Jump to

FRIA Without the Fog: Who Really Needs a Fundamental Rights Impact Assessment, and How to Run One on Top of Your KVKK DPIA

The Fundamental Rights Impact Assessment is the EU AI Act’s most misunderstood document. It is not a privacy assessment with a new name, it is not required from everyone, and — after the omnibus postponement — its deadline is not what most 2025-era articles say. Here is what a Turkey-connected company actually needs to know, and how to run one without duplicating the KVKK work you have already done.

Who must run a FRIA — and who is off the hook

Article 27 puts the duty on deployers, not providers, and only three groups of them: public bodies; private entities providing public services (think education, healthcare, housing, essential utilities); and deployers of two specific Annex III systems — credit scoring (5(b)) and life and health insurance risk assessment and pricing (5(c)).

Translated to the Turkish ecosystem: a fintech whose scoring model decides EU consumers’ access to credit, an insurtech pricing life or health cover in an EU market, and any technology vendor whose product performs a public service in the EU are in the frame. A B2B SaaS selling analytics to private companies is, as a deployer, generally not — though your enterprise customers may be, and they will push the paperwork to you.

The real deadline

FRIA attaches to the deployment of Annex III high-risk systems. With the omnibus agreement moving Annex III obligations to 2 December 2027, the FRIA duty follows that timeline. That is not a reason to file it away: EU enterprise buyers and public tenders are already asking for fundamental-rights documentation contractually, ahead of any legal deadline. A completed FRIA is becoming a procurement asset.

What goes in it

Article 27 requires a description of the deployment process and period, the categories of persons and groups likely to be affected, the specific risks of harm to those groups, the human oversight measures, and what happens when risks materialise — internal governance, complaint channels, remediation. The result is notified to the market surveillance authority using the template the AI Office is mandated to provide.

FRIA and your KVKK DPIA: one workflow, two outputs

If you process personal data at scale you have likely already done a data protection impact assessment. The overlap is real but partial:

DPIA (GDPR 35 / KVKK practice) FRIA (AI Act 27)
Lens Privacy and data protection All fundamental rights: non-discrimination, human dignity, access to services, consumer protection
Trigger High-risk processing of personal data Deployment of specified high-risk AI systems
Focus of analysis Data flows, lawful basis, security Decision impact on affected groups, oversight, redress
Output Internal record; consult authority if risk unmitigated Notification to market surveillance authority

Article 27 explicitly lets you build the FRIA on top of an existing DPIA. The efficient sequence for a Turkish company serving the EU: run the DPIA first (you need it for KVKK and GDPR anyway), then extend it with the FRIA’s group-impact, oversight and redress sections. One assessment cycle, two compliant documents.

A seven-step FRIA workflow

  1. Scope: confirm you are actually in Article 27’s deployer categories before spending a euro.
  2. Map the decision: what does the system decide or materially influence, over what period, at what volume?
  3. Identify affected groups — including non-users affected by outputs (rejected applicants, priced-out customers) and vulnerable groups.
  4. Assess rights impacts per group: discrimination, exclusion from essential services, economic harm, dignity.
  5. Design oversight: who reviews, with what authority to override, on what escalation path.
  6. Build redress: complaint intake, human re-evaluation, correction of the model where patterns emerge.
  7. Document, notify, revisit — the FRIA is not one-and-done; update it when the use changes.

We are preparing a FRIA template mapped to KVKK DPIA practice for the Founder Academy. Until then, the glossary entries on high-risk AI systems and our AI & Algorithm Law practice are the starting points.

This article is for general information only and does not constitute legal advice. It reflects the position as of July 2026, including the omnibus revisions to the AI Act timeline.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals — including crypto-asset infrastructure, fintech and games — bringing a former startup founder's perspective to every engagement.

    View all posts
Considering a similar matter?Talk to counsel that moves at the speed of your round.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 13 July 2026 · last updated: 8 July 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.