By Rafael Luque Ocaña

When FRIA and DPIA overlap: Article 27(4) lets you reuse, not skip one

The text lets the deployer cross-reference the relevant sections of the DPIA, or include parts of it, in the fundamental rights assessment. Reusing is not skipping — and before you get there, it's worth checking whether the FRIA even applies to you, because its list of subjects is short.

Of all the line items that show up when estimating what compliance costs, this is the one most often miscalculated, and in both directions: some budget for it without it applying to them, and others consider it settled with a document they already had.

First: check whether it applies to you, because the list is short

Article 27(1) doesn't bind everyone who deploys a high-risk system. It binds:

"deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III."

Three cases, and the third is very specific: the creditworthiness assessment of natural persons and pricing in life and health insurance.

A private company that doesn't provide public services and does neither of those two things isn't on the list, even if it has high-risk systems. It can carry out the assessment if it finds it useful — that's a defensible best practice — but it isn't an obligation of theirs, and presenting it as one inflates a budget with work the law doesn't ask for.

Second: if it does apply to you, the DPIA doesn't replace it

Here's the point that gives this article its title, and the literal text, as amended by the Digital Omnibus, admits no alternative reading:

"If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the deployer may, when conducting the fundamental rights impact assessment referred to in paragraph 1 of this Article, include cross-references to the relevant sections of that data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment."

Read the subject of the sentence: "the deployer may, when conducting the fundamental rights impact assessment". The facility is granted inside a FRIA that is being carried out. What can be reused is the DPIA's material; what stays is the assessment itself. Nothing in the paragraph says "may be substituted by" or "shall be deemed fulfilled by."

What paragraph 4 grants is real and has value: if part of the work is already done in the DPIA, it doesn't get redone. Processing descriptions, categories of affected persons, security measures, risk analyses already carried out — all of that can be cross-referenced by section or incorporated as relevant parts. And paragraph 5 sends the same signal: the questionnaire template the AI Office is to develop has to give deployers that same possibility.

What it doesn't grant is skipping the assessment. They are different instruments with different subjects: the DPIA looks at the processing of personal data; the FRIA looks at the impact on fundamental rights from using the system. They overlap in material and don't coincide in scope. It's the same distinction we already explained when neither one replaces the other.

What that means for the cost, which is what you were asking

Three consequences, and none of them is a number.

It isn't "two documents from scratch." With a DPIA that's done, and done well, the reusable portion is substantial, and the extra work concentrates on what the DPIA doesn't look at: which rights may be affected, which groups, with what oversight measures and what complaint mechanisms.

Nor is it "a DPIA with a cross-reference on top." The cross-references go into a FRIA that has to exist and carry content of its own, content that only appears in Article 27: the description of the processes in which the system will be used, the period and frequency of use, the categories of affected persons, the specific risks of harm, the human oversight measures, and what will be done if those risks materialise.

And it has two different owners. The DPIA usually falls to whoever handles data protection; the FRIA looks at rights that go beyond data. It's reasonable for a small organisation to assign both to the same person; merging them into a single document without distinguishing what answers to what is not — because the day one of the two has to be produced, what gets produced has to be readable on its own.

The expensive mistake, and the cheap one

The expensive one: doing a FRIA that doesn't apply to you, because someone presented Article 27 as a general obligation of high risk. It's a whole piece of work the law doesn't ask for.

The cheap but worse one: treating the FRIA as satisfied by the DPIA. Cheap today, and found out exactly on the day someone compares the two subjects and sees that one of the two analyses was never done.

Between the two is what the article says: check whether you're on the list of subjects; if you are, reuse everything that's reusable; and don't confuse reusing with avoiding.

The date

Article 27 follows the high-risk calendar of Annex III: 2 December 2027, and the date circulating in many guides is a different one. Today, no non-compliance is possible through this route, and no cost estimate should be presented with a deadline that doesn't exist.

The DPIA under Article 35 GDPR, by contrast, has been enforceable for years whenever its trigger applies. If your estimate includes a pending DPIA, that work isn't brought by the AI Act: it was already there under the earlier regulation.

Content pursuant to Article 27 and Annex III of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (OJ 24 July 2026), and Article 35 of Regulation (EU) 2016/679.

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.