# IAPP CIPT: study planner

Question ranges come from the IAPP CIPT Body of Knowledge, version 4.0.0, effective 1 September 2025, read on 2 October 2026. The 30-hour minimum is the IAPP's recommendation (IAPP Certification FAQs). The hours are our suggestion: each domain gets a share in proportion to the midpoint of its published range. Check the IAPP's CIPT page before you start in case the Body of Knowledge has changed.

## Hours by domain

The midpoints add up to 75, so on 30 hours each midpoint question is worth 24 minutes.

| Domain | Range | Midpoint | 30 hours | 45 hours | 60 hours |
|---|---|---|---|---|---|
| I. The privacy technologist's role in the context of the organization | 15 to 19 | 17 | 6.75 | 10.25 | 13.5 |
| II. Data collection, use, dissemination and destruction | 19 to 23 | 21 | 8.5 | 12.5 | 16.75 |
| III. Privacy risk management | 17 to 21 | 19 | 7.5 | 11.5 | 15.25 |
| IV. Privacy by design | 7 to 9 | 8 | 3.25 | 4.75 | 6.5 |
| V. Privacy engineering and privacy governance | 9 to 11 | 10 | 4 | 6 | 8 |
| **Total** | | **75** | **30** | **45** | **60** |

Hours are in quarter hours: 0.25 is 15 minutes, 0.5 is 30 minutes and 0.75 is 45 minutes. Domains are rounded to quarter hours so that every column adds up to its budget.

## Pace for timed practice

| Set | Questions | Time at the exam's average pace |
|---|---|---|
| One question | 1 | 1 minute 40 seconds |
| Short timed set | 18 | 30 minutes |
| One half of the exam | 45 | 75 minutes |
| Full exam | 90 | 2.5 hours |

## Competencies, largest first

The IAPP prints a range for each competency as well as each domain. The competency ranges do not add up to the domain ranges, so read each figure on its own.

| Competency | Range | Read | Studied | Practiced |
|---|---|---|---|---|
| II.A Demonstrate how to minimize privacy risk during personal data collection | 8 to 10 | [ ] | [ ] | [ ] |
| II.B Demonstrate how to minimize privacy risk during personal data use | 6 to 8 | [ ] | [ ] | [ ] |
| V.A Understand and implement privacy engineering objectives | 6 to 8 | [ ] | [ ] | [ ] |
| I.A Identify and implement legal and procedural roles and responsibilities | 5 to 7 | [ ] | [ ] | [ ] |
| I.B Identify and implement technical roles and responsibilities | 5 to 7 | [ ] | [ ] | [ ] |
| II.C Demonstrate how to minimize privacy risk during personal data dissemination | 4 to 6 | [ ] | [ ] | [ ] |
| III.C Understand the privacy risks and impact of techniques that enable tracking and surveillance | 4 to 6 | [ ] | [ ] | [ ] |
| IV.A Implement privacy by design principles | 4 to 6 | [ ] | [ ] | [ ] |
| III.B Identify privacy risks related to software security | 3 to 5 | [ ] | [ ] | [ ] |
| III.E Demonstrate how to monitor and manage privacy risk | 3 to 5 | [ ] | [ ] | [ ] |
| I.D Understand the connection between data ethics and data privacy | 2 to 4 | [ ] | [ ] | [ ] |
| III.A Demonstrate how to minimize the threat of intrusion and decisional interference | 2 to 4 | [ ] | [ ] | [ ] |
| III.D Understand the privacy risks and impact involved when using workplace technologies | 2 to 4 | [ ] | [ ] | [ ] |
| IV.B Evaluate privacy risks in user experiences | 2 to 4 | [ ] | [ ] | [ ] |
| V.B Manage and monitor privacy-related functions and controls | 2 to 4 | [ ] | [ ] | [ ] |
| I.C Demonstrate knowledge of privacy risk models and frameworks and their roles in legal requirements and guidance | 1 to 3 | [ ] | [ ] | [ ] |

## Before exam day

- [ ] Hours booked in the calendar for your column (our suggestion)
- [ ] At least one timed half: 45 questions in 75 minutes (our suggestion)
- [ ] Multi-select questions practiced: the exam asks for an exact number of answers and gives no partial credit (IAPP)
- [ ] Exam booked at least 24 hours ahead, inside one year of purchase (IAPP rule)
