DPIA & FRIA — Get started

Do you need a DPIA or FRIA?

DocLex reviews your documentation against GDPR and the AI Act, asks clarifying questions where the material is unclear, and collects the result in a structured report with source references — as a basis for your own assessment and sign-off.

Start analysis

Two mandatory assessments that complement each other

DPIA

Data Protection Impact Assessment

A structured assessment of the risks an AI system poses to data subjects' privacy and data protection rights.

Mandatory when processing is likely to result in high risk — e.g. large-scale profiling, processing of health data, or automated decisions with legal effects.

Legal basis: GDPR Art. 35 For: Data controllers Submitted to: Supervisory authority only in case of mandatory prior consultation (Art. 36)
FRIA

Fundamental Rights Impact Assessment

A broader analysis of how an AI system affects fundamental rights — including non-discrimination, privacy, freedom of expression and access to remedies.

Mandatory for public authorities deploying high-risk AI systems, and for certain private actors with publicly accessible services.

Legal basis: EU AI Act Art. 27 For: Public authorities and certain private companies High-risk AI: Defined in EU AI Act Annex III

Many organisations need both. They are ordered separately, and most documents can be used in both analyses.

From documents to report — what happens under the hood?

DocLex is not a simple form. Here is exactly what happens, from the moment you upload to when you receive your report.

1
You upload your documentation

Upload up to 5 files — system descriptions, data inventories, risk assessments, supplier documentation or technical specifications. PDF, Word and Excel are supported. Files are transmitted encrypted and are not stored permanently on our servers.

2
AI analysis Claude (Anthropic)

DocLex sends your documents to Claude — Anthropic's large language model — which reads and understands the full content. The model identifies the AI system's purpose, data flows, risk factors, parties involved and applicable legal requirements. The analysis takes seconds and is significantly more precise than simple keyword extraction.

3
Targeted follow-up questions

Based on the gap analysis, DocLex identifies points not sufficiently covered by your documents. You are presented with 3–5 targeted questions — e.g. about retention periods, third-party suppliers or oversight mechanisms. Your answers supplement the documentation and ensure a complete report.

4
Report generated with legal grounding DocLex Knowledge Graph

DocLex retrieves the relevant articles, guidelines and interpretations from the supervisory authorities via our legal knowledge base (Neo4j graph). The report is written with precise article references, the supervisory authority's DPIA format and structured risk assessments — not generic text.

5
You receive XLSX + Word by email

Within 2–3 minutes you receive two files: an XLSX spreadsheet in the supervisory authority's format and a formatted Word document. Both are structured by the elements of GDPR Art. 35(7) and EU AI Act Art. 27 — for your internal review and assessment.

Ready to get started?

Upload your documents and receive a structured DPIA and/or FRIA report with source references within minutes.

Start analysis
Questions about DPIA, FRIA or the AI Act? → See FAQ