The Catalan Data Protection Authority (APDCAT) today published desktop software that guides organizations through a Fundamental Rights Impact Assessment of artificial intelligence systems, with builds for Windows, macOS and Linux, according to the authority's website and an accompanying 12-page user manual.
The software, labelled version 1.0.0 on the download page, follows the sequence set out in APDCAT's Catalan FRIA model: a system description, a selection of affected rights, four risk ratings per right, mitigation measures and a recalculated residual risk. Results export as PDF or Word. The page carries a last-update stamp matching today's date; neither document states an earlier release date.
In Short
Catalonia's data protection regulator today published a downloadable program that helps an organization work out how an AI system could harm people's rights and what to do about it. That matters to public bodies, providers of public services and some lenders and insurers in Europe, because the EU's AI Act requires them to run this kind of check before deploying certain high-risk AI, and the program turns the job into a fixed set of forms with a four-level risk score. Organizations now get a ready-made template that exports a report in PDF or Word, while the legal date for most of these checks sits in December 2027 after the EU pushed it back.
What the authority published
APDCAT is the independent body that supervises personal data protection in the Catalan public sector and in private entities carrying out public functions, according to its website. The software is its first packaged implementation of a methodology it has promoted since early 2025.
The download page lists three builds - EinaFRIA-1.0.0-Linux, EinaFRIA-1.0.0-Windows and EinaFRIA-1.0.0-MacOS - each with a published SHA-256 checksum for integrity checks. According to the manual, the interface runs in Catalan, Spanish and English, and the language can be switched at any point without losing entered data. Two further downloads sit on the page: an example use case in the program's own file format, and the manual. APDCAT describes the example as illustrative, to be adapted to the characteristics and context of the system under review. The page also links the Catalan FRIA model itself, a PDF of about 1 MB, and the manual's introduction recommends keeping that reference document at hand during use.
On privacy of the data entered, APDCAT states that the application runs on the device and "does not establish remote connections". On the quality of output, it is equally direct: "The results depend on the information and assessments entered by the organization", which remains responsible for analysing them in the context of the specific system.
Lineage of the Catalan model
The methodology is older than the software. APDCAT presented the Catalan FRIA model to the Parliament of Catalonia on January 28, 2025, International Data Protection Day, describing it as the first methodology of its kind in Europe applied to specific cases, according to an APDCAT press release. Four real cases were assessed, according to the same release. Politecnico di Torino, whose professor Alessandro Mantelero led the working group behind the document, said the use cases showed the procedure could be streamlined by avoiding long checklists, according to the university.
Later in 2025, at the CIDAI 2025 congress, APDCAT's data protection officer Joana Marí Cardona said Croatia, Brazil and the Basque Country were already using the model as a reference, and that the authority was designing an application to automate risk identification and mitigation, according to a second APDCAT press release. The same release described parallel work on a combined model joining the fundamental rights assessment with the data protection impact assessment. The software published today matches that description, although the documents do not link the two explicitly.
The six-step workflow
The manual structures the work as six steps. Users move forwards and backwards freely, and data persists across steps.
Project data and Section A
Step 1 captures the system name, which is mandatory before a project can be saved, plus version, owner, the AI models used (GPT-4 and in-house classification models appear as examples) and a short description. Step 2, labelled Section A, poses six questions: the system's objectives, its characteristics, the countries where it will be offered, the types of data processed (personal, non-personal, special categories), the possible rights holders including vulnerable groups, and the parties involved in design, development and deployment along with their roles.
Section B: context and rights selection
Section B has three parts. Part 1 asks three context questions about international or regional human-rights instruments applied at operational level, relevant courts and fundamental rights bodies, and the most relevant decisions and provisions. Part 2 handles rights catalogs. Part 3 is the selection of potentially affected rights, each of which requires a written justification. The manual advises a conservative approach, stating that including a right and concluding that the impact is low is better than excluding a relevant one.
The software ships catalogs built on European and international instruments. One, called "Llista orientativa de drets a Catalunya", integrates rights, freedoms and principles from the EU Charter of Fundamental Rights, the Spanish Constitution and the Statute of Autonomy of Catalonia. The manual says the list is indicative, with no claim to exhaustiveness or legal relevance. Catalogs are switched on and off with a checkbox. A plus button imports a custom catalog in JSON format, and the format is verified automatically before import. A deactivated catalog can be restored from a dedicated tab. Deselecting a catalog that already had rights ticked keeps the data but drops those rights from the active assessment. Rights absent from every catalog can be added by name and category.
