The CIPP/E BoK v1.3.3 covers five domains. Domain II (Data Protection Principles) is explicitly the heaviest — it can carry up to 28 questions, roughly 31% of your score. If you pass or fail CIPP/E, Domain II is usually why. Study it first, study it most. Domain III (Compliance in Practice) is second-heaviest. Domain V (ePrivacy) is often under-studied and gives disproportionate returns per hour.
CIPP/E candidates frequently make the same allocation mistake: spreading preparation time evenly across all five domains as if the exam does the same. It does not. The CIPP/E domain structure is deliberately front-loaded — the foundational legal principles carry far more weight than the institutional or international chapters.
Here is how the weight actually sits, what each domain really tests, and a four-week allocation that matches exam reality.
Still piecing together your CIPP/E prep from too many places?
Most candidates who pass committed to one structured path. That's what this is.
Get the Complete Pack →The Five CIPP/E Domains (BoK v1.3.3, Sep 2026)
The legal and regulatory landscape: EU law hierarchy, GDPR structure, supervisory authority powers, enforcement history, the role of the EDPB (European Data Protection Board), Council of Europe Convention 108+. Essential background but not the heaviest domain.
The core GDPR framework: six lawful bases, consent conditions, special categories (Art. 9), children's data, legitimate interests, purpose limitation, data minimisation, storage limitation, data subject rights, accountability principle. This is the largest domain and the source of most exam failures.
How organisations comply: DPO role under Art. 37–39, records of processing (Art. 30), DPIAs (Art. 35), Privacy by Design (Art. 25), security obligations (Art. 32), processor agreements (Art. 28), breach notification (Art. 33–34). High applied-judgment content — many scenario questions live here.
Transfer mechanisms: adequacy decisions (Art. 45), standard contractual clauses, binding corporate rules (Art. 47), derogations (Art. 49). Post-Schrems II landscape, EU-US Data Privacy Framework. This domain has a high fact-density — transfer mechanisms need to be memorised precisely.
The ePrivacy Directive (2002/58/EC) and pending ePrivacy Regulation: cookies, electronic communications, direct marketing, PECR in the UK context. Often under-studied. Gives disproportionate points per hour of preparation.
The Domain II Problem
Domain II is where CIPP/E exams are won and lost. Up to 28 questions from a single domain means it carries roughly the same weight as Domains IV and V combined.
The specific trap: Domain II questions look like definitional recall, but they are mostly scenario application. "Which legal basis applies here?" "Is this consent valid?" "Does this constitute a special category under Art. 9?" The examiner gives you a fact pattern and expects you to apply the correct principle — not recite it.
This means Domain II needs two kinds of study: (1) genuine memorisation of all six lawful bases, the special categories, and all eight data subject rights, and (2) scenario practice — enough that you can apply them quickly under exam conditions.
Domain II — The Specific Topics That Generate Exam Questions
- Six lawful bases (Art. 6(1)): consent, contract, legal obligation, vital interests, public task, legitimate interests. Know each one's typical scope and the balancing test for legitimate interests.
- Consent conditions (Art. 7, Recital 32): freely given, specific, informed, unambiguous, affirmative action, separable from other terms, withdrawable without detriment.
- Children's consent (Art. 8): 16 by default, member states can lower to 13.
- Special categories (Art. 9): racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, genetic, biometric for ID, health, sex life/orientation. All ten processing bases in Art. 9(2).
- Data subject rights (Art. 12–22): transparency, access, rectification, erasure, restriction, portability, object, automated decision-making. One-month response window.
- Principles (Art. 5): all seven, each one tested as a potential violation framing in scenarios.
A Four-Week Study Allocation
Given the domain weights above, here is how to allocate four weeks of preparation:
Week 1 — Domain II Alone
Read the Cram Guide chapter for Domain II in depth. Do a set of 40–50 Domain II-focused practice questions. You should understand lawful bases, consent, and data subject rights well enough to explain them to a colleague without looking anything up by end of week.
