Verified Digital Agents → C2MD → DPIA / FRIA scaffold
Generate DPIA / FRIA Scaffold
A draft Data Protection Impact Assessment under GDPR Article 35, a Fundamental Rights Impact Assessment under EU AI Act Article 27, or both — structured so a compliance officer reviews and completes it rather than starting from an empty template.
Live · pro tier
Why it starts from your bundle
The scaffold requires a prior compliance bundle. That dependency is deliberate: a DPIA written independently of the agent's actual governance describes an agent that may not exist. Deriving it from the bundle means the processing described in the assessment is the processing the agent is actually permitted to do — and if the governance later changes, the divergence is visible.
DPIA and FRIA are not the same document
| DPIA — GDPR Art. 35 | FRIA — EU AI Act Art. 27 | |
|---|---|---|
| Asks | What is the risk to the rights and freedoms of data subjects from this processing? | What is the risk to fundamental rights from deploying this high-risk system in this context? |
| Triggered by | Likely high risk processing — often large-scale, systematic, or special-category. | Deployment of certain Annex III high-risk systems, by certain deployers. |
| Overlap | Substantial, and that is the trap: they overlap enough to feel duplicative and differ enough that one will not satisfy the other. Generating them together keeps the shared analysis consistent while keeping the two assessments distinct. | |
Whether either is triggered at all comes out of the risk assessment — run that first if you do not already know.
Worked example
Northwind Bank — GDPR Article 35 DPIA Demo data
Ask for it in plain language
- "Generate the DPIA scaffold for our credit-decision agent."
- "We are deploying an Annex III system — produce the FRIA scaffold under Article 27."
- "Produce both the DPIA and the FRIA, keeping the shared analysis consistent."