CIPP/E Study Guide (2026): Free Notes, Plan & Practice
Last reviewed: · By Victor Humenhuk (CIPP/E certified, 2026)
What this guide is
This is a complete, free study guide for the IAPP CIPP/E (Certified Information Privacy Professional/Europe) exam. I'm Victor Humenhuk - I passed the CIPP/E in 2026, along with the CIPP/US and AIGP, and I built this site around the notes I actually used. The full 1,248-question practice bank is a one-time $29 unlock when you're ready to test yourself; everything else here is free.
Everything you need to learn is here at no cost: 247 study notes covering the full body of knowledge, organised into chapter hubs that mirror how the material is examined, plus a free practice set so you can check where you stand - no signup needed for any of it. The only paid thing on this site is the full question bank, which is the part you use once the reading is done, when you want to find out whether you would actually pass.
This page does three jobs: it explains how the exam works, maps every domain of the syllabus to the right notes, and gives you a week-by-week plan to get from zero to a pass.
How the CIPP/E exam works
The facts below are verified against the IAPP's own pages. Details can change, so always check the current blueprint at iapp.org before you book.
| Feature | Detail |
|---|---|
| Questions | 90, all multiple choice - some scenario-based, and some multi-select items with no partial credit |
| Time | 2.5 hours, with an optional 15-minute break halfway through (the break splits the exam into two submitted halves - you cannot go back to the first half) |
| Passing score | 300 on a scale of 100-500. The IAPP is explicit that 300 does not represent 60%; raw scores are converted to the scale across exam forms |
| Scoring rules | No section minimums, no penalty for wrong answers - so never leave a question blank |
| Delivery | Computer-based, year-round: in person at Pearson VUE test centres or online via OnVUE remote proctoring. You must schedule and sit the exam within one year of purchase |
| Results | Immediate on screen - pass/fail plus your scaled score |
| Prerequisites | None. Anyone can register |
Two things worth knowing: the IAPP does not publish pass rates, so ignore any site claiming an official figure. And not every question counts - the IAPP has historically included unscored pilot questions among the 90, though the current split isn't stated on live pages, so check the current blueprint at iapp.org. The practical takeaway is the same either way: a question that feels impossible may not even be scored, so don't let it rattle you.
The body of knowledge, domain by domain
The CIPP/E syllabus breaks down into nine broad areas. Here's what each covers, with links to the hub and the notes I'd start with.
1. Origins, institutions and the legal framework. Where European data protection came from and who makes the rules: human rights foundations, Convention 108, the old Directive, and the EU institutions. Light on volume, but the exam does test it. Hubs: Origins, EU Institutions, Legislative Framework. Start with the GDPR itself, Convention 108 and the CJEU.
2. Personal data, controllers, processors and scope. The definitions everything else hangs on, plus Article 3's territorial reach. Scenario questions constantly turn on who the controller is and whether the GDPR applies at all. Hubs: Personal Data, Controllers & Processors, Territorial & Material Scope. Key notes: personal data's four building blocks, controller vs processor, the targeting and monitoring tests.
3. Principles, lawful bases and consent. Article 5, the six Article 6 bases, and the Article 9 regime for special category data. This is the heart of the exam - most scenario questions test whether you can pick the right principle or basis. Hubs: Article 5 Principles, Lawful Bases, Consent & Special Category Data. Key notes: the principles overview, consent's four conditions, legitimate interests.
4. Transparency and data subject rights. Articles 12-22: privacy notices, access requests, erasure, portability, objection and automated decision-making - including the timing rules examiners love. Hubs: Transparency, Data Subject Rights. Key notes: Article 13 vs Article 14, the right of access, erasure.
5. Security, breaches, accountability and the DPO. Article 32 security, the 72-hour breach clock, DPIAs, records of processing and when a DPO is mandatory. Full of testable numbers and thresholds. Hubs: Security & Breaches, Accountability, DPIAs & the DPO. Key notes: Article 33 notification, DPIAs, the DPO.
6. International data transfers. Adequacy, SCCs, BCRs, the Article 49 derogations - and the Schrems saga that reshaped EU-US transfers. Heavily examined and easy to get wrong if you only skim it. Hub: International Transfers. Key notes: Schrems II and the Data Privacy Framework, SCCs and transfer impact assessments, the Article 49 derogations.
