DEV Community

Logan Foster
Logan Foster

Posted on

DPIA, AIA, FRIA: The AI Governance Acronyms That Sound the Same But Aren't

If you work at the intersection of privacy and AI governance, three acronyms appear constantly: DPIA, AIA, and FRIA. They're all "impact assessments." They all involve analyzing risk before deploying a system. They all produce documentation that regulators may ask to see.

They are not interchangeable. Confusing them in practice — using a DPIA where a FRIA is required, or conflating an AIA with a DPIA — is both a compliance failure and a signal that the practitioner doesn't understand what each assessment is actually for.

Here's the precise distinction.


DPIA — Data Protection Impact Assessment

Source law: GDPR Article 35
Who it applies to: Data controllers processing personal data in the EU
When it's required: When processing is likely to result in a high risk to the rights and freedoms of natural persons — specifically when: (1) using new technologies, (2) processing on a large scale, (3) systematic monitoring of publicly accessible areas, or when the processing falls into one of the categories on supervisory authority "required lists"

What it assesses:

  • The necessity and proportionality of the processing relative to the purpose
  • Risks to data subjects' rights and freedoms
  • Measures to address those risks, including safeguards and data protection mechanisms

Who performs it: The data controller, typically with input from the DPO (who must be consulted per Article 35(2)). External expertise may be used. Prior consultation with the supervisory authority is required when residual risk remains high after mitigation.

What it focuses on: Personal data processing risks. The DPIA lens is: what risks does this data processing create for the people whose data is being processed? It's fundamentally a data protection instrument.

Output: A documented assessment of the processing operation, its necessity and proportionality, risk analysis, and risk mitigation measures. The DPIA must be maintained and updated when the nature of processing changes.


AIA — AI Impact Assessment

Source: Not a single law — AI Impact Assessments are required under several different instruments with different scope and methodology. The EU AI Act doesn't use the term "AIA" as a formal concept; the more precise term in EU law is "conformity assessment" for high-risk systems, and "fundamental rights impact assessment" for a specific subset. "AIA" is used in US and Canadian regulatory contexts with varying definitions.

The most practically important US reference: New York City's Local Law 144 requires a "bias audit" (a form of AIA) for AI systems used in employment decisions. Several proposed US state laws use "AI Impact Assessment" with definitions that vary by jurisdiction.

General purpose of an AIA: Assess the impacts of an AI system on individuals, groups, and society — broader than data protection alone. An AIA typically addresses: accuracy and performance characteristics, fairness and potential for disparate impact, transparency and explainability, human oversight, and societal effects.

Key distinction from DPIA: A DPIA is specifically about personal data processing risks. An AIA covers a broader set of impacts, including effects on individuals who may not even be data subjects of the system being assessed. A DPIA can be a component of an AIA, but an AIA is not a DPIA.

Practical use: In organizations that have formalized their AI governance process, the AIA is often the primary governance instrument for AI system review — the assessment that determines risk tier, required controls, and deployment conditions for any AI system, regardless of whether a DPIA is separately required.


FRIA — Fundamental Rights Impact Assessment

Source law: EU AI Act Article 27
Who it applies to: Deployers (not Providers) of high-risk AI systems listed in Annex III of the EU AI Act — with a specific exemption for small and micro-enterprises in some contexts
When it's required: Before deploying a high-risk AI system in the categories covered by Annex III (employment, education, access to essential services, law enforcement, migration, justice, critical infrastructure, biometrics)

What it assesses:

  • The purpose and context of deployment
  • The categories of persons at risk of being affected
  • The specific fundamental rights at risk: privacy, non-discrimination, dignity, fair trial, freedom of expression, and others
  • The magnitude and probability of impacts on those rights
  • Mitigation measures planned to address identified risks
  • Human oversight mechanisms
  • Specific risks for vulnerable groups (children, people with disabilities, minorities)

Who performs it: The Deployer — the organization that puts the AI system into use — not the Provider (vendor) that built the system. The FRIA is separate from the Provider's conformity assessment obligations.

What it focuses on: Fundamental rights — specifically, the rights in the EU Charter of Fundamental Rights that an AI system in use could affect. The FRIA lens is broader than data protection: it includes due process rights, freedom of expression, rights to equality and non-discrimination, and the right to effective remedy.

Output: A documented assessment specific to the deployer's context and use case. Two organizations using the same high-risk AI system from the same vendor will produce different FRIAs if their deployment contexts differ — different affected populations, different decision-making contexts, different human oversight arrangements.

The Article 27(4) bridge: Where a DPIA is also required for the same processing, the EU AI Act explicitly allows the FRIA and DPIA to be conducted jointly, using Article 35 GDPR as the procedural framework. This is the most efficient path for organizations facing both obligations simultaneously.


Side-by-Side Comparison

DPIA AIA (general) FRIA
Legal basis GDPR Art. 35 Various (NYC LL144, state laws, internal policy) EU AI Act Art. 27
Triggered by High-risk personal data processing AI system deployment (varies by framework) High-risk AI system deployment (Annex III)
Performed by Data controller Varies Deployer
Core focus Personal data risks AI system impacts broadly Fundamental rights impacts
Scope of affected parties Data subjects Anyone affected Anyone affected, with emphasis on vulnerable groups
Regulator involved Supervisory authority (GDPR) Varies Market surveillance authority (AI Act)
Required update When processing changes significantly Varies When AI system or deployment context changes significantly

When You Need Which (And When You Need More Than One)

Deploying an AI-powered HR screening tool in the EU:

  • DPIA: Yes — systematic processing of employee/candidate personal data using new technology, high-risk per GDPR
  • FRIA: Yes — employment AI is explicitly listed in Annex III; deployer must complete before deployment
  • AIA (internal): Strongly recommended as the overarching governance document, with DPIA and FRIA as component sections

Deploying an AI fraud detection system for a financial services firm:

  • DPIA: Yes — large-scale processing of transaction data
  • FRIA: Potentially — depends on whether the system meets the Annex III criteria for "access to essential services" (credit, insurance)
  • AIA: Yes as internal governance

Deploying an AI content recommendation system with no GDPR obligations (non-EU, no personal data):

  • DPIA: No GDPR obligation
  • FRIA: No EU AI Act obligation (assuming non-EU deployment)
  • AIA: Depends on internal governance policy and any applicable local law

The Exam Angle

For AIGP candidates, this is one of the highest-yield topic areas — because it's exactly the kind of practical distinction that scenario-based questions test. A question that describes a high-risk AI deployment in an EU financial institution and asks what assessments are required has a specific, defensible answer that requires knowing all three frameworks and how they interact.

The answer isn't "conduct an impact assessment." It's: DPIA under GDPR Article 35, FRIA under EU AI Act Article 27, potentially using the Article 27(4) combined procedure, with the DPIA process providing the procedural framework.


Further reading:

Top comments (0)