Three abbreviations circulate around the responsible use of data and algorithms and are easily confused: DPIA, IAMA and FRIA. They have a different starting point but overlap strongly. Understand the distinction and you avoid duplicate work.
What they are
- DPIA (data protection impact assessment) comes from the GDPR (Art. 35) and is mandatory when a processing operation carries a high privacy risk. Focus: protection of personal data.
- IAMA (Impact Assessment for Human Rights and Algorithms) is a Dutch instrument that helps an organisation weigh the use of an algorithm carefully — with attention to human rights and the question "is it actually permitted?". It is widely used within central government.
- FRIA (fundamental rights impact assessment) comes from the AI Act (Art. 27) and is mandatory for certain deployers of high-risk AI — particularly public bodies — before they put such a system into use.
Where they overlap
At their core all three ask the same questions: what does this system do, who does it affect, what risks does it bring, and how do we control them? The DPIA looks through a privacy lens, the IAMA and FRIA more broadly at fundamental rights and diligence. In practice you answer largely the same questions — three times, if you're not careful.
The combined approach
Smarter is to run them as one process: one analysis of the system and its impact, from which you derive the specific parts of the DPIA, IAMA and FRIA. That saves time, avoids contradictory outcomes, and gives the board and the regulator one coherent story instead of three separate documents.
Want to know quickly what applies to you? Try the DPIA/IAMA/FRIA decision helper — five questions, an instant indicative view.
When do you start
The core principle is: before deployment, not after. An impact assessment afterwards is an accountability exercise; beforehand it is a design choice that makes the system better. For high-risk AI in government, the AI Act also makes this a hard precondition.
The bottom line
DPIA, IAMA and FRIA are not bureaucracy but the same discipline from three angles. Combine them, do them early, and you keep a grip — on the risks and on the workload.
This article is general information, not legal or organisational advice for your specific situation.