# CIPM interview scorecard

Candidate: ______  Interviewer: ______  Date: ______

| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How would you build a privacy program where there is none? | Find the data and the laws that apply, set a governance model and roles, write a short roadmap, and show early results. | |
| 2 | How do you structure privacy roles across the business? | A clear owner, a network of privacy champions, and defined handoffs with legal, security and product. | |
| 3 | How do you keep the record of processing current? | Owners update it on a cycle and on change, with a trigger in project and vendor intake. | |
| 4 | Walk me through a privacy impact assessment. | When it is triggered, who takes part, how risks are rated and treated, and how sign-off works. | |
| 5 | How do you train staff so it sticks? | Short, role-based, repeated, and measured by behavior, not completion rates. | |
| 6 | Data subject requests double overnight. What do you do? | Triage, automate intake and verification, protect the deadlines, and find the cause. | |
| 7 | Which privacy metrics would you report? | Requests and deadlines met, assessments completed, incidents and time to close, training reach. | |
| 8 | How do you respond to a privacy incident? | Contain, assess the risk to people, decide on notice to regulators and individuals within the legal deadlines, and record it. | |

Source: https://credentialpress.com/guides/cipm-interview-questions