7. Supervision, enforcement and fines. Supervisory authorities, the one-stop shop, the EDPB, and the two-tier fine structure under Article 83. Hub: Supervision & Enforcement. Key notes: the one-stop shop, the two fine tiers, Article 58 powers.
8. Employment, surveillance and marketing. The applied domains: employee monitoring, CCTV, biometrics, and the GDPR/ePrivacy rules on direct marketing and cookies. Hubs: Employee Data, Surveillance & Biometrics, Direct Marketing & ePrivacy. Key notes: why consent fails at work, CCTV, ePrivacy and cookies.
9. Internet technology and outsourcing. Cloud, adtech, IoT, AI and the EU AI Act, plus the Article 28 processor contract rules that govern outsourcing. Hubs: Internet Technology, Outsourcing & Processor Contracts. Key notes: cookies and tracking, AI and the AI Act, Article 28(3) contract terms.
When you want the condensed view, the quick reference hub collects the must-know EDPB guidance, landmark cases and a numbers cheat-sheet, and the blueprint coverage map shows how the notes line up against the official exam domains.
A week-by-week study plan
This is the five-week plan I'd give a friend starting from a reasonable baseline (you've heard of the GDPR, you can commit about an hour a day). If you work in privacy already, compress it to three weeks; if you're brand new, stretch it to seven or eight. The method throughout is active recall: read a note, close it, and try to reproduce the key rules from memory before moving on. Re-reading feels productive but tests poorly.
- Week 1 - Foundations and definitions. Work through Chapters 1-3 quickly (a day or two is enough), then slow right down for Chapter 4 and Chapter 5. Being able to identify the controller in a messy fact pattern is the single highest-value skill on this exam. Use the collapsible key-term questions on each topic page to quiz yourself as you go.
- Week 2 - Principles, lawful bases and transparency. Chapters 6, 7 and 8. Drill the six lawful bases until you can match each to a scenario instantly, and learn the Article 9 exceptions - the exam loves them.
- Week 3 - Rights, security and accountability. Chapters 9, 10 and 11. Memorise the deadlines cold: one month for rights requests, 72 hours for Article 33, 'without undue delay' for Article 34. The Article 33 vs 34 comparison is worth ten minutes on its own.
- Week 4 - Transfers, enforcement and the applied chapters. Give Chapter 12 two full days - transfers punch above their weight. Then Chapter 13, and move through 14-18, which mostly apply rules you already know to new contexts.
- Week 5 - Consolidate and test. Re-read the quick reference pages, take the free practice questions under exam conditions, and spend the rest of the week working the question bank. For every question you miss, go back to the linked topic note and re-learn it - wrong answers are the syllabus telling you where to look.
For exam-day tactics - timing, the break, how to handle scenario questions - see how to pass the CIPP/E.
Test yourself
Reading is half the job; the exam is a question-answering task, so practise it as one. Start with the free practice set - original exam-style questions, no payment, no signup, no catch. It's calibrated to the real thing: scenario stems, plausible wrong answers, and a worked explanation for every question.
If you want more volume - and in my experience volume is what turns a marginal candidate into a comfortable pass - the full question bank has 1,248 questions covering every chapter, each with a worked explanation. It's a one-time unlock with lifetime access: no subscription, no renewal, and it stays available after you pass for whenever you need a refresher.
My rule of thumb: when you're consistently scoring around 80% on fresh questions you've never seen, you're ready to book.
Frequently asked questions
Is this study guide really free? Yes. All 247 topic notes, the chapter hubs, the reference pages and the free practice questions cost nothing, with no signup wall in front of any of them. Only the full question bank is paid.
Do I need the official IAPP textbook or training? No - there are no prerequisites for the exam, and the IAPP doesn't require its own training. I'd still recommend downloading the official body of knowledge and exam blueprint from iapp.org so you can confirm the current domain weightings, but the notes here cover the syllabus in full.
How long does it take to prepare? In my experience, most people need four to eight weeks of steady part-time study. Experienced privacy professionals can do it faster; complete newcomers should allow longer. I've set out my honest view by background in is the CIPP/E exam hard?.
What score do I need to pass? 300 on a scale of 100-500. The IAPP states this does not simply mean 60% - raw marks are converted to the scale, and there are no per-section minimums. You find out whether you passed immediately at the end of the exam.