About DocLex
What is DocLex?
DocLex is an automated compliance service that generates DPIA and FRIA reports for organisations using AI systems. Reports are based on GDPR Art. 35 and EU AI Act Art. 27.
Who is DocLex for?
DocLex is aimed at DPOs, lawyers, IT managers and public authorities who need to document their AI systems' compliance with GDPR and the EU AI Act.
Is DocLex legal advice?
No. DocLex generates structured compliance reports based on the information you provide. Reports should be reviewed by a lawyer or DPO before final submission to a supervisory authority.
DPIA and FRIA
What is a DPIA?
A DPIA (Data Protection Impact Assessment) is required by GDPR Art. 35 when processing of personal data is likely to result in a high risk to the rights and freedoms of natural persons.
It is mandatory for many AI systems that process personal data — in particular systems making automated decisions, large-scale profiling, or processing of special categories of data.
What is a FRIA?
A FRIA (Fundamental Rights Impact Assessment) is required by EU AI Act Art. 27 for public authorities and certain private operators deploying high-risk AI systems.
The FRIA documents how the AI system affects rights such as non-discrimination, privacy, freedom of expression and access to effective remedies.
When is a DPIA mandatory?
A DPIA is mandatory when processing is likely to result in a high risk — for example:
· Systematic and extensive profiling with significant legal effects
· Large-scale processing of special categories of personal data (health, biometric data, etc.)
· Systematic monitoring of a publicly accessible area
The Danish Data Protection Authority (Datatilsynet) has published a list of processing activities that always require a DPIA.
When is a FRIA mandatory?
A FRIA is mandatory for public authorities deploying high-risk AI systems under EU AI Act Art. 27, as well as for private companies using certain high-risk AI systems in publicly accessible services.
High-risk AI systems are defined in Annex III of the EU AI Act and include systems used in critical infrastructure, education, employment and access to public services.
What is the difference between a DPIA and a FRIA?
DPIA focuses on risks to the protection of personal data and is required by GDPR Art. 35. It assesses the likelihood and severity of risks to data subjects' rights and freedoms.
FRIA covers a broader range of fundamental rights — such as non-discrimination, freedom of expression and access to justice — and is required by EU AI Act Art. 27. The two assessments complement each other.
How DocLex works
What happens to my document?
Your document is automatically analysed to identify relevant compliance information. The analysis is performed via Claude (Anthropic), which extracts structured data about the AI system's purpose, data processing and risks.
The document is only used for report generation and is not stored permanently on our servers.
Does DocLex process personal data?
DocLex does not process personal data from end users. Only upload system descriptions and technical documentation — not documents containing sensitive personal information.
All processing takes place within the EU on servers in Denmark.
How much does it cost?
· DPIA report: EUR 499 excl. VAT
· FRIA report: EUR 499 excl. VAT
The price includes an XLSX template in the format recommended by the Danish Data Protection Authority (Datatilsynet) and a formatted Word document, both sent to your email.
How long does it take?
The report is typically generated within 2–3 minutes after payment and receipt of your answers to the follow-up questions. You will receive both files directly in your inbox.
Technical and Legal
Which legislation does DocLex cover?
DocLex covers:
· GDPR (Regulation (EU) 2016/679) — in particular Art. 35 on DPIA
· EU AI Act (Regulation (EU) 2024/1689) — in particular Art. 27 on FRIA
Reports reference specific articles and are structured in accordance with the guidelines of the relevant supervisory authorities.
Can the report be used as a basis for internal documentation and review?
The report is structured as internal compliance documentation containing all mandatory elements pursuant to GDPR Art. 35(7) and EU AI Act Art. 27.
A DPIA is generally not submitted to the supervisory authority — it is internal documentation that is only submitted if the processing is on the authority's list of activities requiring prior consultation (GDPR Art. 36).
We recommend that a DPO or lawyer reviews the report before internal sign-off, as it is based on the information you have provided and does not replace a professional legal assessment.
What happens if my document is insufficient?
If the uploaded material does not contain sufficient information to complete the analysis, DocLex will reject the document and ask you to upload more relevant documentation — such as a system description, data mapping or risk assessment.
You only pay if the analysis completes successfully. Rejected uploads are not charged.
Can I use DocLex if the AI system is supplied by a third party?
Yes. The FRIA obligation under EU AI Act Art. 27 applies to deployers — those who put a high-risk AI system into use — regardless of whether the system was developed in-house or procured externally.
Upload the documentation you have received from the provider (technical documentation, declaration of conformity, instructions for use) combined with your organisation's own system descriptions. The report will flag which elements require information from the provider.