing is uploaded, no account, no server.
That is deliberate. The whole point of the exercise is a document about how carefully you handle personal data, and it would be a poor joke to make you send it somewhere to produce it.
DPIA and the AI Act FRIA, done as one assessment →
GDPR Art. 35 and WP248 rev.01 · AI Act (EU) 2024/1689 Art. 27 · EDPB Opinion 28/2024. Practitioner material, not legal advice.