i
Quick Answer

The CIPP/E exam is 90 multiple-choice questions in 2.5 hours (75 scored, 15 unscored field-test), scored on a 100–500 scale with a passing threshold of 300. It covers five domains built around GDPR, with European Data Protection Law and Regulation carrying the heaviest weight. The current Body of Knowledge (v1.3.3) took effect September 1, 2025, and added EU AI Act and NIS2 content. See also: how CIPP/E fits into the CIPP AI dual-credential pathway.

The CIPP/E Body of Knowledge got reorganized this cycle — what used to be one dense domain covering all of GDPR is now split into three separate domains, which sounds like a bigger change than it actually is. The IAPP has been explicit that the split is purely organizational: same sub-topics, same question allocation, just regrouped into a clearer structure. Here's what the exam actually tests, in the format it's actually tested in, plus the study sequencing and logistics that determine whether that content translates into a pass on exam day.

90
Total Questions
75/15
Scored / Unscored Split
2.5 hrs
Total Testing Time
300/500
Passing Scaled Score

The Exam Format

You'll get 90 multiple-choice questions in 2.5 hours, with a 15-minute break included in that window. Of those 90 questions, only 75 count toward your score — the remaining 15 are unscored field-test questions the IAPP uses to calibrate future exams. You won't know which is which, so every question deserves full attention regardless of how unusual or off-topic it feels. The exam is delivered through Pearson VUE, either in person at a test center or remotely via OnVUE online proctoring, and uses scenario-based questions alongside straightforward knowledge recall — meaning memorizing GDPR article numbers alone won't be sufficient without practice applying them to realistic fact patterns under real time pressure.

The Five Domains, and How They're Weighted

DomainFocusApprox. Weight
I — Introduction to European Data ProtectionHistorical development from the 1995 Directive to the GDPR, foundational concepts, and the human-rights framework underlying European privacy law.~5–10%
II — European Data Protection Law & RegulationThe core of GDPR — the seven principles under Article 5, the six lawful bases under Article 6, consent requirements under Article 7, and data subject rights.~24–37% (heaviest)
III — European Data ProcessingController and processor obligations, security requirements, and the practical mechanics of lawful processing.Moderate
IV — Scope & AccountabilityInternational data transfers, transfer mechanisms (SCCs, adequacy decisions, derogations), and accountability documentation.Moderate
V — Compliance in Specific ContextsEmployment privacy, workplace surveillance, direct marketing, and cookies/ePrivacy issues.~8–16 scored questions
The Reorganization, Explained

This year's reorganization split the old, single mega-domain covering all of GDPR into three separate domains — II, III, and IV — without changing a single sub-topic or shifting a single question's weighting. If your study materials still describe "three domains," they're describing the old structure; the underlying content tested hasn't moved.

What's New in the Current Body of Knowledge

The Body of Knowledge effective September 1, 2025 (v1.3.3) incorporates the EU AI Act, the NIS2 Directive, and broader digital-regulation context — reflecting how deeply data protection now intersects with adjacent EU tech law. The IAPP has been consistent that annual updates add no more than 10–15% new content, so this isn't a wholesale rewrite, but candidates studying older materials should specifically check their coverage of AI Act interplay with GDPR (particularly around automated decision-making and data used for AI training) and NIS2's cybersecurity-adjacent obligations, since these are the areas most likely to differ from a study guide published even a year earlier.

How the Passing Score Actually Works

The scaled score runs 100–500, with 300 as the passing threshold — but the IAPP doesn't publish exactly how many raw questions correct that requires, because the scaling accounts for which specific exam form (out of several in rotation) you receive. Analysis of the IAPP's own scoring documentation suggests the safest planning target is answering close to all 75 of the scored questions correctly to guarantee a pass under the toughest possible form, though the actual bar in practice is meaningfully lower — historical guidance suggests somewhere in the 65–80% range depending on form difficulty. Don't obsess over the exact number; treat 80%+ as your real preparation target across all domains.

Prerequisites and Cost

There's no formal prerequisite to sit the CIPP/E — though the IAPP recommends roughly two years of privacy experience as a benchmark for readiness, many candidates pass through dedicated study alone. The exam costs $550, with no separate member discount on the initial purchase — a genuine difference from the AIGP's member/non-member pricing structure. You must schedule and complete the exam within 12 months of purchase.

What Happens After You Pass

The CIPP/E certification is valid for two years, maintained through 20 Continuing Privacy Education (CPE) credits plus a Certification Maintenance Fee — $250 per two-year term for non-members, waived for active IAPP members. Many CIPP/E holders go on to add the CIPM, which together with a CIPP qualifies you for the Fellow of Information Privacy (FIP) designation — or add the AIGP as AI governance increasingly overlaps with core privacy work.

How the Reorganization Changes What You Actually Study

Because Domains II, III, and IV all descend from the same original GDPR mega-domain, candidates studying older three-domain materials sometimes assume the new five-domain structure means new content to learn. It doesn't — but it does change how you should organize your study sessions. Where a single mega-domain study block might have blended lawful basis, processor obligations, and international transfers into one long study session, the current structure rewards treating them as three genuinely separate study blocks with their own dedicated practice-question sets, since the exam itself now scores and reports them separately on your domain-level score breakdown.

This matters most for diagnostic purposes. If you take a domain-level practice assessment under the old three-domain framing, a single low score in "GDPR core" tells you very little about which specific sub-area to focus your remaining study time on. Under the current five-domain structure, a low score in Domain IV specifically (Scope & Accountability) tells you the gap is in international transfer mechanisms, not lawful basis or data subject rights — a meaningfully more actionable diagnostic.

