CIPP/E (Certified Information Privacy Professional - Europe)

IAPP (International Association of Privacy Professionals)

Complete guide to passing the CIPP/E (Certified Information Privacy Professional - Europe) exam on your first attempt.

HardHigh Search Volume
Key Information at a Glance
Cost

$550

Pass Rate

~60%

Validity

Lifetime (with annual maintenance fee)

Region

Global

Provider

IAPP (International Association of Privacy Professionals)

Salary Impact

$95k-$160k

Are you ready for CIPP/E (Certified Information Privacy Professional - Europe)?

Loading quiz...

Complete Overview

The CIPP/E, or Certified Information Privacy Professional/Europe, is the IAPP credential that tests knowledge of European data protection law, principally the GDPR, and the practical compliance work that follows from it. It is taken by data protection officers, privacy counsel, compliance managers, in-house lawyers, consultants and anyone whose job involves answering GDPR questions for a European operation, and the IAPP store lists the exam at $550. That price covers the exam attempt only, with the textbook, the online training and the practice exam sold separately.

The exam is 90 multiple-choice questions in 2.5 hours, of which 75 are scored and 15 are unscored pretest items that do not count toward your result. Scoring runs on a 100 to 500 scale with 300 as the pass mark, and the IAPP is explicit that 300 does not represent 60 percent: the cut score is set by beta testing and psychometric analysis, then mapped onto the 300 point. Halfway through, the exam offers a 15-minute break that splits the paper into two halves, and you must submit the first half before the break with no way back to those questions.

Delivery is through Pearson VUE, either at one of more than 6,000 test centres or through OnVUE remote proctoring from home or the office. The exam is available in English, French and German, with the French and German versions professionally translated and reviewed rather than machine translated. Once you buy the exam you have one year to schedule and sit it, and the IAPP recommends a minimum of 30 hours of study.

The body of knowledge splits into five domains, and the IAPP publishes a blueprint that gives a minimum and maximum number of questions per domain rather than percentage weights. Domain II, European Data Protection Law and Regulation, is the heaviest at 18 to 28 questions, followed by Domain III, European Data Processing, at 13 to 21. Blueprint version 2.3.0, effective 1 September 2025, reorganised the old three-domain structure into these five without changing the number of questions apportioned to any topic. Its listed content includes the NIS and NIS 2 Directives, the EU Artificial Intelligence Act, Convention 108+, the EU-US Data Privacy Framework and transfer impact assessments.

Certification is a two-year term. Keeping it active takes 20 continuing privacy education credits per certification per term plus a $250 certification maintenance fee, or an IAPP membership that covers the fee. The CIPP/E is accredited by the ANSI National Accreditation Board under ISO/IEC 17024:2012, one of four IAPP certification programmes carrying that accreditation. Holding a CIPP alongside a CIPM, CIPT or AIGP also qualifies you for the IAPP's Fellow of Information Privacy designation.

Why Get CIPP/E (Certified Information Privacy Professional - Europe) Certified?

The CIPP/E is accredited by the ANSI National Accreditation Board under ISO/IEC 17024:2012, which is the standard European employers and regulators look for when a job description names a privacy certification.

The exam is available in English, French and German, with the translated versions produced by professional translation firms under ISO-certified quality assurance and reviewed by native speakers and subject matter experts, so a non-English sitting is not a second-class version.

The blueprint effective 1 September 2025 covers the EU Artificial Intelligence Act, the NIS and NIS 2 Directives, the EU-US Data Privacy Framework and transfer impact assessments, so the syllabus tracks the questions organisations are actually asking now.

At $550 for the exam with a 20-credit continuing education requirement per two-year term, the total cost of ownership is a fraction of a legal qualification while covering the same GDPR ground a compliance role needs daily.

The IAPP's own Salary and Jobs Report 2025-26, built on more than 1,600 responses from over 60 countries, puts the median base salary at $123,000 for professionals working solely in privacy and $169,700 for those covering privacy and AI governance together. At least 77 percent of respondents held an IAPP certification.

Holding CIPP/E plus CIPM gives you both the law and the programme management side, which is the combination most organisations look for when appointing a data protection officer under GDPR Article 37.

The IAPP recommends a minimum of 30 hours of study, which makes CIPP/E one of the few senior-recognised credentials you can realistically prepare for alongside a full-time role in about eight to ten weeks.

