CDPSE
What should you ask in a CDPSE interview, and how should candidates answer?
A CDPSE says someone can design privacy into data and systems. These questions test that work in practice, with what a strong answer covers. Candidates get the questions to prepare for and three to ask back.
What should an employer ask a CDPSE candidate?
Each question maps to an area of the role, so you test what the role needs. Score each answer 1 to 4 on the free scorecard below.
How do you turn privacy requirements into technical controls?
Listen for: Map each requirement to a control, an owner and a test, and keep the mapping current.
Privacy governance
Who decides what personal data a system may process?
Listen for: The business owner with privacy and legal input, recorded and reviewed on change.
Privacy governance
How do you design access control for personal data?
Listen for: Least privilege, role-based access, privileged access controls, and regular reviews.
Privacy architecture
Where do encryption and tokenization fit?
Listen for: Encryption protects data at rest and in transit; tokenization removes real values from systems that do not need them.
Privacy architecture
How do you log access to personal data without over-collecting?
Listen for: Log who, what and when, keep logs only as long as needed, and protect them.
Privacy architecture
How do you find personal data across our systems?
Listen for: Discovery tools, data flow maps and owners who confirm what is there.
Data lifecycle
How do you enforce retention and deletion?
Listen for: Rules in code where possible, scheduled jobs, and evidence they ran.
Data lifecycle
How do you handle personal data in test environments?
Listen for: Synthetic or masked data by default, and approved exceptions only.
Data lifecycle
CDPSE interview scorecard
CDPSE interview scorecard
Candidate: ______ Interviewer: ______ Date: ______
| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How do you turn privacy requirements into technical controls? | Map each requirement to a control, an owner and a test, and keep the mapping current. | |
| 2 | Who decides what personal data a system may process? | The business owner with privacy and legal input, recorded and reviewed on change. | |
| 3 | How do you design access control for personal data? | Least privilege, role-based access, privileged access controls, and regular reviews. | |
| 4 | Where do encryption and tokenization fit? | Encryption protects data at rest and in transit; tokenization removes real values from systems that do not need them. | |
| 5 | How do you log access to personal data without over-collecting? | Log who, what and when, keep logs only as long as needed, and protect them. | |
| 6 | How do you find personal data across our systems? | Discovery tools, data flow maps and owners who confirm what is there. | |
| 7 | How do you enforce retention and deletion? | Rules in code where possible, scheduled jobs, and evidence they ran. | |
| 8 | How do you handle personal data in test environments? | Synthetic or masked data by default, and approved exceptions only. |
Source: https://credentialpress.com/guides/cdpse-interview-questions
Which questions should a CDPSE candidate prepare for?
Why CDPSE?
How to answer: It shows you can engineer privacy, not only govern it. Name a system you changed.
Tell me about a data flow you mapped.
How to answer: What you found, and what changed because of it.
How do you work with legal?
How to answer: Translate their requirements into specifications, and send back the trade-offs.
Which privacy-enhancing technologies have you deployed?
How to answer: Name them and the result.
What should a candidate ask the employer?
- Is there a data inventory, and who keeps it current?
- How are privacy requirements fed into engineering work?
- Which systems hold the most sensitive data?
Where next?
Also free: the CDPSE mind map and the CDPSE 10-question quiz, plus every other credential on our study tools page. For the full syllabus, the CDPSE Exam Guide and the CDPSE Practice Questions go domain by domain.
Frequently asked questions
What should an employer ask a CDPSE candidate?
Questions that test each exam domain in practice, for example: How do you turn privacy requirements into technical controls? Who decides what personal data a system may process? How do you design access control for personal data?
What should a CDPSE candidate ask the employer?
Is there a data inventory, and who keeps it current? How are privacy requirements fed into engineering work? Which systems hold the most sensitive data?
How should a candidate prepare for a CDPSE interview?
It shows you can engineer privacy, not only govern it. Name a system you changed.
Which books go deeper on CDPSE?

A study companion for the ISACA Certified Data Privacy Solutions Engineer examination. 11 chapters, 366 pages.

Practice questions with full rationales, sized to the published domain weights. 213 pages.
Sources
- ISACA, CDPSE certification page
- ISACA, exam candidate guides, read 2 October 2026
- ISACA, CDPSE exam content outline, read 30 September 2026
- ISACA Certification Exam Candidate Guide, version 1.26, read 2 October 2026
Credential Press is independent of ISACA.