Sections C and D
Section C asks two questions: which policies and procedures already assess impact on fundamental rights, including stakeholder participation, and whether a specific assessment such as a data protection impact assessment or a biometrics assessment has been done.
Section D covers due diligence and stakeholder involvement in eight questions. They address the groups and communities affected, including during development; additional stakeholders such as civil society, experts, associations and journalists; other duty-bearers beyond the provider and the deployer, such as national authorities; whether business partners and service providers took part in the assessment; whether the AI provider assessed its own supply chain; whether the provider promoted fundamental rights standards or audits among its suppliers; whether provider and deployer publicly communicated the system's possible repercussions; and whether staff handling management and procurement received training on fundamental rights standards.
The per-right assessment
Step 6 is described by the manual as the core of the exercise. For every right selected in Section B, the program creates a subsection with four tabs. The first holds the justification, a narrative description of the impact and the ratings for four indicators, each with an optional text field for reasoning. The second displays automatically calculated preliminary results. The third records prevention and mitigation measures and asks for a fresh rating of the four indicators to estimate residual risk. The fourth shows the final table, where initial and residual global impact can be compared to check that the measures reduce risk satisfactorily.
The risk metric
All four indicators sit on one scale of four levels: low, medium, high and very high. Probability (P) measures how likely it is that the system causes harm to the right. Exposure (E) measures the share of the identified population that could be affected, from very few individuals to nearly all of them. Gravity (G) measures the intensity of harm, from minor to serious or irreversible. Effort (F) measures how hard the harm is to overcome, from easy, such as annoyance or irritation, to impossible, such as serious illness or death.
From those inputs the program derives three composite values. Likelihood is the combined chance that the risk occurs and touches a significant number of people, which suggests it draws on probability and exposure. Severity is the magnitude of harm, weighing both gravity and difficulty of recovery. Global Impact merges Likelihood and Severity and, per the manual, is the main indicator for decision-making.
The manual does not print the combination rules. It says the calculation thresholds follow the APDCAT Model FRIA methodology and points readers to the reference document for their justification. Outputs carry guidance. Low means acceptable risk, with the reasoning to be documented. Medium means moderate risk, with mitigation to be considered. High means elevated risk, with mitigation necessary. Very high means critical risk, calling for in-depth review and solid measures.
Saving, loading and export
Projects save as JSON files. Partial projects can be saved and resumed, and the manual notes that the program does not save automatically. Each save prompts for a location, proposing the system name as the default file name. Loading a project replaces current data. A loaded file can also serve as the starting point for a new version of a system or a similar one, without overwriting the original until it is saved under a different name.
PDF export produces a cover with system name, version, owner and date; a table of contents with interactive bookmarks in the viewer sidebar; all four form sections with the answers entered; the list of rights identified as potentially affected; the detailed assessment per right; and two summary tables, one for initial impact and one for residual impact. The manual recommends storing the JSON file alongside the PDF, since it is the data source for later review. A Word (.docx) export produces the same report in editable form.
Blank fields are allowed, according to the manual's FAQ, though an incomplete report will have empty sections and may not be valid for formal purposes. On review frequency, the manual says the assessment is to be revisited whenever the AI system changes significantly (a new version, new use cases, new datasets) or when the regulatory or social context shifts, with at least one annual review recommended for systems in production.
Where the documents differ
Do the two documents describe the same behaviour? Not entirely. The download page says the application does not establish remote connections and that an assessment can be completed without transmitting the entered information to external services. The manual, in section 7.2, says that on the first PDF export the program automatically downloads typographic resources, a step that can take several minutes and requires an internet connection; later exports run faster.
The statements can be reconciled if the download involves fonts and no project data, but neither document says so. The manual's FAQ does list a missing internet connection on the first export as a possible cause of failure. The manual adds that the Word export needs no internet connection but requires Microsoft Word to be installed on the machine.
A smaller inconsistency concerns vocabulary. The English download page names the four indicators as likelihood, exposure, severity and effort. The manual's Catalan labels instead call the third indicator gravity and reserve severity, together with likelihood, for computed values. Neither document specifies system requirements, licensing terms or a schedule for later versions.
The legal frame: Article 27 and a moving calendar
Article 27 of the AI Act requires a fundamental rights impact assessment before deployment of certain high-risk systems, according to the text published by the European Commission's AI Act Service Desk. The duty falls on deployers that are bodies governed by public law or private entities providing public services, and on deployers of the systems listed in points 5(b) and (c) of Annex III, which cover credit scoring and life and health insurance pricing. Systems in the area of Annex III point 2 are excepted. Where a data protection impact assessment already satisfies part of the duty, the new assessment complements it. Deployers may rely on earlier assessments or on those already carried out by the provider in similar cases. The article also tasks the AI Office with a questionnaire template, including through an automated tool; the APDCAT documents make no reference to such a template.
