# IAPP CIPM: study planner

Question ranges come from the IAPP CIPM Body of Knowledge, version 4.2.0, effective 1 September 2025, read on 2 October 2026. The 30-hour minimum is the IAPP's recommendation (IAPP Certification FAQs). The hours are our suggestion: each domain gets a share in proportion to the midpoint of its published range. Check the IAPP's CIPM page before you start in case the Body of Knowledge has changed.

## Hours by domain

The midpoints add up to 75, so on 30 hours each midpoint question is worth 24 minutes.

| Domain | Range | Midpoint | 30 hours | 45 hours | 60 hours |
|---|---|---|---|---|---|
| I. Privacy Program: Developing a Framework | 14 to 18 | 16 | 6.5 | 9.5 | 12.75 |
| II. Privacy Program: Establishing Program Governance | 12 to 16 | 14 | 5.5 | 8.5 | 11.25 |
| III. Privacy Program Operational Life Cycle: Assessing Data | 12 to 16 | 14 | 5.5 | 8.5 | 11.25 |
| IV. Privacy Program Operational Life Cycle: Protecting Personal Data | 9 to 13 | 11 | 4.5 | 6.5 | 8.75 |
| V. Privacy Program Operational Life Cycle: Sustaining Program Performance | 7 to 9 | 8 | 3.25 | 4.75 | 6.5 |
| VI. Privacy Program Operational Life Cycle: Responding to Requests and Incidents | 10 to 14 | 12 | 4.75 | 7.25 | 9.5 |
| **Total** | | **75** | **30** | **45** | **60** |

Hours are in quarter hours: 0.25 is 15 minutes, 0.5 is 30 minutes and 0.75 is 45 minutes. Domains are rounded to quarter hours so that every column adds up to its budget.

## Pace for timed practice

| Set | Questions | Time at the exam's average pace |
|---|---|---|
| One question | 1 | 1 minute 40 seconds |
| Short timed set | 18 | 30 minutes |
| One half of the exam | 45 | 75 minutes |
| Full exam | 90 | 2.5 hours |

## Competencies, largest first

The IAPP prints a range for each competency as well as each domain. The competency ranges do not add up to the domain ranges, so read each figure on its own.

| Competency | Range | Read | Studied | Practiced |
|---|---|---|---|---|
| II.A Create policies and processes to be followed across all stages of the privacy program life cycle | 6 to 8 | [ ] | [ ] | [ ] |
| I.C Indicate in-scope laws, regulations and standards applicable to the program | 5 to 7 | [ ] | [ ] | [ ] |
| VI.A Respond to data subject access requests and privacy rights | 5 to 7 | [ ] | [ ] | [ ] |
| I.A Define program scope and develop a privacy strategy | 4 to 6 | [ ] | [ ] | [ ] |
| I.B Communicate organizational vision and mission statement | 4 to 6 | [ ] | [ ] | [ ] |
| IV.A Apply information security practices and policies | 4 to 6 | [ ] | [ ] | [ ] |
| III.A Document data governance systems | 3 to 5 | [ ] | [ ] | [ ] |
| III.D Evaluate technical controls | 3 to 5 | [ ] | [ ] | [ ] |
| IV.C Apply organizational guidelines for data use and ensure technical controls are enforced | 3 to 5 | [ ] | [ ] | [ ] |
| V.C Manage continuous assessment of the privacy program | 3 to 5 | [ ] | [ ] | [ ] |
| VI.B Follow organizational incident handling and response procedures | 3 to 5 | [ ] | [ ] | [ ] |
| II.C Define privacy metrics for oversight and governance | 2 to 4 | [ ] | [ ] | [ ] |
| III.E Evaluate risks associated with shared data in mergers, acquisitions and divestitures | 2 to 4 | [ ] | [ ] | [ ] |
| II.B Clarify roles and responsibilities | 1 to 3 | [ ] | [ ] | [ ] |
| II.D Establish training and awareness activities | 1 to 3 | [ ] | [ ] | [ ] |
| III.B Evaluate processors and third-party vendors | 1 to 3 | [ ] | [ ] | [ ] |
| IV.B Integrate the main principles of Privacy by Design (PbD) | 1 to 3 | [ ] | [ ] | [ ] |
| V.A Use metrics to measure the performance of the privacy program | 1 to 3 | [ ] | [ ] | [ ] |
| V.B Audit the privacy program | 1 to 3 | [ ] | [ ] | [ ] |
| VI.C Evaluate and modify current incident response plan | 1 to 3 | [ ] | [ ] | [ ] |
| III.C Evaluate physical and environmental controls | 0 to 2 | [ ] | [ ] | [ ] |

## Before exam day

- [ ] Hours booked in the calendar for your column (our suggestion)
- [ ] At least one timed half: 45 questions in 75 minutes (our suggestion)
- [ ] Multi-select questions practiced: the exam asks for an exact number of answers and gives no partial credit (IAPP)
- [ ] Exam booked at least 24 hours ahead, inside one year of purchase (IAPP rule)