Exam Format & Structure

Duration

2.5 hours, with a 15-minute break offered at the halfway point

Questions

90 questions, of which 75 are scored and 15 are unscored pretest items

Passing Score

300 on a scale of 100 to 500. The IAPP states that 300 does not represent 60 percent and that the cut score is set by beta testing and psychometric analysis before being mapped to 300

Question Types

  • Multiple-choice questions with a single correct answer
  • Multiple-choice questions with more than one correct answer, flagged as such on the question
  • Scenario items where you read a fact pattern and answer several questions about it

Delivery Method

Computer-based through Pearson VUE, either at a test centre from a network of more than 6,000, or through OnVUE remote proctoring

Exam Domains & Topics

Introduction to European data protection
not published

The IAPP blueprint sets this domain at 7 to 13 questions of the 90. It covers the historical rationale for data protection, the human rights instruments and early laws that shaped it, the European institutions that make and interpret the rules, and the legislative framework that runs from the 1981 Council of Europe Convention through to the GDPR and the EU AI Act.

Key Topics to Master:

  • Historical rationale for data protection and early human rights instruments
  • OECD Guidelines, the Treaty of Lisbon, Convention 108 and Convention 108+
  • How the harmonised European approach developed, and challenges such as Brexit
  • Roles of the Council of Europe, the European Court of Human Rights, the European Parliament, the European Commission, the European Council and the Court of Justice of the European Union
  • The 1981 Council of Europe Convention on automatic processing of personal data
  • Directive 95/46/EC, the ePrivacy Directive 2002/58/EC as amended, and the Electronic Commerce Directive 2000/31/EC
  • Principles and goals of GDPR (EU) 2016/679
  • The NIS and NIS 2 Directives and the EU Artificial Intelligence Act
European data protection law and regulation
not published

This is the largest domain in the blueprint at 18 to 28 questions. It covers the definitional core of the GDPR, the security obligations that attach to processing, and data subject rights in full. The rights competency alone is set at 8 to 12 questions, so a candidate who cannot separate erasure from restriction from objection loses more points here than anywhere else on the paper.

Key Topics to Master:

  • Personal data, sensitive personal data and special categories of personal data
  • Pseudonymous versus anonymous data and the difference between them
  • Controller, processor and data subject, with EDPB guidance on the distinction
  • Appropriate technical and organisational measures such as encryption and access controls
  • Breach notification requirements and risk reporting, with EDPB guidance
  • Vendor management and sharing personal data with third parties
  • Rights of access, rectification, erasure and the right to be forgotten
  • Rights of restriction, objection and data portability, plus rights around automated decision-making and profiling
  • Consent and the right of withdrawal, and restrictions on data subject rights
European data processing
not published

The blueprint sets this domain at 13 to 21 questions. It covers the processing principles in GDPR Article 5, the six lawful bases and special category processing, transparency and privacy notices, and the whole international transfer regime including the Schrems litigation and the mechanisms that survived it.

Key Topics to Master:

  • Fairness and lawfulness, purpose limitation, proportionality, accuracy, storage limitation and integrity and confidentiality
  • The lawful bases: consent, contractual necessity, legal obligation, vital interests, public interest and legitimate interest
  • Processing of special categories of personal data
  • The transparency principle, key components of privacy notices and layered notices
  • The rationale for prohibiting transfers and the concept of adequate jurisdiction
  • Safe Harbor, Privacy Shield, the Schrems decisions and the EU-US Data Privacy Framework
  • Standard Contractual Clauses and Binding Corporate Rules
  • Codes of conduct, certifications and derogations
  • Transfer impact assessments and EDPB guidance on them
European data protection: scope and accountability
not published

The blueprint sets this domain at 8 to 18 questions, the widest range of any domain. It covers who the GDPR applies to and where, the accountability duties that flow from that, the supervisory architecture from national authorities up to the EDPB and EDPS, and the consequences when things go wrong, including fines, class actions and compensation.

Key Topics to Master:

  • Establishment and non-establishment in the EU, with EDPB guidance
  • Territorial and material scope of the GDPR and its exemptions
  • Accountability duties of controllers, joint controllers and processors
  • Data protection by design and by default
  • Documentation obligations and cooperation with regulators
  • Data protection impact assessments and the established criteria for conducting one
  • The mandatory data protection officer requirement and the role of auditing in a privacy programme
  • Roles and powers of the EDPB, the EDPS and national supervisory authorities, and the lead supervisory authority concept
  • GDPR infringement procedures, fine tiers, class actions and compensation to data subjects
Compliance with European data protection law and regulation
not published

The blueprint sets this domain at 8 to 16 questions. It is the applied domain, covering four settings where GDPR compliance gets difficult: the employment relationship, surveillance, direct marketing, and internet technology. Questions here are usually scenario based and ask what a controller should do, not what the law says in the abstract.

