DPIA overlap: reuse your FRIA where the GDPR meets the EU AI Act
Art. 27(4) lets the FRIA draw on the GDPR Art. 35 DPIA and Art. 26(9) sends the instructions for use into it — Veritome shows both routes, maps completed FRIA answers onto the DPIA's four pillars and exports an input pack for your privacy team. None of it counts as coverage.
Most high-risk AI systems that need a FRIA (EU AI Act Art. 27) also process personal data in ways that need a DPIA (GDPR Art. 35). They are different legal assessments — one about fundamental rights, one about data-protection risk — but the factual groundwork overlaps heavily, and the EU AI Act says so in its own text. If your team fills in the same facts twice in two templates, something is wrong.
What the Act itself grants
Two of the six places where the Act says existing work counts are about exactly this:
- Art. 27(4) — where any of the FRIA obligations is already met through a DPIA carried out under GDPR Art. 35, the FRIA complements that DPIA. You may cross-reference it or incorporate the relevant parts.
- Art. 26(9) — a deployer of a high-risk system shall use the information the provider gives under Art. 13 — the instructions for use — to carry out its DPIA.
Veritome shows each route as a statutory reuse card on the obligation it reduces: what the Act says, the shared document, and a place to record the arrangement you rely on. Three things a route never does, by design: it never counts toward coverage, a completion percentage or the Statement of Applicability; it never changes the obligation's status; and it never asserts that the two requirements are equivalent — that would need the European standard prEN 18286 cited in the Official Journal, and it is not. You declare reliance; the status stays yours, because whether your DPIA truly reaches the fundamental-rights questions is not a fact the product can see.
The mapping
A DPIA must contain four things (GDPR Art. 35(7)): a description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to the rights and freedoms of data subjects, and the measures that address them. Veritome maps your completed FRIA answers onto those four pillars — the deployer's processes and affected persons feed the description, the FRIA's risk analysis feeds the risks section, its oversight and mitigation measures feed the measures.
The combined view, per system, shows which DPIA sections arrive with a FRIA source behind them and which need genuinely new privacy analysis — data flows, retention, lawful basis, necessity — things the FRIA does not ask. Where a mapped FRIA answer is still empty, the view links you to the FRIA to answer it.
The input pack
Export the DPIA input pack produces a PDF structured along the DPIA's four sections, pre-populated with the mapped FRIA content and clearly marked where privacy-team input is still required. Hand it to your DPO or privacy counsel — they complete the DPIA in whatever tool they use, with the EU AI Act half already done and referenced.
Veritome deliberately does not claim to produce a finished DPIA: the DPIA is the controller's GDPR artefact and usually lives with the privacy function. The overlap workspace makes sure the EU AI Act work you have already done arrives there intact.
Where the DPIA itself lives
The per-system GDPR Art. 35 row is an engine obligation, generated when the system's data answers put it on the DPIA list — solely automated decisions, special categories, workplace use, emotion recognition or biometric categorisation, for a controller or joint controller. The organisation-wide DPIA methodology and screening record is a step in the GDPR programme's Map phase. See GDPR for AI systems.
Do this in order
Complete the FRIA first — FRIA: the fundamental-rights impact assessment, step by step — then open the combined view from Assessments and export the pack. An input pack from a half-done FRIA is mostly blank headers.