Quick answer

To pass the CIPP/E in 2026, study the GDPR as a set of decisions, not a list of articles. Spend most of your time on the core of the regulation — principles, lawful bases, data subject rights, controller and processor obligations, and international transfers — and practise them through scenario questions. Most working professionals need 6–10 weeks at 5–8 hours a week. The plan below covers it in 8 weeks, with the final two reserved for timed practice and weak-area repair.

The CIPP/E is 90 multiple-choice questions in 2.5 hours, 75 of them scored, marked on a 100–500 scale with 300 to pass. Those are the facts in every exam guide (ours is here). What most guides skip is the part that decides whether you pass: how the exam asks about the GDPR.

Very few questions ask "what does Article X say?" Most give you a company, a processing activity and a problem, and ask what the GDPR requires. You can know every article number and still fail, because you've learned the regulation as text instead of as a set of decisions. This guide is built around those decisions.

Before You Start: Three Things to Set Up

  1. Download the current Body of Knowledge. The CIPP/E Body of Knowledge and Exam Blueprint on the IAPP CIPP/E page lists every topic and the question ranges per domain. The version effective September 2025 (v1.3.3) brought in EU AI Act and NIS2 context. Our BoK change guide lists what moved.
  2. Keep the GDPR text open. Use the official consolidated text on EUR-Lex. Read the recitals for anything confusing — the exam's scenarios often hinge on the reasoning in the recitals.
  3. Book a tentative exam date. A date eight to ten weeks out keeps the plan honest. You have 12 months from purchase to sit the exam, and in-person appointments can be rescheduled up to 48 hours ahead.

What to Study: The Six Topic Blocks

The Body of Knowledge is organised into domains, but for studying it's more useful to think in six blocks. The middle three carry most of the exam.

BlockKey contentExam weightTypical difficulty
1. Foundations and institutionsECHR Art. 8, EU Charter Arts. 7–8, Convention 108, the 1995 Directive, EU institutionsLightLow — memorisable
2. GDPR core conceptsDefinitions, material and territorial scope (Arts. 2–3), principles (Art. 5), lawful bases (Art. 6), consent (Art. 7), special categories (Art. 9)HeavyHigh — applied judgement
3. Data subject rightsTransparency and the rights in Arts. 12–22, including conditions and exceptionsHeavyMedium-high
4. Controller and processor obligationsAccountability, privacy by design (Art. 25), processor contracts (Art. 28), records (Art. 30), security (Art. 32), breaches (Arts. 33–34), DPIAs (Art. 35), DPOs (Arts. 37–39)HeavyMedium-high
5. Transfers, supervision and enforcementChapter V transfers, one-stop shop, EDPB, fines (Art. 83), compensation (Art. 82)ModerateHigh for transfers
6. Compliance in specific contextsEmployment, surveillance, direct marketing, cookies and ePrivacy, internet technologies, AI Act interplayModerateMedium

Block 1 — Foundations and institutions

Know the lineage: Article 8 of the European Convention on Human Rights, Articles 7 and 8 of the Charter of Fundamental Rights, Convention 108, the 1995 Data Protection Directive and the GDPR that replaced it in 2018. Know which EU institution does what (the Commission proposes, Parliament and Council legislate, the CJEU interprets). These questions are mostly recall. Don't overspend here — it's the lightest part of the exam.

Block 2 — GDPR core concepts

This is where the exam is won or lost. For each concept, learn the test you'd apply, not just the definition:

  • Personal data and pseudonymisation: pseudonymised data is still personal data; truly anonymous data is not.
  • Territorial scope (Art. 3): establishment in the EU, or offering goods and services to people in the EU, or monitoring their behaviour there. A non-EU company with no EU office can be fully in scope.
  • The seven principles (Art. 5): lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability.
  • Lawful bases (Art. 6): the six bases, when each is available, and when each is not — legitimate interests isn't available to public authorities performing their tasks, and consent is rarely valid in employment.
  • Special categories (Art. 9): need an Article 6 basis and an Article 9(2) condition. Criminal conviction data is Article 10, not Article 9.

Our breakdown of the GDPR concepts that cost candidates the most points has worked scenarios for the hardest of these.

Block 3 — Data subject rights

Learn each right with its trigger, its limits and its deadline. The exam tests the limits more than the rights:

  • Responses are due within one month, extendable by two further months for complex or numerous requests (Art. 12(3)).
  • Erasure (Art. 17) has grounds and exceptions — freedom of expression, legal obligations, public health, archiving and legal claims.
  • Portability (Art. 20) applies only to data the person provided, processed by automated means, on the basis of consent or contract.
  • Article 22 applies only to decisions based solely on automated processing with legal or similarly significant effects.

Block 4 — Controller and processor obligations

Expect questions where you have to decide who is the controller, who is the processor and who is a joint controller — and what each must do. Know the mandatory content of an Article 28 contract, when records of processing are required, the 72-hour breach notification to the authority (Art. 33) versus the "high risk" threshold for notifying individuals (Art. 34), when a DPIA is mandatory, and when a DPO must be appointed.