Key Topics to Master:

  • Legal basis for processing employee data, personnel record storage and the risks in handling employee data
  • Workplace monitoring, data loss prevention and bring your own device programmes
  • EU works councils and whistleblowing systems
  • Surveillance by public authorities and the laws on interception of communications
  • CCTV, geolocation and biometrics or facial recognition, with EDPB guidance
  • Marketing compliance requirements and online behavioural targeting
  • Cloud computing compliance issues
  • Web cookies, social media platforms and dark patterns
  • Search engine marketing, and the compliance and ethical issues raised by artificial intelligence and machine learning

Recommended Study Plan

Week 1: Set the baseline and get the current blueprint
6-8 hours
  • 1Download the current CIPP/E Body of Knowledge and Exam Blueprint from iapp.org and check the version and effective date on the cover, since the IAPP reviews it annually and gives 90 days notice of changes
  • 2Copy the five domains and their question ranges into a tracker so you know Domain II carries 18 to 28 questions and Domain I only 7 to 13
  • 3Buy the exam and note the one-year deadline to schedule and sit it
  • 4Read GDPR Articles 1 to 11 in the official text, not in a summary
  • 5Decide now between a Pearson VUE test centre and OnVUE, because the reschedule deadlines differ sharply
Week 2: Domain I: origins, institutions and legislative framework
8-10 hours
  • 1Learn what Convention 108 did and what Convention 108+ changed
  • 2Build a one-page map distinguishing the Council of Europe, the European Council, the Council of the EU, the Commission, the Parliament, the CJEU and the ECHR, because these are the questions candidates lose to confusion rather than ignorance
  • 3Read the recitals to Directive 95/46/EC and note what the GDPR carried over
  • 4Skim the NIS 2 Directive and the EU AI Act for their stated purpose and scope, which is the depth Domain I asks for
Week 3: Domain II part one: core definitions and security
10-12 hours
  • 1Work through GDPR Articles 4, 5, 32, 33 and 34 line by line
  • 2Write out the difference between pseudonymous and anonymous data with a worked example, since this distinction recurs across domains
  • 3Learn the 72-hour breach notification obligation, who it runs to and when data subjects must also be told
  • 4Read the EDPB guidelines on controller and processor concepts and take notes on the joint controller examples
Week 4: Domain II part two: data subject rights
10-12 hours
  • 1Read GDPR Articles 12 to 23 and build a table with one row per right: scope, time limits, grounds for refusal and interaction with other rights
  • 2Learn where restriction and objection differ, because scenario questions hinge on it
  • 3Study Article 22 on automated decision-making including profiling, and the exceptions
  • 4Read the EDPB guidelines on the right of access and on the right to be forgotten
  • 5Self-test on 8 to 12 rights questions, matching the blueprint weighting for this competency
Week 5: Domain III part one: principles, lawful bases and transparency
10-12 hours
  • 1Memorise the six lawful bases and be able to identify which applies in a scenario, plus the extra Article 9 conditions for special category data
  • 2Learn the legitimate interests balancing test as a three-step structure you can apply on the spot
  • 3Study Articles 13 and 14 and list what a privacy notice must contain in each case
  • 4Understand why layered notices exist and what the EDPB says about transparency
Week 6: Domain III part two: international transfers
10-12 hours
  • 1Trace the chain from Safe Harbor to Schrems I to Privacy Shield to Schrems II to the EU-US Data Privacy Framework, with what each decision actually held
  • 2Learn the difference between an adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, codes of conduct, certifications and Article 49 derogations
  • 3Study what a transfer impact assessment is for and what EDPB guidance says about supplementary measures
  • 4Take the IAPP practice exam for the first time and score it by domain rather than overall
Week 7: Domain IV: scope, accountability and enforcement
10-12 hours
  • 1Work through Article 3 on territorial scope, including the targeting and monitoring limbs, and Article 2 on material scope and exemptions
  • 2Learn when a DPIA is mandatory under Article 35 and what the established criteria are
  • 3Learn when a DPO is mandatory under Article 37 and what independence requirements attach
  • 4Study the one-stop-shop and lead supervisory authority mechanism, and how the EDPB consistency mechanism resolves disputes
  • 5Memorise the two fine tiers in Article 83 and which infringements fall into each
Week 8: Domain V: applied compliance
10-12 hours
  • 1Study employment data: lawful bases in the employment context, personnel record retention, monitoring limits and BYOD
  • 2Learn the role of works councils and the rules on whistleblowing systems
  • 3Cover CCTV, geolocation and biometric processing, with the EDPB guidance on each
  • 4Study the ePrivacy rules on cookies alongside GDPR consent, since candidates commonly answer the cookie questions using GDPR alone
  • 5Read the EDPB material on dark patterns on social media platforms and the compliance issues around AI and machine learning
Week 9: Full-length practice and gap closure
8-10 hours
  • 1Sit a full 90-question practice run in 2.5 hours, including a 15-minute break at the halfway mark to rehearse the real structure
  • 2Practise submitting the first half without going back, because the real exam does not let you return to those questions
  • 3Score by domain and rework the two weakest against the blueprint ranges
  • 4Reread the GDPR articles behind every question you got wrong rather than the explanation alone
Week 10: Exam week
6-8 hours
  • 1Confirm the name on your MyIAPP profile exactly matches the ID you will present, and edit it in Edit My Profile if it does not
  • 2For a test centre, plan to arrive 15 minutes early and confirm you have two qualifying forms of ID that meet Pearson VUE's requirements
  • 3For OnVUE, use a personal computer rather than a work-issued one, turn off any VPN and run the system check on the same network you will test on
  • 4Review only your rights table, lawful bases table and transfer mechanisms table
  • 5After the exam, buy the certification maintenance fee or IAPP membership so the certification activates

