Fundamental Rights Impact Assessment (FRIA)
The Fundamental Rights Impact Assessment (FRIA) is an obligation applying to a narrow set of actors — bodies governed by public law, private entities providing public services, and deployers of creditworthiness-assessment or insurance risk-assessment systems — that requires assessing a high-risk AI system's impact on fundamental rights before it is put into use. An average private company's HR use of AI does not fall within this category.
The obligation is set out in Article 27(1)–(5), read together with Article 6(2) and points 5(b) and 5(c) of Annex III. The personal scope is closed and narrow: bodies governed by public law (typically state or municipal actors), and, from the private sector, only entities providing public services and deployers carrying out creditworthiness assessment or life- or health-insurance risk assessment. The impact assessment must cover the persons or categories of persons affected by the system's intended use, the likely risks, the exercise of human oversight, and complaint mechanisms. An important distinction: the FRIA is not the same as the GDPR's data protection impact assessment (DPIA) — the protected interest and the group of obligated actors differ — but Article 27(4) establishes a complementary relationship between them, so they can be carried out in a single, two-part document.
Most Hungarian SMEs are not affected by this obligation — but if the company provides a public service or carries out creditworthiness assessment, the FRIA must be carried out BEFORE deploying the high-risk system, not afterwards.
Need documented AI-literacy training?
Article 4 is a duty of diligence: what counts is not knowledge in the abstract, but demonstrable, documented effort. Our starter package lets you begin free.
Start freeRelated terms
- Data Protection Impact Assessment (DPIA)The Data Protection Impact Assessment (DPIA) is a separate legal instrument under the GDPR — not the AI Act — which the data controller must carry out where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons. Many AI-based HR or credit-assessment solutions are typically subject to a DPIA, even where the AI Act's FRIA does not apply to the actor in question.
- High-risk AI systemAn AI system is high-risk if it is a safety component of, or is itself, a product covered by the Union product-safety legislation listed in Annex I, or if it falls within one of the eight areas and listed use cases of Annex III. Classification attaches to the intended purpose, not to the underlying technology.
- DeployerA deployer is a person that uses an AI system under its own authority in the course of a professional activity — unless the system is used in the course of a purely personal, non-professional activity. Mere use, however intensive, does not make a company a provider; deployers are subject to the far narrower Article 26.
Related questions in the knowledge base (Hungarian)
- Kire vonatkozik az alapjogi hatásvizsgálat (FRIA), és mi a viszonya a GDPR szerinti DPIA-hoz?Zárt, szűk alanyi kör: közjog által szabályozott szervek, közszolgáltatást nyújtó magánszervezetek, valamint a hitelképesség-értékelő és az élet- vagy egészségbiztosítási kockázatértékelő rendszerek alkalmazói. Egy átlagos magáncég HR-célú AI-használata nem esik ide — ott viszont a GDPR 35. cikk szerinti adatvédelmi hatásvizsgálat jellemzően kötelező.
- Mi a különbség a DPIA és a FRIA között, és összevonható-e a kettő?Más a védett érdek, a kötelezett és a kiváltó ok. A DPIA az adatkezelőt terheli, tárgya a személyesadat-kezelés; a FRIA az alkalmazót, tárgya az alapjogi hatás. Egyik sem váltja ki a másikat, de a 27. cikk (4) kiegészítő viszonyt ír elő, így egyetlen, kétfejezetes dokumentumban elvégezhetők.