Block 5 — Transfers, supervision and enforcement

Transfers are consistently one of the hardest areas. Apply the hierarchy: adequacy decision first, then appropriate safeguards (standard contractual clauses, binding corporate rules), and only then the narrow Article 49 derogations. Know what Schrems II changed and why transfer impact assessments followed. For enforcement, know the two fine tiers in Article 83 (up to EUR 10 million or 2% of global turnover, and up to EUR 20 million or 4%) and how the one-stop-shop mechanism assigns a lead supervisory authority.

Block 6 — Compliance in specific contexts

These are applied scenarios: employee monitoring, CCTV, marketing emails, cookie banners. The key is the interplay between the GDPR and the ePrivacy Directive — for cookies, consent under ePrivacy Article 5(3) is required for non-essential cookies regardless of what the GDPR lawful basis would otherwise be. Since 2025 you should also be comfortable with how the EU AI Act and NIS2 sit alongside the GDPR.

Reading the GDPR isn't the same as answering CIPP/E questions.

The CIPP/E Complete Pack has 300 practice questions — 220 of them scenario-based across 18 scenario blocks — plus a cram guide with a five-scenario masterclass, mapped to BoK v1.3.3.

Get the Complete Pack →

The 8-Week CIPP/E Study Plan

Built for 5–8 hours a week. If you have no GDPR background, stretch weeks 2–5 to two weeks each. If you work with the GDPR daily, you can compress to five or six weeks — see how many hours to study for the CIPP/E for estimates by background.

Week 1 — Foundations and the GDPR map

Block 1 in full. Read the GDPR's chapter structure and Articles 1–4 closely. Take a 25-question diagnostic to find your starting point — don't worry about the score.

Week 2 — Scope, principles and lawful bases

Articles 2, 3, 5, 6 and 7. For every lawful basis, write one scenario where it applies and one where it doesn't. Finish with 30 scenario questions on these topics.

Week 3 — Special categories and data subject rights

Articles 9, 10 and 12–22. Build a one-page table of each right: trigger, exceptions, deadline. Practise 30–40 questions.

Week 4 — Controllers, processors and accountability

Articles 24–39. Focus on role classification, Article 28 contracts, breach notification thresholds, DPIAs and DPO rules. Practise 40 questions, including joint controller scenarios.

Week 5 — Transfers and enforcement

Chapter V, Schrems II, SCCs, BCRs and derogations; then supervisory authorities, the EDPB, fines and remedies. Practise 40 questions. Expect this week to feel hardest.

Week 6 — Specific contexts

Employment, surveillance, marketing, cookies, ePrivacy, AI Act and NIS2 interplay. Practise 30 questions, then review every wrong answer from weeks 2–5.

Week 7 — Full timed practice

One full 90-question mock in 2.5 hours under exam conditions. Spend more time reviewing than sitting it: for every miss, write down why the right answer is right and why yours was wrong.

Week 8 — Repair and cram

Target your two weakest blocks. A second full mock mid-week. Last three days: a condensed cram review, not new material — our CIPP/E last-week cram guide lays it out day by day.

Study Resources: What to Use and What to Skip

ResourceCostVerdict
GDPR text and recitals (EUR-Lex)FreeEssential — the exam is built on it
EDPB guidelinesFreeUse selectively: consent, controller/processor, Art. 22, transfers, breach notification
IAPP official textbookPaidGood coverage of the Body of Knowledge; dense
IAPP official practice testPaidUseful calibration, but too short to be your only practice
Scenario question bankPaidThe highest-impact resource for applied questions — see what to look for in a CIPP/E question bank
Flashcards and article-number drillsFree–cheapSkip as a main method — the exam rarely asks for article numbers alone

How to Know You're Ready

Because the exam is scaled, there's no published raw score that guarantees a pass. Use these signals instead:

  • You consistently score 80% or more on fresh scenario questions you haven't seen before.
  • You can explain why each wrong option is wrong, not only why the right one is right.
  • You finish a 90-question timed mock with at least 15 minutes to spare.
  • No single block is below 70% in your practice data.

If you're not there, move your date. Rescheduling is free inside the allowed window; a retake costs USD 375. Our CIPP/E pass rate analysis explains where first attempts usually go wrong.

The one rule that matters

Every hour you spend reading the GDPR should be matched by time applying it to scenarios. Candidates who fail the CIPP/E rarely fail for lack of knowledge — they fail because they recognise the right article and still pick the wrong answer when the facts get specific.

Frequently Asked Questions

How long should I study for the CIPP/E?

Most working professionals need 6–10 weeks at 5–8 hours per week, roughly 40–70 hours in total. People who work with the GDPR daily can often prepare in 5–6 weeks; those new to EU data protection should plan for 10 weeks or more.

What is the hardest part of the CIPP/E?

International transfers, lawful basis selection, controller and processor classification, and automated decision-making under Article 22 are the areas candidates most often get wrong, because they require applying the rules to specific facts rather than recalling them.

Can I pass the CIPP/E with self-study?

Yes. Many candidates pass with the GDPR text, selected EDPB guidelines, a structured plan and a large bank of scenario practice questions. Official IAPP training helps if you need structure, but it isn't required.

Do I need to memorise GDPR article numbers?

It helps to know the key ones, but the exam mostly asks what the GDPR requires in a given scenario. Understanding how each rule applies, and its exceptions, matters far more than memorising numbers.

Is the CIPP/E exam open book?

No. IAPP exams are closed book, taken through Pearson VUE either at a test centre or by online proctoring.

Sources