Ready to pass CIPP/E (Certified Information Privacy Professional - Europe)?

Get 500+ practice questions, video walkthroughs, and a pass guarantee.

94% pass rate on first attempt
$275$138

Best Study Resources

CIPP/E Body of Knowledge and Exam Blueprint

Official blueprint

The authoritative document listing all five domains, their competencies, their performance indicators and the minimum and maximum number of exam questions per domain and per competency. Available in English, French and German. Check the version and effective date, since the IAPP updates it annually.

Free

IAPP Certification Candidate Handbook

Official policy document

Covers scheduling, the 48-hour test centre reschedule deadline, the OnVUE rules, the 15-minute midpoint break, the 100 to 500 scoring scale, the seven-day minimum before a retake appointment and the no-show policy. Read it before booking, not after.

Free

CIPP/E exam registration in the IAPP store

Official exam purchase

Buys the exam attempt only. The listing states the exam must be completed within one year of purchase and that the textbook, practice exam and online training are separate purchases.

$550

European Data Protection: Law and Practice

Official textbook

The IAPP textbook written against the CIPP/E body of knowledge. It is the closest thing to a single source that follows the domain structure, and it is the reference the exam development board works from.

Priced separately in the IAPP store

The GDPR official text on EUR-Lex

Primary legal source

Regulation (EU) 2016/679 in full, in every official EU language. Many CIPP/E questions are article-specific, so reading Articles 4, 5, 6, 9, 12 to 23, 32 to 35, 37, 44 to 49 and 83 in the original beats any summary.

Free

European Data Protection Board guidelines and opinions

Regulatory guidance

The blueprint names EDPB territory across the domains: controller and processor concepts, breach notification, data subject rights, lawful bases including the 2024 legitimate interests guidelines, international transfers and transfer impact assessments, and the notion of main establishment. Read the guidance the blueprint points to rather than summaries of it.

Free

IAPP CIPP/E practice exam

Official practice test

The only practice material built by the IAPP against the current body of knowledge. Use it to test pacing across 90 questions and 2.5 hours as well as content.

Priced separately in the IAPP store

IAPP CPE policy

Official policy

Sets out the 20 credits per certification per two-year term, the recommendation to submit within 90 days of the activity, the carryover of up to 10 excess credits earned in the last six months of a term, and how multiple certifications align to your first earned certification end date.

Free

IAPP CIPP/E free study materials and study guide

Official free resources

IAPP publishes a study guide with exam format explanation and sample questions, plus a set of free study materials, on the CIPP/E certification page. Start here before spending on third-party courses.

