AI for business · Impact assessment

AI impact assessment — DPIA and FRIA in one template

Required before AI that evaluates, monitors or profiles people (GDPR) and, from December 2027, before certain high-risk AI (AI Act Art. 27). Fill in the sections — each has guidance and an example.

Saved only in this browser.

1. The AI system and its purpose

What does the system do, who provides it, for what decision or task, how often, since when?

2. Our role and classification

Provider or deployer? Risk level under the AI Act (prohibited, high, transparency, minimal) and why.

3. Data

Which personal data, from whom, special categories, sources, retention, recipients, transfers outside the EU.

4. Legal basis and necessity

Legal basis (GDPR Art. 6/9); why AI is necessary and proportionate; less intrusive alternatives.

5. Affected people and groups

Who is affected, including vulnerable groups (age, disability, origin, gender).

6. Risks to rights and freedoms

For each risk: what can go wrong, likelihood, impact (low/medium/high).

7. Human oversight

Who reviews AI results, with what training and authority to override; how you avoid blindly following the AI.

8. Measures to reduce risks

Technical and organisational measures: data minimisation, bias tests, security, contracts, logs, training.

9. Transparency and complaints

How people are informed; how they can ask for explanation, human review or complain.

10. Conclusion and review

Is the residual risk acceptable? Who approved it, when is the next review? Consult the Information Commissioner if high risk remains.

When is a DPIA required?

When processing is likely to result in high risk: systematic evaluation or profiling, large-scale sensitive data, monitoring of employees or public areas, new technologies such as AI with personal data.

Who must do a fundamental rights impact assessment?

Public bodies, private providers of public services, and deployers of high-risk AI for credit scoring or life and health insurance pricing — from 2 Dec 2027. It can reuse your DPIA.

What if a high risk remains?

Consult the Information Commissioner before starting the processing (GDPR Art. 36).

General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.