Week 2 — Domain I + Domain III
Domain I gives you context (EU law hierarchy, GDPR structure, supervisory authority powers). Domain III is where compliance obligations live — heavy on scenario questions about DPIAs, breach notifications, processor agreements. Do 40–50 practice questions covering these two domains.
Week 3 — Domain IV + Domain V
Domain IV requires memorisation of specific transfer mechanisms (adequacy, SCCs, BCRs, derogations) and the post-Schrems II landscape. Domain V (ePrivacy) is relatively compact but appears on every exam. Do 30–40 practice questions covering transfers and ePrivacy.
Week 4 — Full Mock + Final Review
Early in Week 4: full 90-question timed practice mock (Set 3 of the Archuz question bank, which runs 100 questions for extra margin). Score immediately. Final 3–4 days: targeted review of missed questions, light re-read of weakest domain, logistics on D-1.
About the BoK v1.3.3 Update (Sep 2026)
The September 2026 BoK update for CIPP/E primarily refined Domain III (compliance obligations, particularly around AI systems and automated decision-making under GDPR Art. 22) and Domain IV (updated SCCs and post-Brexit transfer considerations). If you are studying with pre-2026 materials, these sections may be out of date.
The Archuz CIPP/E Cram Guide is current to BoK v1.3.3 and flags what changed in the September 2026 revision. You will know exactly which parts of the exam content are new and which are stable.
Common Allocation Mistakes
- Spending equal time per domain. If you spend 20% of your time on Domain V (which is 10% of the exam), you have under-invested in Domain II (31% of the exam).
- Skipping Domain V entirely. ePrivacy is small but reliably on every sitting. Dropping 8–12 points you could have earned with four hours of preparation is a bad trade.
- Reading Domain IV only once. Transfer mechanisms are fact-dense. One read is not enough — the exam tests specific details on SCCs, adequacy, and derogations that need deliberate memorisation.
- Confusing Domain II and Domain III. Domain II is the principles (what the law is). Domain III is the compliance (what you do about it). Questions sometimes blur the line, but study them separately.
Frequently Asked Questions
What is the heaviest domain on CIPP/E?
Domain II (Data Protection Principles), carrying up to 28 of 90 questions — roughly 31% of the exam. It is explicitly the heaviest domain under BoK v1.3.3.
How long is the CIPP/E exam?
90 questions, 2.5 hours (150 minutes). Scaled score. IAPP does not publish the exact passing score. Fees are $550 for a first IAPP cert, $375 for a subsequent cert.
What is in the CIPP/E BoK v1.3.3 update?
The September 2026 update refined Domain III (compliance obligations around AI and Art. 22 automated decision-making) and Domain IV (updated SCCs and post-Brexit transfer considerations). The five-domain structure is unchanged.
How long should I study for CIPP/E?
80–120 hours over 5–8 weeks for candidates without prior GDPR exposure. 50–80 hours over 4–6 weeks for candidates with prior privacy practice. The 4-week plan in this article assumes the latter.
Can I pass CIPP/E without studying Domain V?
Possibly, but you are forfeiting 8–12 questions. ePrivacy is small enough to study in 4–6 hours and reliably on every sitting. The return on preparation hours is high.
Is Domain II the same as GDPR Chapter 2?
Overlapping but not identical. Domain II covers the GDPR principles and lawful bases that mostly map to Chapter 2 (Principles), but also includes material from Chapter 3 (Rights) and the accountability provisions in Chapter 4. The BoK structure follows exam logic, not GDPR chapter order.
How many scenario questions are on CIPP/E?
The majority — roughly 60–70% of CIPP/E questions use scenario framing, with 15–20 of those typically grouped into shared-scenario blocks of 3–5 questions each. The Archuz CIPP/E Question Bank contains 220 scenario-type questions across its 300 total.
What is the fastest way to study Domain II for CIPP/E?
Read the Cram Guide Domain II chapter twice. Do 40–50 Domain II-focused scenario questions. Re-read any Domain II section where you missed two or more questions in the practice set. Repeat until your Domain II accuracy exceeds 80% on fresh questions.