Free

Court of Justice of the European Union case law on data protection

Primary legal source

The blueprint requires understanding transfers in light of fundamental CJEU case law. Reading the Schrems I and Schrems II judgments, and the Google Spain right to be forgotten decision, gives you the reasoning behind several questions.

Free

Common Mistakes to Avoid

Studying a GDPR summary blog or a third-party course instead of the article text, then failing article-specific questions.

The blueprint asks you to know lawful processing bases, the criteria for a DPIA and the fine tiers at a level of precision summaries drop. Read Articles 5, 6, 9, 12 to 23, 32 to 35 and 83 in the official EUR-Lex text and note the exact conditions and time limits.

Confusing the Council of Europe, the European Council and the Council of the European Union.

Domain I asks about the roles and functions of these institutions, and they are three different bodies with different memberships and functions. Build a one-page comparison table early, since these are free points once the distinction sticks.

Treating the right to restriction and the right to object as interchangeable.

The data subject rights competency carries 8 to 12 questions, the single heaviest block on the exam. Learn each right separately: its trigger, its time limit, the grounds a controller can refuse on, and what the controller must do while a request is pending.

Answering cookie questions using the GDPR alone.

Cookie consent obligations come from the ePrivacy Directive 2002/58/EC as amended, with the GDPR supplying the consent standard. Domain I names the ePrivacy Directive and Domain V names web cookies, so study both instruments together.

Learning the transfer mechanisms as a list of names without knowing what each one requires.

Domain III asks about the content, purpose and use of Standard Contractual Clauses and Binding Corporate Rules, the role of codes of conduct and certifications, the rationale for derogations and the goal of a transfer impact assessment. Learn what each mechanism obliges the exporter to do, not just that it exists.

Using an outdated body of knowledge downloaded years ago.

The IAPP reviews the body of knowledge every year and gives at least 90 days notice before new content appears. Body of Knowledge 1.3.3 and Exam Blueprint 2.3.0, both effective 1 September 2025, split the old Domain II into three domains and added three EDPB documents: Guidelines 1/2024 on legitimate interests under Article 6(1)(f), Opinion 22/2024 on processor and sub-processor obligations, and Opinion 04/2024 on the notion of main establishment. Redownload both and check the version number on the cover.

Planning to go back and change first-half answers after the break.

The 15-minute break splits the exam into two halves, and you must submit the first half before taking it, with no return. Treat the first 45 questions as a self-contained paper and resolve everything you flagged before you submit.

Assuming a passing score of 300 means answering 60 percent correctly.

The IAPP explicitly states that 300 does not represent 60 percent and warns against averaging the percentages on your score report. The raw number of correct answers behind a 300 varies by exam form, so aim well above what feels like a bare pass.

Booking OnVUE on a work laptop, then being blocked by corporate software or a VPN at check-in.

The candidate handbook states OnVUE exams should be taken on a personal computer and that candidates may not use a VPN. Run the OnVUE system check on the exact machine and network you will test on, in the room you will test in.

Exam Day Tips

  • 1

    Check that the first and last name on your MyIAPP profile exactly matches the ID you will present, and edit it under Edit My Profile in advance. The name is verified at check-in.

  • 2

    At a Pearson VUE test centre, arrive 15 minutes early. Arriving late can mean being recorded as a no-show, which consumes the exam attempt and forfeits all fees.

  • 3

    Bring two qualifying forms of ID to a test centre. Only IDs meeting Pearson VUE's test centre requirements are accepted, and candidates turned away for improper identification forfeit their fees.

  • 4

    No reading material of any kind is admitted into the test centre exam room, and no electronic devices. Some centres have lockers and some will ask you to leave devices in your vehicle, so check before you travel.

  • 5

    For OnVUE, the check-in Begin button appears 30 minutes before your appointment. You will photograph yourself and a government-issued ID, and AI plus face recognition verifies the match, with a human greeter as fallback. You can opt out of AI verification by contacting Pearson VUE in advance, which may delay scheduling.

  • 6

    OnVUE requires four webcam photos of your surroundings and possibly a work area scan, so clear the desk and walls of anything that looks like study material before check-in.

  • 7

    Under OnVUE rules you may not leave your workspace outside scheduled breaks, may not wear headphones, may not speak or mouth words, and may not have food. One beverage is allowed.

  • 8

    Take the 15-minute break offered at the halfway point even if you feel fine. It is built into the appointment and it is the only structured pause, but remember it locks the first half.

