Who has to run a fundamental rights impact assessment?

Article 27 binds public bodies, private providers of public services, and two Annex III uses. A DPIA can be reused, but it does not replace the assessment.

Scope check EU

In short

  • Article 27 binds three groups: bodies governed by public law, private entities providing public services, and deployers of the Annex III point 5(b) and 5(c) uses.
  • Those two points are creditworthiness assessment and risk assessment and pricing in life and health insurance, which puts most of the private sector burden on financial services.
  • The assessment has 6 required elements, including the categories of person affected and the specific harms likely to reach them.
  • Article 27(3) requires the deployer to notify the market surveillance authority of the results, using the template the Article provides for.
  • Article 27(4) lets you reuse a DPIA where it already covers an element, but a GDPR assessment does not discharge the duty on its own.
Advertisement

What do AI assistants say about your organisation?

Model answers are becoming a channel your communications team does not control. EntityRise audits how assistants describe your company and whose name they give instead. From $19.

Audit your AI visibility at EntityRise.ai →

The fundamental rights impact assessment is the obligation most often assumed to apply to everyone, and it does not.

It reaches a defined set of deployers, and outside that set it is good practice rather than law. Which set you are in depends on whether you are the deployer or the provider.

01Which deployers are actually in scope?

Three groups, named in the text.

Scope read from the operative text of Article 27 of Regulation (EU) 2024/1689 and the Annex III points it names.
DeployerBasisTypical example
Body governed by public lawArticle 27(1)Municipality, benefits agency
Private entity providing public servicesArticle 27(1)Contracted health or education provider
Creditworthiness assessmentAnnex III, 5(b)Consumer lending decision system
Life and health insurance pricingAnnex III, 5(c)Underwriting and risk pricing model

Note what is absent. A retailer running a recommendation engine is not in scope. Nor is an employer using a high-risk hiring tool, even though hiring appears elsewhere in Annex III, because Article 27 names points 5(b) and 5(c) specifically rather than Annex III generally.

That narrowness is deliberate and it cuts both ways. Organisations outside the list have no duty. Organisations inside it cannot argue their way out by pointing at the size of the deployment.

02What are the six elements?

A description of use, and an honest account of who it lands on.

The assessment must set out the deployer’s processes in which the system will be used in line with its intended purpose, the period of time and frequency of intended use, the categories of natural persons and groups likely to be affected, the specific risks of harm likely to affect those groups, the arrangements for human oversight as set out in the provider’s instructions, and the measures to take if those risks materialise, including internal governance and complaint mechanisms.

The third and fourth elements are the ones that take real work. Naming the categories of person affected forces a claim about who the system touches, and naming the specific harms forces a claim about what goes wrong for them. Both are checkable later against complaints.

03How much of a DPIA can be reused?

The overlapping parts, and there are several.

Overlap assessment prepared by The Guardrail from the operative text of Article 27 and Article 35 GDPR. Editorial judgement, not a legal opinion.
ElementCovered by a DPIAExtra work under Article 27
Description of processing and purposeYesReframe around intended purpose
Period and frequency of usePartlyState explicitly
Categories of person affectedYesExtend to groups, not only data subjects
Specific risks of harmData protection risks onlyFundamental rights beyond data protection
Human oversight arrangementsRarelyUsually new
Complaint mechanismPartlyName the route and the owner

Article 27(4) is explicit that where an obligation is already met through a DPIA under Article 35 of the GDPR, the fundamental rights assessment shall complement it. Two of the six elements typically transfer intact, two transfer with rework, and two are usually written from scratch.

The mistake is filing the DPIA and treating the box as ticked. The two regimes ask about different harms, in the same way that an AI audit and a management system audit ask about different objects. A system can be flawless on data protection and still distribute its errors unevenly across a protected group.

04What happens after the assessment?

It goes to the regulator, which changes how it should be written.

Article 27(3) requires the deployer to notify the market surveillance authority of the results and to submit the completed template as part of the notification. An assessment that will be read by an authority is a different document from one filed internally: vaguer language reads as evasion, and a risk section with no named harms reads as an assessment that was not performed.

The date matters too. The assessment belongs before first use, not after deployment, because its purpose is to change the deployment rather than to describe it.

05What should an organisation do now?

Answer one question per high-risk system and record the answer.

Are we a public body, a private provider of a public service, or a deployer of a 5(b) or 5(c) use? If the answer is no for all three, write that down with the date and the reasoning, and revisit it when the use changes. If the answer is yes for any, the assessment is due before the system goes live, and the Annex III deadline of 2 December 2027 is the outer limit rather than the target.

06Frequently asked questions

Who must carry out a fundamental rights impact assessment under the AI Act?

Deployers that are bodies governed by public law, private entities providing public services, and deployers of high-risk systems falling under points 5(b) and 5(c) of Annex III, which cover creditworthiness assessment and risk pricing in life and health insurance.

Is a DPIA enough to satisfy Article 27?

No, but it counts. Article 27(4) provides that where an obligation is already met through a data protection impact assessment under Article 35 GDPR, the fundamental rights assessment may complement or incorporate those sections rather than repeat them.

What has to be in the assessment?

Six elements: the deployment processes and intended purpose, the period and frequency of use, the categories of person and group affected, the specific risks of harm to them, the human oversight arrangements, and the mitigation measures including internal governance and complaint mechanisms.

Does the assessment go to a regulator?

Yes. Article 27(3) requires the deployer to notify the market surveillance authority of the results and to submit the completed template as part of that notification.

07References and method

  1. Regulation (EU) 2024/1689, Article 27, for the scope, the six required elements, the notification duty in Article 27(3) and the interaction with the GDPR in Article 27(4).
  2. Regulation (EU) 2024/1689, Annex III, points 5(b) and 5(c), for the creditworthiness and insurance pricing uses named in Article 27.
  3. Regulation (EU) 2016/679, Article 35, for the data protection impact assessment that Article 27(4) allows to be reused.
  4. Application dates reflect the amendments approved by the European Parliament on 16 June 2026, deferring Annex III high-risk obligations to 2 December 2027.
RA

, Assurance Correspondent

Covers assurance: management systems, audit evidence, and what certification bodies actually ask to see. Reach them at ruth@theguardrailreport.com.