# IAPP CIPP/E: study planner

Question ranges come from the IAPP CIPP/E Body of Knowledge, version 1.3.3, effective 1 September 2025, read on 2 October 2026. The 30-hour minimum is the IAPP's recommendation (IAPP Certification FAQs). The hours are our suggestion: each domain gets a share in proportion to the midpoint of its published range. Check the IAPP's CIPP/E page before you start in case the Body of Knowledge has changed.

## Hours by domain

The midpoints add up to 75, so on 30 hours each midpoint question is worth 24 minutes.

| Domain | Range | Midpoint | 30 hours | 45 hours | 60 hours |
|---|---|---|---|---|---|
| I. Introduction to European Data Protection | 7 to 13 | 10 | 4 | 6 | 8 |
| II. European Data Protection Law and Regulation | 18 to 28 | 23 | 9.25 | 13.75 | 18.5 |
| III. European Data Processing | 13 to 21 | 17 | 6.75 | 10.25 | 13.5 |
| IV. European Data Protection: Scope and Accountability | 8 to 18 | 13 | 5.25 | 7.75 | 10.5 |
| V. Compliance with European Data Protection Law and Regulation | 8 to 16 | 12 | 4.75 | 7.25 | 9.5 |
| **Total** | | **75** | **30** | **45** | **60** |

Hours are in quarter hours: 0.25 is 15 minutes, 0.5 is 30 minutes and 0.75 is 45 minutes. Domains II to V are rounded to the nearest quarter hour, alternately up and down, so every column still adds up to its budget.

## Pace for timed practice

| Set | Questions | Time at the exam's average pace |
|---|---|---|
| One question | 1 | 1 minute 40 seconds |
| Short timed set | 18 | 30 minutes |
| One half of the exam | 45 | 75 minutes |
| Full exam | 90 | 2.5 hours |

## Competencies, largest first

Tick each one when you have read it in the Body of Knowledge, studied it, and done practice questions on it.

| Competency | Range | Read | Studied | Practiced |
|---|---|---|---|---|
| II.C Understand data subjects' rights | 8 to 12 | [ ] | [ ] | [ ] |
| II.B Understand the requirements involved in maintaining the security of personal data | 7 to 11 | [ ] | [ ] | [ ] |
| I.C Understand the legislative framework underpinning the principles of European data protection | 5 to 8 | [ ] | [ ] | [ ] |
| IV.B Understand the various accountability requirements under the GDPR | 4 to 8 | [ ] | [ ] | [ ] |
| III.C Understand information provision obligations | 4 to 6 | [ ] | [ ] | [ ] |
| III.D Understand the principles of, and the risks involved in, international data transfers | 4 to 6 | [ ] | [ ] | [ ] |
| II.A Understand basic GDPR data protection concepts | 3 to 5 | [ ] | [ ] | [ ] |
| III.B Know what constitutes a lawful processing basis | 3 to 5 | [ ] | [ ] | [ ] |
| V.A Compliance in the workplace, specifically as it relates to employment relationships | 3 to 5 | [ ] | [ ] | [ ] |
| III.A Understand the principles of European data processing | 2 to 4 | [ ] | [ ] | [ ] |
| IV.A Understand issues related to the territorial and material scope of the GDPR | 2 to 4 | [ ] | [ ] | [ ] |
| V.C Compliance related to direct marketing | 2 to 4 | [ ] | [ ] | [ ] |
| V.D Compliance related to internet technology and communications | 2 to 4 | [ ] | [ ] | [ ] |
| I.A Understand the origins and historical context of European data protection laws | 1 to 3 | [ ] | [ ] | [ ] |
| IV.C Understand the European data protection supervision and enforcement structure | 1 to 3 | [ ] | [ ] | [ ] |
| IV.D Understand the consequences for GDPR violations | 1 to 3 | [ ] | [ ] | [ ] |
| V.B Compliance related to surveillance activities | 1 to 3 | [ ] | [ ] | [ ] |
| I.B Understand the roles and functions of significant European Union institutions | 1 to 2 | [ ] | [ ] | [ ] |

Competency names for domain V are shortened; the Body of Knowledge gives the full wording.

## Before exam day

- [ ] Hours booked in the calendar for your column (our suggestion)
- [ ] At least one timed half: 45 questions in 75 minutes (our suggestion)
- [ ] Multi-select questions practiced: the exam asks for an exact number of answers and gives no partial credit (IAPP)
- [ ] Exam booked at least 24 hours ahead, inside one year of purchase (IAPP rule)
