Data Protection Impact Assessment (DPIA)
The Data Protection Impact Assessment (DPIA) is a separate legal instrument under the GDPR — not the AI Act — which the data controller must carry out where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons. Many AI-based HR or credit-assessment solutions are typically subject to a DPIA, even where the AI Act's FRIA does not apply to the actor in question.
The legal basis is Article 35 of the GDPR; the AI Act connects to it via cross-reference in Article 26(9) and Article 27(1)–(5). There are three key differences between the DPIA and the FRIA: the protected interest (the DPIA examines personal data processing, the FRIA examines impact on fundamental rights), the obligated actor (the DPIA falls on the data controller, the FRIA on a narrow category of deployers), and the triggering event (the DPIA is triggered by high-risk processing, the FRIA by deploying a high-risk AI system). In practice, for an average Hungarian SME deploying HR-related AI, the FRIA typically does not apply (as it falls outside the narrow personal scope), but the DPIA typically does, since AI-based profiling of employee data usually qualifies as high-risk processing under the GDPR. Under Article 27(4), the two assessments have a complementary relationship, so they can be carried out in a single, two-part document.
An SME deploying HR-related AI typically needs to carry out not the FRIA but the GDPR's DPIA — the two are often confused, yet the obligated actors and the procedure differ.
Need documented AI-literacy training?
Article 4 is a duty of diligence: what counts is not knowledge in the abstract, but demonstrable, documented effort. Our starter package lets you begin free.
Start freeRelated terms
- Fundamental Rights Impact Assessment (FRIA)The Fundamental Rights Impact Assessment (FRIA) is an obligation applying to a narrow set of actors — bodies governed by public law, private entities providing public services, and deployers of creditworthiness-assessment or insurance risk-assessment systems — that requires assessing a high-risk AI system's impact on fundamental rights before it is put into use. An average private company's HR use of AI does not fall within this category.
- Data governanceData governance covers eight practices applicable to the training, validation and testing data sets of a high-risk AI system, and the substantive standard that data sets be relevant, sufficiently representative, and, to the best extent possible, free of errors and complete. The legislator does not demand flawless data sets, but documented diligence proportionate to the intended purpose.
- DeployerA deployer is a person that uses an AI system under its own authority in the course of a professional activity — unless the system is used in the course of a purely personal, non-professional activity. Mere use, however intensive, does not make a company a provider; deployers are subject to the far narrower Article 26.
Related questions in the knowledge base (Hungarian)
- Mi a különbség a DPIA és a FRIA között, és összevonható-e a kettő?Más a védett érdek, a kötelezett és a kiváltó ok. A DPIA az adatkezelőt terheli, tárgya a személyesadat-kezelés; a FRIA az alkalmazót, tárgya az alapjogi hatás. Egyik sem váltja ki a másikat, de a 27. cikk (4) kiegészítő viszonyt ír elő, így egyetlen, kétfejezetes dokumentumban elvégezhetők.
- Hogyan viszonyul egymáshoz az EU AI Act és a GDPR?Párhuzamosan, egymás mellett alkalmazandók — egyik sem váltja ki a másikat. Az AI Act termékbiztonsági logikájú, a GDPR jogalap-logikájú. Egy rendszer lehet AI Act-konform és mégis GDPR-sértő, és fordítva is. A 2. cikk (7) bekezdés kimondja, hogy a rendelet nem érinti az uniós adatvédelmi jogot.
- Kire vonatkozik az alapjogi hatásvizsgálat (FRIA), és mi a viszonya a GDPR szerinti DPIA-hoz?Zárt, szűk alanyi kör: közjog által szabályozott szervek, közszolgáltatást nyújtó magánszervezetek, valamint a hitelképesség-értékelő és az élet- vagy egészségbiztosítási kockázatértékelő rendszerek alkalmazói. Egy átlagos magáncég HR-célú AI-használata nem esik ide — ott viszont a GDPR 35. cikk szerinti adatvédelmi hatásvizsgálat jellemzően kötelező.