  • 9

    At a test centre you may leave the room for a restroom break at any time, but the timer keeps running and no extra time is given.

  • 10

    Results appear immediately on screen as a pass or fail with your score on the 100 to 500 scale, and an email follows with instructions for accessing a section breakdown. Allow up to two business days for results to show in the IAPP system.

  • 11

    You are not certified until you hold IAPP membership or have purchased the certification maintenance fee. Sort that out promptly, because the digital certificate is not issued until the certification is active.

Career Paths & Salary Ranges

Data protection officer

The statutory role under GDPR Article 37, required for public authorities and for controllers whose core activities involve large-scale regular monitoring or large-scale special category processing. Domain IV covers the mandatory DPO requirement directly.

IAPP's 2025-26 report puts the privacy-only median at $123,000; DPO roles sit above it

Privacy counsel or in-house data protection lawyer

Advises on lawful bases, transfer mechanisms and regulator engagement. The CIPP/E is often listed alongside a legal qualification rather than instead of one, and it is the credential that signals GDPR depth specifically.

Above the $123,000 privacy-only median in the IAPP's 2025-26 report

Privacy programme manager

Runs records of processing, DPIAs, vendor due diligence and breach response. Pairing CIPP/E with the IAPP CIPM covers both the legal knowledge and the programme management skills this role uses.

Around the $123,000 privacy-only median in the IAPP's 2025-26 report

Privacy consultant

Advises multiple clients on GDPR readiness, transfer impact assessments and remediation after regulator contact. Consultancies commonly require CIPP/E before client-facing work because it is ANAB accredited and therefore defensible.

At or above the $123,000 privacy-only median, depending on billable seniority

Compliance manager with privacy responsibility

Holds privacy alongside broader regulatory compliance in a financial services, healthcare or technology organisation. Domain V, covering employment data, surveillance, marketing and cloud, is the part of the syllabus this role uses most.

Below the $123,000 privacy-only median where privacy is one duty among several

Privacy analyst or data protection officer support

Handles data subject access requests, maintains processing records and drafts privacy notices. The rights competency and the transparency competency in the blueprint map directly onto the daily work.

Well below the $123,000 privacy-only median; this is the entry rung

Prerequisites & Requirements

  • There are no formal prerequisites for the CIPP/E. No degree, legal qualification or minimum experience is required to buy the exam.
  • The IAPP recommends a minimum of 30 hours of study for each of its certifications.
  • You must complete the exam within one year of purchasing it.
  • IAPP membership or a purchased certification maintenance fee is required for a passed exam to become an active certification in good standing.
  • You need two qualifying forms of ID for a test centre appointment, or one government-issued photo ID for OnVUE check-in, matching the name on your MyIAPP profile.

Frequently Asked Questions

How many questions is the CIPP/E and how long is the exam?

The CIPP/E is 90 questions in 2.5 hours. Of those, 75 are scored and 15 are unscored pretest items that do not affect your result. A 15-minute break is offered halfway through, dividing the exam into two halves of 45 questions each.

What is the passing score for the CIPP/E?

You need 300 or above on a scale of 100 to 500. The IAPP states plainly that 300 does not represent 60 percent. The cut score is determined by beta testing, psychometric analysis and review by the exam development board, then mapped onto 300, so the raw number of correct answers behind a pass varies between exam forms.

How much does the CIPP/E exam cost?

The IAPP store lists the CIPP/E exam at $550 in US dollars, the same price for members and non-members, and the IAPP prices its certifications globally rather than by region. That fee covers the exam attempt only. The textbook, online training and practice exam are separate purchases, and the certification maintenance fee is $250 per two-year term.

What happens if I fail the CIPP/E?

You purchase a new exam, which becomes available once your result appears in your MyIAPP profile. The candidate handbook states that retake candidates cannot schedule an appointment for a date sooner than seven days after their previous attempt. Retakes are offered at a discounted price for candidates who already hold an IAPP certification.

How long do I have to sit the exam after buying it?

One year from purchase. The IAPP store listing and the certification process page both state that the exam must be scheduled and completed within one year, so buy it when you are ready to start studying rather than well ahead.

Can I take the CIPP/E at home?

Yes, through OnVUE, Pearson VUE's remote online proctoring platform. The alternative is an in-person appointment at one of more than 6,000 Pearson VUE test centres. Both are scheduled through the Schedule button in your MyIAPP profile.

What ID do I need for the CIPP/E?

