AI impact assessment — DPIA and FRIA in one template
Required before AI that evaluates, monitors or profiles people (GDPR) and, from December 2027, before certain high-risk AI (AI Act Art. 27). Fill in the sections — each has guidance and an example.
Saved only in this browser.
AI impact assessment (DPIA / FRIA)
What does the system do, who provides it, for what decision or task, how often, since when?
Provider or deployer? Risk level under the AI Act (prohibited, high, transparency, minimal) and why.
Which personal data, from whom, special categories, sources, retention, recipients, transfers outside the EU.
Legal basis (GDPR Art. 6/9); why AI is necessary and proportionate; less intrusive alternatives.
Who is affected, including vulnerable groups (age, disability, origin, gender).
For each risk: what can go wrong, likelihood, impact (low/medium/high).
Who reviews AI results, with what training and authority to override; how you avoid blindly following the AI.
Technical and organisational measures: data minimisation, bias tests, security, contracts, logs, training.
How people are informed; how they can ask for explanation, human review or complain.
Is the residual risk acceptable? Who approved it, when is the next review? Consult the Information Commissioner if high risk remains.
When is a DPIA required?
When processing is likely to result in high risk: systematic evaluation or profiling, large-scale sensitive data, monitoring of employees or public areas, new technologies such as AI with personal data.
Who must do a fundamental rights impact assessment?
Public bodies, private providers of public services, and deployers of high-risk AI for credit scoring or life and health insurance pricing — from 2 Dec 2027. It can reuse your DPIA.
What if a high risk remains?
Consult the Information Commissioner before starting the processing (GDPR Art. 36).
General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.