Art. 27

Article 27: Fundamental Rights Impact Assessment (FRIA)

Article 27 requires certain deployers — public-sector bodies, private operators of essential public services, and deployers of specific Annex III systems such as creditworthiness assessment and life/health insurance risk pricing — to carry out a Fundamental Rights Impact Assessment before first using a high-risk system, and to notify the market surveillance authority. A GDPR data protection impact assessment can be credited toward this duty but does not automatically satisfy it.

deployer high-risk
When it applies
What it requires
What you keep on file
Commonly misread

A GDPR DPIA is often assumed to automatically satisfy the FRIA requirement; it can be credited toward it, but the FRIA has its own scope (fundamental rights broadly, not only data protection) and its own narrower addressee list.

Unsettled: Whether the FRIA deadline explicitly moved to 2 December 2027 along with the rest of Annex III, or is governed by its own timing, was not confirmed by any primary source found in the underlying research — the 2 December 2027 date here is a logical inference from Article 27's link to Annex III applicability, not a directly verified fact.

Recent activity

What regulators published on Art. 27

  1. Loading from the public feed…

Informational content only. Not legal advice and not a substitute for qualified counsel. Dates reflect Regulation (EU) 2026/1744 as of 04 Aug 2026.