# IAPP CIPP/US: study planner

Question ranges come from the IAPP CIPP/US Body of Knowledge, version 2.6.1, effective 1 September 2025, read on 2 October 2026. The 30-hour minimum is the IAPP's recommendation (IAPP Certification FAQs). The hours are our suggestion: each domain gets a share in proportion to the midpoint of its published range. Check the IAPP's CIPP/US page before you start in case the Body of Knowledge has changed.

## Hours by domain

The midpoints add up to 75, so on 30 hours each midpoint question is worth 24 minutes.

| Domain | Range | Midpoint | 30 hours | 45 hours | 60 hours |
|---|---|---|---|---|---|
| I. The U.S. Privacy Environment | 27 to 33 | 30 | 12 | 18 | 24 |
| II. Federal Privacy Laws | 15 to 19 | 17 | 6.75 | 10.25 | 13.5 |
| III. Government and Court Access to Private-sector Information | 3 to 5 | 4 | 1.75 | 2.5 | 3.25 |
| IV. Workplace Privacy | 4 to 6 | 5 | 2 | 3 | 4 |
| V. State Privacy Laws | 17 to 21 | 19 | 7.5 | 11.25 | 15.25 |
| **Total** | | **75** | **30** | **45** | **60** |

Hours are in quarter hours: 0.25 is 15 minutes, 0.5 is 30 minutes and 0.75 is 45 minutes. Domains II, III and V are rounded to quarter hours so that every column adds up to its budget.

## Pace for timed practice

| Set | Questions | Time at the exam's average pace |
|---|---|---|
| One question | 1 | 1 minute 40 seconds |
| Short timed set | 18 | 30 minutes |
| One half of the exam | 45 | 75 minutes |
| Full exam | 90 | 2.5 hours |

## Competencies, largest first

The IAPP prints a range for each competency as well as each domain. The competency ranges do not add up to the domain ranges, so read each figure on its own.

| Competency | Range | Read | Studied | Practiced |
|---|---|---|---|---|
| I.C Understand the principles of information management from a U.S. perspective | 18 to 22 | [ ] | [ ] | [ ] |
| V.B Understand the key concepts and principles of state data privacy and security laws | 13 to 17 | [ ] | [ ] | [ ] |
| I.B Understand the enforcement framework for U.S. privacy and security laws | 5 to 7 | [ ] | [ ] | [ ] |
| I.A Understand the U.S. legal framework | 3 to 5 | [ ] | [ ] | [ ] |
| II.A Understand how the Federal Trade Commission addresses consumer protection in regard to privacy and security | 3 to 5 | [ ] | [ ] | [ ] |
| II.B Understand how healthcare and medical privacy is regulated | 3 to 5 | [ ] | [ ] | [ ] |
| II.C Understand how financial sector privacy is regulated | 3 to 5 | [ ] | [ ] | [ ] |
| II.E Understand how privacy is regulated in telecommunications and marketing activities | 2 to 4 | [ ] | [ ] | [ ] |
| IV.B Understand workplace privacy issues that arise before, during and after employment | 2 to 4 | [ ] | [ ] | [ ] |
| V.C Understand the key principles of state data breach notification laws | 2 to 4 | [ ] | [ ] | [ ] |
| II.D Understand how education sector privacy is regulated | 1 to 3 | [ ] | [ ] | [ ] |
| III.B Understand the relationship between national security and privacy | 1 to 3 | [ ] | [ ] | [ ] |
| IV.A Understand the issues involved in workplace privacy | 1 to 3 | [ ] | [ ] | [ ] |
| III.A Understand the relationship between law enforcement and privacy issues | 1 to 2 | [ ] | [ ] | [ ] |
| III.C Understand issues regarding civil litigation and privacy | 1 to 2 | [ ] | [ ] | [ ] |
| V.A Understand concepts of authority governing state privacy laws | 1 to 2 | [ ] | [ ] | [ ] |

## Before exam day

- [ ] Hours booked in the calendar for your column (our suggestion)
- [ ] At least one timed half: 45 questions in 75 minutes (our suggestion)
- [ ] Multi-select questions practiced: the exam asks for an exact number of answers and gives no partial credit (IAPP)
- [ ] Exam booked at least 24 hours ahead, inside one year of purchase (IAPP rule)
