DPIA overlap: reuse your FRIA where the GDPR meets the AI Act
Art. 27(4) lets the FRIA and the GDPR Art. 35 DPIA complement each other — Veritome maps completed FRIA sections onto the DPIA structure and exports an input pack for your privacy team.
Assessments → DPIA Overlap exists because most high-risk AI systems that need a FRIA (AI Act Art. 27) also process personal data in ways that need a DPIA (GDPR Art. 35) — and Art. 27(4) explicitly says the two should complement, not duplicate, each other. If your team fills in the same facts twice in two templates, something is wrong.
The mapping
A DPIA answers four things: a description of the processing, its necessity and proportionality, the risks to rights and freedoms, and the measures that address them. Veritome maps your completed FRIA content onto those four sections — the deployer's context and affected persons feed the description, the FRIA's risk analysis feeds the risks section, its mitigations feed the measures.
The workspace shows, per system, how much of a DPIA is already covered by FRIA work: which sections arrive substantially pre-filled and which need genuinely new privacy analysis (data flows, retention, lawful basis — things the FRIA doesn't ask).
The input pack
Export the DPIA input pack produces a PDF structured along the DPIA's sections, pre-populated with the mapped FRIA content and clearly marked where privacy-team input is still required. Hand it to your DPO or privacy counsel — they complete the DPIA in whatever tool they use, with the AI Act half already done and referenced.
Veritome deliberately does not claim to produce a finished DPIA: the DPIA is the controller's GDPR artefact and usually lives with the privacy function. The overlap workspace makes sure the AI Act work you've already done arrives there intact.
Do this in order
Complete the FRIA first — FRIA: the fundamental-rights impact assessment, step by step — then export the pack. An input pack from a half-done FRIA is mostly blank headers.