At a test centre you need two qualifying forms of ID that meet Pearson VUE's test centre requirements. For OnVUE you photograph yourself and one government-issued ID at check-in, and AI checks that the ID is legal, current and name-matched before face recognition compares the photo to you. Candidates turned away for improper identification forfeit all exam fees.

Can I use notes, the GDPR text or a calculator during the CIPP/E?

No. The candidate handbook states that no reading material of any kind is admitted into the test centre exam room and no electronic devices are allowed. OnVUE requires four webcam photos of your surroundings and possibly a work area scan to confirm no study materials are present. The exam is closed book.

How long do results take?

Results are immediate. The screen displays pass or fail along with your score on the 100 to 500 scale as soon as you finish, and you receive an email with instructions for accessing a section breakdown. Allow up to two business days for the result to appear in the IAPP system.

How long is the CIPP/E valid?

The certification runs in two-year terms. To keep it active you submit 20 continuing privacy education credits per certification per term and pay the $250 certification maintenance fee, or hold IAPP membership which covers the fee. If you hold more than one IAPP certification, all terms align to the end date of your first earned certification.

What counts as a CPE credit for CIPP/E maintenance?

IAPP-purchased content is credited automatically. Advisory board participation, conducting trainings and attending IAPP-sponsored events also count. The IAPP recommends submitting credits within 90 days of the activity, and allows up to 10 excess credits earned in the last six months of a term to carry into the next term.

Are accommodations available?

Yes. When you click Schedule in MyIAPP you are asked whether you require special accommodations, and selecting yes notifies the IAPP certification team who will contact you. Accommodations include measures such as extra time and a sign language interpreter. Approved documentation is deleted one year after approval, so you must reapply if you test again after that.

Can I reschedule or cancel my exam appointment?

For an in-person test centre appointment you can reschedule or cancel up to 48 hours before the appointment time. For an OnVUE appointment you can reschedule or cancel up to 15 minutes past the scheduled time. You are not rescheduled until you receive the confirmation email from Pearson VUE.

What happens if I miss my exam appointment?

The result is recorded as a no-show, the exam attempt is consumed and it cannot be rescheduled. A new exam must be purchased. The IAPP will only consider reopening a no-showed exam under extenuating circumstances such as a medical emergency, handled case by case through Pearson VUE.

What languages is the CIPP/E offered in?

English, French and German. The IAPP states the French and German versions were translated from the English exam by professional translation firms with ISO-certified quality assurance, reviewed multiple times by native speakers and subject matter experts, and that no machine translation was used. The body of knowledge is published in all three languages.

How does the CIPP/E compare to the CIPM?

The CIPP/E tests knowledge of European data protection law, while the CIPM tests how to build and run a privacy programme regardless of jurisdiction. The two are complementary, and holding both is the combination most often sought for a data protection officer appointment. Both are ANAB accredited under ISO/IEC 17024:2012 and both carry the same 20 CPE per two-year term requirement.

How does the CIPP/E compare to the CIPP/US or the AIGP?

CIPP/US covers United States privacy law rather than European, so the two share almost no substantive content and privacy professionals working across both regions often hold each. The AIGP, the IAPP's AI Governance Professional credential, covers AI governance specifically. The CIPP/E now touches the EU AI Act and AI compliance issues in Domains I and V, but at an awareness level rather than the depth AIGP goes to.

Is the CIPP/E accredited?

Yes. The IAPP's CIPM, CIPP/E, CIPP/US and CIPT credentials are accredited by the ANSI National Accreditation Board under ISO/IEC 17024:2012. The body of knowledge document notes that this accreditation means the credentials meet a global benchmark and are consistent and comparable worldwide.

Which domain should I spend the most time on?

Domain II, European Data Protection Law and Regulation, carries 18 to 28 of the 90 questions in the published blueprint, the largest range of any domain. Within it, the data subject rights competency alone is set at 8 to 12 questions. Domain III, European Data Processing, is next at 13 to 21.

50% OFF

Pass CIPP/E (Certified Information Privacy Professional - Europe), Guaranteed

94% pass rate on first attempt

500+ Real QuestionsUpdated weekly
Video Walkthroughs20+ hours
Pass or Full RefundGuaranteed
Lifetime AccessFree updates
SAVE $137
$138
$27550% OFF

One-time • Lifetime access

Secure Instant
4.9/5 (2,847 reviews)
30-Day Guarantee, Pass or get 100% refund