How CIPP/E Compares to CIPP/US in Structure

Candidates evaluating both credentials, or transitioning from one to the other, often ask how directly the exam mechanics compare. The answer: nearly identically in format — both run 90 questions, 75 scored, 2.5 hours, same 100–500 scaled scoring with a 300 passing threshold. What differs entirely is content: CIPP/US is organized around the fragmented US regulatory landscape (federal sectoral laws, state comprehensive privacy statutes, enforcement bodies), while CIPP/E is anchored almost entirely in a single unified framework, the GDPR. Candidates who've taken one sometimes find the other's exam mechanics immediately familiar, even though the substantive law being tested is completely different.

A Realistic Study Approach by Domain

Given the domain weighting above, a structured study sequence tends to outperform working through the Body of Knowledge cover to cover in order. A practical approach many candidates report success with:

PhaseFocus
Phase 1Domain II first, given its outsized weight. Master the seven Article 5 principles, the six Article 6 lawful bases, and consent requirements before moving on — everything else in the exam assumes fluency here.
Phase 2Domains III and IV together, since processor/controller obligations and international transfer mechanisms both build directly on Domain II's lawful-basis foundation.
Phase 3Domain I and Domain V last. Domain I's historical context is genuinely lighter-weight, and Domain V's specific-context scenarios (employment, cookies, marketing) are easiest to absorb once the core legal framework from Domains II–IV is already solid.
Phase 4Full-length scenario-based practice exams in the final two weeks, tracking domain-level performance to identify any remaining specific gaps before booking.
Don't Skip Domain V

Because Domain V carries a smaller question count, candidates sometimes deprioritize it entirely. This is a mistake — its scenario-based questions on employment privacy, workplace surveillance, and cookies test practical application skills that don't automatically transfer from mastering Domain II's more abstract legal principles. A handful of missed Domain V questions matters just as much toward your final scaled score as questions from any other domain.

Who Should Take CIPP/E vs. a Different IAPP Credential First

CIPP/E is the right starting point for most candidates working with or planning to work with European personal data, regardless of where they're physically based — the GDPR's extraterritorial reach means US and Asia-based privacy professionals handling EU customer data need this credential just as much as EU-based practitioners. Candidates whose work is exclusively US-focused should generally start with CIPP/US instead, following the identical exam-mechanics logic but studying the US regulatory patchwork rather than GDPR.

For candidates already deep in AI governance work who are wondering whether CIPP/E adds anything AIGP doesn't already cover: it does. AIGP tests AI-specific governance frameworks and doesn't substitute for GDPR-level legal depth, and a meaningful share of AI systems processing EU personal data will trigger GDPR obligations regardless of how well-governed the AI-specific risk is. The two credentials answer genuinely different questions, which is exactly why the CIPP/E-plus-AIGP stack shows up so consistently in EU-focused AI governance hiring criteria.

Exam Day Logistics Worth Knowing in Advance

Beyond the content itself, a few CIPP/E-specific logistics catch candidates off guard. The exam is delivered exclusively through Pearson VUE, and the identification requirements mirror the strict standards used across IAPP's certification family — two forms of valid, matching-name ID, with the primary form being a government-issued photo ID. If you're testing via OnVUE remote proctoring rather than an in-person test center, confirm your testing environment meets the platform's requirements (a private room, a functioning webcam, and a stable internet connection) well before your scheduled time, since connectivity issues mid-exam can be far more disruptive to recover from than a similar issue at a staffed physical test center.

Unlike some professional exams, there's no open-book or reference-material allowance during the CIPP/E — you won't have access to the GDPR text itself during the exam, which is exactly why the Domain II study emphasis above matters so much. The exam tests your internalized understanding of the law's structure and application, not your ability to look up the correct article number under time pressure during a fixed 2.5-hour window.

Frequently Asked Questions

How many questions are on the CIPP/E exam?

90 multiple-choice questions total, of which 75 are scored and 15 are unscored field-test questions, administered over 2.5 hours.

What is the passing score for the CIPP/E exam?

300 on a scaled range of 100–500. The IAPP doesn't publish the exact raw-question threshold, since it varies by exam form, but 80% or higher across all domains is a reasonable preparation target.

How many domains does the CIPP/E exam cover?

Five, following a recent reorganization that split the former single GDPR-focused domain into three separate domains without changing the underlying content or question weighting.

Do I need privacy experience to take the CIPP/E exam?

No formal prerequisite exists, though the IAPP recommends roughly two years of privacy experience as a general readiness benchmark.

Is the current five-domain structure harder than the old three-domain version?

No. The IAPP has been explicit that the reorganization is purely structural — the same sub-topics and the same total question weighting apply, just regrouped into more granular domain labels. Candidates studying current five-domain materials aren't facing a harder exam, just a more precisely organized one.

Bottom Line

CIPP/E's five-domain structure is a reorganization, not a rewrite — the underlying GDPR content and question weighting haven't shifted, just the labels around them. Focus your heaviest study time on Domain II, treat the 300 scaled score as roughly an 80% target rather than obsessing over the exact conversion, confirm your materials reflect the current v1.3.3 Body of Knowledge including its EU AI Act and NIS2 additions, and don't underestimate Domain V's practical scenario weight just because its question count is smaller.

Related reading: CIPP/E vs. CIPM: which to take first and the CIPP/E retake policy.

Related reading: what changed in the CIPP/E Body of Knowledge for 2026 · the CIPP/E retake policy, cost and waiting period.