The date from which that duty applies has moved. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on July 24, 2026 and entered into force on July 27, 2026, setting December 2, 2027 as the new application date for the main obligations on stand-alone Annex III systems, according to Hunton Andrews Kurth. A provisional political agreement had been reached on May 7, 2026, according to Sidley Austin. Because Article 27 refers to the Article 6(2) category, which is the Annex III list, December 2, 2027 is the relevant horizon on that reading. The APDCAT documents themselves state no date.
The path there was uneven. Parliament's internal market and civil liberties committees backed fixed dates of December 2027 and August 2028 in March 2026, and then overnight negotiations in Brussels failed in late April 2026, leaving the original August 2, 2026 date standing at the time.
Why it matters for marketing and advertising
For advertising and marketing technology businesses the link is indirect but traceable. PPC Land reported in March that systems analysing employment history or financial data as audience signals may fall within high-risk categories. The Article 27 duty attaches to deployers, the organizations using a system, rather than to vendors. Its scope names credit and insurance use cases alongside public-sector and public-service deployers. Agencies and platforms serving banks, insurers or government bodies therefore sit one step away from the obligation, and their customers may need assessments of systems those vendors supply.
Section D of the APDCAT software makes that supply-chain angle concrete. It asks whether business partners and service providers took part in the assessment, whether the AI provider examined its own supply chain, and whether supplier audits on fundamental rights were promoted. A template that asks such questions of a deployer ends up generating requests for vendor documentation. The authority's page adds that the Catalan model can guide organizations beyond those named in Article 27, so uptake outside the legal perimeter is possible, although APDCAT's own 2025 account of Croatia, Brazil and the Basque Country using the model as a reference is the only adoption evidence in the materials.
The release also lands in a period of regulatory churn. A program built on a regional authority's methodology, published after the EU postponed the main high-risk dates, gives organizations an early structure for work that the law will require later. Whether the AI Office's own questionnaire template arrives, and how it compares, is not addressed in either APDCAT document.
Timeline
- January 28, 2025 - APDCAT presents the Catalan FRIA model to the Parliament of Catalonia on International Data Protection Day
- 2025 (exact date not stated) - At the CIDAI 2025 congress, APDCAT says it is designing an application to automate risk identification and mitigation
- March 18, 2026 - Parliament's internal market and civil liberties committees adopt a report backing fixed high-risk dates, by 101 votes to 9
- Late April 2026 - Overnight Brussels talks on the AI Act changes fail, leaving the August 2, 2026 date in place at the time
- May 7, 2026 - Provisional political agreement reached on the Digital Omnibus on AI
- July 24, 2026 - Regulation (EU) 2026/1744 published in the Official Journal
- July 27, 2026 - Regulation (EU) 2026/1744 enters into force
- October 7, 2026 (today) - APDCAT publishes version 1.0.0 of the FRIA application and its manual
- December 2, 2027 - New application date for main obligations on stand-alone Annex III high-risk systems
Related PPC Land coverage
- EU Parliament committee backs AI Act delay with fixed 2027 deadline - Covers the March 2026 committee report proposing December 2, 2027 and August 2, 2028 as fixed application dates for high-risk AI obligations.
- Brussels AI Act talks collapse - but the August 2026 deadline holds - Covers the failed overnight negotiations of late April 2026 and what the original August 2, 2026 date triggered at that point.
Summary
Who: The Catalan Data Protection Authority (APDCAT), the independent supervisor for personal data protection in the Catalan public sector and in private entities with public functions. The software targets organizations assessing AI systems, including deployers covered by Article 27 of the AI Act.
What: Version 1.0.0 of a desktop application, with a 12-page manual, that guides a Fundamental Rights Impact Assessment through six steps, rates four risk indicators per affected right on a four-level scale, computes Likelihood, Severity and Global Impact, and exports PDF or Word reports. Builds exist for Windows, macOS and Linux, in Catalan, Spanish and English.
When: Today, according to the download page's last-update stamp. The manual carries no date.
Where: Distributed through the APDCAT website from Barcelona. The software runs locally on the user's computer, with a first-run internet download for PDF export described in the manual.
Why: Article 27 of the AI Act requires certain deployers of high-risk AI systems to assess fundamental rights impact before deployment, and APDCAT built the software on its own FRIA model so that organizations have a structured template. The main high-risk dates have since moved to December 2, 2027, and the authority's page states that the model can also serve organizations outside the Article 27 perimeter.
Discussion