By Rafael Luque Ocaña

The AEPD's Article 35(4) list: when your AI requires a DPIA even if it is not high-risk under the AI Act

The AEPD list usually requires a DPIA when processing meets two or more criteria, even if the system is not high-risk under the AI Act.

This article is for anyone who uses AI with personal data in their company and has concluded, rightly, that their system is not high-risk under the AI Act: a customer-service chatbot, a tool that scores customers for campaigns, a system that summarises calls. The conclusion is correct, and it does not answer another question, the GDPR one: does that processing need a data protection impact assessment, a DPIA? The two classifications follow different rules, and in Spain the second is made concrete by a list from the Spanish Data Protection Agency, the AEPD.

FRIA and DPIA: two independent instrumentsArticle 27 of Reg. (EU) 2024/1689 and Article 35 of Reg. (EU) 2016/679WHOWHENWHATFRIAARTICLE 27 AI ACTDeployerbody governed by public law,or private entity providingpublic services, with AnnexIII high risk except point 2;or any deployer of Annex III,point 5, points (b) and (c)Beforefirst useArticle 27(1) and (2)Six contents · Article 27(1)(a) processes in which it will beused(b) period and frequency of use(c) persons and groups affected(d) specific risks of harm(e) human oversight measures(f) measures if the risksmaterialiseIndependent instrumentsevidence can be reused · Article 27(4)cross-referencesor parts of the DPIADPIAARTICLE 35 GDPRControllerwhere the processing islikely to result in a highrisk to the rights andfreedoms of natural personsPrior to theprocessingArticle 35(1)Minimum content · Article 35(7)(a) processing operations andpurposes(b) necessity and proportionality(c) risks to rights and freedoms(d) measures to address the risksArticle 27 of Reg. (EU) 2024/1689, as worded by Reg. (EU) 2026/1744 ·Article 35 of Reg. (EU) 2016/679
Independent instruments: neither replaces the other. If any obligation of Article 27 is already met through the DPIA, Article 27(4) lets the FRIA cross-refer to its relevant sections or include its relevant parts.

The figure sets the two instruments side by side. The FRIA, under Article 27 of the AI Act, is owed by the deployer that is a body governed by public law or a private entity providing public services, with an Annex III high-risk system other than point 2, or by any deployer of the systems in Annex III, point 5, points (b) and (c); it is carried out before first use and has six contents. The DPIA, under Article 35 GDPR, is owed by the controller where the processing is likely to result in a high risk to the rights and freedoms of natural persons; it is carried out prior to the processing and has a minimum content of four points. Between them runs a band: they are independent instruments, and Article 27(4) lets the FRIA reuse the evidence of the DPIA.

What the GDPR requires

Article 35(1) requires the controller to carry out an impact assessment "where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons". The test is high risk to people, not the label on the technology. And that general obligation does not depend on any list: if a high risk is likely, the assessment is needed even if the processing fits none of the criteria.

Article 35(3) lists three cases in which the assessment is required "in particular": a systematic and extensive evaluation of personal aspects, based on automated processing, on which decisions are based that produce legal effects or similarly significantly affect people; processing on a large scale of special categories of data or of criminal data; and systematic monitoring of a publicly accessible area on a large scale.

And Article 35(4) adds the piece that matters here: "The supervisory authority shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment".

The AEPD list

The list published by the AEPD, available in Spanish only, sets out eleven criteria and a rule for combining them: a DPIA (an EIPD, in its Spanish acronym) is needed in most cases where the processing meets two or more criteria, unless the processing is on the list of operations that do not require one (Article 35(5)). The more criteria it meets, the list says, the greater the risk and the more certain it is that the assessment is needed. And it presents itself as a non-exhaustive list.

Two of its criteria describe a good deal of the AI a company uses:

  • Criterion 1: processing involving profiling or evaluation of individuals.
  • Criterion 2: processing involving automated decision-making, or processing that contributes to a large extent to such decisions.

Others are more specific but just as common: special categories of data (criterion 4), biometric data used to identify a person uniquely (criterion 5), large-scale processing (criterion 7), data about vulnerable people (criterion 9) and new technologies or innovative uses of established ones (criterion 10).

Under that rule, a tool that scores customers to prioritise campaigns, and does so on a large scale, meets at least two criteria, 1 and 7, and the list says that in most such cases a DPIA is needed. The same system is not high-risk under the AI Act: scoring customers for marketing campaigns is not among the Annex III uses, which do include, for instance, evaluating the creditworthiness of natural persons. It still needs the assessment.

A DPIA is not only about security

The underlying confusion is usually a different one: thinking of the DPIA as an IT security analysis. Article 35(7) requires it to contain, at a minimum, "an assessment of the risks to the rights and freedoms of data subjects". Rights and freedoms, not only the confidentiality of the data.

That is why the DPIA for a candidate-screening filter, when one is carried out, has to assess discrimination: the risk that the system rejects people for reasons that should not count is a risk to their rights, and it falls within what the assessment covers. That filter is also high-risk under the AI Act, and once Article 26 applies to it — from 2 December 2027 for high-risk systems under Annex III and from 2 August 2028 for those under Annex I — its paragraph 9 will require the deployer to "use the information provided under Article 13 of this Regulation" for that assessment, the information the provider has to give it.

Two classifications that are not the same

None of the above depends on the AI Act. Whether a system is high-risk comes from the AI Regulation; whether a DPIA is needed comes from the GDPR and the AEPD list. A system can be minimal-risk under one and require an assessment under the other, and a high-risk system does not escape the DPIA by having a FRIA. Both terms have their glossary entry: DPIA and FRIA.

The Article 27 FRIA is a different instrument, with a different subject and a different date. For Annex III high-risk systems other than point 2, it is owed by deployers that are bodies governed by public law or private entities providing public services, and by those deploying the systems in Annex III, point 5, points (b) and (c); its only date of application is 2 December 2027. Where the two coincide, Article 27(4) lets the FRIA "include cross-references to the relevant sections of that data protection impact assessment or include relevant parts thereof". Reuse, not replacement.

In practice

  • Run each AI processing operation through the list before it goes live. Count the criteria and record the result, including when it is "not needed".
  • If it touches health data, read the private healthcare case carefully. Article 35(3)(b) requires large-scale processing, and not every centre reaches it.
  • If it uses biometrics, the distinction between verifying and identifying settles a great deal. Criterion 5 of the list is about identifying a person uniquely.
  • Revisit the DPIA when the processing changes. A system that starts out summarising calls and ends up scoring customers has changed criteria, and the assessment you made at the start no longer holds.
  • Do not wait for 2027. The GDPR already applies, and so does the list.

This article is for informational purposes only and does not constitute legal advice.

Frequently asked questions

Is it mandatory because of "new technologies"?

Not on its own. Article 35(1) GDPR mentions new technologies as a factor in high risk, and the AEPD list includes them as one of its eleven criteria, number 10. The list considers a DPIA necessary, in most cases, when two or more criteria are met.

One DPIA for several tools?

It can be. Article 35(1) allows a single assessment to address a set of similar processing operations that present similar high risks. If the tools process different data or serve different purposes, the prudent course is to assess them separately.

Who signs it off without a DPO?

The assessment is an obligation of the controller (Article 35(1)). The data protection officer advises on it where one has been designated (Article 35(2)); where there is none, the responsibility does not change hands, and whoever decides on behalf of the controller signs it off.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (NIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es) or with the supervisory authority of your Member State (Article 77 GDPR). More information in the privacy policy.